I stole the data in millions of people’s Google accounts
blog.usejournal.com
blog.usejournal.com
Maybe because I don't store anything on my Google throwaway accounts, but whatever the reason, I did not mind the title being what it is.
I personally use an email with a custom domain which I pay for so I am relatively secure of keeping access to my email address. Moreover, I use a local password manager to store all my passwords. This setup is a bit of a pain but it is also liberating as I am not at the mercy of any third party when I am transacting with a service.
https://news.ycombinator.com/item?id=25717156
It's the exact same article by the same author.
This is just a teasing/enticing title to well researched and detailed content.
Wikipedia re: clickbait:
"something designed to make readers want to click on a hyperlink, especially when the link leads to content of dubious value or interest" (...) "A more commonly used definition is a headline that intentionally over-promises and under-delivers."
Blog writers don't owe HN readers anything specific, nor are they beholden to them to give them the titles/content they like. Besides clickbait there is such a thing as wanting a nice title to grab the readers attention as opposed to some description that gives away your whole ruse inside the article (which is the point here).
The title was designed to make me click on it. Even the author admitted the title is misleading just to create attention.
I flagged it. You can vouch for it if you feel differently.
> Blog writers don't owe HN readers anything specific, nor are they beholden to them to give them the titles/content they like
Even the readers of HN do not owe the blog writers anything, nor are they beholden to them to give them the votes/comments they like.
The difference being authors and posts can exist without caring about HN, but HN can't exist without content to link to. So I'd say the reverse is not true, except to individual authors. Authors dont owe HN anything, but HN does owe authors that make it to the frongpage something.
On the matter of clickbait, let's agree to disagree.
To me it's only "bait" if the result is the fish being hooked, taken out of the sea, killed and/or eaten - or, in this case, a person served BS and ads in exchange for their link clicking attention.
If the fisherman just tries to grab the fishes attention to feed it instead, and the fish even likes the food, it wouldn't be clickbait, or it wouldn't have the negative form. And same if a post author wants to use an attractive title (it's not as if all titles should be utilitarian description by decree).
Now, some decide to downvote a (IMO) good post, on the grounds they didn't like the title. I find that shallow. And I'm with the post authors on their right to give whatever title the want (but I don't agree with the readers right to complain about it when the content is good).
> Nothing I did would technically be considered an ‘exploit’
Erm, yes it can? It's exploiting a glaring vulnerability in Google's auth flow, or at the very least a dodgy way to expose master tokens.
It led to outcry from people who have custom compiled browser builds that were also caught up in the restrictions.
I'm surprised a limited time + per app + per user code isn't used, where limited time is enough to be useful for app purposes but not worth storing for long enough to be swept up in some data grab.
Scope limited is far better, and something android is bad at. I suspect they are highly constrained by the need to maintain compatibility all the way back to Android 1.0.
In my opinion, they should drop support for old android versions by default, and if you want the ability to sign into an old non-updated device, force you to go to a real browser and enable some option like "allow insecure devices".
There's really nothing stopping anyone from making an entirely fake "Sign in with X" popup and people would believe it (me included), I think teaching people to give away their Google, FB, GH etc credentials on random pages is scary.
Sometimes, i don't even understand my closest friends. This should not be anything you need to tell anyone...
From usability perspective this is better. The question is trust and security.
Even desktop software requires accounts these days. I tried to get started on a Unity project again and I spent an hour managing accounts for all the related software instead. Half my day is logging in and out of stuff.
Can you expand on this? Having been a user of multiple password managers over the years (LastPass previously, BitWarden currently) and this is exactly why I use a password manager. I have at current count, 253 different logins/passwords all with different passwords (none of which I know) saved and accessing them is automatic in my browser and a quick search (on first time use) on Android. After that it's automatic.
The problem is I can't trust Google not to send me ads (sometimes just right in my email) related to the services am signed in to.
I sleep much better these days with the above remedy.
Apart from $work, I've always opted for username, password, and 2nd factor over federated authentication. A password manager makes this very easy.
Let's say you were Google and to "help" people, you were going to "login on their behalf" to "index and organize" their info. No need to obtain consent, just fake a login and scrape away.
The rest of us can replace with quoted words with 'exploit', 'hack', and 'sell their personal info on the market to the highest bidder' but when Google does it, its ok.
EDIT: i should believe where he said he didn't do it, not whee he said he did it
> As many of you may have suspected, this post is not entirely truthful. I have not released this fitness app onto the Play Store, nor have I collected millions of master tokens. Thanks to this post for inspiration. But yes, these methods do work. I absolutely could release such an app, and so could anyone else (and maybe they have).