6 ms·
It's a pretty nasty one, since it uses their standard OAuth flow with an app "Google Docs" to have users grant full access to their email and contacts. 1. I ca
by hemancuso 9y ago
It's a pretty nasty one, since it uses their standard OAuth flow with an app "Google Docs" to have users grant full access to their email and contacts.
1. I can't believe Google doesn't have basic filters to disallow developers from registering an app named "Google Docs"
2. Perhaps there should be some more validation/limits associated with allowing apps on the platform that can gain full access to email. A secure email account is the One True Source of authentication in the digital world. Google should make it way harder for people to get tricked into granting full access to their inbox.
- the_mitsuhiko 9y agoIs it actually Google or is there some unicode trickery going on?
- hemancuso 9y agoDoesn't look like a unicode trick on the app-strings I'm getting
- oh_sigh 9y agoIs there a database of homoglyphs for common fonts that one could use to write a visual string matching algorithm?
- mintplant 9y agohttp://www.unicode.org/Public/security/8.0.0/confusables.txt http://www.unicode.org/Public/security/8.0.0/confusables.txt https://github.com/codebox/homoglyph https://github.com/codebox/homoglyph http://homoglyphs.net/ http://homoglyphs.net/
- aaronmiler 9y agoFrom what I can tell, it's actually Google, but then they redirect you to a malicious URL after auth/approval
- creichert 9y agoSeems like it's allowed in the oauth form: https://pbs.twimg.com/media/C-7NlIzXUAErblp.jpg:large https://pbs.twimg.com/media/C-7NlIzXUAErblp.jpg:large
- Alex3917 9y ago> A secure email account is the One True Source of authentication in the digital world. The gmail account you use to talk with people shouldn't be the same one you use to send password resets to. It's fine to allow CRM apps or whatever to have OAuth access to your regular gmail account, you just shouldn't give read-write access to the one you use for your retirement account or whatever. (Read-only access is much less dangerous, because even if someone can trigger a password reset email they can't delete it afterwards.)
- kelnos 9y ago> The gmail account you use to talk with people shouldn't be the same one you use to send password resets to. The vast majority of services don't support setting a separate password reset email, so that would be a showstopper for most people. You'd end up just having another email account you have to check all the time (since non-reset email would also go to this account), and could still easily get bitten by this sort of spam/phishing.
- Alex3917 9y ago> You'd end up just having another email account you have to check all the time You'd need an extra tab open in your browser that you'd need to check multiple times per day. But most automated messages don't require a response within fifteen minutes or whatever, so there isn't much extra cognitive overhead. And for most people you probably also don't need that email address authed on your phone.
- kelnos 9y agoThe cognitive overhead is not my objection (and I agree it wouldn't be much). The problem is that most people's personal email isn't primarily about correspondence anymore; it's about interacting with the various services where you have accounts or subscriptions. So your special password-reset email is also the place where you receive your social media notifications (because your social media account doesn't let you set a separate email for notifications and password resets). So now your password-reset email account is just as vulnerable to phishing because it's _not_ just your password-reset email, and there's no way to make it so.
- math0ne 9y agoI think they do, I got an app shut down because it was named too similar to one of their products, this was just a week ago or so.
- Flammy 9y agoManual review if it is reported? Because if it was manually reviewed before first use this never would have gotten through.
- discordianfish 9y ago> 1. I can't believe Google doesn't have basic filters to disallow developers from registering an app named "Google Docs" Believe! I think this is just one of the many cases where after the fact everyone is like "oh wow, how didn't they think about it". But that doesn't say you would have thought about this before reading this.
- wahnfrieden 9y agoThey reportedly knew about this since 2012: https://news.ycombinator.com/item?id=14260298 https://news.ycombinator.com/item?id=14260298