TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Pokemon Go is a huge security risk

780 pointsby patchoulolalmost 9 years ago

51 comments

RKoutnikalmost 9 years ago
It&#x27;s worth noting that Niantic Labs (the folks who licensed Pokemon from Nintendo and made Pokemon Go) are actually <i>owned</i> by Google [0]. This is Google giving itself permission to do Google things. Dollars to doughnuts they tried to use some internal-only API because things kept falling over at pokemon.com. Is this a massive UX failure? Certainly. Is giving Google permission to access Google stuff a &quot;Huge security risk&quot;? No more than putting your stuff in Google&#x27;s hands in the first place.<p>Niantic are also the folks behind Ingress, if you&#x27;ve heard of that.<p>[0] Specifically, Alphabet owns a significant portion of Niantic, along with Nintendo: <a href="https:&#x2F;&#x2F;nianticlabs.com&#x2F;blog&#x2F;niantic-tpc-nintendo&#x2F;" rel="nofollow">https:&#x2F;&#x2F;nianticlabs.com&#x2F;blog&#x2F;niantic-tpc-nintendo&#x2F;</a> (they were previously wholly-owned by Google).
评论 #12075357 未加载
评论 #12073812 未加载
评论 #12073020 未加载
评论 #12073636 未加载
评论 #12073044 未加载
评论 #12074235 未加载
评论 #12073045 未加载
评论 #12076719 未加载
评论 #12079958 未加载
评论 #12073819 未加载
评论 #12073039 未加载
评论 #12073255 未加载
评论 #12076610 未加载
ChrisLTDalmost 9 years ago
Update from Niantic in this Game Informer article <a href="http:&#x2F;&#x2F;www.gameinformer.com&#x2F;b&#x2F;news&#x2F;archive&#x2F;2016&#x2F;07&#x2F;11&#x2F;pokemon-go-has-access-to-your-entire-google-account.aspx" rel="nofollow">http:&#x2F;&#x2F;www.gameinformer.com&#x2F;b&#x2F;news&#x2F;archive&#x2F;2016&#x2F;07&#x2F;11&#x2F;pokemo...</a><p><i>&quot;We recently discovered that the Pokémon GO account creation process on iOS erroneously requests full access permission for the user’s Google account. However, Pokémon GO only accesses basic Google profile information (specifically, your User ID and email address) and no other Google account information is or has been accessed or collected. Once we became aware of this error, we began working on a client-side fix to request permission for only basic Google profile information, in line with the data that we actually access. Google has verified that no other information has been received or accessed by Pokémon GO or Niantic. Google will soon reduce Pokémon GO’s permission to only the basic profile data that Pokémon GO needs, and users do not need to take any actions themselves.&quot;</i>
评论 #12076697 未加载
评论 #12076435 未加载
hughesalmost 9 years ago
If google auth as a platform grants <i>full access</i> to your google account without any sort of confirmation, isn&#x27;t <i>that</i> the security risk? Whether or not it&#x27;s intentional or malicious on the part of Niantic, that seems like the real problem here.
评论 #12072792 未加载
评论 #12072840 未加载
评论 #12072926 未加载
评论 #12072809 未加载
评论 #12073272 未加载
arielweisbergalmost 9 years ago
And just like that I will never sign in with Google anywhere ever again. I just assumed that an app couldn&#x27;t grant itself full permissions without notifying me, but now I can see why that might not be the case since they are free to present whatever UI they want in app.<p>In my dream world Google would revoke Niantic&#x27;s API access forever in order to make an example out of them. Maybe, eventually, if they can prove that they didn&#x27;t hoover up all the information they had access to they can be unbanned after a year.<p>Unlikely though considering they used to be a part of Google.
