Live data from Hacker News

Pokemon Go is a huge security risk

adamreeve.tumblr.com

261–269 of 269 posts

Re: Pokemon Go is a huge security risk

#261
post #215

Earlier quoted context omitted.

I really disagree with this. Google has extremely strict safeguards in place to prevent eg. employee Joe from accessing ex-girlfriend Mary's Gmail. Very few people would have full access to individuals' Google accounts. This kind of privacy breach would be very damaging to Google. Niantic is a tiny startup with around 50 employees. I would expect most developers within the team would have full access to the productio…

> Google has extremely strict safeguards in place to prevent eg. employee Joe from accessing ex-girlfriend Mary's Gmail I know a bit about google's internal privacy safeguards (including how long they've been in place), and I know a bit (nothing that wasn't in the news) about the NSA's internal privacy safeguards from a certain point in time. Obviously I don't know what it's like at the NSA today, but it's worth laug…

That's because the NSA does a lot more thorough background checks and has a nation-centered mission, while Google hires people relatively unchecked and of all nationalities and all over the world.

Re: Pokemon Go is a huge security risk

#262
post #237

Earlier quoted context omitted.

You're absolutely right - Niantic's history with Google does not preclude them having crummy security practices that we aren't aware of. However, "Popular thing possibly has crummy security practices (we just don't know)" isn't HN-worthy, it's just FUD. I think both of us would prefer a HN full of well-researched articles over one full of clickbait FUD.

Not FUD to me. I am not going to install Pokemon Go until this is cleared up. I am glad he pointed it out, since I may have clicked through given I would have made quick judgements about them being Google-owned.

May or may not be an issue for you - affects iOS only, if I'm reading this correctly.

Re: Pokemon Go is a huge security risk

#263
post #155

Earlier quoted context omitted.

Not true, don't worry :)

This was the case on an android phone using Google login. His nexus 6X was on a beta build so he was unable to install the app. He started playing the game on an older device while he downgraded his 6X. After it was complete, he logged into his 6X using his google credentials and it prompted him to start over.

I've gone between three phones this week for various reasons, and this has not been an issue.

Re: Pokemon Go is a huge security risk

#264

It's worth noting that Niantic Labs (the folks who licensed Pokemon from Nintendo and made Pokemon Go) are actually owned by Google [0]. This is Google giving itself permission to do Google things. Dollars to doughnuts they tried to use some internal-only API because things kept falling over at pokemon.com. Is this a massive UX failure? Certainly. Is giving Google permission to access Google stuff a "Huge security ri…

Most tech people realized 20 years ago email is a terrible place for confidential information unless you have OPSEC and use PGP. If you trust your plain text email traveling around the world and stored in Google's cloud it seems stupid to worry about someone accessing it.

Also Gmail allows you to create more than one account. Instead of all this alarmism in media just tell people they should create a separate account in Gmail just for games instead of using the one you are worried about some big billion dollar company accessing it (which they already do).

Re: Pokemon Go is a huge security risk

#265
post #261

Earlier quoted context omitted.

> Google has extremely strict safeguards in place to prevent eg. employee Joe from accessing ex-girlfriend Mary's Gmail I know a bit about google's internal privacy safeguards (including how long they've been in place), and I know a bit (nothing that wasn't in the news) about the NSA's internal privacy safeguards from a certain point in time. Obviously I don't know what it's like at the NSA today, but it's worth laug…

That's because the NSA does a lot more thorough background checks and has a nation-centered mission, while Google hires people relatively unchecked and of all nationalities and all over the world.

And in terms of abuse (i.e. LOVEINT), which strategy do you think has proven to be more sound? Hiring only good people, as verified by a thorough background check? Or hiring probably good people, and then using robust checks and balances anyway?

Re: Pokemon Go is a huge security risk

#267

Here's a weird question. https://www.facebook.com/NationalMallNPS/photos/a.3795806520... Pokemon Go is designed to not only augment places where people already are but also to direct them to other places. My friend just ran down the Ninatic/Google connection. Can the app be used to direct people away from polling places and/or to congest areas around polling places? To wit, would anyone be interested in tracking (I c…

screw pooling places, what about locations of businesses (restaurants etc) that spend serious $$ for Google advertising?

I mean... that'd be an issue. I don't think it'd be as big an issue as widespread electoral fraud or electioneering. But it'd probably be an issue...

Re: Pokemon Go is a huge security risk

#268

Here's a weird question. https://www.facebook.com/NationalMallNPS/photos/a.3795806520... Pokemon Go is designed to not only augment places where people already are but also to direct them to other places. My friend just ran down the Ninatic/Google connection. Can the app be used to direct people away from polling places and/or to congest areas around polling places? To wit, would anyone be interested in tracking (I c…

Also... the Clinton campaign just announced it would be having an event at a 'Pokestop,' and Clinton referenced the game. http://thehill.com/blogs/ballot-box/presidential-races/28779...
Post reply on HN