Live data from Hacker News

Pokemon Go is a huge security risk

adamreeve.tumblr.com

221–230 of 269 posts

Re: Pokemon Go is a huge security risk

#221
post #219

Earlier quoted context omitted.

That's what my parents said 20 years ago... hasn't died yet

You should try the Go game. It may have some lasting power I haven't seen yet, but its not the normal Pokemon game by any stretch. The core gameplay is actually pretty boring once you've done it for a little while (i.e. once the initial euphoria of catching things wears off).

Oh I have been playing and while it is far inferior to the core Pokemon gameplay, I have met over 30 new people because of this game in less than a week. People who I've never talked to at work, I am now talking to.

I have honestly never used an app that has brought me closer together to the people around me. I don't see this being a fad.

Re: Pokemon Go is a huge security risk

#222

Earlier quoted context omitted.

They were an Alphabet company, but were spun off last year: https://www.theguardian.com/technology/2015/aug/14/niantic-l...

Right, so not only did they spend a significant amount of time steeping in Google itself, the big G then invested a significant amount of cash into the now-spun-out company. I'd say that qualifies as 'owned'.

Well, at least a stockholder. Which is nothing like complete ownership, especially considering Nintendo is the other elephant with equity.

Re: Pokemon Go is a huge security risk

#224
post #169

It's worth noting that Niantic Labs (the folks who licensed Pokemon from Nintendo and made Pokemon Go) are actually owned by Google [0]. This is Google giving itself permission to do Google things. Dollars to doughnuts they tried to use some internal-only API because things kept falling over at pokemon.com. Is this a massive UX failure? Certainly. Is giving Google permission to access Google stuff a "Huge security ri…

Google's own apps often don't request this much permission. Basic security principles.

If you connect Chrome to your account it does get full permissions for some reason. Perhaps Chromebook-related?

Re: Pokemon Go is a huge security risk

#225
post #187
post #121

Earlier quoted context omitted.

Those are just things it has access to on your phone. That's not the permissions you give it on your Google account, which might include sending email as you. Those you can find here https://security.google.com/settings/security/permissions?pl...

I checked that page already. I can only speak for myself but for me it has no listing on the Google Permissions page so it looks like it does permissions correctly to me.

I'm running Android 6.0.1 on a Nexus 6 btw.

Re: Pokemon Go is a huge security risk

#227

And just like that I will never sign in with Google anywhere ever again. I just assumed that an app couldn't grant itself full permissions without notifying me, but now I can see why that might not be the case since they are free to present whatever UI they want in app. In my dream world Google would revoke Niantic's API access forever in order to make an example out of them. Maybe, eventually, if they can prove that…

> In my dream world Google would revoke Niantic's API access forever in order to make an example out of them. Maybe, eventually, if they can prove that they didn't hoover up all the information they had access to they can be unbanned after a year.

I'm really glad you're not making that decision then. Banning some company based on their use of public, legal APIs would be an absolutely toxic decision for Google's platform.

It's Google's fault for allowing this kind of access with no notification (yes, the fault here might lie somewhere in OAuth, but there's plenty that Google could do to make this less serious). Don't blame people for leveraging options at their disposal.

Re: Pokemon Go is a huge security risk

#228
post #26

Earlier quoted context omitted.

Seriously; I created one just to avoid entering 2fa every time servers go down.

The pokemon trainer site does work, just requires a lot of refreshing...

I tend to trust easy to revoke, well tried auth mechanisms over someone's home-grown version—especially judging by e.g. playstation network's terrible history. I simply don't trust Nintendo to not require me to reset my password with a breach, and I'm lazy as hell.

Re: Pokemon Go is a huge security risk

#230
post #132
post #103

Earlier quoted context omitted.

Well then that is a strange security lapse on Google's part. A spin-off company that had internal high-level access privileges, is spun off, and can still retains those high-level access privileges? That seems like a mistake somewhere.

You can make an app that does the same thing right now. What are you talking about? It's developer laziness.

I don't know the android ecosystem well. Can any random app ask for and be granted full access without informing the user of that elevated access request?
Post reply on HN