Live data from Hacker News

Google launches new security features to protect users from unverified apps

techcrunch.com

61–65 of 65 posts

Re: Google launches new security features to protect users from unverified apps

#62

I just can't shrug off the thought that manual review approach is a lost game in the long run. It's a process than requires skilled human and can't be fully automated while generating malicious code perfectly can.

They already do manual review for many of their high-serving ads, and people shouldn't shy away from some human intervention in these processes. AI and machine learning are most effective these days when they help assist people (flagging potentially malicious code, bubbling up anomalies, etc.), and it isn't that expensive to get a pair of eyeballs to double check conclusions!

I'd love to see an ad system with manual review for all ads... and have a review fee when ads are changed/cycled.

Re: Google launches new security features to protect users from unverified apps

#64
post #41

Earlier quoted context omitted.

It's also worth noting that this likely would stop phishing attacks like the one that happened earlier this year. https://www.theverge.com/2017/5/3/15534768/google-docs-phish... https://news.ycombinator.com/item?id=14258918

I reported a bug to Google just a couple of days, which is very similar to this. It allows an attack to present a user with a real Google 'account select' page with their account listed, but if they click that link it actually redirects them to another site (which you can dress up to look like the password page the user is expecting). It is arguably worse than the previous issue, as I don't need a hoax extension, I c…

I'm not sure it's worse, since it requires users to type their password into a non- google.com domain. Whereas the oauth phishing, everything was on google.com so it looked legit.

Re: Google launches new security features to protect users from unverified apps

#65
post #64

Earlier quoted context omitted.

I reported a bug to Google just a couple of days, which is very similar to this. It allows an attack to present a user with a real Google 'account select' page with their account listed, but if they click that link it actually redirects them to another site (which you can dress up to look like the password page the user is expecting). It is arguably worse than the previous issue, as I don't need a hoax extension, I c…

I'm not sure it's worse, since it requires users to type their password into a non- google.com domain. Whereas the oauth phishing, everything was on google.com so it looked legit.

That is a good point. The flip side is having the account password is far more devastating.
Post reply on HN