评论 #12072632 未加载
评论 #12075774 未加载
评论 #12074590 未加载
评论 #12072448 未加载
评论 #12072450 未加载
评论 #12072458 未加载
评论 #12074387 未加载
drivers99almost 9 years ago
&quot;Pokemon Go Release&quot; has &quot;full access&quot; and yet &quot;Ingress&quot; (a game very similar to Pokemon Go from the same company) only has &quot;basic account info&quot;. I removed the access and when I started the app, it crashed right away. (I&#x27;m on iOS, by the way.) Subsequent launch I&#x27;m stuck on the &quot;LOADING...&quot; screen, and then it says &quot;Failed to get player information from the server.&quot; I hope the servers are just down and I didn&#x27;t lock myself out. (Or maybe I should be glad until this fix this breach.) Edit: Deleting the app and reinstalling allowed me to log in again.<p>It appears to be the iOS version only that&#x27;s doing this, according to this article:<p><a href="http:&#x2F;&#x2F;9to5google.com&#x2F;2016&#x2F;07&#x2F;11&#x2F;psa-pokemon-go-full-access-google-accounts-iphone&#x2F;" rel="nofollow">http:&#x2F;&#x2F;9to5google.com&#x2F;2016&#x2F;07&#x2F;11&#x2F;psa-pokemon-go-full-access-...</a>
评论 #12072595 未加载
评论 #12072523 未加载
评论 #12072639 未加载
seagrayalmost 9 years ago
I don&#x27;t see any access granted to Pokemon Go (it&#x27;s not even listed) in the &quot;Apps Connected to your Account&quot; page: <a href="https:&#x2F;&#x2F;security.google.com&#x2F;settings&#x2F;security&#x2F;permissions" rel="nofollow">https:&#x2F;&#x2F;security.google.com&#x2F;settings&#x2F;security&#x2F;permissions</a><p>I am running on a Nexus 6 and signed in with my Google Account when I first launched the app.<p>Try revoking access and see what happens. Worst case, it might ask you to sign in again.
评论 #12073072 未加载
评论 #12072453 未加载
评论 #12072470 未加载
评论 #12076269 未加载
评论 #12072374 未加载
评论 #12072846 未加载
评论 #12072566 未加载
评论 #12074533 未加载
评论 #12075472 未加载
评论 #12072602 未加载
评论 #12072490 未加载
评论 #12073538 未加载
NeonVicealmost 9 years ago
&quot;[T]his section of the privacy page on the Google account settings website is only showing up for those that have played on iOS and signed in using the Google button. Android users who used the same login method are not seeing the “Pokemon Go Release” at all on the permissions site (nor do they see Ingress), so we’re not sure yet if those users have trusted Niantic with their entire Google account as well.&quot; source: <a href="http:&#x2F;&#x2F;9to5google.com&#x2F;2016&#x2F;07&#x2F;11&#x2F;psa-pokemon-go-full-access-google-accounts-iphone&#x2F;" rel="nofollow">http:&#x2F;&#x2F;9to5google.com&#x2F;2016&#x2F;07&#x2F;11&#x2F;psa-pokemon-go-full-access-...</a>
评论 #12072739 未加载
评论 #12073464 未加载
rwallacealmost 9 years ago
Caveat: I&#x27;ve seen a number of players state or imply that playing this game has been the first decent exercise they&#x27;ve had in years. Lack of exercise is a far greater threat to your well-being than having your Google account hacked, so if that&#x27;s what it takes, go ahead and play the game anyway.
评论 #12072503 未加载
评论 #12072977 未加载
maknzalmost 9 years ago
Full access is bad enough, but the really dodgy thing going on is that you never get asked to approve or deny that access for Pokemon Go when doing the OAuth flow. You just log in, proceed through 2fa, and you&#x27;re magically logged into the app. Pokemon Go Release then shows up as an authorised app... except I never authorised it.<p>My theory is that they&#x27;re injecting JavaScript into the web view to automatically press the &#x27;Approve&#x27; button and hiding that from the user. If true, that&#x27;s very worrying. They&#x27;d be effectively circumventing the whole OAuth framework by forging the user&#x27;s approval of the app. Every user should have been asked up-front whether or not they wanted to approve or deny Pokemon Go&#x27;s full access.
nappy-dooalmost 9 years ago
I spoke with a friend of mine at Niantic. They are in communication with the oauth group at Google, and are fixing the issue.
