Verifying your customer’s identity through a passport or driver license scan can be an effective way to verify the identity of your customer. Due to the sensitive nature of these documents, and their ability to be used for identity theft, we recommend using the require authentication to download feature. While regular attachments are secured using a token, a URL that is considerably complex and random, they could be potentially exposed through a misdirected email. Require authentication to download makes sure your user is signed in when viewing the attachment. You can certainly use Zendesk without requiring authentication to download, but be mindful of what you ask your customers to send you to lower the risk of accidental exposure.
Note that attachments are not indexed by search engines unless the link for the attachment itself has been published in a Help Center article or something similar. This is the case whether require authentication to download is enabled or not.
To enable require authentication to download go to
Admin (
)
>
Settings
>
Tickets
.
Please note, until the require authentication to download is associated with a specific group or agent, uploaded files are visible to any authenticated user. Once an attachment is associated with a ticket or post, visibility is restricted to users with access to the ticket or post that has the authentication to download.
2 Comments
I believe there may be an issue with the security of Zendesk attachments.
I have the 'Include attachments in emails' checkbox selected and the 'Require authentication to download' disabled.
If I navigate to the Help Centre and view an attachment in one of my tickets, I can see the attachment as expected. However, if I copy the attachment link to another person, they can also see the attachment without any need to sign in to the Help Centre, or indeed have a Zendesk account at all.
Is this expected behaviour?
I would've thought this attachment wouldn't be accessible to anyone else?
Thanks,
Stuart
Hi Stuart,
If you're copying the attachment over to another user and you don't have Require authentication to download enabled then this is most likely expected behavior. If you were to enable Require authentication to download enabled then the user you're copying the attachment over to would need to sign into your Help Center to access the attachment.
This is actually why we encourage users to enable this feature as in some cases an attachment may get unintentionally forwarded to a user that should not have access to that information. With the feature disabled they would be able to view the attachment without logging into your Help Center.
Let me know if you have any other questions for me.
Cheers!
Please sign in to leave a comment.