Security & Privacy + Software & Apps

Google Drive Desktop Client Allows Access to Other Google Services, Creates Security Concern

Posted on October 25th, 2012 by

Security is always a tricky balance between usability and protection. If you err too far on the side of protection, people will find using your product slow and painful and they might not use it. But if you err on the side of being too permissive, you open people’s machines and data to possible malicious behavior.

Google Drive’s desktop client for Windows and OS X has recently been discovered to be erring too far on the side of usability. If a user chooses to visit Google Drive on the web, it automatically logs them into other Google services such as Email and Calendar, rather than just Google Drive. This behavior occurs even if a user is previously logged out or if they have 2-Factor Authentication enabled.

Being able to view your Google Drive on the web, even if you have the desktop client installed, can certainly be a help at times. However, Google Drive should ask their users to authenticate before proceeding if they’re not presently logged in. And it definitely seems like poor form to automatically log them into other Google services as well. Thankfully, this problem is limited to shared machine rather than being open to remote machines. But it’s likely people would not want other folks (even those they share a computer with) to be able to access confidential things such as their email or calendar without explicit permission.

Until this issue is fixed, people will need to be extra vigilant about logging off from all Google services before letting other people use their machine. This is always a good thing to remember to do when you’re using a shared machine, but people may not normally think to do this when they’re using apps or desktop clients rather than going directly to websites.

  • 0579186585

    Isn’t this essentially normal behavior for a Google account? Is it even possible to sign-in to just a single Google service??

  • LysaMyers

    Whether or not it’s normal, it’s not desirable in this case. It’s one thing if you explicitly log in to the website and it allows you to access all your Google resources. But that’s not what’s happening here. You can specifically log out from all your Google resources and then choose to visit the website with the desktop client, and it will automatically log you in to all your Google resources with no request to log in.

  • Disgruntled Drive User

    The issue is someone could click one of your google docs files and have full access to all of your google services (email, calendar, etc..). how is this not an issue for anyone who shares or may ever share their computer with someone is beyond me.

    Google needs to fix this ASAP.

Join Our Awesome Email Newsletter

Enter your email address below to start receiving the best Mac Security Updates.

{"url":"\/marketo\/json\/add-to-newsletter","data":"list_name=Blog Roadblock"}