ISSUE 11 · 6 MIN READ ·

The share link set to 'anyone with the link'

A folder shared as 'anyone with the link' to unblock a client can stay public and indexable for years. How to audit your Drive, Dropbox and buckets in ten minutes.

A client needed a file in a hurry and the permissions were being awkward, so you did the quick, reasonable thing: right-clicked the folder, set it to “anyone with the link can view”, pasted the link into an email, and got on with your day. It worked. The client got the file, nobody complained, and you never thought about it again.

The link, though, is still live. “Anyone with the link” doesn’t mean “anyone I sent it to” — it means anyone at all who ends up holding that web address, and it stays that way until someone deliberately turns it off. The link travels: it’s forwarded, pasted into a chat, saved in a browser history, sometimes picked up and indexed so it can surface in search results. Months or years later, a folder you opened up for one afternoon is quietly readable by strangers, and the files inside — contracts, a spreadsheet of customers, an old export with more in it than you remember — are sitting in plain view.

That’s the quiet failure: not a break-in, but a door you propped open for a good reason and never went back to close, because nothing about your day ever reminded you it was open.

Why it stays invisible

Nothing in the tool nudges you. A shared link doesn’t expire on its own, doesn’t email you a reminder, and doesn’t appear on any list you’d naturally pass. To you, the folder looks the same as always — you’re signed in, so you see it exactly as you did before you shared it. The exposure is only visible to someone who isn’t you, which is precisely the person you’ll never be.

It’s also easy to underestimate what’s reachable. Share a folder and you often share everything beneath it — sub-folders, and files added later, all inherit the open link without a fresh decision. So the thing you exposed grows over time: the folder that held one PDF in 2024 might hold this year’s payroll summary now, still governed by that same afternoon’s “anyone with the link”.

And the people looking aren’t only the ones you’d imagine. Automated scanners trawl for exposed cloud storage constantly — misconfigured storage remains one of the most common causes of data leaks precisely because it’s so mundane and so rarely revoked. The uncomfortable figure is how long it goes unnoticed: IBM’s 2025 Cost of a Data Breach report puts the average time to identify and contain a breach at 241 days — and a quiet exposure like an open link, which triggers no alarm at all, has even less reason to be noticed.

Find it yourself

You can audit your own sharing in about ten minutes per service. You don’t need any tools beyond the ones you already use.

  1. In Google Drive, list what’s shared. Open Drive on the web, and in the search box type sharedwith:public — this surfaces files shared publicly. On a work (Google Workspace) account, sharedwith:external also lists everything shared outside your organisation. And you can check any folder directly by right-clicking → Share and reading the General access line (“Anyone with the link” vs “Restricted”).

  2. In Dropbox, review shared links. Sign in on the web and open Shared (or your account’s Shared links view). Each entry shows whether it’s open to anyone with the link or limited to specific people. OneDrive and SharePoint have a similar Manage access panel per file, and Microsoft 365 admins can run a sharing report across the tenant.

  3. For cloud buckets, check the “public” flag. If your business uses Amazon S3, Google Cloud Storage or Azure Blob storage, this is where the worst exposures live. In the AWS console, S3 flags buckets as Public right in the bucket list, and “Block Public Access” should be on. The equivalent exists in Google Cloud and Azure. If that sentence didn’t apply to you, skip this step — but if you have developers, ask them to confirm no bucket is public that shouldn’t be.

  4. Search for yourself. As a rough sanity check, try searching the web for your company name alongside terms like site:docs.google.com or your domain — occasionally an indexed shared file turns up. It’s crude, but it’s exactly what an opportunist would try.

The usual surprise is at step 1: not the folder you meant to share, but three others you’d forgotten, still open from projects long finished.

The fix

Closing these is quick, and the point is to make “open to the world” a deliberate, temporary choice rather than a permanent accident.

Revoke what no longer needs to be open. For every shared link you don’t actively need, switch the access back to specific people, or remove the link entirely. In Drive that’s Share → change “Anyone with the link” to “Restricted”; in Dropbox, delete the shared link. The file stays exactly where it is — you’re only changing who can reach it.

Share to people, not to links, by default. When you genuinely need to send someone a file, share it to their email address rather than generating an open link. It’s the difference between a key cut for one person and a key left under the mat for whoever walks past.

Use expiry and view-only where the tool allows it. Business tiers of Google Drive, Dropbox and OneDrive let you set a link to expire on a date and to disable downloading. If you must use an open link to unblock someone, set it to expire in a few days — so the door you prop open closes itself.

Lock the buckets shut. For cloud storage, keep “Block Public Access” (or its equivalent) on at the account level, so a public bucket can’t be created by accident in the first place. This is the single setting that prevents the most damaging version of this failure.

Look again on a schedule. New shares accumulate the same way the old ones did, so a quarterly ten-minute pass through your shared-links list keeps it from drifting back open. Put it next to whatever other quarterly tidy-up you already do.

None of this needs a security review or a consultant. It needs someone to remember that “anyone with the link” is a promise that outlives the afternoon you made it — and to spend ten minutes taking back the links that afternoon is long over.

Check your inbox — confirm and you're in. Latest issue: The Remote Desktop you opened "just for now" is still open.

One real, fixable exposure every week. Free.