Live data from Hacker News

Pokemon Go is a huge security risk

adamreeve.tumblr.com

91–100 of 269 posts

Re: Pokemon Go is a huge security risk

#91
post #87

I read people are chasing "pokemon" everywhere. I do not even know what a Pokemon is but I'm pretty sure Descartes would not care. Reading the press, I understand we may expect to see random people looking in their phone on the street chasing virtual pets. And still some people complains about the security risk of sharing his google account. Nobody seems to see the big picture. I guess that is the "Idiocracy" future…

The amount of self-aggrandizing and general contempt for people I see on HN really astounds me sometimes.

Re: Pokemon Go is a huge security risk

#92

"[T]his section of the privacy page on the Google account settings website is only showing up for those that have played on iOS and signed in using the Google button. Android users who used the same login method are not seeing the “Pokemon Go Release” at all on the permissions site (nor do they see Ingress), so we’re not sure yet if those users have trusted Niantic with their entire Google account as well." source: h…

> Android users who used the same login method are not seeing the “Pokemon Go Release” at all on the permissions site (nor do they see Ingress)

This is interesting, I can't test this myself as I have previously played Ingress on both iPhone and Android.

My Android device is mostly for development/testing, so I'm not nearly as regular a user of the platform as I am for iOS.

Could any Android users comment on if this is normal to not see Android apps like Ingress on this authorization list?

Re: Pokemon Go is a huge security risk

#93

And just like that I will never sign in with Google anywhere ever again. I just assumed that an app couldn't grant itself full permissions without notifying me, but now I can see why that might not be the case since they are free to present whatever UI they want in app. In my dream world Google would revoke Niantic's API access forever in order to make an example out of them. Maybe, eventually, if they can prove that…

This issue only affects apps though. When granting OAuth permission via the web, you are actually redirected to google's website, and then afterwards redirected back to the site you were on.

Google recommends using the browser workflow for installed apps too.

https://developers.google.com/identity/protocols/OAuth2Insta...

Which probably isn't very helpful, as lots of users won't notice whether they are using a browser or not.

Does anybody know how Pokemon Go ends up interacting with accounts that have 2 factor authentication turned on? I sure wouldn't type my main password into some app, I'd at least use an app password:

https://support.google.com/accounts/answer/185833?hl=en

Re: Pokemon Go is a huge security risk

#95
post #51

There are enough kids playing this maybe the FTC will get involved. Maybe some sort of basic privacy requirement. How is it possible that signing in didn't inform me what permissions I was granting? I didn't think I was giving anything except my email address.

Kids (under 13 in USA, under 16 in Netherlands) aren't allowed to have gmail accounts AFAIK https://support.google.com/accounts/answer/1350409?hl=en

Yes, so if the age is under 13 the "Google" option to signup is disabled. So you are forced to use the "Pokemon Trainer" account which I know nothing about.

Re: Pokemon Go is a huge security risk

#96
post #90
post #85

I'm running iOS 9.3.2, and signing in to Pokemon Go caused it to have full access to my Google account. Just revoked it and looks like I can still play the game just fine. Perhaps they misconfigured the Google auth sign-in? It's rather worrisome that it's this easy for an application to gain full access to your account, though.

Did you check the permissions again? I did the same, running the same iOS version, and it just restored the same full-access when I opened the app again.

Yep, just checked. It's not here at all. Were you asked to sign in again after you revoked?

Re: Pokemon Go is a huge security risk

#97

Here I thought the article was going to be on how Pokemon Go encourages people to wonder into dangerous or restricted areas while paying attention to their phone. The odds of someone getting attacked in a rough area would seem to go up with such an app given how critical situational awareness is. I don't know enough about how the app works to assess that, though. One app that got me thinking about these things was Go…

Already happened: http://abcnews.go.com/US/armed-robbers-pokemon-app-target-vi...

Re: Pokemon Go is a huge security risk

#98
post #18

Isn't Niantic actually affiliated with (part of?) Google in some way? So it would seem natural, if odd, that it doesn't ask for full permissions for the account is actually already has full permissions to. In the same way google docs doesn't ask, but gets, full permissions to your google account, or google+ doesn't ask, but gets, full permissions to your google account.

Google no longer owns Niantic

Re: Pokemon Go is a huge security risk

#99
A lot of aspects of Pokemon Go are less than polished from an app dev perspective. The way they ask for device permissions doesn't follow best practices at all (no explanation of why they need them). The interface has too much explanatory text in some places (how much useless backstory did I need to click through to start playing?) and not enough in others (it took me forever to figure out what I was supposed to do once I found a pokemon). My sister-in-law was complaining about how all the pokemon graphics are very 2D, when they could easily have sprung for some shading or shadows.

I suspect they built an MVP and launched it and it happened to take off, and we'll see some more polish in the future.

For this particular issue though - I'd bet that Niantic has some sort of data-sharing agreement with Google, anyway, making this point moot. They started as an internal startup at Google, and they make really heavy use of the Maps & Places APIs that would probably cost a fortune if they didn't have some sort of bulk data sharing agreement.

Re: Pokemon Go is a huge security risk

#100
post #54

If google auth as a platform grants full access to your google account without any sort of confirmation, isn't that the security risk? Whether or not it's intentional or malicious on the part of Niantic, that seems like the real problem here.

Yes! I did notice there wasn't a "This app will have access to…" screen when I signed up (I've never seen that before), but that just made me assume they were asking for like the absolute minimal permissions possible or something.

"[random game on a whim] has Full Access to your Google Account" is scary

Post reply on HN