Welcome to WebmasterWorld Guest from 54.162.117.84

Forum Moderators: incrediBILL & lawman

Message Too Old, No Replies

Report: Google Android One-Click Login Is A User Risk

     
11:55 am on Aug 5, 2013 (gmt 0)

Administrator from GB 

WebmasterWorld Administrator engine is a WebmasterWorld Top Contributor of All Time 10+ Year Member Top Contributors Of The Month

joined:May 9, 2000
posts:23150
votes: 344


A feature that allows Android users to authenticate themselves on Google websites without having to enter their account password can be abused by rogue apps to give attackers access to Google accounts, a security researcher showed Saturday at the Defcon security conference in Las Vegas.

The feature is called "weblogin" and works by generating a unique token that can be used to directly authenticate users on Google websites using the accounts they have already configured on their devices.

Report: Google Android One-Click Login Is A User Risk [pcworld.com]
12:39 pm on Aug 5, 2013 (gmt 0)

Senior Member from LK 

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month

joined:Nov 16, 2005
posts: 2509
votes: 31


This is not so bad: it requires a "rogue app" with certain permissions.

I do not think ANY OS is secure against malicious software installed by a user.

Desktops are better IF you configure them correctly (Linux with App Armour for example - no idea what Mac/Windows equivalents would be), but VERY few people do that.

In fact, Android is quite good because it does limit permissions at the App level by default, so if you keep an eye on what you are doing when you install, you may spot something suspicious about these apps.