Pokemon Go gets full access to users' Google accounts

Developer Niantic says it is working to fix the issue

Pokemon Go can get full access to users' Google accounts, according to an IT expert who accused the game's developer of infringing users' privacy.

Adam Reeve, an IT architect at security analytics firm RedOwl, said the game, released by development house Niantic last week,  is granted full permissions to people's Google accounts, and people must have Google accounts to play the game.

Advertisement - Article continues below

"To play the game you need an account. Weirdly, Niantic won't let you just create one - you need to sign in with an existing account from one of two services - the pokemon.com website or Google. Now the Pokemon site is for some reason not accepting new signups right now so if you're not already registered there you'll need to use a Google account - and that's where the fun begins," he said in a Tumblr post.

But Reeve later looked at his Google account to see which permissions the game was granted when he logged in. He said that it had "full access" to his account.

Reeve added that full access would allow Pokemon Go to read email and send email as the account user, access Google Drive files, view search history and access private photos stored in Google Photos.

Advertisement
Advertisement - Article continues below

"What's more, given the use of email as an authentication mechanism (think "Forgot password" links) they now have a pretty good chance of gaining access to your accounts on other sites too," said Reeve.

Advertisement - Article continues below

For iOS users, there doesn't appear to be an option to edit permissions, while on Android, the app doesn't appear under Google account security permissions at all.

He added that the developers probably did this as a "result of epic carelessness", rather than planning some "global personal information heist".

In a statement to the press, Niantic, which was spun out of Google in 2015, said that it discovered that the Pokmon Go account creation process on iOS erroneously requests full access permission for the user's Google account.

"However, Pokmon Go only accesses basic Google profile information (specifically, your user ID and email address) and no other Google account information is or has been accessed or collected," the developer said.

"Once we became aware of this error, we began working on a client-side fix to request permission for only basic Google profile information, in line with the data that we actually access. Google has verified that no other information has been received or accessed by Pokmon Go or Niantic. Google will soon reduce Pokmon Go's permission to only the basic profile data that Pokmon Go needs, and users do not need to take any actions themselves."

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now
Advertisement

Recommended

Visit/software/video-conferencing/355410/zoom-50-adds-256-bit-encryption-and-ui-refresh
video conferencing

Zoom 5.0 adds 256-bit encryption to address security concerns

23 Apr 2020
Visit/security/hacking/355382/whatsapps-flaw-shoulder-surfing
hacking

WhatsApp flaw leaves users open to 'shoulder surfing' attacks

21 Apr 2020
Visit/security/cyber-security/355368/microsoft-builds-ai-to-detect-security-flaws-with-99-accuracy
cyber security

Microsoft AI can detect security flaws with 99% accuracy

20 Apr 2020
Visit/security/vulnerability/355276/businesses-brace-for-second-fujiwhara-effect-of-2020-as-patch-tuesday
vulnerability

Businesses brace for second 'Fujiwhara effect' of 2020 as Patch Tuesday looms

9 Apr 2020

Most Popular

Visit/operating-systems/microsoft-windows/355781/microsoft-confirms-further-issues-with-troublesome
Microsoft Windows

Microsoft's latest Windows 10 update is causing yet more issues

26 May 2020
Visit/mobile/5g/355712/nokia-5g-speed-record
5G

Nokia breaks 5G record with speeds nearing 5Gbps

20 May 2020
Visit/security/data-breaches/355777/easyjet-faces-class-action-lawsuit-over-data-breach
data breaches

EasyJet faces class-action lawsuit over data breach

26 May 2020