Skip to content

INC-001A — Revoke anonymous access to the membership-response artifact #180

Description

@daliu

Problem

A metadata-only Google Drive review, performed after a member reported spam soon after providing a phone number, confirmed one membership-response artifact with a permission of type anyone and role reader. Link discovery is disabled, but that does not restrict a person or crawler that obtains the link. Timing does not prove this artifact caused the spam.

No response row, member record, file content, download, or export was opened during the review. The exact file locator, permission identifier, owner, collaborators, and activity evidence are intentionally omitted from this public issue and belong only in the approved private incident record.

Atomic outcome

An authorized Google Drive owner removes the single anonymous reader permission, preserves minimal private before/after metadata and access evidence, and proves by permission-list readback that no anyone or unintended domain permission remains. Then the incident/privacy owner records a scoped follow-up decision without copying member data into GitHub.

Owner-only containment steps

  1. Approve revocation of the identified anonymous reader permission.
  2. Use the owning club Google account to change General access to Restricted or remove that exact permission.
  3. Do not open, download, export, sort, search, or screenshot response rows.
  4. Read back permission metadata only and prove there is no anyone or unintended domain permission.
  5. Privately preserve the check time, target revision/permission metadata, approver, actor, and before/after result.
  6. Privately review Drive activity, sharing history, Form destination, add-ons/scripts, account sessions, and named collaborators using minimum access.
  7. Route scope, notification, retention, and outside-advice decisions through DATA-001B — Inventory personal data and approve a minimization/retention matrix #110 and OPS-SEC-001 — Establish private security/privacy reporting and rehearse incident response #112; do not infer them from spam timing.

Acceptance criteria

  • A named owner explicitly authorizes the provider-side permission change.
  • The anonymous reader permission is removed by an authorized Google Drive owner.
  • A metadata-only readback proves no anyone or unintended domain permission remains.
  • Minimal private before/after evidence and relevant activity/sharing evidence are preserved in the approved incident location.
  • Named collaborator access is reviewed for least privilege without publishing identities.
  • Form destination, add-ons/scripts, and account-session risks receive separate redacted outcomes or tickets.
  • No response row, phone number, email, emergency contact, screenshot, export, private URL, or permission identifier is placed in GitHub, email, or an AI tool.
  • The incident owner records whether further containment or communication is required; this issue makes no legal or breach conclusion.

Stop conditions

Stop and escalate if the actor is not the owner, the target cannot be identified from the private record, the requested change would remove named collaborators or alter/delete responses, metadata readback cannot prove the result, activity review would expose rows, or credentials/recovery codes are requested.

Dependencies and coordination

Officer impact: the authorized Google Drive owner performs one narrowly scoped sharing change; other officers must not inspect or distribute response data.

Officer documentation: None — current incident and emergency procedures remain authoritative; update them only if the verified provider workflow changes.

Deployment evidence: source not affected; website/Firebase not affected; Google Drive configuration and metadata readback must be recorded separately; production-data contents must not be used as proof.

Metadata

Metadata

Assignees

Labels

area:google-sitesGoogle Sites and Google Groups accessarea:privacyPersonal data, consent, minimization, retention, and privacy operationsneeds-external-configRequires provider console or external configurationpriority:P0Launch blocker or urgent security risksize:XSOwner decision or very narrow changestatus:blocked-ownerRequires an owner or external decisiontype:operationsOperational setup or runbooktype:securitySecurity or privacy boundary

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions