Ah, this is a helpful insight. I didn't realise that this is how the integration works. It seems that, at most, Google could force Slack to update their integration's behaviour (and take down the integration till that happens). But as you mentioned, they can't really fix it themselves.
I probably wouldn't have posted this if I had received this explanation from Google. :)
This was their response:
"Hi! We've decided that the issue you reported is not severe enough for us to track it as a security bug: when someone with access to a doc sends a link over slack, they express their intent to share this document, hence the preview shared independently from the sharing setup on the doc does not represent a significant risk."
Wow, 3 separate mentions on HN is pretty high (and those were the ones you were able to find). This must have been reported dozens of times to Google.
That said, if (a) this is only occurring with the 2 conditions you mentioned and (b) if Google Drive integrations are only allowed with vetted partners, then I suppose this is less exploitable. Someone would have to intentionally put the link into a 3rd party application that had some people who shouldn't have access.
Though it still be a problem I think, privacy is important even internally. Sometimes access needs to be revoked, or people are unaware of all the people who have access to a channel etc.
A very interesting concept, will definitely need to read more on this!
But what about the kind of research that talks about the dangers of living in cities... like "living in a polluted city is like smoking X cigarettes a day"?