OK Google: A stranger with stash of pirated films is spamming my Google Team Drive
For the love of cloud, don't click on anything
Google seems powerless to stop its Google Drive file sharing service being exploited by a spammer who has linked other users to their stash of pirated movies, among other dubious files, users have complained.
Team Drives is part of Google’s G Suite offering, aimed at businesses, education and other professional organisations. It allows administrators to create a shared drive, controlling access.
But for weeks, Team Drive users have found themselves joined to a public #huyannet Team Drive. Google was alerted six weeks ago but has been unable to come up with a fix and extract #huyannet and its files from legitimate paying users’ workspaces.
The public #huyannet space contains terabytes of copyright infringing material. New additions caused storms of spam with legitimate users who have unwillingly been joined to the unwanted drives.
Team Drive user Simon Worthington, who alerted us to the failure, told us he was dismayed by Google’s response, and said it lacked the appropriate procedures to remove the offenders.
“Google have no process for a Team Drive recipient accepting access to a share, the recipient can only remove themselves after (which is bad in itself),” he told us. “But to make matters worse in this instance, spammers are able to add those email addresses to a distribution group within the Team Drive, so you can't remove yourself from the share.”
In the official support forum, one #huyannet victim wrote:
“I received a spam email days ago notifying that I was added to this spam drive, but simply deleted the email and didn't think twice about it, until I just noticed it in my drive. “
The person added: “Let's hope Google 1) deals with these obvious movie pirates that are storing terabytes of copyrighted movies and tv shows on their servers, and 2) gives users a method to remove themselves from spammed team drives, and 3) comes up with a method to prevent spammed team drives from automatically showing up in Drive - you should be required to verify that you would like to join. “
“Why is it impossible to Block a Spammer from sharing a doc to my Drive??”
Incredibly, once a third party has been unwillingly joined to #huyannet, they are unable to remove it.
“I suspect the obvious fix for them breaks things elsewhere, which is why they can't deploy it,” Worthington speculated.
We have asked Google for comment and will update this story when it gets back to us.
Google Drive Help Forum "top contributor" David King told users at the weekend: "I've escalated this issue as a priority to the Drive community manager. I understand this will be a confusing and frustrating experience – all I can advise from reading your reports is not to click on or open any files."
Not a great advert for Google – or the cloud. ®
Sponsored: Becoming a Pragmatic Security Leader