Pokemon Go is a huge security risk
Updates: Niantic have addressed the issue, see my final post here. I’ve also posted responses to some FAQs in a post here. Original post is below.
I figured I’d post this because I don’t see anyone else talking about it and it bothers me. If you didn’t know, Pokemon Go is the latest in the long running series of games from Nintendo (although Go is actually made by a developer called Niantic). It’s also the first (I think) to run on your phone. Needless to say, it’s a huge hit. And it looks like a ton of fun - pretty much everyone I know is playing it.
But there’s a problem.
To play the game you need an account. Weirdly, Niantic won’t let you just create one - you need to sign in with an existing account from one of two services - the pokemon.com website or Google. Now the Pokemon site is for some reason not accepting new signups right now so if you’re not already registered there you’ll need to use a Google account - and that’s where the fun begins.
I started the game, hit the Google button, and was redirected to log in. Normally you’d see a little message saying what data the app is going to be able to access - something like “This app will be able to view your email address and name”. For some reason that’s not shown in this case, but I went ahead and logged in anyway. Then on a whim I went to see which permissions it was granted (you can see for your own account right here). To say I was a little stunned is putting it lightly - it said:
Pokemon Go has full access to your Google account
Here are a couple of excerpts from the Google help page about what this means:
When you grant full account access, the application can see and modify nearly all information in your Google Account
This “Full account access” privilege should only be granted to applications you fully trust, and which are installed on your personal computer, phone, or tablet.
Let me be clear - Pokemon Go and Niantic can now:
- Read all your email
- Send email as you
- Access all your Google drive documents (including deleting them)
- Look at your search history and your Maps navigation history
- Access any private photos you may store in Google Photos
- And a whole lot more
What’s more, given the use of email as an authentication mechanism (think “Forgot password” links) they now have a pretty good chance of gaining access to your accounts on other sites too.
And they have no need to do this - when a developer sets up the “Sign in with Google” functionality they specify what level of access they want - best practices (and simple logic) dictate you ask for the minimum you actually need, which is usually just simple contact information.
Now, I obviously don’t think Niantic are planning some global personal information heist. This is probably just the result of epic carelessness. But I don’t know anything about Niantic’s security policies. I don’t know how well they will guard this awesome new power they’ve granted themselves, and frankly I don’t trust them at all. I’ve revoked their access to my account, and deleted the app. I really wish I could play, it looks like great fun, but there’s no way it’s worth the risk.
cerealdealer reblogged this from adamreeve
kittylovesbooks reblogged this from godly-sinsx
godly-sinsx reblogged this from adamreeve
mattelka liked this
piratelorddoflamingo reblogged this from a-redharlequin
zjalthehappyhedgehog19 reblogged this from adamreeve
a-redharlequin reblogged this from adamreeve
a-redharlequin liked this
pensandthings liked this
boozer-pitt reblogged this from adamreeve and added:http://antoine-roquentin.tumblr.com/post/147326249333/john-hanke-the-guy-who-founded-niantic-the
boozer-pitt liked this
subconscious-madness liked this
rattile reblogged this from adamreeve
carneliane liked this
cinnamon-r011 liked this
eydgamer liked this
thepaperlibrarian reblogged this from thepaperlibrarian and added:I posted this a while back after I heard the security risk, but I wanted to update now since Niantic fixed it. Pokemon...
stickybiscuits liked this
ohmyoverland liked this
desmondssmiles reblogged this from adamreeve and added:i do get your point, but a) it’s very easy to find the privacy policy of niantic (it’s right here –>...
hirotak liked this
aylinmoon reblogged this from adamreeve
sunlit-sonder reblogged this from catws
sunlit-sonder liked this
whsupbro reblogged this from adamreeve
whsupbro liked this
snowsoldier liked this
ssupernnovaa reblogged this from catws
fantasticsimplyfantastic liked this
michaelfassbendr liked this
catws reblogged this from cortney
schumbug reblogged this from adamreeve
aintnomessnomo liked this
pixelpiano reblogged this from adamreeve
pixelpiano liked this
j-h-s liked this
kapitanluffy liked this
marrylouharry reblogged this from adamreeve
lucypl reblogged this from latining
blogawaend reblogged this from latining and added:nah this has been debunked
trubutt reblogged this from adamreeve and added:lmao this is fake
ferventbeing liked this
latining reblogged this from thefeistybirb
achanisbored reblogged this from adamreeve
respectyoursister reblogged this from ninarosehotchkiss
ninarosehotchkiss liked this
ninarosehotchkiss reblogged this from xmagnet-o
navy-knight liked this
lettersiarrange reblogged this from absentlyabbie- Show more notes