Live data from Hacker News

Pokemon Go – Permissions Update

support.pokemongo.nianticlabs.com

91–100 of 112 posts

Re: Pokemon Go – Permissions Update

#91
post #61

I wonder how many applications do the same thing and haven't been called out on it.

The difference here is the "grant full access" screen was never shown to users. That shouldn't be possible and speculation is that either the app somehow hijacked past the screen, or Niantic being an ex-google company was whitelisted to avoid this.

I can easily see how the second would happen, I wonder if Ingress (their previous inside google app) even showed up on your list of authorized third parties?

Re: Pokemon Go – Permissions Update

#93
post #4

Earlier quoted context omitted.

Exactly, that's what I'm more worried about - Google needs to present clear information about what access is provided BEFORE I accept the account connection. It's not necessarily Niantic's fault for asking for too much, it's Google's for not at least making me aware.

the thing is...as long as its a frame inside the app i have zero way of knowing whether im actually looking at googles login page, or if niantic is reading the traffic/javascript. At least when I get bounced out to safari I only have to trust apple, which I already implicitly do.

If you want to be paranoid, you could run a MITM proxy from your computer between your phone and Niantic's servers.

Re: Pokemon Go – Permissions Update

#94
post #91
post #61

I wonder how many applications do the same thing and haven't been called out on it.

The difference here is the "grant full access" screen was never shown to users. That shouldn't be possible and speculation is that either the app somehow hijacked past the screen, or Niantic being an ex-google company was whitelisted to avoid this. I can easily see how the second would happen, I wonder if Ingress (their previous inside google app) even showed up on your list of authorized third parties?

From what others have posted here, any native app that loads the oauth flow in a web view control or whatever it's called, has full control over it, and so can do anything it wants.

Re: Pokemon Go – Permissions Update

#95

Earlier quoted context omitted.

the thing is...as long as its a frame inside the app i have zero way of knowing whether im actually looking at googles login page, or if niantic is reading the traffic/javascript. At least when I get bounced out to safari I only have to trust apple, which I already implicitly do.

If you want to be paranoid, you could run a MITM proxy from your computer between your phone and Niantic's servers.

And see TLS traffic? How would this help anyone?

Re: Pokemon Go – Permissions Update

#96

I'm glad they involved google to make sure the change happens to anyone and also to verify their claims about access. This is the type of response we should expect/demand from other companies. Well done.

The company is actualy owned by Google.

The company WAS owned by Google. They left Google in August 2015 to become an independent entity.

Re: Pokemon Go – Permissions Update

#97
post #77

Earlier quoted context omitted.

Web of trust I suppose. I trust Nintendo and I also don't think Google would allow such a brazen and public endorsement if it were untrue. If google does indeed reset permissions then you know they've at least been in contact. If it were a smaller company I'd like to see proof.

> If it were a smaller company I'd like to see proof. Amazing how much trust the mere size of a company ensues.

The bigger the company, the higher the chances that a public statement - especially one admitting to a mistake - has to pass through PR and legal, and that one of those stops you from implicating a third party company in your actions if they aren't really being a part.

Too much to lose, not enough to gain.

Re: Pokemon Go – Permissions Update

#98
post #77

Earlier quoted context omitted.

> If it were a smaller company I'd like to see proof. Amazing how much trust the mere size of a company ensues.

It's not size directly, but the risk of goodwill. A bigger company stands to lose more goodwill.

I disagree. I think the bigger the company, the more likely they less care about users/support/their image. They're 'too big to fall' and the sheep are already on the ship. I believe there's plenty of examples out there, I can give you two straight away [1], [2].

[1] https://news.ycombinator.com/item?id=5523992

[2] https://news.ycombinator.com/item?id=12034608

Re: Pokemon Go – Permissions Update

#99

Earlier quoted context omitted.

If you want to be paranoid, you could run a MITM proxy from your computer between your phone and Niantic's servers.

And see TLS traffic? How would this help anyone?

A MITM proxy typically means a decrypting proxy, so you can see all the traffic, irregardless of if it's wrapped in TLS.

Re: Pokemon Go – Permissions Update

#100
post #26

Isn't this a bit: "Accidentally left open gate to castle. Now closed. No fix in place to make sure other people working closely with Alphabet/Google won't leave door open again. Share and enjoy." ? On another note, from the "privacy policy": 1. REVISIONS TO THIS PRIVACY POLICY Any information that is collected via our services is covered by the privacy policy in effect at the time such information is collected we may…

> So, they'll let you know if they apply retroactive changes to the policy?

Pretty standard for a lot of apps and web services. The alternative is not to use them, or to be very conscious about what data you supply them with. Most people just click accept (as with any EULA).

Post reply on HN