Be careful what you put in “anyone with the link” Google Docs
Brief
The next time you type something sensitive into a Google Doc—or any other online tool with a sharing feature—be careful about the permissions you grant.
Speaking with The Register , the founder of QR generation service Pageloot said that he learned that the hard way. Siim Kostabi recalled how a contractor working for the company accidentally exposed login details for its staging environment—credentials that were never meant to leave an internal testing setup.
The hapless developer had access to a staging environment (used to test new software code before it goes live). They stored the login details in a Google Doc and then set it to “anyone with the link can view.”
It turns out Google Search can index Google Docs with that setting if the link becomes discoverable on the public web.
All credited sources
Highest-trust first. Dates are the publisher's original publish time.
Be careful what you put in “anyone with the link” Google Docs
The next time you type something sensitive into a Google Doc—or any other online tool with a sharing feature—be careful about the permissions you grant.
Speaking with The Register , the founder of QR generation service Pageloot said that he learned that the hard way. Siim Kostabi recalled how a contractor working for the company accidentally exposed login details for its staging environment—credentials that were never meant to leave an internal testing setup.
The hapless developer had access to a staging environment (used to test new software code before it goes live). They stored the login details in a Google Doc and then set it to “anyone with the link can view.”
It turns out Google Search can index Google Docs with that setting if the link becomes discoverable on the public web. “Anyone with the link” files aren’t automatically indexed, so we don’t know exactly how Google discovered this particular document. What we do know is that it did: The credentials file ended up in Google Search.
A Pageloot developer typed the company’s domain into Google while debugging, and Google’s autocomplete feature surfaced a staging hostname followed by what looked like a credential string. Sure enough, the document was accessible online. Google Search was surfacing information from a document that had been shared too widely.
To its credit, Pageloot moved quickly. It cut the contractor’s access and changed every affected credential. It also banned password storage in Google Docs, Slack, Notion, and any other shared workspace.
The problem is that none of those fixes existed before autocomplete surfaced the password. If nobody had spotted it, the credentials could have remained exposed.
People share private data in online tools all the time
If there was ever an example of why you should use a password manager, this is it. Instead, the contractor typed their login details into a Google Doc, presumably to keep them handy.
Be careful what you put in “anyone with the link” Google Docs
The next time you type something sensitive into a Google Doc—or any other online tool with a sharing feature—be careful about the permissions you grant.
Speaking with The Register , the founder of QR generation service Pageloot said that he learned that the hard way. Siim Kostabi recalled how a contractor working for the company accidentally exposed login details for its staging environment—credentials that were never meant to leave an internal testing setup.
The hapless developer had access to a staging environment (used to test new software code before it goes live). They stored the login details in a Google Doc and then set it to “anyone with the link can view.”
It turns out Google Search can index Google Docs with that setting if the link becomes discoverable on the public web. “Anyone with the link” files aren’t automatically indexed, so we don’t know exactly how Google discovered this particular document. What we do know is that it did: The credentials file ended up in Google Search.
A Pageloot developer typed the company’s domain into Google while debugging, and Google’s autocomplete feature surfaced a staging hostname followed by what looked like a credential string. Sure enough, the document was accessible online. Google Search was surfacing information from a document that had been shared too widely.
To its credit, Pageloot moved quickly. It cut the contractor’s access and changed every affected credential. It also banned password storage in Google Docs, Slack, Notion, and any other shared workspace.
The problem is that none of those fixes existed before autocomplete surfaced the password. If nobody had spotted it, the credentials could have remained exposed.
