Feeds

Google Docs suffers serious security lapse

Cloudbusting bug shares documents

Internet Security Threat Report 2014

Google confessed to a serious bug in its Docs sharing system over the weekend, but downplayed the security cockup by claiming only a tiny number of users had been affected.

The internet search kingpin said that less than 0.05 per cent of Google Docs accounts were hit by a privacy breach after documents were shared “inadvertently” with other users.

Mountain View said in a blog post, penned by Docs product manager Jennifer Mazzon, that the security lapse was “limited to people with whom the document owner, or a collaborator with sharing rights, had previously shared a document.”

She claimed that very “few users” would have been affected by the bug “because it only could have occurred for a very small percentage of documents, and for those documents only when a specific sequence of user actions took place.”

Google said the error was limited to its Docs system within Google Apps and did not affect its spreadsheet system, though some presentations were also hit by the error.

The company fixed the bug by using what it described as an “automated process to remove collaborators and viewers from the documents” that had been exposed to the security glitch.

In other words it stripped all sharing privileges from the documents affected by the bug and then informed affected users that they would have to manually re-share their documents.

“We're sorry for the trouble this has caused. We understand our users' concerns (in fact, we were affected by this bug ourselves) and we're treating this very seriously,” said Mazzon.

Google has recently been attempting to woo businesses away from desktop-based Office suites in favour of adopting the company's cloud-based Apps system.

In January Google confirmed it had inked deals with IT resellers to sell its online applications to biz customers. From the end of this month authorised resellers will be able to flog, customise and support premium versions of Google Apps.

However, this latest bug could lead some businesses to conclude that pushing their personal information up into the clouds simply poses too big a security risk. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Netscape Navigator - the browser that started it all - turns 20
It was 20 years ago today, Marc Andreeesen taught the band to play
Sway: Microsoft's new Office app doesn't have an Undo function
Content aggregation, meet the workplace ... oh
Do Moan! MONSTER 6-day EMAIL OUTAGE hits Domain Monster
Customers freaked out by frightful service
Sign off my IT project or I’ll PHONE your MUM
Honestly, it’s a piece of piss
Return of the Jedi – Apache reclaims web server crown
.london, .hamburg and .公司 - that's .com in Chinese - storm the web server charts
NetWare sales revive in China thanks to that man Snowden
If it ain't Microsoft, it's in fashion behind the Great Firewall
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.