13 ms·
Google launches new security features to protect users from unverified apps
- mrkrabo 9y agoIn case you don't feel like clicking, this doesn't concern Android apps, but OAuth apps that want access to your Google account.
- dovdovdov 9y agoI used up my 1 click effort coupon to get here to the comments, so thank you!
- kyrra 9y agoIt's also worth noting that this likely would stop phishing attacks like the one that happened earlier this year. https://www.theverge.com/2017/5/3/15534768/google-docs-phishing-attack-share-this-document-with-you-spam https://www.theverge.com/2017/5/3/15534768/google-docs-phish... https://news.ycombinator.com/item?id=14258918 https://news.ycombinator.com/item?id=14258918
- TomAnthony 9y agoI reported a bug to Google just a couple of days, which is very similar to this. It allows an attack to present a user with a real Google 'account select' page with their account listed, but if they click that link it actually redirects them to another site (which you can dress up to look like the password page the user is expecting). It is arguably worse than the previous issue, as I don't need a hoax extension, I can just manipulate the link to inject the malicious redirect behaviour. They have triaged it and I'll probably write up a report once they are happy for me to do so.
- Buge 9y agoI'm not sure it's worse, since it requires users to type their password into a non- google.com domain. Whereas the oauth phishing, everything was on google.com so it looked legit.
- TomAnthony 9y agoThat is a good point. The flip side is having the account password is far more devastating.
- deleted 9y ago[deleted]
- pietroalbini 9y agoDoes this also appear on websites only using Google OAuth for authentication, requesting only the email address?
- eeveewoofwoof 9y agoNo, it doesn't appear for email/basic profile scopes.
- akuji1993 9y agoThanks for that info, if it's setup like this it doesn't affect me at all instead of being really annoying to work with (since most of my apps are still in development).
- Camille77 9y agoMy Uncle Hayden got an awesome metallic Volvo S60 T6 R by working part-time online. > Open this >>>>>>>>>>>http://www.joinmate2.Com http://www.joinmate2.Com
- pietroalbini 9y agoThank you, one less thing to worry about!
- cft 9y agoGoogle has become the judge, the jury and the executioner of the internet. Recently a malicious user embedded an image from a site that is on Google's Safe Browsing list in a forum that is itself embedded on a third party site. This nuked a popular third party site where the forum is embedded: it is now flashing red (malicious software detected) in Chrome.
- adtac 9y agoI was wondering how HN would spin this into Evil-Google. It's just tiring at this point. This is a perfectly valid security guard that protects their users.
- DanielBMarkham 9y agoIt is, and with Google in a position of owning much of what happens online, it's also Google acting unilaterally in ways that multiple actors might not. Both statements are true: It's a good thing. It's not right to have one company with so much power No evil Google required.
- JoshTriplett 9y agoThere are plenty of cases where you might reasonably question how much control they have. But this is a mechanism to protect access controls to your Google account, almost the definition of something first-party that they should gate very carefully.
- deleted 9y ago[deleted]
- pdkl95 9y ago> you might reasonably question how much control they have "Доверяй, но проверяй" (trust, but verify) It's very important to always question decisions made from a position of power; vigilance is the price of freedom. Questioning does not necessarily mean disapproval. Everyone concerned about the future of the internet should be questioning Google's motives and intentions every time they unilaterally exercise their power to judge which apps are "acceptable". In this case, it shouldn't take long to find the answers to that question: Google should have implemented this kind of dismissible warning a long time ago. Hiding the "continue" option behind the possibly-misleading "Advanced" link is a minor problem, but some sort of warning is obviously necessary. (I'm actually impressed they used a type-this-word check instead of yet another ignorable "go away" button.)
- otp124 9y agoI like the forced UX of typing something, though "continue" might be glossed over. It would be an interesting study to determine if typing "I know the risk" is a better safety mechanism for users (can be A/B tested for less pass-through events) than "continue".
- amelius 9y agoI'm guessing yes, because users are more likely to abort the installation process.
- askvictor 9y agoTyping something unique (eg the name of the app) might also be useful as it forces some cognitive processing.
- Moru 9y agoOr "I allow LeetHaxorApp to access all my data" But I guess that is a bit too much typing for most people.
- timlyo 9y agoMight be a good thing for apps that try and looking like something else, G00GLE or FACEB00K could be missed, but having to type a zero manually instead of an O would (hopefully) eliminate that.
- deleted 9y ago[deleted]
- askvictor 9y agoNice, though it would probably just cause confusion for a heap of people, and would result in them not installing the app (good) and blaming Google for it (bad for their brand). I would have thought by now it would be pretty easy for algorithms or AI to pick up on these kinds of tricks, whether by a similarity score or an image processing approach.
- philo23 9y agoI'm not sure I'm a fan of the way Google is re-using the Chrome error page styling for this, but I can't put my finger on why exactly...
- martin-adams 9y agoBecause you associate it with an error that you have no control over? I find that I'm tuned to recognise patterns of behaviour, so when the patterns look similar to other things, but aren't the same, it's quite confusing.
- deleted 9y ago[deleted]
- samtoday 9y agoIt is literally training users to dismiss these kind of errors. In Chrome, these errors are really bad, like a safebrowsing warning or a TLS error. On the other hand, this warning will probably happen a lot! Is Google going to be able to "validate" apps fast enough?
- noway421 9y agoG-Suite and Chrome are different products, so yes, It's perfectly reasonable to expect them to be separate.
- Spivak 9y agoBecause it blurs the line between a web page and the browser chrome. Any web page that attempts to look like the browser should be considered malware.
- ComodoHacker 9y agoI just can't shrug off the thought that manual review approach is a lost game in the long run. It's a process than requires skilled human and can't be fully automated while generating malicious code perfectly can.
- londons_explore 9y agoBut making legit apps does take human effort. If an app takes days to make, requiring 5 minutes extra review effort to get it whitelisted seems fine.
- yjftsjthsd-h 9y agoOnly if similar numbers of people work on each side. With thousands or millions of developers to a handful of reviewers, it may go as well as Google's other attempts at human support (read: terrible).
- PeterisP 9y agoCharge money for that. If an app takes days to make, then you can also to pay for an hour of reviewers work if you want to distribute it to the public. A non-prohibitive barrier to entry wouldn't be a big issue, as users in general want stricter filters that mean less shitty apps instead of looser filters that mean simply more apps.
- eterm 9y agoTasks of classifying things (in this case into "approved" or "rejected") that humans can routinely do but machines find difficult are areas where ML shines. Human reviewers today, but once the training set is large enough you can start to let computers take over with human reviewers reviewing the lower certainty cases until the certainties rise further.
- ComodoHacker 9y agoI bet we first hear about ML shining at generating malicious code obfuscated as legit.
- rallycarre 9y agoNo point 0Auth apps if google has access to it. Rather pay for my e-mail service than to use google, whose source of revenue is directly in conflict with my interest of privacy and security. I highly recommend protonemail.com. Has all the bells and whistles and its major feature is user privacy and security.
- paradite 9y agoI see that you don't use ProtonMail often.
- pkamb 9y ago> Type Continue to go to example.com User types "continue"
- pbhjpbhj 9y agoMore like "malware app that user installed to type continue at all such prompts types 'continue'".
- Walf 9y agoBut they still don't let you create app-specific passwords/tokens without enabling 2FA. How they think enabling "less secure apps" is better is beyond me. Trying to force an office full of luddites into 2FA does not go down well.