01 The mistakes that actually cost people

close-up of a share-link dialog with password and expiry fields highlighted
Password and expiry fields in a share-link dialog are the two controls that prevent accidental open access

The most common file-sharing error isn't a hack — it's carelessness. You create a share link, paste it into an email, and move on. But that link probably has no password, no expiry date, and "anyone with the link can view" permissions. Forward that email once, post it somewhere public, or just let it sit in someone's sent folder, and the file is effectively public.

Set a password and a link expiry on anything sensitive. Many services — such as Dropbox, OneDrive and Proton Drive, depending on plan — let you do both in the share dialog; most people never touch those settings. An expiry of a few days is plenty for a one-off transfer. If your service doesn't offer expiry dates, that's a reason to reconsider using it for anything private.

The second mistake is trusting "encrypted" at face value. Standard cloud storage encrypts your files in transit (HTTPS/TLS) and at rest (scrambled on the provider's disks) — which protects against a rogue employee or a server breach, but not against the provider itself. Google and Dropbox hold the decryption keys, so they can read your files, respond to legal requests, and scan content for policy enforcement. That's a considered trade-off, not a secret, but it's worth knowing you're making it.

If you need real privacy — medical records, legal documents, commercially sensitive work — use a zero-knowledge service like Proton Drive or Tresorit, where the provider stores only encrypted data it mathematically cannot read. End-to-end encryption means only you and your recipient hold the keys. The service in the middle is blind.

Third: metadata. A photo taken on your phone embeds GPS coordinates, the exact time, your device model, sometimes your name. Share that photo and you've shared all of that too. Strip metadata before sending anything you'd rather keep vague — free tools like ExifTool, or the built-in options in macOS Preview and Windows Photos, handle it in seconds.

Finally, don't share more than you need to. If someone asks for one document, share one document — not a link to your whole project folder. Over-permissioned shares are the file equivalent of handing someone a keyring when they only needed to borrow a car.

None of this is complicated. Passwords, expiry, zero-knowledge when stakes are high, metadata stripped, minimum permissions. That's the whole checklist.

Jargon, decoded — 7 terms
TermWhat it means
encryption in transitscrambles data while it moves over the network (HTTPS/TLS)
encryption at restscrambles data while it sits on the provider's disks
end-to-end encryption (E2E)only sender and recipient can read it; not the provider
zero-knowledgeprovider stores only encrypted data it cannot read or hand over
share linka URL granting file access; safety depends on password and expiry settings
link expirymakes a share link stop working after a set date or number of opens
metadatahidden data inside a file, e.g. a photo's GPS location and timestamp