Live data from Hacker News

Pokemon Go is a huge security risk

adamreeve.tumblr.com

241–250 of 269 posts

Re: Pokemon Go is a huge security risk

#241

I spoke with a friend of mine at Niantic. They are in communication with the oauth group at Google, and are fixing the issue.

Can you also tell them to read a few Reddit threads, or Twitter? There are many, many issues which will limit the lifetime of this game.

Re: Pokemon Go is a huge security risk

#242
Update from Niantic in this Game Informer article http://www.gameinformer.com/b/news/archive/2016/07/11/pokemo...

"We recently discovered that the Pokémon GO account creation process on iOS erroneously requests full access permission for the user’s Google account. However, Pokémon GO only accesses basic Google profile information (specifically, your User ID and email address) and no other Google account information is or has been accessed or collected. Once we became aware of this error, we began working on a client-side fix to request permission for only basic Google profile information, in line with the data that we actually access. Google has verified that no other information has been received or accessed by Pokémon GO or Niantic. Google will soon reduce Pokémon GO’s permission to only the basic profile data that Pokémon GO needs, and users do not need to take any actions themselves."

Re: Pokemon Go is a huge security risk

#243

Update from Niantic in this Game Informer article http://www.gameinformer.com/b/news/archive/2016/07/11/pokemo... "We recently discovered that the Pokémon GO account creation process on iOS erroneously requests full access permission for the user’s Google account. However, Pokémon GO only accesses basic Google profile information (specifically, your User ID and email address) and no other Google account information i…

Impressed by the quick turnaround on this!

Re: Pokemon Go is a huge security risk

#244
post #26

Earlier quoted context omitted.

Seriously; I created one just to avoid entering 2fa every time servers go down.

The pokemon trainer site does work, just requires a lot of refreshing...

Yikes, I had no idea who Monte Davidoff was. I've actually read his floating point routines! This is embarrassing; I wish I could edit my other post still.

Anyway, my point stands—Bill started as a coder, good enough to code on the pdp-11(?); Steve never was one.

Re: Pokemon Go is a huge security risk

#245
post #235
post #21

> I really wish I could play, it looks like great fun, but there’s no way it’s worth the risk. Why not just create a separate google account if one's so eager to play?

Or just sign in with your e-mail address. It's an option provided by the app.

RTFA

Re: Pokemon Go is a huge security risk

#246
post #230
post #132

Earlier quoted context omitted.

You can make an app that does the same thing right now. What are you talking about? It's developer laziness.

I don't know the android ecosystem well. Can any random app ask for and be granted full access without informing the user of that elevated access request?

That is a feature of the Google sign-in system.

The security policies for that sign-in system are not as granular as Android's security policies.

Normally an app would request permissions at run-time or install-time.

Re: Pokemon Go is a huge security risk

#247
post #237

Earlier quoted context omitted.

You're absolutely right - Niantic's history with Google does not preclude them having crummy security practices that we aren't aware of. However, "Popular thing possibly has crummy security practices (we just don't know)" isn't HN-worthy, it's just FUD. I think both of us would prefer a HN full of well-researched articles over one full of clickbait FUD.

Not FUD to me. I am not going to install Pokemon Go until this is cleared up. I am glad he pointed it out, since I may have clicked through given I would have made quick judgements about them being Google-owned.

One thing the article is wrong about is that you can create a new account a pokemon.com (bypassing the google kerfuffle). You just need to keep reloading until it let's you past the "try again in an hour" message.

Re: Pokemon Go is a huge security risk

#248

It's worth noting that Niantic Labs (the folks who licensed Pokemon from Nintendo and made Pokemon Go) are actually owned by Google [0]. This is Google giving itself permission to do Google things. Dollars to doughnuts they tried to use some internal-only API because things kept falling over at pokemon.com. Is this a massive UX failure? Certainly. Is giving Google permission to access Google stuff a "Huge security ri…

Genetic Fallacy

Re: Pokemon Go is a huge security risk

#249

Update from Niantic in this Game Informer article http://www.gameinformer.com/b/news/archive/2016/07/11/pokemo... "We recently discovered that the Pokémon GO account creation process on iOS erroneously requests full access permission for the user’s Google account. However, Pokémon GO only accesses basic Google profile information (specifically, your User ID and email address) and no other Google account information i…

I actually just finished wrangling social log in for a system that is waaaay less popular than Pokemon GO. Rather amusing to see an organization operating at a vastly bigger scale still hitting the same sorts of speed bumps.
Post reply on HN