I stole the data in millions of people’s Google accounts
ethanblake4.medium.com
ethanblake4.medium.com
> As many of you may have suspected, this post is not entirely truthful. I have not released this fitness app onto the Play Store, nor have I collected millions of master tokens. ... But yes, these methods do work. I absolutely could release such an app, and so could anyone else (and maybe they have).
0: https://9to5google.com/2019/04/18/google-block-man-in-the-mi...
Finally the author admits... > Nothing I did would technically be considered an ‘exploit’
and of course, admits he lied about the title and multiple sentences in his blog... > As many of you may have suspected, this post is not entirely truthful.
Poor form.
>Mobile applications should be using the system browser, not a WebView
Maybe honest ones, however there is no reason a dishonest app that is trying to steal your Google account should stick to best practices.
>I can also make an application which opens an OAuth page to a fake-google.com which looks exactly like Google
You have ignored the part about bypassing Google's IP and location based fraud detection. Your idea wouldn't work.
- there exists a powerful token (like a master key) using which a person can read all my emails, drive, etc bypassing the email alert and unknown device check?
Or, if you mean "can Google employees read my email", then they can since almost no Google service is end-to-end encrypted (although you can e2ee Chrome sync[0]). Gmail, Drive, and Docs are completely unencrypted unless you use encryption on top of it (like with rclone[1] or cryptomator[2]).
0: https://support.google.com/chrome/answer/165139?co=GENIE.Pla....
1: https://www.section.io/engineering-education/encrypting-gdri...
Arguably, everything here is working as intended.
Users giving their password on random popups asking for it is not something google can control.
Doesn't matter what security the user has added: if they are willing to type their credentials into a web view they lose their trust.