I spoke with a friend of mine at Niantic. They are in communication with the oauth group at Google, and are fixing the issue.
Pokemon Go is a huge security risk
241–250 of 269 posts
Re: Pokemon Go is a huge security risk
#242"We recently discovered that the Pokémon GO account creation process on iOS erroneously requests full access permission for the user’s Google account. However, Pokémon GO only accesses basic Google profile information (specifically, your User ID and email address) and no other Google account information is or has been accessed or collected. Once we became aware of this error, we began working on a client-side fix to request permission for only basic Google profile information, in line with the data that we actually access. Google has verified that no other information has been received or accessed by Pokémon GO or Niantic. Google will soon reduce Pokémon GO’s permission to only the basic profile data that Pokémon GO needs, and users do not need to take any actions themselves."
Re: Pokemon Go is a huge security risk
#243Update from Niantic in this Game Informer article http://www.gameinformer.com/b/news/archive/2016/07/11/pokemo... "We recently discovered that the Pokémon GO account creation process on iOS erroneously requests full access permission for the user’s Google account. However, Pokémon GO only accesses basic Google profile information (specifically, your User ID and email address) and no other Google account information i…
Re: Pokemon Go is a huge security risk
#244Earlier quoted context omitted.
Seriously; I created one just to avoid entering 2fa every time servers go down.
The pokemon trainer site does work, just requires a lot of refreshing...
Anyway, my point stands—Bill started as a coder, good enough to code on the pdp-11(?); Steve never was one.
Re: Pokemon Go is a huge security risk
#245Re: Pokemon Go is a huge security risk
#246Earlier quoted context omitted.
You can make an app that does the same thing right now. What are you talking about? It's developer laziness.
I don't know the android ecosystem well. Can any random app ask for and be granted full access without informing the user of that elevated access request?
The security policies for that sign-in system are not as granular as Android's security policies.
Normally an app would request permissions at run-time or install-time.
Re: Pokemon Go is a huge security risk
#247Earlier quoted context omitted.
You're absolutely right - Niantic's history with Google does not preclude them having crummy security practices that we aren't aware of. However, "Popular thing possibly has crummy security practices (we just don't know)" isn't HN-worthy, it's just FUD. I think both of us would prefer a HN full of well-researched articles over one full of clickbait FUD.
Not FUD to me. I am not going to install Pokemon Go until this is cleared up. I am glad he pointed it out, since I may have clicked through given I would have made quick judgements about them being Google-owned.
Re: Pokemon Go is a huge security risk
#248It's worth noting that Niantic Labs (the folks who licensed Pokemon from Nintendo and made Pokemon Go) are actually owned by Google [0]. This is Google giving itself permission to do Google things. Dollars to doughnuts they tried to use some internal-only API because things kept falling over at pokemon.com. Is this a massive UX failure? Certainly. Is giving Google permission to access Google stuff a "Huge security ri…
Re: Pokemon Go is a huge security risk
#249Update from Niantic in this Game Informer article http://www.gameinformer.com/b/news/archive/2016/07/11/pokemo... "We recently discovered that the Pokémon GO account creation process on iOS erroneously requests full access permission for the user’s Google account. However, Pokémon GO only accesses basic Google profile information (specifically, your User ID and email address) and no other Google account information i…