Urgent.News

What's breaking now, across thousands of outlets.

Tech

Passwords stored in public Google Doc then showed up in search results

Developer spotted hostname and credential string lurking in autocomplete

Passwords stored in public Google Doc then showed up in search results

In the latest installment of PWNED, a weekly column exposing security lapses, Pageloot co-founder Siim Kostabi recounts a story that underscores the grave risks of improper credential management. Kostabi's firm enlisted a contractor for API integrations, who gained access to the staging server's credentials. Seeking an easy way to manage the credentials across multiple devices, the contractor opted to store them in a public Google Doc, setting the document to allow public view.

The folly of this choice was soon exposed when a company employee found the Google Doc in a Google Search, which had indexed the URL containing the credentials. Kostabi's company swiftly revoked the contractor's access and rotated all exposed credentials. From this incident, Kostabi urges companies to exercise strict control over access, ensuring former employees lose access immediately and current contractors are trustworthy.

He emphasizes the importance of proper offboarding, regular access reviews, and not treating shared documents as private vaults. Another incident involved a mid-sized retailer whose QR codes led users to a competitor's site due to a disgruntled ex-employee retaining access. Both scenarios underscore the need for diligent security practices.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Thursday 13 August →