I read people are chasing "pokemon" everywhere. I do not even know what a Pokemon is but I'm pretty sure Descartes would not care. Reading the press, I understand we may expect to see random people looking in their phone on the street chasing virtual pets. And still some people complains about the security risk of sharing his google account. Nobody seems to see the big picture. I guess that is the "Idiocracy" future…
Pokemon Go is a huge security risk
91–100 of 269 posts
Re: Pokemon Go is a huge security risk
#92"[T]his section of the privacy page on the Google account settings website is only showing up for those that have played on iOS and signed in using the Google button. Android users who used the same login method are not seeing the “Pokemon Go Release” at all on the permissions site (nor do they see Ingress), so we’re not sure yet if those users have trusted Niantic with their entire Google account as well." source: h…
This is interesting, I can't test this myself as I have previously played Ingress on both iPhone and Android.
My Android device is mostly for development/testing, so I'm not nearly as regular a user of the platform as I am for iOS.
Could any Android users comment on if this is normal to not see Android apps like Ingress on this authorization list?
Re: Pokemon Go is a huge security risk
#93And just like that I will never sign in with Google anywhere ever again. I just assumed that an app couldn't grant itself full permissions without notifying me, but now I can see why that might not be the case since they are free to present whatever UI they want in app. In my dream world Google would revoke Niantic's API access forever in order to make an example out of them. Maybe, eventually, if they can prove that…
This issue only affects apps though. When granting OAuth permission via the web, you are actually redirected to google's website, and then afterwards redirected back to the site you were on.
https://developers.google.com/identity/protocols/OAuth2Insta...
Which probably isn't very helpful, as lots of users won't notice whether they are using a browser or not.
Does anybody know how Pokemon Go ends up interacting with accounts that have 2 factor authentication turned on? I sure wouldn't type my main password into some app, I'd at least use an app password:
Re: Pokemon Go is a huge security risk
#94Re: Pokemon Go is a huge security risk
#95There are enough kids playing this maybe the FTC will get involved. Maybe some sort of basic privacy requirement. How is it possible that signing in didn't inform me what permissions I was granting? I didn't think I was giving anything except my email address.
Kids (under 13 in USA, under 16 in Netherlands) aren't allowed to have gmail accounts AFAIK https://support.google.com/accounts/answer/1350409?hl=en
Re: Pokemon Go is a huge security risk
#96I'm running iOS 9.3.2, and signing in to Pokemon Go caused it to have full access to my Google account. Just revoked it and looks like I can still play the game just fine. Perhaps they misconfigured the Google auth sign-in? It's rather worrisome that it's this easy for an application to gain full access to your account, though.
Did you check the permissions again? I did the same, running the same iOS version, and it just restored the same full-access when I opened the app again.
Re: Pokemon Go is a huge security risk
#97Here I thought the article was going to be on how Pokemon Go encourages people to wonder into dangerous or restricted areas while paying attention to their phone. The odds of someone getting attacked in a rough area would seem to go up with such an app given how critical situational awareness is. I don't know enough about how the app works to assess that, though. One app that got me thinking about these things was Go…
Re: Pokemon Go is a huge security risk
#98Isn't Niantic actually affiliated with (part of?) Google in some way? So it would seem natural, if odd, that it doesn't ask for full permissions for the account is actually already has full permissions to. In the same way google docs doesn't ask, but gets, full permissions to your google account, or google+ doesn't ask, but gets, full permissions to your google account.
Re: Pokemon Go is a huge security risk
#99I suspect they built an MVP and launched it and it happened to take off, and we'll see some more polish in the future.
For this particular issue though - I'd bet that Niantic has some sort of data-sharing agreement with Google, anyway, making this point moot. They started as an internal startup at Google, and they make really heavy use of the Maps & Places APIs that would probably cost a fortune if they didn't have some sort of bulk data sharing agreement.
Re: Pokemon Go is a huge security risk
#100If google auth as a platform grants full access to your google account without any sort of confirmation, isn't that the security risk? Whether or not it's intentional or malicious on the part of Niantic, that seems like the real problem here.
"[random game on a whim] has Full Access to your Google Account" is scary