Live data from Hacker News

More Than 1M Google Accounts Breached by Gooligan

blog.checkpoint.com

11–20 of 183 posts

Re: More Than 1M Google Accounts Breached by Gooligan

#11

Malware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. You can see if your account has been affected here: https://gooligan.checkpoint.com/

>Malware on your Android device picked up from third party app stores

well ok then.

Re: More Than 1M Google Accounts Breached by Gooligan

#14
post #8
post #6

Does anyone else use a special account for their Android phone that they don't use for anything else?

I don't use a Google account on my android phone. Cyanogenmod sans google anything.

So I guess you don't have access to Google Play?

How do you get apps?

Re: More Than 1M Google Accounts Breached by Gooligan

#15

Malware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. You can see if your account has been affected here: https://gooligan.checkpoint.com/

>Malware on your Android device picked up from third party app stores

They say that, but then Google's G+ post[1] says "These apps are most often downloaded outside of Google Play"

You could read "most often" as "some of these were downloaded from Google Play".

Either way, they are exploiting known vulnerabilities. The big issue to me is that phone manufacturers / carriers, by choice, stop patching phones whenever they please.

[1]https://plus.google.com/+AdrianLudwig/posts/GXzJ8vaAFsi

Re: More Than 1M Google Accounts Breached by Gooligan

#17
post #12

So wait this is phishing, not actually hacking into Google to breach accounts if I understood it correctly? In that case, I suppose the title might be technically correct (those accounts are indeed breached), but it makes it sound like Google is to blame.

Not really phishing, just malware hosted on different app stores. And the Google post[1] seems to indicate perhaps some of them were on the official Play store. I read "These apps are most often downloaded outside of Google Play" as "maybe some were downloaded from Google Play".

[1]https://plus.google.com/+AdrianLudwig/posts/GXzJ8vaAFsi

Re: More Than 1M Google Accounts Breached by Gooligan

#18
post #8
post #6

Does anyone else use a special account for their Android phone that they don't use for anything else?

I don't use a Google account on my android phone. Cyanogenmod sans google anything.

No gmail, gmaps, gphotos ? do you have replacements ?

pse: thanks all AP a lot for suggestions :)

Re: More Than 1M Google Accounts Breached by Gooligan

#19
post #16
post #6

Does anyone else use a special account for their Android phone that they don't use for anything else?

Yes. It never occurred to me to connect my portable devices to any accounts that mattered. Who does that?

People who don't think with a security-first mindset or who prefer to gain the benefits of cloud-integration with their devices.

Re: More Than 1M Google Accounts Breached by Gooligan

#20
post #16
post #6

Does anyone else use a special account for their Android phone that they don't use for anything else?

Yes. It never occurred to me to connect my portable devices to any accounts that mattered. Who does that?

It never occured to me that anything sent or received from a gmail account was private.
Post reply on HN