> For someone who resisted hard using a professional service to digitize the videos out of privacy concerns, I'm extremely surprised they ended up create world-readable gcs buckets for files!
I was wondering about this for a similar project recently and the best I came up with is that is if someone has a bad browser extension or their system is compromised in general. Couldn't that leak the bucket name to a untrusted 3rd party?
What I am trying to say is your good from random people on the internet, but the minute someone compromises one of the systems that has legitimate access they could extract the info they needed to access anything that user accessed.
To be clear, I think the risk of this is low and still use security through obscurity myself.
I was wondering about this for a similar project recently and the best I came up with is that is if someone has a bad browser extension or their system is compromised in general. Couldn't that leak the bucket name to a untrusted 3rd party?
What I am trying to say is your good from random people on the internet, but the minute someone compromises one of the systems that has legitimate access they could extract the info they needed to access anything that user accessed.
To be clear, I think the risk of this is low and still use security through obscurity myself.