TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

More Than 1M Google Accounts Breached by Gooligan

450 点作者 idoco超过 8 年前

12 条评论

ohyoutravel超过 8 年前
Malware on your Android device picked up from third party app stores (FDroid? Amazon?) that steals email accounts and auth tokens. Looks like it only works on the older Android 4 Jellybean software (and some Android 5 Lollipop) and below, so mostly concentrated in Asia where there are lower-end phones.<p>You can see if your account has been affected here:<p><a href="https:&#x2F;&#x2F;gooligan.checkpoint.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;gooligan.checkpoint.com&#x2F;</a>
评论 #13072025 未加载
评论 #13071923 未加载
评论 #13075365 未加载
评论 #13072211 未加载
评论 #13072531 未加载
评论 #13071664 未加载
评论 #13072042 未加载
评论 #13073527 未加载
评论 #13071633 未加载
评论 #13071862 未加载
pierrec超过 8 年前
Just to be clear, they didn&#x27;t obtain any passwords, but auth tokens. This would potentially allow them to log into accounts, but only as long as the tokens are valid.<p>Also, they don&#x27;t reveal which &quot;third party app stores&quot; served infected apps, but they do provide a list of infected apps, and searching for these yields some real shady download sites: <a href="http:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;0luW3" rel="nofollow">http:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;0luW3</a>
评论 #13072563 未加载
评论 #13072070 未加载
n1tro超过 8 年前
I used to work in an ad-tech company focused on mobile cpi offers that for several months paid the salaries of everyone involved by injecting malware in cracked apps on several third party app stores (they were making a profit out of it enough to dedicate a team only for this).<p>They even managed to automate all the process of &quot;selling&quot; cracked apps on third party stores. It is amazing how easy it is to trick broke 13yr old kids into installing stuff on their phones.<p>I left shortly after i found out about this.
评论 #13075566 未加载
devy超过 8 年前
We were just reading &quot;Android security in 2016 is a mess&quot;[1] 2 days ago and now we have another great example for it.<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=13056288" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=13056288</a>
评论 #13072254 未加载
m00dy超过 8 年前
Checking your email address in such sites looks like a great way to collect email addresses
评论 #13073060 未加载
评论 #13072975 未加载
mapleoin超过 8 年前
Does anyone else use a special account for their Android phone that they don&#x27;t use for anything else?
评论 #13071795 未加载
评论 #13072020 未加载
评论 #13072230 未加载
评论 #13072726 未加载
评论 #13071789 未加载
评论 #13072477 未加载
评论 #13072058 未加载
评论 #13072072 未加载
评论 #13071796 未加载
评论 #13071937 未加载
alexcason超过 8 年前
Cached: <a href="http:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache:http:&#x2F;&#x2F;blog.checkpoint.com&#x2F;2016&#x2F;11&#x2F;30&#x2F;1-million-google-accounts-breached-gooligan&#x2F;" rel="nofollow">http:&#x2F;&#x2F;webcache.googleusercontent.com&#x2F;search?q=cache:http:&#x2F;&#x2F;...</a>
lucb1e超过 8 年前
So wait this is phishing, not actually hacking into Google to breach accounts if I understood it correctly?<p>In that case, I suppose the title might be technically correct (those accounts are indeed breached), but it makes it sound like Google is to blame.
评论 #13071949 未加载
评论 #13072479 未加载
评论 #13071907 未加载
jrochkind1超过 8 年前
&gt; While Google implemented multiple mechanisms, like two-factor-authentication, to prevent hackers from compromising Google accounts, a stolen authorization token bypasses this mechanism and allows hackers the desired access as the user is perceived as already logged in.<p>What&#x27;s the right fix here? Should auth tokens be ip-address-tied? How much will that break? Or would that not even fix it?
评论 #13072249 未加载
评论 #13072085 未加载
评论 #13072100 未加载
评论 #13072202 未加载
评论 #13072184 未加载
评论 #13072384 未加载
neotek超过 8 年前
And still people complain that Apple refuses to allow third-party app stores.
评论 #13076190 未加载
X86BSD超过 8 年前
The difference between iOS and android could not be more clear in this regard. It&#x27;s interesting to see the difference in security between the two. It&#x27;s night and day. Google has some serious problems to address. But it seems like they don&#x27;t care. Their track record is deplorable regarding android security. Is this really the best google can do?
评论 #13074597 未加载
jalajc超过 8 年前
Is there a way to know if my email is on list of breached?
评论 #13072270 未加载
评论 #13072278 未加载