The Power BI Lock
This is a creative idea and could be a fun way to "lock down" a report with public data. While it might stop the majority of people from accessing the publish to web content, readers should be aware that it's not truly secure. The access key appears in a few places behind the scenes if you know where to look (and not simply because it's in the visual textbox). Only use Publish to Web with PUBLIC data.
- PowerAnalytics8 years ago
Advocate II
Hi deldersveld!
Indeed, I had already tested with some of my security colleagues, and the Key appears in the HMTL properties if it is selected.
In this POC example you actually know the key and hence when selected you can identify the property that contains it, but otherwise, I have tested it and it will not show up because it depends on the underlying context of a measure.
Not knowing the key you can test all the keys via brute force and it will show a different property once the correct combination is selected. But is it manageable to brute force attack if I setup 3 slicers with 1 million combinations of 3 slicers each?
What I am curious to know is if the Power BI server allow such brute force attacks or are they cut out after a few attempts?