6 ms·
These personal details could then be used to access the users' bank details. That's also more than enough information to be able to access your other
by recurser 14y ago
These personal details could then be used to access the users' bank
details. That's also more than enough information to be able to access
your other devices which could also be mined for more data - insurance
information, other credit cards - which could then be used to access
your banking credentials.
Do developers have access to users' bank details? How would anyone access 'other devices' with just a name, address and email? This seems a little far-fetched.
- taproot 14y agoSocial engineering, name, address and email is enough to own anyone. For most things, maybe not on their own, but having these three keys its pretty easy to track down ph number, dob, and a number of other details. The only reason this poses a security "threat" is because utility companies, banks, and other institutions use these "personal" bits of information like a password. And from what I hear, in the US your SSN's are used like this rather often as well. I once had a long discussion with some call center manager about how using my DOB as a password to being able to cancel my account was hideously crappy and insecure, needless to say "its company policy" and there wasn't anything I could do to avoid it. (Yes I'm one of those people, but I really had nothing better to do and trolling some random call center staff is one of my favorite pastimes) I probably should have put this nearer the top but oh well, to conclude, its not really a big deal, and hardly any different to any other commerce where you hand over this information along with your credit card. The only reason people are up and arms about it is because its too easy to get snagged by some identity thief uploading an seemingly legit application. In reality, there is easier ways to own someone in a targeted attack. Simple solution: don't use your main google account for the play store, you can have multiple google accounts applied to android and pick and choose which to use for play store and which to use for gmail etc.
- kysol 14y agoWorse case scenario that I can think of is that they use the same password for their email as they used for the in-app auth in the App they bought. Next step would be for the app creator to login, see what they can use to create requests for other personal credentials. Facebook password reminder, they get in, then they have the user's DoB and family information (for those stupid companies still using "what's your mothers maiden name" password reminder questions). You could probably do a fair chunk of damage, but that's all based off the fact that the user would have to be silly enough to still use the same password over multiple services. Yes I know... we've been telling them for far too long, but people still don't listen. They think that if their bank password and their email password are different then they are safe.
- eurleif 14y agoIf the user is already setting a password in the app, couldn't the app just ask for the user's email address? It doesn't seem like having the email address for free really buys a malicious developer that much.
- kysol 14y agoThe argument there would be that the user "provided" the app owner with their email address, where at this point Google is just giving it to them. Don't get me wrong, I'm on the, I don't care side. I was in a store one day when the clerk asked the customer for their postcode, the customer went nuts saying that he shouldn't have to tell them. Three minutes of arguing could have been shortened to "INSERT FAKE NUMBER" if he was really that against giving his real post code.