Live data from Hacker News

Pokemon Go is a huge security risk

adamreeve.tumblr.com

191–200 of 269 posts

Re: Pokemon Go is a huge security risk

#191
post #6

I don't see any access granted to Pokemon Go (it's not even listed) in the "Apps Connected to your Account" page: https://security.google.com/settings/security/permissions I am running on a Nexus 6 and signed in with my Google Account when I first launched the app. Try revoking access and see what happens. Worst case, it might ask you to sign in again.

on iPhone 6s, checked and saw it had full access. I revoked access and opened the app up. It was stuck loading so I logged out and back in. Went back to check app permissions on google and it had full access again.

Wait, you revoked access from within google, and then the pokemon app was able to give itself access again without asking for permission?

Re: Pokemon Go is a huge security risk

#192

And just like that I will never sign in with Google anywhere ever again. I just assumed that an app couldn't grant itself full permissions without notifying me, but now I can see why that might not be the case since they are free to present whatever UI they want in app. In my dream world Google would revoke Niantic's API access forever in order to make an example out of them. Maybe, eventually, if they can prove that…

or just use a burner email for stuff you don't trust

Re: Pokemon Go is a huge security risk

#193

Earlier quoted context omitted.

In summary, if you give a nefarious app your password it can do a nefarious thing? I'm curious how exactly this is specific to the UIWebView implementation.

It's because the app has access to and control over the DOM of the UIWebView. Suppose some app called EvilGameFoo is asking you to authenticate with your Google account. They should kick you to a UI controlled by Google, which EvilGameFoo cannot in any way inspect or access, where you enter your credentials. Google then tells EvilGameFoo that they can vouch for you. Instead, UIWebView lets the app asking you to sign…

Right, but what if they didn't use the UIWebView tactic and instead used custom chrome to submit the data. Couldn't they just tap it at that level?

Outside of the Android model where it does the auth for you upon request and only hands the app a token, I don't really see how you don't open yourself to this attack.

iOS really doesn't provide a way for other vendors in an inner ring of consumer trust and power to deal with this. While I'm not a fan of the decision to give full access to Pokemon Go, I didn't find it surprising that it did so on iOS and I had to make a conscious decision to "trust" Pokemon Go as part of the process.

Re: Pokemon Go is a huge security risk

#194

Earlier quoted context omitted.

on iPhone 6s, checked and saw it had full access. I revoked access and opened the app up. It was stuck loading so I logged out and back in. Went back to check app permissions on google and it had full access again.

Wait, you revoked access from within google, and then the pokemon app was able to give itself access again without asking for permission?

if true, something is seriously messed up

Re: Pokemon Go is a huge security risk

#195
post #6

I don't see any access granted to Pokemon Go (it's not even listed) in the "Apps Connected to your Account" page: https://security.google.com/settings/security/permissions I am running on a Nexus 6 and signed in with my Google Account when I first launched the app. Try revoking access and see what happens. Worst case, it might ask you to sign in again.

Same here. I recall a "give pokemon go access to your google contacts" dialog (or similar), which I denied.

Re: Pokemon Go is a huge security risk

#196

Earlier quoted context omitted.

It's because the app has access to and control over the DOM of the UIWebView. Suppose some app called EvilGameFoo is asking you to authenticate with your Google account. They should kick you to a UI controlled by Google, which EvilGameFoo cannot in any way inspect or access, where you enter your credentials. Google then tells EvilGameFoo that they can vouch for you. Instead, UIWebView lets the app asking you to sign…

Right, but what if they didn't use the UIWebView tactic and instead used custom chrome to submit the data. Couldn't they just tap it at that level? Outside of the Android model where it does the auth for you upon request and only hands the app a token, I don't really see how you don't open yourself to this attack. iOS really doesn't provide a way for other vendors in an inner ring of consumer trust and power to deal…

Oh yeah, for sure, there are plenty of other ways a nefarious app could scrape a user's credentials during OAuth on iOS.

If UIWebView didn't allow the app access to the DOM then it wouldn't be possible this way. But,of course, the user has no way to know how the UI is implemented.

Re: Pokemon Go is a huge security risk

#198

Earlier quoted context omitted.

They were an Alphabet company, but were spun off last year: https://www.theguardian.com/technology/2015/aug/14/niantic-l...

Right, so not only did they spend a significant amount of time steeping in Google itself, the big G then invested a significant amount of cash into the now-spun-out company. I'd say that qualifies as 'owned'.

Even if Google Inbox were asking for full permissions I'd be extremely sketched out about that, but it wouldn't happen because Google developers are, by and large, on top of things.

A third-party company, even with significant investment and history with Alphabet, requesting full access to my Google account despite needing ZERO access (i.e. for what they need, requesting no permissions would suffice) is sketchy and inherently untrustworthy.

Re: Pokemon Go is a huge security risk

#199

And just like that I will never sign in with Google anywhere ever again. I just assumed that an app couldn't grant itself full permissions without notifying me, but now I can see why that might not be the case since they are free to present whatever UI they want in app. In my dream world Google would revoke Niantic's API access forever in order to make an example out of them. Maybe, eventually, if they can prove that…

Elsewhere in the thread it is alleged that this is a bug (or misbehaviour) with Google's iOS authentication library. It's possible that Niantic is not requesting any permissions and the library defaults that to 'full access' and not 'no access'.

I've yet to see it confirmed, though.

Re: Pokemon Go is a huge security risk

#200
post #87

I read people are chasing "pokemon" everywhere. I do not even know what a Pokemon is but I'm pretty sure Descartes would not care. Reading the press, I understand we may expect to see random people looking in their phone on the street chasing virtual pets. And still some people complains about the security risk of sharing his google account. Nobody seems to see the big picture. I guess that is the "Idiocracy" future…

I bet you are in your underwear inside your room with several half empty cans of warm beer around your desk.

Please don't feed trolls, and certainly not with personal attacks.
Post reply on HN