All files currently have "All Users" permission. This is sometimes unexpected, not really very desirable, and generates reports on HackerOne. Specifically, the expectation is that when you upload a file to an object (like a Conpherence) it should have very narrow default permissions and then an exception punched through them for the object.
This is mostly supported in other applications (especially after T2222) and we should be able to finish implementation now.