Live data from Hacker News

Pokemon Go is a huge security risk

adamreeve.tumblr.com

231–240 of 269 posts

Re: Pokemon Go is a huge security risk

#231

Earlier quoted context omitted.

It's because the app has access to and control over the DOM of the UIWebView. Suppose some app called EvilGameFoo is asking you to authenticate with your Google account. They should kick you to a UI controlled by Google, which EvilGameFoo cannot in any way inspect or access, where you enter your credentials. Google then tells EvilGameFoo that they can vouch for you. Instead, UIWebView lets the app asking you to sign…

How are you supposed to know that it is actually a UI controlled by google and not a simulation of a UI controlled by google? The OAuth model not only enables phishing directly even worse than that, it disarms people's natural skepticism towards phishing attempts. Its adoption was a terrible idea.

> How are you supposed to know that it is actually a UI controlled by google and not a simulation of a UI controlled by google?

I have a certificate signed by Symantec guaranteeing that it's authentic!

Re: Pokemon Go is a huge security risk

#232

It's worth noting that Niantic Labs (the folks who licensed Pokemon from Nintendo and made Pokemon Go) are actually owned by Google [0]. This is Google giving itself permission to do Google things. Dollars to doughnuts they tried to use some internal-only API because things kept falling over at pokemon.com. Is this a massive UX failure? Certainly. Is giving Google permission to access Google stuff a "Huge security ri…

Interestingly, it does not work on Android Nougat.

Yea but it had to work on iOS..

Re: Pokemon Go is a huge security risk

#233
post #169

Earlier quoted context omitted.

Google's own apps often don't request this much permission. Basic security principles.

If you connect Chrome to your account it does get full permissions for some reason. Perhaps Chromebook-related?

Pretty much. Google was trying to cram the entire Chrome OS platform in their browser a while back (remember Chrome's Windows 8 mode?), although they've kind of taken a step back from it lately.

Re: Pokemon Go is a huge security risk

#234
post #161

Earlier quoted context omitted.

What's funny is that nobody seems to provide a workflow to actually create accounts for kids. I want to set up a supervised google account for my son for hangouts et al... and I have no idea how. I guess that's not a thing.

>I want to set up a supervised google account for my son for hangouts et al... Why?

Same reason I have a landline, so he and his friends can talk. He's 8.

Re: Pokemon Go is a huge security risk

#235
post #21

> I really wish I could play, it looks like great fun, but there’s no way it’s worth the risk. Why not just create a separate google account if one's so eager to play?

Or just sign in with your e-mail address. It's an option provided by the app.

Re: Pokemon Go is a huge security risk

#236
post #161

Earlier quoted context omitted.

What's funny is that nobody seems to provide a workflow to actually create accounts for kids. I want to set up a supervised google account for my son for hangouts et al... and I have no idea how. I guess that's not a thing.

It is for some services/websites that have policies in place. Google probably doesn't care enough to have a process, not worth it for them.

Since I can't edit here is an example:

http://www.neopets.com/coppa/consentform.phtml

Google doesn't care because it takes more effort for them to obey by the law than its worth for them at this time.

Re: Pokemon Go is a huge security risk

#237

Earlier quoted context omitted.

Even if they are a startup within Google, what does that mean for my security as a user? Do they store this API key with full access to a Google account the same way that an official Google app (e.g. Gmail itself) stores my secret data? If so, I probably trust it. Or do they just throw it in a GCE database without a whole lot of thought around a security policy since they're still a fast-moving startup, and maybe my…

You're absolutely right - Niantic's history with Google does not preclude them having crummy security practices that we aren't aware of. However, "Popular thing possibly has crummy security practices (we just don't know)" isn't HN-worthy, it's just FUD. I think both of us would prefer a HN full of well-researched articles over one full of clickbait FUD.

Not FUD to me. I am not going to install Pokemon Go until this is cleared up. I am glad he pointed it out, since I may have clicked through given I would have made quick judgements about them being Google-owned.

Re: Pokemon Go is a huge security risk

#238

Earlier quoted context omitted.

Wait, you revoked access from within google, and then the pokemon app was able to give itself access again without asking for permission?

Yes. I'm not sure if I need to re-log in the app or not though. Maybe if it didn't freeze and I didn't have to re-log then it might have left the access revoked. But it seems that once I re-log the full access goes back into effect.

re-logging in is re-authorization

Re: Pokemon Go is a huge security risk

#239
post #6

I don't see any access granted to Pokemon Go (it's not even listed) in the "Apps Connected to your Account" page: https://security.google.com/settings/security/permissions I am running on a Nexus 6 and signed in with my Google Account when I first launched the app. Try revoking access and see what happens. Worst case, it might ask you to sign in again.

According to an update posted now on the article, the problem is only on the iOS version

Re: Pokemon Go is a huge security risk

#240
post #195
post #6

I don't see any access granted to Pokemon Go (it's not even listed) in the "Apps Connected to your Account" page: https://security.google.com/settings/security/permissions I am running on a Nexus 6 and signed in with my Google Account when I first launched the app. Try revoking access and see what happens. Worst case, it might ask you to sign in again.

Same here. I recall a "give pokemon go access to your google contacts" dialog (or similar), which I denied.

Same here. I guess "gotta catch 'em" all means something else in this instance
Post reply on HN