Security News > 2020 > January > Trello exposed! Search turns up huge trove of private data

Trello exposed! Search turns up huge trove of private data
2020-01-30 17:07

Not only that, search engines such as Google index public Trello boards, making it simple for anyone to uncover the boards' contents using a specialised type of search called a 'dork'.

One of the worst Trello boards I came across, a HR onboarding Trello board, it's been reported and removed now.

An enthusiastic Trello user himself, Craig quickly found a trove of highly sensitive data sprayed out by sizeable numbers of public Trello boards.

For me, any benefit in indexing Trello boards is far outweighed by the risk of making it possible to access inadvertently exposed data.

If you are a Trello user, go and check the status of your boards and set anything with sensitive data in it to "Private".


News URL

https://nakedsecurity.sophos.com/2020/01/30/trello-exposed-search-turns-up-huge-trove-of-private-data/