Hallo zusammen,
ich schaffe es erst jetzt, mich zu melden.
Also, ich hatte ein Ticket mit Synology aufgesetzt und erst jetzt geraden denen meine Antwort gepostet (die sagen, sie wissen von nichts):
Thank you for your reply. I will write you in English, although you are probably as myself in Germany, but then you may be able to route this somewhere internationally.
So, this is a huge issue and I suspect it has come to Synology's awareness as I noticed on the eventing of the problem that the "Synology Drive Client" had disappeard from the download page in its Windows version. I also posted the problem here:
https://www.synology-forum.de/threads/datenleck-in-synology-drive-client.115084/#post-945909
To clarify: We have 2 companies (
www.smartinmedia.com and
www.easyradiology.net), which both have 2 independent Synology systems. It happened on both of them.
What happened: appr. 3-4 years ago we configured the system that we have only 1 "Shared folder" (because it is tedious to configure e. g. 10 share folders and connect to them single-handedly with the Synology drive client for each employee) and all employees had "Read access" to the highest level and below that different access rights to the next folder level.
E. g. the Shared folder's name was "Share" and below that we had "Marketing", "Sales", "Product management", "HR", "Legal", etc pp.
Employees had Synology Drive Client (latest version 11112) running on their windows machines.
By now we have almost 30 employees and had set the access rights for them via e. g. groups. This ALWAYS worked correctly.
Then, in order to install the Drive client for a new employee, the software said that we needed to upgrade the server software from Cloud Station Server to Drive Station Server, which I did. If it happened because of that I cannot say, but anyway even on the Synology of the other company (where Synology Drive Station Server was running all the time without the need for upgrade), the problem ocurred.
On June 8th, an employee called me that she had access to all folders, which she never had. We immediately secured all computers of all employees and stopped the Synology service and in appr. 50% of the employees they had unrightfully full access to the folders, the other did not.
When I logged on with their respective account into the browser-UI and opened "File Station", all the rights were set correctly, i. e. the employees could not see what they were not supposed to see, but on Windows in the Synology Drive Client they could.
We now moved all critical folders to separate Shared folders and haven't had a problem since, but I am 100% sure that there is a huge security flaw in your system. Again, it ran perfectly for years and then it ocurred on 2 different systems.
I am happy to make a e. g. Teams / Zoom call with you and guide you through our system and its settings.
This is the "Shared folder":
We had blocked inheritance from that Shared folder for all users:
And in an example folder below, only management group should have had access (not all users):
Best regards