9 ms·
How to confirm a Google user’s specific email address
- robin_reala 9y agoDead server, Google Cache is at https://webcache.googleusercontent.com/search?q=cache:http%3A%2F%2Fwww.tomanthony.co.uk%2Fblog%2Fconfirm%2Dgoogle%2Dusers%2Demail%2F https://webcache.googleusercontent.com/search?q=cache:http%3...
- TomAnthony 9y agoYeah, I was fiddling with the caching. Should be back now! Thanks! :)
- patorjk 9y ago> which allows an attacker to confirm whether a visitor to a web page is logged in to any one of a list of specific Google accounts I actually reported a similar problem to Google that would allow you to do the same thing back in 2013 (and like you, I used the load and onerror methods for detection). I didn't get a reward either :/. However, Facebook paid me $1,000 for finding this problem for a particular area of their website (http://patorjk.com/blog/2013/03/01/facebook-user-identification-bug/ http://patorjk.com/blog/2013/03/01/facebook-user-identificat...). So I wouldn't write off this kind of security issue. It seems to depend on who's giving out the bounty.
- TomAnthony 9y agoNice catch! Interesting that they considered it a bug. I thought mine would qualify, but appreciate it is a pretty specific issue.
- Merovius 9y agoGiven that I regularly see my Facebook account name and photo on third party websites, without giving them any permission to see those, I find it hard to believe that Facebook cares about this…
- theGimp 9y agoIt's probably in a Facebook iframe, which is a different story.
- patorjk 9y agoI agree with theGimp. From my experience they do seem to care about this. I actually still carry the debt card they sent me in my wallet (http://imgur.com/TuVKm5k http://imgur.com/TuVKm5k). Facebook also seems to be the most generous in terms of giving out a reward. I ended up submitting a few more issues after this and always got something reasonable (usually 1k to 1.5k).
- dpkonofa 9y agoIs this really even a big issue? For one, you have to already have knowledge of the email address in advance. Then you have to somehow get this user to go to a page that you have control over. Then you have to get them to wait around on your page while you run through 1000 possible email addresses every 25 seconds. Unless this got onto a really, really compelling page, I don't think anyone is going to sit around waiting for a page like this to do its business. The chances of getting a successful match are so low that I can understand why it's not a priority to fix this.
- raldi 9y agoI could use this to make a website where, when an HN admin looked at it, it looked great, but when anyone else did, it was full of ads, redirected to malware, or whatever. Reddit could use it to figure out whether various celebrities were redditors and track what they look at. Even if they never log in! And if they did log in, reddit could find out what their username was. And that's just what I was able to think up in 30 seconds.
- dpkonofa 9y agoWith your first example, you could do that but it wouldn't be realistic to do that. Like I said, you'd have to know the admin's logged in Google email address already and then they'd have to sit on that page for over 2 hours before you even hit a statistical probability of a match. It would really only work if you were trying to target one specific person. If you were fishing for users from a leak of users or something, this would literally do nothing. As for the Reddit option, Reddit would already know if the celebrities were redditors because they'd have to know their email address in advance anyways for this trick to work. No celebrity is going to risk setting up a Reddit account without an email address so Reddit already has that info. On top of that, what's reddit going to do with a celebrity's email address and username? It's already required for verification on anything important a celebrity would use it for (like an AMA or promos). Val Kilmer is a redditor. What exactly would I gain from knowing if Val Kilmer is logged in to his Google account?
- 9y ago
- yorick 9y agoNote that the demo sends your email address to the server if it's a hit. $.ajax({ url: "/google_leak/save.php?info=manual_hit:" + email }); update: gone now. still pings that it ran. don't forget to hit ctrl-shift-r to bypass your cache.
- stocktech 9y agoThis is why we can't have nice things.
- noja 9y agoThen the post should be flagged.
- marksomnian 9y agoYeah, not cool.
- AgentME 9y agoAccording to Google, the leak is working as intended, so I think your problem should be with Google if you don't like their features. Who wants to guess how long until advertisers use this to confirm their guesses for people's identities.
- TomAnthony 9y agoSorry - that was for debugging purposes and I forgot to remove it. I've removed that and purged the log.
- marksomnian 9y agoThank you - I had assumed malice, glad I was proven wrong.
- FRex 9y agoStill there for me..
- proactivesvcs 9y ago> 18th July – The team came back to me and asked me what my suggestions for handling this would be. Surely they would make an offer of how much they would like to pay the OP before they expect the OP to work for them?
- royalharsh95 9y agoyou cannot if you are using privacy badger.
- seanalltogether 9y agoI'm trying to understand the implications here. Is the author suggesting that real world attack would involve randomly generating email addresses to see if they are valid or not based on whether they might match the current user. Or would the attack involve purchasing a list known email addresses from spammers, and then doing lookup against that list for every visitor that comes to your website? Option 1 seems like it would take impossibly long to match, and I'm not sure what actionable information you get from option 2, other then maybe verifying that the email address is still active?
- TomAnthony 9y agoI didn't necessarily have a specific attack in mind when I looked for the issue. However, the way I would use it is any scenario where I want to either find out more information about a certain list of people, or where I want to alter the content I show to specfic people. It is a pretty specific attack vector, but a verifiable identification could be high impact in those few cases, and it would also be trivial to fix it.
