Live data from Hacker News

Pokemon Go is a huge security risk

adamreeve.tumblr.com

41–50 of 269 posts

Re: Pokemon Go is a huge security risk

#41
post #24

Earlier quoted context omitted.

They no longer own them. They were spun during the housecleaning before the Alphabet announcement.

Yep, though they also soon after made a further investment in Niantic. It may sound bizarre at first, but there might be good reasons why they did that. For instance, Nintendo might've been less likely to team up with a wholly Google-owned Niantic. (purely speculation on my part) https://nianticlabs.com/blog/niantic-tpc-nintendo/

I strongly suspect a direct Google/Nintendo tie was considered less favorable than some little ex-Google company that still uses Google servers working on a Nintendo game. The announcement timing was pretty close.

Re: Pokemon Go is a huge security risk

#42
post #36

And just like that I will never sign in with Google anywhere ever again. I just assumed that an app couldn't grant itself full permissions without notifying me, but now I can see why that might not be the case since they are free to present whatever UI they want in app. In my dream world Google would revoke Niantic's API access forever in order to make an example out of them. Maybe, eventually, if they can prove that…

> I just assumed that an app couldn't grant itself full permissions without notifying me, but now I can see why that might not be the case since they are free to present whatever UI they want in app. Is that the case? Doesn't this still require going through the standard prompts?

Anecdote: On Android 6.0 the Pokemon Go game requested 4 permissions on first launch. Account, Camera, Storage, and one other I believe. I had to individually approve each one.

Re: Pokemon Go is a huge security risk

#43

Doesn't Google OWN Niantic? So now Google has access to our Google data? Don't see the issue.

> So now Google has access to our Google data? Don't see the issue.

Even if they were still owned by Google, a compromised phone with Pokemon Go has a nice juicy access token with admin rights to your account to siphon off.

Re: Pokemon Go is a huge security risk

#45
"Pokemon Go Release" has "full access" and yet "Ingress" (a game very similar to Pokemon Go from the same company) only has "basic account info". I removed the access and when I started the app, it crashed right away. (I'm on iOS, by the way.) Subsequent launch I'm stuck on the "LOADING..." screen, and then it says "Failed to get player information from the server." I hope the servers are just down and I didn't lock myself out. (Or maybe I should be glad until this fix this breach.) Edit: Deleting the app and reinstalling allowed me to log in again.

It appears to be the iOS version only that's doing this, according to this article:

http://9to5google.com/2016/07/11/psa-pokemon-go-full-access-...

Re: Pokemon Go is a huge security risk

#46
post #6

I don't see any access granted to Pokemon Go (it's not even listed) in the "Apps Connected to your Account" page: https://security.google.com/settings/security/permissions I am running on a Nexus 6 and signed in with my Google Account when I first launched the app. Try revoking access and see what happens. Worst case, it might ask you to sign in again.

I also do not have a Pokemon/Niantic entry in my list there. No idea what happened for OP

Re: Pokemon Go is a huge security risk

#48
post #36

And just like that I will never sign in with Google anywhere ever again. I just assumed that an app couldn't grant itself full permissions without notifying me, but now I can see why that might not be the case since they are free to present whatever UI they want in app. In my dream world Google would revoke Niantic's API access forever in order to make an example out of them. Maybe, eventually, if they can prove that…

> I just assumed that an app couldn't grant itself full permissions without notifying me, but now I can see why that might not be the case since they are free to present whatever UI they want in app. Is that the case? Doesn't this still require going through the standard prompts?

According to the article, it does not.

Re: Pokemon Go is a huge security risk

#49
It's a free game everyone.

When something is free to play, and involves you walking around with geo services and a camera on, you and your data are the product.

This is just massive data collection disguised as a video game.

Re: Pokemon Go is a huge security risk

#50

Caveat: I've seen a number of players state or imply that playing this game has been the first decent exercise they've had in years. Lack of exercise is a far greater threat to your well-being than having your Google account hacked, so if that's what it takes, go ahead and play the game anyway.

> Lack of exercise is a far greater threat to your well-being than having your Google account hacked...

This is by no means universally true. Plenty of people get enough exercise outside of the app, and plenty of people have Google accounts for which compromise could be very significant.

It should at the very least be disclosed in the OAuth flow that I'm giving away admin rights to the app. Facebook's flow won't even let me give away my email address without an explicit decision to do so. The current silent-but-deadly flow is inexcusably risky.

Post reply on HN