Slashdot Mirror


Microsoft Yanks Docs.com Search After Complaints of Exposed Sensitive Files (zdnet.com)

Microsoft has quietly removed a feature on its document sharing site Docs.com that allowed anyone to search through millions of files for sensitive and personal information. From a report on ZDNet: Users had complained over the weekend on Twitter that anyone could use the site's search box to trawl through publicly-accessible documents and files stored on the site, which were clearly meant to remain private. Among the files reviewed by ZDNet, and seen by others who tweeted about them, included password lists, job acceptance letters, investment portfolios, divorce settlement agreements, and credit card statements -- some of which contained Social Security and driving license numbers, dates of birth, phone numbers, and email and postal addresses. The company removed the site's search feature late on Saturday, but others observed that the files were still cached in Google's search results, as well as Microsoft's own search engine, Bing.

8 of 55 comments (clear)

  1. Information wants to be free by ColdWetDog · · Score: 5, Insightful

    Well, your information, not ours.

    FTFA (and a major WTF)

    All of the documents would have been uploaded by their owners, but they may not have realized that each document could be made public, which is Docs.com's default uploading setting, compared to files created or edited with Word and Excel Online, which are private until set otherwise.

    --
    Faster! Faster! Faster would be better!
    1. Re:Information wants to be free by MightyYar · · Score: 4, Interesting

      Maybe, but the site does declare "Showcase and discover Microsoft Word, Excel, PowerPoint, OneNote, Sway, Minecraft world and PDF documents for free" in like 40-point font at the top of the home page. Why are people using this if they don't want to "showcase"?

      --
      W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.
  2. Isn't the cloud great? by danomac · · Score: 4, Insightful

    I don't know why people use the cloud to store sensitive documents. It just doesn't seem like a smart thing to do.

    1. Re:Isn't the cloud great? by MightyYar · · Score: 4, Insightful

      Because sometimes it's just sort of "fuck it". You can stress over every move you make online, or you can take reasonable precautions and risk recovering from something like identity theft later on. One of those reasonable precautions should probably be using something reputable and purpose-built like Dropbox or Drive rather than something that proclaims on the front page "Showcase and discover Microsoft Word, Excel, PowerPoint, OneNote, Sway, Minecraft world and PDF documents for free". Don't use a showcase site for your private files...

      Along the lines of "fuck it", I regularly put my tax documents in Dropbox during tax season. It's reasonably safe, I think, compared to putting them in my pocket in an easily-lost USB stick or on a frequently-stolen laptop. It's not like the physical world is completely safe, either, and Dropbox and Google are going to be better at IT than I am.

      --
      W..w..W - Willy Waterloo washes Warren Wiggins who is washing Waldo Woo.
  3. The homepage of Docs.com states by fattmatt · · Score: 4, Funny

    The homepage of Docs.com states ...
    -Tap below to upload your documents.
    -Later, you can choose who may view your documents.

    How much later is anyone's guess.

  4. Re:"as well as Microsoft's own search engine, Bing by Opportunist · · Score: 4, Funny

    Q: What is Bing?
    A: The sound a MS service makes when it crashes.

    Any Windows user knows it.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  5. Privacy in the "Cloud"? What's that? by Frosty+Piss · · Score: 4, Informative

    Never heard of Docs.com, but come on, uploading documents to Microsoft (or worse, Google)? You know some algorithm is looking at them even if some random human cant access them.

    --
    If you want news from today, you have to come back tomorrow.
  6. Microsoft restores feature. by goombah99 · · Score: 5, Informative

    this is tacked onto the bottom of the linked article:
    Update on March 27: the search feature has been added back, and is still exposing personal information. Microsoft hasn't explained why it reintroduced the feature again.

    --
    Some drink at the fountain of knowledge. Others just gargle.