Security concerns in SkyDrive Hotmail integration
There are some security concerns in sharing documents through SkyDrive instead of sending as email attachments. Read this article to find out more about few points you need to be aware of.
Microsoft introduced the cloud based storage system called SkyDrive several months ago. SkyDrive is a great platform to store, manage and share documents online. Microsoft has done a good job in integrating SkyDrive with Hotmail and various office products.
If you are sending an email with attachments through Hotmail, you have the option to upload the file to SkyDrive and share the link to the email recipient. There are few security issues involved in sharing documents through SkyDrive instead of sending as a plain attachments.
In this article, I want to talk about a specific issue related to security in the Hotmail - SkyDrive integration.
When you send a mail from hotmail and add some attachments, you have the option to share it through SkyDrive. This feature is integrated well with Hotmail and it can be done without much extra efforts. However, you must be aware that all such files shared through SkyDrive integration in Hotmail are shared publicly and those get access to the URL of such files can access the files. This is very similar to the Google Docs feature with the security settings as 'Anyone with URL can access the file'.
When you email a document to someone, do you expect it will be accessible to the others? That is what happens when you use the SkyDrive feature in Hotmail to send documents to email recipients. Well, not exactly.
Anyone with a link to the file can read and download the file. If you are sending a sensitive document to a business user, imagine how much damage it can cause to your business if it reaches your competitor. I don't have to talk much about the issues involved in sharing sensitive documents to the world.Security issues in Hotmail SkyDrive integration
Let us see how this works.
- Person A want to send a sensitive document to Person B.
- Now person A log in to his Hotmail account, types a brief email to person B and adds the file to be sent. The file is automatically added to the SkyDrive and the link is shared through the email to person B.
- Now, person B reads the email in a public computer, access the file from SkyDrive, Signs out from his mail and goes away.
- Now person C comes to the same computer. He simply checks the URLs accessed by the previous user in the browser and finds the links to the file in SkyDrive. He visit the file in SkyDrive, downloads it and sends to some business competitors. - Now person C follows few others links in the SkyDrive site and gets access to thousands of other files in SkyDrive which person A sent through Hotmail to various other people. (I am striking it out because I can no longer see all other attachments after I deleted all old attachments and started testing with new attachments. However, the security flaw still exists - anyone who get the link can see your file. The links can be easily found from the browsing history or other sources.)
This is a security flaw in the SkyDrive - Hotmail integration. Many users who share files through SkyDrive Hotmail integration do not know they are sharing the files publicly, even though it require getting access to the link. May be Microsoft can claim they use the word "share", but no where they make it clear that "it is shared publicly".
In fact, the options page in Hotmail make it highly misleading to the users. See the screenshot below:
Steps to reach the above options page:
- Login to Hotmail
- Click on the "Options" in the top right corner in hotmail inbox view.
- Click on More options
- Click on "Attachments" under "Writing Email"
You will see the below options:
Attachments
Big attachments can clog your friends' inboxes. But when you use SkyDrive, you send links to files instead of the files themselves. This makes it easy to share hundreds of files at a time with the people you choose.
Always send files using SkyDrive
Always send files as attachments
Let Hotmail choose (use SkyDrive for large attachments and Office docs)
Take a close look at this part: share hundreds of files at a time with the people you choose
Where do you have the option to choose the people? No where. The only option you have is to send the email to one or more recipients, but any one who gets the link is free to share the link with anyone else or leave some traces of it unknowingly leading to access to your documents. Or, someone who see your browsing history can access all such files from the senders SkyDrive.
SkyDrive would be a great enhancement to Hotmail, if few changes are made
I recommend Microsoft make the following changes to make SkyDrive a great feature to the Hotmail users:
1. During the attachment step, make it clear to the users that the files can be accessed by anyone who get a link.
2. Allow the recipient to transfer the file from the SkyDrive of sender to the SkyDrive of recipient
3. Show some status in the SkyDrive of the sender that the file is transferred or accessed so that it can be safely removed from the senders SkyDrive.
You can change the setting of the file to be "view only". This isn't something new - know your facts before posting it.
I do it all the time - go into SkyDrive, and set it as "view only".
Granted, there is no password protection or anything, but the third-party won't be able to download the file, only view it.
Microsoft's implementation works, and works well. I don't see major security flaw with this. Microsoft specifies you are sending a link - you can't expect the link to not be distributed in one way or the other.