Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

[Trello] Are all attachments unsecure?

Dylan K
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
August 1, 2019

Anyone know why all the attachments on the boards are exposed unsecurely? I can grab URL of an attachment from any of my boards and email it to friends and they can open it!

 

Not cool. Is this an unknown security breach or a setting in Trello I am overlooking needs to be turned on.

1 answer

0 votes
Mike
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
August 5, 2019

Hi Dylan,

 

This isn't any unknown security breach, but a part of how Trello's attachments are designed to work.

 

We talk about this on this page: https://help.trello.com/article/769-adding-attachments-to-cards

 

Whenever you upload a file, each attachment is assigned a unique link with an unguessable, cryptographically strong random component, and are only accessible using a secure HTTPS connection. This means that anyone with access to the link to the attachment can access the file, but these are not indexed on Google, unless the board itself is public. Sorry for the confusion!

Suggest an answer

Log in or Sign up to answer
TAGS
AUG Leaders

Atlassian Community Events