Skip to content
Search AI Powered

Latest Stories

Coding Error In Popular Pokemon Go Game Leaves Nintendo Scrambling To Reassure Users

Coding Error In Popular Pokemon Go Game Leaves Nintendo Scrambling To Reassure Users

[DIGEST: CNN, The Guardian]

Niantic Labs, the developers of augmented reality game Pokemon Go, made emergency fixes to the game after discovering the app inadvertently had been granted full access to users’ Google accounts. The permissions appeared to affect players who signed up with their Google accounts on Apple devices. According to Google, “full access” means Pokemon Go "can see and modify nearly all information in your Google Account." This includes access to email. Nintendo of America, which owns the Pokemon brand, declined comment. Pokemon Go’s release last Thursday shattered industry records and sent Nintendo’s stock soaring. To date, the game has been downloaded on Android and Apple devices more than 5 million times.


The news sparked fears that playing the game would allow its developers to not only read and send email, but edit and delete documents in Google Drive and Google Photos and access individual browser and map histories. In a statement Monday night, Niantic assured users it only sought minimal information, specifically a user’s unique player ID and email address and that it was working to reduce the user permissions required to play the smartphone game. The company admitted, however, that “the Pokemon Go account creation process on iOS erroneously requests full access."

Credit: Source.

It does not appear Niantic intentionally sought access to users’ personal data––Ingress, Niantic’s other augmented reality game, only requests minimal information from its users––but the company uses an outdated version of Google’s shared sign-on service. This approach is favored by app developers because it makes sign-up quicker and easier for players. It negates the need to create another online account using credentials already stored on their phones. Ideally, shared sign-ons should ask the user what permissions they want to grant the app. In this case, the permission-granting step was skipped because Niantic used an unsupported and out-of-date version of the sign-on process. This error then prompted Google to default to warning users that Pokemon Go had “full access” to their accounts.

It is difficult to ascertain just how much of the blame for the security scare can be apportioned between both parties, but it appears Google may have presented

the limited permissions granted as full access. “Once we became aware of this error, we began working on a client-side fix to request permission for only basic Google profile information, in line with the data that we actually access,” Niantic said. “Google has verified that no other information has been received or accessed by Pokémon Go or Niantic. Google will soon reduce Pokémon Go’s permission to only the basic profile data that Pokémon Go needs, and users do not need to take any actions themselves.”

Adam Reeve, a computer security expert at cybersecurity firm RedOwl, claimed he discovered the security vulnerability. In a blog post written Monday, Reeve said, "This is probably just the result of epic carelessness. I don't know how well they will guard this awesome new power they've granted themselves... I really wish I could play, it looks like great fun, but there's no way it's worth the risk." Mark Nunnikhoven, a computer security expert with cyber security firm Trend Micro, echoed Reeve’s concerns. "A game shouldn't require this amount of access to your data,” he said.

Credit: Source.

However, fellow cyber security expert and Trail of Bits CEO Dan Guido cast doubt on Reeve’s claim after reaching out to Google tech support. Google assured him that “full account access” does not mean a third party can read or send email, let alone access files. In a statement, Google said that “In this case, we checked that the Full account access permission refers to most of the My account settings. Specific actions such as sending emails, modifying folders, etc, require explicit permissions to that service (the permission will say "Has access to Gmail").” Reeve has since backtracked on his claim, saying he wasn’t “100 percent sure” his blog post was true. Reeve, a former senior engineering manager at Tumblr, admitted he had never built an application that uses Google account permissions and had never tested the claims he makes in his blog post.

More from News

Images from police bodycam footage of University of Iowa fraternity hazing
@TimothyJones92/X

Bodycam Footage Of Cops Discovering Bizarre Hazing Ritual In Basement Of Frat House Has The Internet Creeped Out

Disturbing video footage of a University of Iowa fraternity hazing ritual has gone viral after local authorities released police bodycam footage.

The videos show a bizarre and discomfiting scene of 56 mostly shirtless students pledging the Alpha Delta Phi fraternity seemingly confined in a filthy basement.

Keep ReadingShow less
JD Vance
Jamie McCarthy/Getty Images

JD Vance Slammed For His Comically Evil Laugh After Fox Host Asks Him About Running For President In 2028

On Tuesday, MAGA Republican Vice President JD Vance appeared on Fox News' The Story with Martha MacCallum. During the segment, Vance was asked about his future plans.

MacCallum played a clip of President Donald Trump calling Vance "fantastic," but also praising the "great job" Secretary of State Marco Rubio is doing. The Fox host then asked the VP if he wished Trump would would endorse him for President over Rubio.

Keep ReadingShow less
Meghan McCain
Roy Rochlin/Getty Images

Meghan McCain Mocked For Seemingly Just Realizing That MAGA Wants Women To Stay Home And Raise Kids

Former The View co-host Meghan McCain was widely mocked after complaining about MAGA conservatives' "harsh views" about women who don't want children—prompting many to wonder if she's been paying any attention at all.

McCain's remarks come as conservatives increasingly encourage women, particularly younger women, to prioritize motherhood. Several women tied to the administration, including Press Secretary Karoline Leavitt, Katie Miller—wife of Deputy Chief of Staff Stephen Miller—and Second Lady Usha Vance, have recently spoken publicly about their pregnancies.

Keep ReadingShow less
Reverend Jesse Jackson leads children in his empowering “I Am Somebody” chant during a 1972 appearance on Sesame Street.
Courtesy of PBS

'Sesame Street' Shares Sweet Throwback Clip Of Late Rev. Jesse Jackson Empowering Kids With 'I Am Somebody' Chant

Reverend Jesse Jackson’s iconic “I Am Somebody” declaration once again resonated with audiences of all ages when Sesame Street revisited a 1972 episode featuring the civil rights leader reciting the poem with young viewers.

In the clip, a 31-year-old Jackson stands on the show’s familiar brownstone stoop, his Afro softly rounded beneath the studio lights. He wears a purple, white, and black striped shirt and a gold medallion bearing a high-relief profile of Dr. Martin Luther King Jr., a tribute resting squarely over his heart.

Keep ReadingShow less
Screenshots of Robert F. Kennedy Jr. and Kid Rock working out
@SecKennedy/X

RFK Jr. Posts Bonkers Video Working Out Shirtless In Jeans With Kid Rock—And The Internet Can't

Health and Human Services (HHS) Secretary Robert F. Kennedy Jr. had people rolling their eyes after he shared his new "Rock Out Work Out" video promoting the Make America Healthy Again (MAGA) movement that features him and far-right singer Kid Rock working out shirtless and hanging out together.

At one point during the oddball video, the two men are shown drinking whole milk in a pool, a decision that follows the release of new federal dietary guidelines under the Trump administration that encourage consumption of full-fat dairy. Kennedy has even previously shared a video of himself drinking a glass of whole milk as a flex, footage that was amplified by the White House.

Keep ReadingShow less