- stevep98 9y agoWhat about if I sent a proposal with my website to a bunch of investors that I know, and I want to see which ones clicked on it.
- Viper007Bond 9y agoYou could also just use unique URLs (tracking, etc.).
- michaelhoffman 9y agoThis is an issue for those of us who do anonymous peer review of publications that include references to the authors' web sites. It's bad enough that people have tried to identify me just by location in their logs. I recommend using Tor now. But most people won't.
- TomAnthony 9y agoThat is an interesting use case. I think there are probably many similar ones.
- semi-extrinsic 9y agoWe did a a paper last year on a scientific web app; we specifically told reviewers up front that if they visited the actual page, they would show up in the logs, and gave them code+instructions for running it on localhost if they cared about that. I don't think most people are even aware; referees are domain experts, not web devs.
- askvictor 9y agoWouldn't incognito mode block this particular attack?
- bigiain 9y agoPossibly, depending on how you use it. You can be logged in to Gmail while in incognito though (I sometimes use an incognito window to log in to a personal gmail account while I've got a work account open in a non-incognito window...)
- nl 9y agoTor won't help if you are logged into Google. The best solution here against that problem is incognito mode plus a VPN.
- michaelhoffman 9y agoI only use Tor for anonymous reviewing purposes so I don't log into Google with it. But that's a good point.
- jtokoph 9y agoGoogle can probably prevent the information leak via image tags by not using a 302 redirect and instead using a 200 response and a combination of <meta refresh> and JS document.location. This way, the image tag will always fire the onError
- askmike 9y agonot that hard to replace the image with a function that does an ajax call and checks response code.
- twiss 9y agoYou can't read the response of cross-origin ajax requests unless the response specifically allows it (with CORS).
- TomAnthony 9y agoMy suggestion was simply that they add a has to go with the email parameter (since they generated the URL), such that you can't just check against an email (and you can't generate the hash). The scope of the issue is limited, but the fix also does not seem that hard. However, I appreciate it is easy to throw out such an idea, and the reality of implementing it is probably a bit harder. :)
- leephillips 9y agoYet another reason I'm glad I use uBlock Origin set to block all 3rd party requests. To get the demo to work, I had to disable uBlock.
- quakeguy 9y agoEven better to use Umatrix for browsing i think. You can enable several or all elements on a site and so on. Use it with a hosts file like the one from: someonewhocares.org and you are even better off. imo.
- TomAnthony 9y agoWorth noting that this also works with GSuite email addresses. Reddit user 'unsafeword' has suggested (https://www.reddit.com/r/netsec/comments/6smdq0/how_to_confirm_a_google_users_specific_email/ https://www.reddit.com/r/netsec/comments/6smdq0/how_to_confi...) that for organisations like schools/universities could use this for identifying their own users, as the list isn't that large.
- Cardiologist 9y agoThis would be invaluable in disaggregating traffic on a single IP, for example figuring out which student at a high school or university is connecting from a NAT address. This also works for G Suite Google accounts, such as those used by many schools? If so, given that it's easy to get the enrollment list for most schools, and given that there is usually a standard way of labeling mail accounts, you should be able to use this to identify any student at such a school. I'm surprised Google didn't deem this to be worth addressing.
- biftek 9y agoThis seems like a handy way to confirm email addresses when a user signs up to your service. If it returns false, send a regular "confirm your email" email.
- gkoberger 9y agoFirefox's BrowserID/Persona used to do something similar. If you were logged into an email account (which supported it) and you signed up for a site (which supported it), it would auto-confirm your email. I never saw it in the wild, but the demo was awesome. I wish browsers found an easy, secure way to bake this into the product. I'd much rather a confirmation modal than having to go to your email and click a link.
- spicyj 9y agoNot a great idea since it would require trusting the client unless I'm missing something.
- Retr0spectrum 9y agoIt depends on why you're checking emails. If it's just for password recovery, for example, then it's the user's loss if they intentionally use an invalid email.
- progval 9y agoThis check only works client-side, so you can't trust it to protect against spammers.
- hobarrera 9y agoWon't disabling third party cookies avoid this sort of issues?
- chrisparton1991 9y agoThis is neat, worked for me (I'm signed in to two Google accounts, both were detected). This is really neither here nor there, but your email input field isn't escaped, so JS can be injected into the email field e.g. <script>alert('Hi Tom!')</script>. I enjoy the irony of a security-minded page having this issue, even though there's no good reason for you to bother escaping the field :)
- bkovacev 9y agoOff-topic, but shout out to Tom (author of the article) and Duncan @Distilled for being great guys. I interviewed with them for a developer position few years back, and while I usually forget the interviewers these two were extremely nice. I didn't get the job, but they left a great impression. If they're hiring in the RD department at Distilled make sure to apply!
- AndrewCHM 9y ago||accounts.google.com^$image,third-party ||google.com/accounts/*$image,third-party For those that want to prevent the attack with ublocko, without filtering all 3rd party requests
- Timshel 9y agoThose issues make https://wiki.mozilla.org/Security/Contextual_Identity_Project/Containers https://wiki.mozilla.org/Security/Contextual_Identity_Projec... essential. I hope Mozilla will continue to improve the feature.