Engineering Evil

Intel Portal for Weighted Data and Information ( ARCHIVED – HISTORICAL)

  • Home
  • Home
  • Psionic / Psychic Warfare Archives
  • Historical Hacking Archive
  • Biologically Wired Differently Conservatives and Liberals

Home › Technology › Cyber Security › Hey, you know Android apps can ‘access ALL’ of your Google account?

Hey, you know Android apps can ‘access ALL’ of your Google account?

By Ralph Turchiano on August 6, 2013

 

One-click login hands over keys to Gmail, Google Drive et al, says researcher

By       Bill Ray

Posted in Security,               6th August 2013 13:03 GMT      

The single-click Google account login for Android apps is a little too convenient for hackers, according to Tripwire’s Craig Young, who has demonstrated a flaw in the authentication method.

The mechanism is called “weblogin”, and basically it allows users to use their Google account credentials as authentication for third-party apps, without sharing the username and password itself: a token is generated to represent the user’s login details.

Young claimed the unique token used by Google’s weblogin system can be harvested by a rogue app and then used to access all of the advertising’s giants services as that user.

To demonstrate the flaw at this month’s Def Con 21 hacking conference in Las Vegas, Young created an Android app that asks for access to the user’s Google account to display stocks from Google Finance.

Assuming the user grants permission the app, it issues a token to access the requested data. The rogue app sends that token back to the hacker, who can paste it into a web session to access all of the user’s Google services, said Young.

That includes unrestricted access to Gmail, Google Drive, Google Calendar and so forth, even though the permission was only given for an Android app to access Google Finance, we’re told.

Users do have to give multiple permissions to the app first: to access local accounts; to access the network; and to kick off a web session accessing finance.google.com – the last bit being when the web-usable token is issued. But if the user is expecting integration with Google Finance, then none of that would surprise them.

Handing over the keys to their Google Drive files would, however.

Once the miscreant has a valid token then they could see their mark’s search history, among other things. Young points out that should our victim happen to be a Google Administrator then the attacker could take control of the administered accounts, changing passwords, modifying privileges, etc.

But they’ll have to move fast – Google’s automated scanning may not have noticed the app’s behaviour (his rogue app was only removed from the Google Play app store following a complaint despite being clearly marked as a security test) but since being informed about the vuln in February the Chocolate Factory has been working to close the security hole. (The the PC World blog has more details on the bloke’s research.)

The flaw is typical of what happens when simplicity overtakes security in developers’ order of priorities. It’s unlikely that anyone but the most-dedicated spear-phisher would take advantage of a flaw like this, but its exposure reminds us to be aware of the permissions we grant – and keeps Google et al fixing flaws which shouldn’t exist in the first place. ®

Related stories

  •                   Earn £8,000 a MONTH with bogus apps from Russian malware factories                                  (5 August 2013)http://www.theregister.co.uk/2013/08/05/mobile_malware_lookout/
  •                   Psst. Want to stop the data drip of leaky clouds but don’t know how? Look here                                  (5 August 2013)                  http://www.theregister.co.uk/2013/08/05/keep_on_syncingsafely/
  •                   Lost phone? Google’s got an app for that, coming this month                                  (3 August )

 

 

Original URL: http://www.theregister.co.uk/2013/08/06/android_oneclick_authentication_open_to_hacking/

 

Share this:

  • Click to share on Reddit (Opens in new window) Reddit
  • Click to email a link to a friend (Opens in new window) Email
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on X (Opens in new window) X
  • Click to share on Tumblr (Opens in new window) Tumblr
  • Click to share on Pinterest (Opens in new window) Pinterest
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to print (Opens in new window) Print
Like Loading...

‹ Radioactive water at Fukushima an emergency / Contaminated water could rise to the ground’s surface within three weeks
Military Tests Data Mining of Social Media for Special Ops “QUANTUM LEAP” ›

Categories: Cyber Security

Tags: Android, Craig Young, Gmail, Google, Google Account, Google Drive, Google Finance, PC World

Related Articles
  • Researchers hide information in plain text
  • Bitcoin wallet devices vulnerable to security hacks, study shows
  • Developing a secure, un-hackable net
  • NTU study finds that hackers could guess your phone PIN using its sensor data

Now Archiving and Organizing Historical Data

  • Biologically Wired Differently Conservatives and Liberals
  • Historical Hacking Archive
  • Psionic / Psychic Warfare Archives

Search Articles

Translator

Enter your email address to follow this blog and receive notifications of new posts by email.

Join 1,878 other subscribers

Top Trending Articles (Last 48 hours)

  • Is the end of the world really nigh? Authorities reassure Russians over Mayan Armageddon prophecy amid reports of 'unusual behaviour'
  • Shame Tags for Vaccine Refusers
  • Boy, 15, kills himself after 'facing expulsion and being put on sex offender registry' for STREAKING at high school football game
  • Common parasite may trigger suicide attempts - "seven times more likely to attempt suicide"
  • Doctor Burnout at epidemic levels as we push for 24 hour work shifts

Recent Posts: CLINICALNEWS.ORG

The Effects of Rhodiola on Athlete Fatigue and Recovery Ep.1270 DEC 2025

New Study: Vitamin D Reduces Recurrent Heart Attacks by 50%? Ep. 1269 NOV 2025

NAD+ Reverses Alzheimer’s Deficits: New Study Explains How | Ep. 1268 (NOV 2025)

New Study: Billygoat Weed Improves Osteoarthritis Pain in 12 Weeks Ep. 1267 NOV 2025

New Study: Dark Chocolate Boosts Speed & Reduces Fatigue Ep. 1266 NOV 2025

Cannot load blog information at this time.

Engineering Evil Tweets

Tweets by RalphTurchiano

EngineeringEvil

EngineeringEvil

Traffic Velocity

  • 1,113,532 hits

EngineeringEvil

EngineeringEvil
Create a free website or blog at WordPress.com.
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.
To find out more, including how to control cookies, see here: Cookie Policy
  • Reblog
  • Subscribe Subscribed
    • Engineering Evil
    • Join 1,538 other subscribers
    • Already have a WordPress.com account? Log in now.
    • Engineering Evil
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Copy shortlink
    • Report this content
    • View post in Reader
    • Manage subscriptions
    • Collapse this bar
%d