评论 #12076309 未加载
cheshire137almost 9 years ago
I know Google lets you see which apps are connected to your account via <a href="https:&#x2F;&#x2F;security.google.com&#x2F;settings&#x2F;security&#x2F;permissions" rel="nofollow">https:&#x2F;&#x2F;security.google.com&#x2F;settings&#x2F;security&#x2F;permissions</a> but is there any page where I can see what activity was done on my account by particular apps?
nostrademonsalmost 9 years ago
A lot of aspects of Pokemon Go are less than polished from an app dev perspective. The way they ask for device permissions doesn&#x27;t follow best practices at all (no explanation of why they need them). The interface has too much explanatory text in some places (how much useless backstory did I need to click through to start playing?) and not enough in others (it took me forever to figure out what I was supposed to do once I found a pokemon). My sister-in-law was complaining about how all the pokemon graphics are very 2D, when they could easily have sprung for some shading or shadows.<p>I suspect they built an MVP and launched it and it happened to take off, and we&#x27;ll see some more polish in the future.<p>For this particular issue though - I&#x27;d bet that Niantic has some sort of data-sharing agreement with Google, anyway, making this point moot. They started as an internal startup at Google, and they make really heavy use of the Maps &amp; Places APIs that would probably cost a fortune if they didn&#x27;t have some sort of bulk data sharing agreement.
MBCookalmost 9 years ago
There are enough kids playing this maybe the FTC will get involved. Maybe some sort of basic privacy requirement.<p>How is it possible that signing in didn&#x27;t inform me what permissions I was granting? I didn&#x27;t think I was giving <i>anything</i> except my email address.
评论 #12072561 未加载
评论 #12072619 未加载
kamacalmost 9 years ago
&gt; I really wish I could play, it looks like great fun, but there’s no way it’s worth the risk.<p>Why not just create a separate google account if one&#x27;s so eager to play?
评论 #12072401 未加载
评论 #12076132 未加载
评论 #12072565 未加载
评论 #12072524 未加载
toufkaalmost 9 years ago
Isn&#x27;t Niantic actually affiliated with (part of?) Google in some way? So it would seem natural, if odd, that it doesn&#x27;t ask for full permissions for the account is actually already has full permissions to. In the same way google docs doesn&#x27;t ask, but gets, full permissions to your google account, or google+ doesn&#x27;t ask, but gets, full permissions to your google account.
评论 #12072777 未加载
nickpsecurityalmost 9 years ago
Here I thought the article was going to be on how Pokemon Go encourages people to wonder into dangerous or restricted areas while paying attention to their phone. The odds of someone getting attacked in a rough area would seem to go up with such an app given how critical situational awareness is. I don&#x27;t know enough about how the app works to assess that, though.<p>One app that got me thinking about these things was Google Maps. I noticed it directed me through The Hood of a murder capital to save 3 minutes on a route. An area where people are known to surround cars or level guns on their owners. I had to wonder how much more risk like this is in any GPS-enabled app that sends you from point A to B.
评论 #12072894 未加载
评论 #12072771 未加载
评论 #12072418 未加载
评论 #12072567 未加载
beckleralmost 9 years ago
It should be noted that it sounds like only iOS users are seeing this.<p>I signed in with my Android, and I didn&#x27;t see anything from Niantic or Pokemon Go in my security settings.
评论 #12072607 未加载
thoreauwayalmost 9 years ago
Doesn&#x27;t Google OWN Niantic? So now Google has access to our Google data? Don&#x27;t see the issue.
评论 #12072333 未加载
评论 #12072426 未加载
评论 #12072327 未加载
评论 #12072599 未加载
评论 #12072344 未加载
评论 #12072474 未加载
评论 #12072345 未加载
评论 #12072409 未加载
ceejayozalmost 9 years ago
This seems like a massive security fail on Google&#x27;s part. There&#x27;s no reason the OAuth flow should be able to request admin privileges <i>silently</i>. As a user, I really must get a prompt asking me (and warning me!).
mschuster91almost 9 years ago
On a sidenote: does anyone know why the fuck are the servers so overcrowded? In a world with a whole bunch of automated cloud management solutions and auto-scaling, where is the problem?
dopualmost 9 years ago
I&#x27;m running iOS 9.3.2, and signing in to Pokemon Go caused it to have full access to my Google account. Just revoked it and looks like I can still play the game just fine.<p>Perhaps they misconfigured the Google auth sign-in? It&#x27;s rather worrisome that it&#x27;s this easy for an application to gain full access to your account, though.
