6 ms·
Worse case scenario that I can think of is that they use the same password for their email as they used for the in-app auth in the App they bought. Next step w
by kysol 14y ago
Worse case scenario that I can think of is that they use the same password for their email as they used for the in-app auth in the App they bought.
Next step would be for the app creator to login, see what they can use to create requests for other personal credentials. Facebook password reminder, they get in, then they have the user's DoB and family information (for those stupid companies still using "what's your mothers maiden name" password reminder questions).
You could probably do a fair chunk of damage, but that's all based off the fact that the user would have to be silly enough to still use the same password over multiple services. Yes I know... we've been telling them for far too long, but people still don't listen. They think that if their bank password and their email password are different then they are safe.
- eurleif 14y agoIf the user is already setting a password in the app, couldn't the app just ask for the user's email address? It doesn't seem like having the email address for free really buys a malicious developer that much.
- kysol 14y agoThe argument there would be that the user "provided" the app owner with their email address, where at this point Google is just giving it to them. Don't get me wrong, I'm on the, I don't care side. I was in a store one day when the clerk asked the customer for their postcode, the customer went nuts saying that he shouldn't have to tell them. Three minutes of arguing could have been shortened to "INSERT FAKE NUMBER" if he was really that against giving his real post code.