Slash Boxes

SoylentNews is people

Submission Preview

No link to story available

[please merge with #20089, Google: attack affected “fewer than 0.1 percent” of Gmail users]

Accepted submission by butthurt at 2017-05-09 10:07:28

According to a Motherboard article [], the attacker was able to use OAuth [] to impersonate Google, and a security researcher says

[...] he warned Google directly about this vulnerability in 2012, and suggested that Google address it by checking to [...] ensure the name of any given app matched the URL of the company behind it.

Original Submission