Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Make it Home takes interior design on the road

    2025 Vikings game-by-game predictions: Will J.J. McCarthy prove to be right QB move?

    Phillies place Bryce Harper on injured list with wrist inflammation

    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest VKontakte
    Sg Latest NewsSg Latest News
    • Home
    • Politics
    • Business
    • Technology
    • Entertainment
    • Health
    • Sports
    Sg Latest NewsSg Latest News
    Home»Technology»Apps gives security gaps access to total user files – Research Snipers
    Technology

    Apps gives security gaps access to total user files – Research Snipers

    AdminBy AdminNo Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Millions of users could unconsciously have granted access to their OneDrive files. A security gap in the Onedrive File Picker allows apps such as chatt or slack full reading access to all content. However, Microsoft is not particularly concerned.

    Dangerous access rights for OneDrive uploads

    Microsoft is constantly working on his cloud storage service OneDrive. Finally, users were promised a AI boost and more memory. Password protection for PDFs should also exist soon. Finally, the focus was also on networking with other programs. Files from other cloud services have been imported directly for about a year.

    However, a serious security problem has now come to light when networking with other applications. Because if you upload files from your OneDrive into services such as Slack or Trello, you often give these apps unintentionally access to your entire cloud memory. This is to blame for a problematic implementation discovered by security researchers in Microsoft Onedrive File Picker, which enables foreign services to access all content of cloud storage – not just the files selected for upload.

    Too wide permissions

    The problem lies in too extensive Oauth permissions and misleading approval screens that users do not clearly convey which access rights they actually give. Numerous popular web applications such as chatt, zoom and clickup that have integrated their services in OneDrive are affected.

    Like the security company Oasis Security reports, the OneDrive File Picker calls for reading access to the entire drive – even if only one file is to be uploaded. This results from the lack of fine granular Oauth permissions for OneDrive. The consent dialog that users see in front of a file upload is also very vague from Microsoft and does not sufficiently communicate which access level is actually granted.

    Competition makes it better

    In comparison, other cloud providers offer safe solutions. Google Drive has OAWH permissions that only allow apps access to self-created or explicitly approved files. With its Chooser SDK, Dropbox uses a proprietary end point that even does without a typical Oauth river and thus minimizes the risk. In addition, the authorization tokens created by Microsoft are often saved unsafely, namely in plain text in the browser memory. Refresh tokens can also be issued that grant applications permanent access to user data without the user having to register again.

    Data protection problems

    This could be particularly critical for companies. Employees could unintentionally violate confidentiality guidelines if they share corresponding company data via OneDrive with third-party apps. Experts therefore advise organizations to request the approval of an administrator or to force conditional access guidelines for apps that request more than a reading approval.

    Private users can check their access authorizations by registering with their Microsoft account at OneDrive, selecting the “app access” under “Data Protection” and going through the list of apps with access rights. There, access can also be revoked if necessary.

    Redmond remains calm

    Microsoft has recognized the problem after the opened by Oasis Security, but has not yet provided a solution. In a statement, the company explained: “We appreciate the partnership with Oasis Security in the responsible disclosure of this problem. This technique does not meet our criteria for immediate remedy, since a user of the application has to agree before it is allowed. We will consider improvements in a future version.” So whether you will actually make an adjustment remains completely open.

    Priti RajpootPriti Rajpoot

    Continue Reading

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Admin
    • Website

    Related Posts

    Make it Home takes interior design on the road

    Elon Musk tries to avoid EU wrath by revealing how meaningless X verification is

    Simulations find ghostly whirls of dark matter trailing galaxy arms

    How to fix iOS 18.5 Mail crash

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Microsoft’s Singapore office neither confirms nor denies local layoffs following global job cuts announcement

    Google reveals “material 3 expressive” design – Research Snipers

    Trump’s fast-tracked deal for a copper mine heightens existential fight for Apache

    Top Reviews
    9.1

    Review: Mi 10 Mobile with Qualcomm Snapdragon 870 Mobile Platform

    By Admin
    8.9

    Review: Xiaomi’s New Loudspeakers for Hi-fi and Home Cinema Systems

    By Admin
    8.9

    Comparison of Mobile Phone Providers: 4G Connectivity & Speed

    By Admin
    Sg Latest News
    Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
    • Get In Touch
    © 2025 SglatestNews. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.