Live data from Hacker News

More Than 1M Google Accounts Breached by Gooligan

blog.checkpoint.com

111–120 of 183 posts

Re: More Than 1M Google Accounts Breached by Gooligan

#112
post #95

Checking your email address in such sites looks like a great way to collect email addresses

Fine print: "Check Point will not collect, store, or use your email address for any other purpose."

It is just a text. How do you know ?

Re: More Than 1M Google Accounts Breached by Gooligan

#113
post #95

Checking your email address in such sites looks like a great way to collect email addresses

Hey Eren, It's not like that email addresses are that hard to find when they are listed on websites publically... ereny*gdir*n[@AT]gm*il

Indeed. Literally all you are providing to the site is an email address. I could check my coworkers' email addresses. They have a list, I'm checking to see if something is on the list.

Any site that requires you to provide an email address and password (or any other "verifiable info") to check is probably a scam.

Re: More Than 1M Google Accounts Breached by Gooligan

#114
post #84
post #29

Earlier quoted context omitted.

Thanks for making this comment. This post is a wonderful example of the rampant marketing that has given the security industry a bad name. - The title is technically accurate, which is the best kind of accurate for clickbait. This is not a novel vulnerability representative of an application security flaw within Google - the malware campaign specifically targets older devices using previously known vulnerabilities.[1…

That's not to say Google has no responsibility in this. Google's OS has a terrible security-update policy. Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. Now, there are valid technical reasons that Google can't be as good as Microsoft at pushing out updates to every device running their OS, but still, it's hard to say t…

> Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices.

This seems like the kind of problem the free market could solve. Just get one phone vendor to guarantee secruity updates for a few years and then some customers will start buying those phones. After a while other vendors will start promising it or losing sales.

Re: More Than 1M Google Accounts Breached by Gooligan

#115
post #95

Checking your email address in such sites looks like a great way to collect email addresses

Hey Eren, It's not like that email addresses are that hard to find when they are listed on websites publically... ereny*gdir*n[@AT]gm*il

It requires manual interaction and obviously not scalable.

Re: More Than 1M Google Accounts Breached by Gooligan

#116
post #112

Earlier quoted context omitted.

Fine print: "Check Point will not collect, store, or use your email address for any other purpose."

It is just a text. How do you know ?

What is the downside of someone having your email address, especially with no other context.

If they have other data on your email address, they don't need your email address to do anything with it. If they don't have other data, then there's no issue.

You're not concerned about people having public access to your twitter handle, why would you be concerned about people having public access to your email address.

Re: More Than 1M Google Accounts Breached by Gooligan

#117
post #114
post #84

Earlier quoted context omitted.

That's not to say Google has no responsibility in this. Google's OS has a terrible security-update policy. Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. Now, there are valid technical reasons that Google can't be as good as Microsoft at pushing out updates to every device running their OS, but still, it's hard to say t…

> Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. This seems like the kind of problem the free market could solve. Just get one phone vendor to guarantee secruity updates for a few years and then some customers will start buying those phones. After a while other vendors will start promising it or losing sales.

Blackberry android phones does this. They patch phones the same day google nexus is patched or even earlier for beta program users. Still no one is buying them

Re: More Than 1M Google Accounts Breached by Gooligan

#118
post #114
post #84

Earlier quoted context omitted.

That's not to say Google has no responsibility in this. Google's OS has a terrible security-update policy. Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. Now, there are valid technical reasons that Google can't be as good as Microsoft at pushing out updates to every device running their OS, but still, it's hard to say t…

> Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. This seems like the kind of problem the free market could solve. Just get one phone vendor to guarantee secruity updates for a few years and then some customers will start buying those phones. After a while other vendors will start promising it or losing sales.

   the kind of problem the free market could solve
Yet the free market doesn't solve this problem.

Re: More Than 1M Google Accounts Breached by Gooligan

#119
post #116
post #112

Earlier quoted context omitted.

It is just a text. How do you know ?

What is the downside of someone having your email address, especially with no other context. If they have other data on your email address, they don't need your email address to do anything with it. If they don't have other data, then there's no issue. You're not concerned about people having public access to your twitter handle, why would you be concerned about people having public access to your email address.

Well, they at least know my email address and my interest for android phones. Am I only one thinking that It is so easy to sell the whole list to a Chinese manufacturer ?

Re: More Than 1M Google Accounts Breached by Gooligan

#120
post #114
post #84

Earlier quoted context omitted.

That's not to say Google has no responsibility in this. Google's OS has a terrible security-update policy. Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. Now, there are valid technical reasons that Google can't be as good as Microsoft at pushing out updates to every device running their OS, but still, it's hard to say t…

> Being able to buy a new computing device from a store that will receive no security updates is terrible, and is fairly common in Android devices. This seems like the kind of problem the free market could solve. Just get one phone vendor to guarantee secruity updates for a few years and then some customers will start buying those phones. After a while other vendors will start promising it or losing sales.

The underlying assumption is that a multitude of users would switch to devices produced by such a manufacturer. This, I think, overestimates how much most users currently care about security.

As it turns out, there are more secure devices in the marketplace than the affected phones, but they cost more. All other things equal, a contractual obligation for security policies would increase the cost (and thus price) of devices, and users would likely stick with cheaper options.

Post reply on HN