I don't see any access granted to Pokemon Go (it's not even listed) in the "Apps Connected to your Account" page: https://security.google.com/settings/security/permissions I am running on a Nexus 6 and signed in with my Google Account when I first launched the app. Try revoking access and see what happens. Worst case, it might ask you to sign in again.
on iPhone 6s, checked and saw it had full access. I revoked access and opened the app up. It was stuck loading so I logged out and back in. Went back to check app permissions on google and it had full access again.
Pokemon Go is a huge security risk
191–200 of 269 posts
Re: Pokemon Go is a huge security risk
#192And just like that I will never sign in with Google anywhere ever again. I just assumed that an app couldn't grant itself full permissions without notifying me, but now I can see why that might not be the case since they are free to present whatever UI they want in app. In my dream world Google would revoke Niantic's API access forever in order to make an example out of them. Maybe, eventually, if they can prove that…
Re: Pokemon Go is a huge security risk
#193Earlier quoted context omitted.
In summary, if you give a nefarious app your password it can do a nefarious thing? I'm curious how exactly this is specific to the UIWebView implementation.
It's because the app has access to and control over the DOM of the UIWebView. Suppose some app called EvilGameFoo is asking you to authenticate with your Google account. They should kick you to a UI controlled by Google, which EvilGameFoo cannot in any way inspect or access, where you enter your credentials. Google then tells EvilGameFoo that they can vouch for you. Instead, UIWebView lets the app asking you to sign…
Outside of the Android model where it does the auth for you upon request and only hands the app a token, I don't really see how you don't open yourself to this attack.
iOS really doesn't provide a way for other vendors in an inner ring of consumer trust and power to deal with this. While I'm not a fan of the decision to give full access to Pokemon Go, I didn't find it surprising that it did so on iOS and I had to make a conscious decision to "trust" Pokemon Go as part of the process.
Re: Pokemon Go is a huge security risk
#194Earlier quoted context omitted.
on iPhone 6s, checked and saw it had full access. I revoked access and opened the app up. It was stuck loading so I logged out and back in. Went back to check app permissions on google and it had full access again.
Wait, you revoked access from within google, and then the pokemon app was able to give itself access again without asking for permission?
Re: Pokemon Go is a huge security risk
#195I don't see any access granted to Pokemon Go (it's not even listed) in the "Apps Connected to your Account" page: https://security.google.com/settings/security/permissions I am running on a Nexus 6 and signed in with my Google Account when I first launched the app. Try revoking access and see what happens. Worst case, it might ask you to sign in again.
Re: Pokemon Go is a huge security risk
#196Earlier quoted context omitted.
It's because the app has access to and control over the DOM of the UIWebView. Suppose some app called EvilGameFoo is asking you to authenticate with your Google account. They should kick you to a UI controlled by Google, which EvilGameFoo cannot in any way inspect or access, where you enter your credentials. Google then tells EvilGameFoo that they can vouch for you. Instead, UIWebView lets the app asking you to sign…
Right, but what if they didn't use the UIWebView tactic and instead used custom chrome to submit the data. Couldn't they just tap it at that level? Outside of the Android model where it does the auth for you upon request and only hands the app a token, I don't really see how you don't open yourself to this attack. iOS really doesn't provide a way for other vendors in an inner ring of consumer trust and power to deal…
If UIWebView didn't allow the app access to the DOM then it wouldn't be possible this way. But,of course, the user has no way to know how the UI is implemented.
Re: Pokemon Go is a huge security risk
#197Re: Pokemon Go is a huge security risk
#198Earlier quoted context omitted.
They were an Alphabet company, but were spun off last year: https://www.theguardian.com/technology/2015/aug/14/niantic-l...
Right, so not only did they spend a significant amount of time steeping in Google itself, the big G then invested a significant amount of cash into the now-spun-out company. I'd say that qualifies as 'owned'.
A third-party company, even with significant investment and history with Alphabet, requesting full access to my Google account despite needing ZERO access (i.e. for what they need, requesting no permissions would suffice) is sketchy and inherently untrustworthy.
Re: Pokemon Go is a huge security risk
#199And just like that I will never sign in with Google anywhere ever again. I just assumed that an app couldn't grant itself full permissions without notifying me, but now I can see why that might not be the case since they are free to present whatever UI they want in app. In my dream world Google would revoke Niantic's API access forever in order to make an example out of them. Maybe, eventually, if they can prove that…
I've yet to see it confirmed, though.
Re: Pokemon Go is a huge security risk
#200I read people are chasing "pokemon" everywhere. I do not even know what a Pokemon is but I'm pretty sure Descartes would not care. Reading the press, I understand we may expect to see random people looking in their phone on the street chasing virtual pets. And still some people complains about the security risk of sharing his google account. Nobody seems to see the big picture. I guess that is the "Idiocracy" future…
I bet you are in your underwear inside your room with several half empty cans of warm beer around your desk.