It's worth noting that Niantic Labs (the folks who licensed Pokemon from Nintendo and made Pokemon Go) are actually owned by Google [0]. This is Google giving itself permission to do Google things. Dollars to doughnuts they tried to use some internal-only API because things kept falling over at pokemon.com. Is this a massive UX failure? Certainly. Is giving Google permission to access Google stuff a "Huge security risk"? No more than putting your stuff in Google's hands in the first place.
Niantic are also the folks behind Ingress, if you've heard of that.
Google has extremely strict safeguards in place to prevent eg. employee Joe from accessing ex-girlfriend Mary's Gmail. Very few people would have full access to individuals' Google accounts. This kind of privacy breach would be very damaging to Google.
Niantic is a tiny startup with around 50 employees. I would expect most developers within the team would have full access to the production database, or would be given access if they had a need for it. It's unlikely that there's any oversight over who can access data - it's just a 'game'.
Where are their backups stored? Are they encrypted? Who has access to the decryption keys? We don't know, but I would bet any amount of money that their systems are vastly less secure than Google's are.
The relationship between Google and Niantic isn't relevant as to whether they are capable of keeping these credentials secure.
> Google has extremely strict safeguards in place to prevent eg. employee Joe from accessing ex-girlfriend Mary's Gmail
I know a bit about google's internal privacy safeguards (including how long they've been in place), and I know a bit (nothing that wasn't in the news) about the NSA's internal privacy safeguards from a certain point in time.
Obviously I don't know what it's like at the NSA today, but it's worth laughing (or crying) at the fact that there was a time when Google placed more restrictions and security in place to protect its users from rogue employees than the NSA did.
That's because the NSA does a lot more thorough background checks and has a nation-centered mission, while Google hires people relatively unchecked and of all nationalities and all over the world.
And in terms of abuse (i.e. LOVEINT), which strategy do you think has proven to be more sound? Hiring only good people, as verified by a thorough background check? Or hiring probably good people, and then using robust checks and balances anyway?
Even if they are a startup within Google, what does that mean for my security as a user?
Do they store this API key with full access to a Google account the same way that an official Google app (e.g. Gmail itself) stores my secret data? If so, I probably trust it. Or do they just throw it in a GCE database without a whole lot of thought around a security policy since they're still a fast-moving startup, and maybe my credentials get logged somewhere, or synced to an analytics system that's not treated as classified and a whole bunch of employees can inadvertantly access, etc
Seems like I have no way of knowing (unless maybe it's in their terms of service?). It could very well be a "Huge security risk"
You're absolutely right - Niantic's history with Google does not preclude them having crummy security practices that we aren't aware of.
However, "Popular thing possibly has crummy security practices (we just don't know)" isn't HN-worthy, it's just FUD. I think both of us would prefer a HN full of well-researched articles over one full of clickbait FUD.
>However, "Popular thing possibly has crummy security practices (we just don't know)" isn't HN-worthy, it's just FUD.
Bullcrap. Best security policy is trust, but verify.
Assuming that well established businesses have good security practices without doing proper review is what allowed all those fraudulent SWIFT transactions to go through a few months ago. It's perfectly valid to ask why the hell Pokemon Go thinks it needs access to your private email.
Actually, that's all there is to "research" about this topic, as there is nothing available to read around what they could possibly use the full access tokens in any terms of service or application literature.
Not FUD to me. I am not going to install Pokemon Go until this is cleared up. I am glad he pointed it out, since I may have clicked through given I would have made quick judgements about them being Google-owned.
One thing the article is wrong about is that you can create a new account a pokemon.com (bypassing the google kerfuffle). You just need to keep reloading until it let's you past the "try again in an hour" message.
Right, so not only did they spend a significant amount of time steeping in Google itself, the big G then invested a significant amount of cash into the now-spun-out company. I'd say that qualifies as 'owned'.
How does that make the permission creep OK? If they were part of Google, and already had access to the data, that's one thing. But they aren't, and they don't.
Even if Google Inbox were asking for full permissions I'd be extremely sketched out about that, but it wouldn't happen because Google developers are, by and large, on top of things.
A third-party company, even with significant investment and history with Alphabet, requesting full access to my Google account despite needing ZERO access (i.e. for what they need, requesting no permissions would suffice) is sketchy and inherently untrustworthy.
Pretty much. Google was trying to cram the entire Chrome OS platform in their browser a while back (remember Chrome's Windows 8 mode?), although they've kind of taken a step back from it lately.
Niantic Labs became independent from Google during the forming of Alphabet so it is to say you are still giving an independent third party access to your google account.
This doesn't mean shit. You still give another legal entity access to your data. Different company, different people, different management, different EULA.
I saw the prototype of Pokemon Go in 2014 as an April 1st campaign by Google Maps, surely this is a very tight bond with Google. I won't worry about it either.
>Dollars to doughnuts they tried to use some internal-only API
Not at all necessary for this situation to occur. I just finished implementing a system (nothing to do with Pokemon) that also requests permission from external sites in a similar way. The mechanics for doing this are fiddly and checking this is actually set up correctly is likely well down the priority list provided things at least appear to work.
It is entirely possible that someone who had never done it before set it up in a hurry then everyone in the dev team just blindly clicked through without ever properly reading what was being requested because they were all in a rush to finish their stuff.
Most tech people realized 20 years ago email is a terrible place for confidential information unless you have OPSEC and use PGP. If you trust your plain text email traveling around the world and stored in Google's cloud it seems stupid to worry about someone accessing it.
Also Gmail allows you to create more than one account. Instead of all this alarmism in media just tell people they should create a separate account in Gmail just for games instead of using the one you are worried about some big billion dollar company accessing it (which they already do).
Niantic are also the folks behind Ingress, if you've heard of that.
[0] Specifically, Alphabet owns a significant portion of Niantic, along with Nintendo: https://nianticlabs.com/blog/niantic-tpc-nintendo/ (they were previously wholly-owned by Google).