评论 #12072727 未加载
评论 #12073387 未加载
raouldukealmost 9 years ago
Here&#x27;s a weird question. <a href="https:&#x2F;&#x2F;www.facebook.com&#x2F;NationalMallNPS&#x2F;photos&#x2F;a.379580652053692.97287.151776458167447&#x2F;1186299898048426&#x2F;?type=3&amp;theater" rel="nofollow">https:&#x2F;&#x2F;www.facebook.com&#x2F;NationalMallNPS&#x2F;photos&#x2F;a.3795806520...</a> Pokemon Go is designed to not only augment places where people already are but also to direct them to other places. My friend just ran down the Ninatic&#x2F;Google connection. Can the app be used to direct people away from polling places and&#x2F;or to congest areas around polling places?<p>To wit, would anyone be interested in tracking (I can do it for at least some locations) the locations of gyms in comparison to polling places? (I haven&#x27;t used the app; can one get a location of gyms?)<p>[lol. let me clarify my interest would be in thwarting rather than harnessing this possibility.]
评论 #12102642 未加载
评论 #12077911 未加载
randomh3r0almost 9 years ago
Any idea how long the signup page is down? I made my account yesterday and, when forced between using my google auth and making some pokemon.com account, it was a no brainer to not use my google account. It took me a few tries but since this is a game and not something in the realm of life-and-death, I found it wasn&#x27;t horrible to actually wait. And try again.<p>The entire issue is predicated on using your google account credentials which isn&#x27;t really mandatory. Maybe I&#x27;m overly cautious but I don&#x27;t use my google account to auth anywhere. If that&#x27;s the only option, and it&#x27;s not a google product.. then it looks like I&#x27;m not using that service.
评论 #12071777 未加载
评论 #12072898 未加载
Mendenhallalmost 9 years ago
Thing like this is why i dont use google, facebook etc and only have 4 apps. I love technology but it looks like hardly anyone is looking out for the consumer,let alone a non tech savvy consumer.
lowbloodsugaralmost 9 years ago
I&#x27;m more worried about my daughter getting hit by a car (because she walks in front of it, or because the driver is playing) than I am about my google account being hijacked!
评论 #12077988 未加载
gesmanalmost 9 years ago
So the solution is to create a throw away gmail account, I guess? Or not bother playing at all.
lllorddinoalmost 9 years ago
Just revoked access because the app never disclosed this information on signing up with my Google account. This is sick.
BadassFractalalmost 9 years ago
I detected that immediately when I signed up with google at first. No double-checking what I was ok with sharing with the company. Had to remove their permission from my account settings right away. Signed up with their email&#x2F;password system, much better.
tlrobinsonalmost 9 years ago
Report it here: <a href="https:&#x2F;&#x2F;support.pokemongo.nianticlabs.com&#x2F;hc&#x2F;en-us&#x2F;requests&#x2F;new?ticket_form_id=319988" rel="nofollow">https:&#x2F;&#x2F;support.pokemongo.nianticlabs.com&#x2F;hc&#x2F;en-us&#x2F;requests&#x2F;...</a>
gregorkasalmost 9 years ago
On Android 6.0 I got the correct permissions dialog and I was able to select what the app sees and what it can do. Is this just me?
评论 #12072574 未加载
评论 #12072482 未加载
peterjleealmost 9 years ago
Seem like a issue with Google Auth on iOS. I&#x27;ve logged into Pokemon Go from my Android and iPhone. I revoked the access of &quot;Pokemon Go release&quot; from Connected Apps page then logged in again from my Android phone. &quot;Pokemon Go release&quot; doesn&#x27;t show up in my Connected Apps page anymore even after a login from Android.
