TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

I stole the data in millions of people’s Google accounts

107 点作者 fgblanch超过 4 年前

10 条评论

ghusbands超过 4 年前
Can the title be altered to contain the truth? (That this is a hypothetical scenario, and no data has been stolen.) The article is a bait and switch but that doesn't mean HN should do the same. Changing "stole" to "could steal" would work.
评论 #25760284 未加载
wheresvic4超过 4 年前
I think that these days it is safe to assume that one could always be locked out of their google account for whatever reason. It is best practice to simply create a local account with whatever app&#x2F;service that one wants to use.<p>I personally use an email with a custom domain which I pay for so I am relatively secure of keeping access to my email address. Moreover, I use a local password manager to store all my passwords. This setup is a bit of a pain but it is also liberating as I am not at the mercy of any third party when I am transacting with a service.
评论 #25763318 未加载
kwijibob超过 4 年前
And sometimes they ask for &quot;Sign in with Google&quot;, you say yes, and then they still try to make you create a unique password.
ffpip超过 4 年前
This was flagged for clickbait a day ago<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25717156" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25717156</a><p>It&#x27;s the exact same article by the same author.
评论 #25760688 未加载
petargyurov超过 4 年前
I don&#x27;t get this:<p>&gt; Nothing I did would technically be considered an ‘exploit’<p>Erm, yes it can? It&#x27;s exploiting a glaring vulnerability in Google&#x27;s auth flow, or at the very least a dodgy way to expose master tokens.
评论 #25760406 未加载
评论 #25768887 未加载
matsemann超过 4 年前
I&#x27;m always suspicious when I click &quot;Sign in with X&quot; and it prompts me to enter details. Normally I would already by logged in. But not always, for instance I mostly use Firefox on my phone, and those sessions aren&#x27;t shared with webviews. So one can never know.<p>There&#x27;s really nothing stopping anyone from making an entirely fake &quot;Sign in with X&quot; popup and people would believe it (me included), I think teaching people to give away their Google, FB, GH etc credentials on random pages is scary.
jojobas超过 4 年前
&quot;Sign in to X with Y&quot; is a terrible idea all around. Even if X does not get access your Y account, Y definitely has access to your account in X.
评论 #25759992 未加载
评论 #25760008 未加载
评论 #25760061 未加载
评论 #25760017 未加载
评论 #25760086 未加载
评论 #25759989 未加载
barrkel超过 4 年前
It&#x27;s amusing to see a (valid, IMO) security issue with Google being continuously flagged as clickbait because of how the article is written.
cr3ative超过 4 年前
So weaponise it and get your money from the bug bounty programme. Put up or shut up. ;)
selckin超过 4 年前
what a world, where you can proudly announce you tricked million of people into sharing their private information without any consequences<p>EDIT: i should believe where he said he didn&#x27;t do it, not whee he said he did it
评论 #25760112 未加载
评论 #25760132 未加载
评论 #25760121 未加载