Passwords stored in public Google Doc then showed up in search results
Developer spotted hostname and credential string lurking in autocomplete
In the latest installment of PWNED, a weekly column exposing security lapses, Pageloot co-founder Siim Kostabi recounts a story that underscores the grave risks of improper credential management. Kostabi's firm enlisted a contractor for API integrations, who gained access to the staging server's credentials. Seeking an easy way to manage the credentials across multiple devices, the contractor opted to store them in a public Google Doc, setting the document to allow public view.
The folly of this choice was soon exposed when a company employee found the Google Doc in a Google Search, which had indexed the URL containing the credentials. Kostabi's company swiftly revoked the contractor's access and rotated all exposed credentials. From this incident, Kostabi urges companies to exercise strict control over access, ensuring former employees lose access immediately and current contractors are trustworthy.
He emphasizes the importance of proper offboarding, regular access reviews, and not treating shared documents as private vaults. Another incident involved a mid-sized retailer whose QR codes led users to a competitor's site due to a disgruntled ex-employee retaining access. Both scenarios underscore the need for diligent security practices.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- You may now qualify for Google’s new Search profile, here’s how to check androidauthority.com
- Passwords stored in public Google Doc then showed up in search results theregister.com