Hacker News new | ask | show | jobs
by gorlilla 982 days ago
A preview of the first page is absolutely enough to put companies on the wrong side of government and/or industry regulations/compliance.

It may not be as astronomically bad as you immediately imagined, but I don't see how the nuance makes any material difference with the urgency in which this would need to be contained/analyzed/investigated and reported timely where required.

2 comments

> A preview of the first page is absolutely enough to put companies on the wrong side of government and/or industry regulations/compliance.

So that whole, “This page intentionally left blank”, is a security feature?

Could be, except it's unlikely to be put on the first page, so at the very least, this integration is leaking the title, classification and authorship - and through that, existence - of a potentially sensitive document.
Until the preview uses machine learning to skip that and show the first page containing content :)
This is the point of the Slack app though. It does notify you if x recipients can't see a document, but it doesn't attempt to hide it from those who don't already have access.

Companies can turn off the Google Drive app in their Slack workspace and block it in Google Workspace admin (and generally allowlist which apps can request Drive permissions: https://support.google.com/a/answer/7281227?hl=en ).