Anyone know why all the attachments on the boards are exposed unsecurely? I can grab URL of an attachment from any of my boards and email it to friends and they can open it!
Not cool. Is this an unknown security breach or a setting in Trello I am overlooking needs to be turned on.
Hi Dylan,
This isn't any unknown security breach, but a part of how Trello's attachments are designed to work.
We talk about this on this page: https://help.trello.com/article/769-adding-attachments-to-cards
Whenever you upload a file, each attachment is assigned a unique link with an unguessable, cryptographically strong random component, and are only accessible using a secure HTTPS connection. This means that anyone with access to the link to the attachment can access the file, but these are not indexed on Google, unless the board itself is public. Sorry for the confusion!
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.