....Sounds like an awesome opportunity to fuzz that API, and dump the entirety of Google's "compromised credential" DB.
For research purposes only of course. I'm sure they provisioned enough instance to handle a rather aggressive fuzzing as well seeing as this thing is surely built to stand up to the entire Chrome using internet logging in at the same time, right?
And surely there is no way whatsoever one could use this data to potentially compromise other accounts...
Or use it as a basis for birthday attacks on unreported compromised accounts. Or, set up some unique credentials in compromised systems, then checking the googleapi call for it to see if the intrusion has been reported/caught yet.
Ahhhh side channels. Yes, side channels. Fnord.