Jump to content


Disable file links in email transcript


3 replies to this topic

#1 XN-Matt

    Advanced Member

  • Members
  • PipPipPip
  • 35 posts

Posted 01 September 2018 - 12:15 AM

The new screenshot feature is good but noticed that it sends a link in the chat to the visitor.

This has no protection it appears and could be a security risk.

Please can you enable a feature where we can disable file upload links to not be sent in clear email transcripts?

Thanks!

#2 Patrick Keil

    Administrator

  • Administrators
  • 3635 posts
  • LocationSingen, Germany

Posted 03 September 2018 - 01:40 PM

Hi,

Thanks for bringing this to our attention.

What kind of risk do you see?

Visitors can download his own files and screenshots now but can't access other files and can't execute code.

We don't want to add more configuration unless they are essential.

Cheers.

#3 XN-Matt

    Advanced Member

  • Members
  • PipPipPip
  • 35 posts

Posted 05 September 2018 - 01:26 PM

What about on a shared computer where that file contains sensitive information?

We cannot assume the person chatting is then the person that could have access to that email or link. This itself would be considered a flaw because it is essentially "open" for anyone to view on that device.

Given some data should only be kept in the chat box/window and not shown elsewhere, the link should be optional to include in the transcript.

#4 Patrick Keil

    Administrator

  • Administrators
  • 3635 posts
  • LocationSingen, Germany

Posted 06 September 2018 - 07:47 AM

Hi Matt,

Thanks for your thoughts.

I have added this to our list.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users