Animatsalmost 9 years ago
Where there&#x27;s a security hole, there&#x27;s an exploit.[1]<p>[1] <a href="https:&#x2F;&#x2F;thestack.com&#x2F;security&#x2F;2016&#x2F;07&#x2F;11&#x2F;infected-pokemon-go-apk-carries-dangerous-android-backdoor&#x2F;" rel="nofollow">https:&#x2F;&#x2F;thestack.com&#x2F;security&#x2F;2016&#x2F;07&#x2F;11&#x2F;infected-pokemon-go...</a>
评论 #12074104 未加载
auganovalmost 9 years ago
Wow. This game must be the fastest thing to skyrocket into worldwide popularity. Yesterday I noticed someone on social media talking about it. &quot;Some random game pokemon fans like&quot; - I figured. Today it seems like everyone around the world is playing it. And it was released just a week ago? Never seen anything quite like it.
meowsusalmost 9 years ago
This article, though rife with paranoia, brings up some interesting points.<p><a href="http:&#x2F;&#x2F;blackbag.gawker.com&#x2F;pokemon-go-is-a-government-surveillance-psyop-conspirac-1783461240" rel="nofollow">http:&#x2F;&#x2F;blackbag.gawker.com&#x2F;pokemon-go-is-a-government-survei...</a>
test6554almost 9 years ago
Could you simply create a new google account for the sole purpose of playing pokemon go?
test6554almost 9 years ago
Could you not simply create a new google account strictly for use with pokemon go?
评论 #12072801 未加载
ultramancoolalmost 9 years ago
Title isn&#x27;t exactly accurate - can we edit this to indicate iOS only?
darkboltyoutubealmost 9 years ago
People die doing this: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=B2KXVfnw4rg" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=B2KXVfnw4rg</a>
Zigurdalmost 9 years ago
I got a number of permission requests at runtime the first time launching the app. If anything, it appears to be running into more of the Android 6 runtime permissions.
guillegettealmost 9 years ago
Funny enough when I downloaded the app I didn&#x27;t use my official account and I logged in with a secondary account wondering exactly about this.
guillegettealmost 9 years ago
Funny enough, when I installed the game I didn&#x27;t use my official Google account and I used my test one thinking about this. Glad I did it.
131hnalmost 9 years ago
kind of a scam, just a bad wording from google &quot;full access&quot; and old oauth workflow - but no real security threat<p>TLDR: Pokemon Go can&#x27;t read your gmail - he checked<p><a href="https:&#x2F;&#x2F;gist.github.com&#x2F;arirubinstein&#x2F;fd5453537436a8757266f908c3e41538" rel="nofollow">https:&#x2F;&#x2F;gist.github.com&#x2F;arirubinstein&#x2F;fd5453537436a8757266f9...</a>
thecourieralmost 9 years ago
I&#x27;m usingn the android version. they aren&#x27;t even a connected application. so no risk in Android.
Darsstaralmost 9 years ago
So, Pokemon Go is not listed under my account... Could it be the mallware version?
评论 #12072519 未加载
评论 #12072895 未加载
throw7almost 9 years ago
I see google Chrome gets full account access... I guess this is required? Or not?
minimaxiralmost 9 years ago
Better&#x2F;more neutral title: Pokemon Go asks for full Google permissions
评论 #12071192 未加载
评论 #12072465 未加载
评论 #12072447 未加载
评论 #12072506 未加载
carsonreinkealmost 9 years ago
Why in the world would they do this? Or was this just merely an accident?
评论 #12072521 未加载
Dowwiealmost 9 years ago
I can&#x27;t tell whether this game is the most heavily marketed social-media blitz of all time or truly viral. A virtual treasure hunt game finally gets people outside? Come on.
julioncalmost 9 years ago
Jesus Christ, They wants to catch &#x27;em all
zeffralmost 9 years ago
It&#x27;s a free game everyone.<p>When something is free to play, and involves you walking around with geo services and a camera on, you and your data are the product.<p>This is just massive data collection disguised as a video game.
评论 #12072514 未加载
评论 #12072525 未加载
Alexsandrosalmost 9 years ago
I fond of e-sport. So it’s interesting for me to test new game. Pokemon go stole the scene at a grate pace. But this game is a really risky for cybersecurity. Maybe we don’t need such program.