Earlier quoted context omitted.
I don't use a Google account on my android phone. Cyanogenmod sans google anything.
So I guess you don't have access to Google Play? How do you get apps?
More Than 1M Google Accounts Breached by Gooligan
21–30 of 183 posts
Re: More Than 1M Google Accounts Breached by Gooligan
#22Does anyone else use a special account for their Android phone that they don't use for anything else?
I don't use a Google account on my android phone. Cyanogenmod sans google anything.
Re: More Than 1M Google Accounts Breached by Gooligan
#23Earlier quoted context omitted.
I don't use a Google account on my android phone. Cyanogenmod sans google anything.
So I guess you don't have access to Google Play? How do you get apps?
Re: More Than 1M Google Accounts Breached by Gooligan
#24What's the right fix here? Should auth tokens be ip-address-tied? How much will that break? Or would that not even fix it?
Re: More Than 1M Google Accounts Breached by Gooligan
#25Earlier quoted context omitted.
I don't use a Google account on my android phone. Cyanogenmod sans google anything.
So I guess you don't have access to Google Play? How do you get apps?
Re: More Than 1M Google Accounts Breached by Gooligan
#26Earlier quoted context omitted.
I don't use a Google account on my android phone. Cyanogenmod sans google anything.
So I guess you don't have access to Google Play? How do you get apps?
Re: More Than 1M Google Accounts Breached by Gooligan
#27Does anyone else use a special account for their Android phone that they don't use for anything else?
Re: More Than 1M Google Accounts Breached by Gooligan
#28Also, they don't reveal which "third party app stores" served infected apps, but they do provide a list of infected apps, and searching for these yields some real shady download sites: http://imgur.com/a/0luW3
Re: More Than 1M Google Accounts Breached by Gooligan
#29Malware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones. You can see if your account has been affected here: https://gooligan.checkpoint.com/
- The title is technically accurate, which is the best kind of accurate for clickbait. This is not a novel vulnerability representative of an application security flaw within Google - the malware campaign specifically targets older devices using previously known vulnerabilities.[1] There is no new exploit research here.
- There's a logo and cute name for something which is, again, not a novel vulnerability.[2]
- Scaremongering tactics are used throughout to hype up the finding.[3][4] Deliberately ominous language like "...for now" is perhaps tolerable when it's coming from a media outlet, but it's certainly unacceptable from a firm conducting original security research.
All things told, this is closer to "threat intelligence" than real security research. A much better source for this news is the blog post by Google's Director of Android Security, Adrian Ludwig (first footnote, linked elsewhere in this thread as well). In particular, notice the succinctness and the serious, yet detached professionalism associated with the post.
In any case, there are legitimate arguments to be made in favor of extending software or device support lifetimes for vulnerability patches, but the onus is on device manufacturers to coordinate this. In the meantime, it would be great if fewer firms practiced this sort of manic self-promotion, but unfortunately there's little incentive not to.
-------
1. https://plus.google.com/+AdrianLudwig/posts/GXzJ8vaAFsi
2. http://blog.checkpoint.com/wp-content/uploads/2016/11/goo_bl...
3. http://blog.checkpoint.com/wp-content/uploads/2016/11/info_4...
4. http://blog.checkpoint.com/wp-content/uploads/2016/11/info_2...
Re: More Than 1M Google Accounts Breached by Gooligan
#30Does anyone else use a special account for their Android phone that they don't use for anything else?
Yes. It never occurred to me to connect my portable devices to any accounts that mattered. Who does that?