Skip to content
Search AI Powered

Latest Stories

Coding Error In Popular Pokemon Go Game Leaves Nintendo Scrambling To Reassure Users

Coding Error In Popular Pokemon Go Game Leaves Nintendo Scrambling To Reassure Users

[DIGEST: CNN, The Guardian]

Niantic Labs, the developers of augmented reality game Pokemon Go, made emergency fixes to the game after discovering the app inadvertently had been granted full access to users’ Google accounts. The permissions appeared to affect players who signed up with their Google accounts on Apple devices. According to Google, “full access” means Pokemon Go "can see and modify nearly all information in your Google Account." This includes access to email. Nintendo of America, which owns the Pokemon brand, declined comment. Pokemon Go’s release last Thursday shattered industry records and sent Nintendo’s stock soaring. To date, the game has been downloaded on Android and Apple devices more than 5 million times.


The news sparked fears that playing the game would allow its developers to not only read and send email, but edit and delete documents in Google Drive and Google Photos and access individual browser and map histories. In a statement Monday night, Niantic assured users it only sought minimal information, specifically a user’s unique player ID and email address and that it was working to reduce the user permissions required to play the smartphone game. The company admitted, however, that “the Pokemon Go account creation process on iOS erroneously requests full access."

Credit: Source.

It does not appear Niantic intentionally sought access to users’ personal data––Ingress, Niantic’s other augmented reality game, only requests minimal information from its users––but the company uses an outdated version of Google’s shared sign-on service. This approach is favored by app developers because it makes sign-up quicker and easier for players. It negates the need to create another online account using credentials already stored on their phones. Ideally, shared sign-ons should ask the user what permissions they want to grant the app. In this case, the permission-granting step was skipped because Niantic used an unsupported and out-of-date version of the sign-on process. This error then prompted Google to default to warning users that Pokemon Go had “full access” to their accounts.

It is difficult to ascertain just how much of the blame for the security scare can be apportioned between both parties, but it appears Google may have presented

the limited permissions granted as full access. “Once we became aware of this error, we began working on a client-side fix to request permission for only basic Google profile information, in line with the data that we actually access,” Niantic said. “Google has verified that no other information has been received or accessed by Pokémon Go or Niantic. Google will soon reduce Pokémon Go’s permission to only the basic profile data that Pokémon Go needs, and users do not need to take any actions themselves.”

Adam Reeve, a computer security expert at cybersecurity firm RedOwl, claimed he discovered the security vulnerability. In a blog post written Monday, Reeve said, "This is probably just the result of epic carelessness. I don't know how well they will guard this awesome new power they've granted themselves... I really wish I could play, it looks like great fun, but there's no way it's worth the risk." Mark Nunnikhoven, a computer security expert with cyber security firm Trend Micro, echoed Reeve’s concerns. "A game shouldn't require this amount of access to your data,” he said.

Credit: Source.

However, fellow cyber security expert and Trail of Bits CEO Dan Guido cast doubt on Reeve’s claim after reaching out to Google tech support. Google assured him that “full account access” does not mean a third party can read or send email, let alone access files. In a statement, Google said that “In this case, we checked that the Full account access permission refers to most of the My account settings. Specific actions such as sending emails, modifying folders, etc, require explicit permissions to that service (the permission will say "Has access to Gmail").” Reeve has since backtracked on his claim, saying he wasn’t “100 percent sure” his blog post was true. Reeve, a former senior engineering manager at Tumblr, admitted he had never built an application that uses Google account permissions and had never tested the claims he makes in his blog post.

More from News

Teacher leading math class
Compassionate Eye Foundation/Steven Errico/Getty Images

Teacher Stunned After Student Argues That People Shouldn't Have To 'Think Anymore' Thanks To ChatGPT

There's no doubt that ChatGPT and similar tools are growing in relevance and application, and they're growing fast. The problem is that many people, especially younger individuals, seem to struggle with how much they should depend on the tools.

We already knew that ChatGPT could be a problem regarding critical thinking and creativity, so maybe we should have anticipated the mindsets that would develop, snubbing independent thinking when tools like ChatGPT are available.

Keep ReadingShow less
Rapunzel and crows at Tokyo DisneySea
@PopBase/X

Video Of Crows Ripping Out Animatronic Rapunzel's Hair At Tokyo DisneySea Goes Viral—And Yikes!

Disney princesses are usually known for their whimsical singing and befriending creatures from all across the animal kingdom, but Princess Rapunzel at Tokyo DisneySea may have misunderstood the assignment.

Earlier this week, Rapunzel was caught on video at DisneySea in Tokyo, but she didn't go viral for her cheery demeanor or her singing voice, which passers-by can hear from the base of her elegant tower. Rather, it was a pair of intruders who put her in the spotlight.

Keep ReadingShow less
Man getting a haircut
YakobchukOlena/Getty Images

Bald Men Are Up In Arms Over Viral Chart That Predicts Political Affiliation Based On A Man's Haircut

Can a man's haircut tell you his political affiliation? Scientifically, of course not... but we probably all have a gut feeling about it, regardless!

And a TikToker has followed that lead by developing a chart that predicts a man's political persuasion based on his hair alone—and bald men are NOT happy about it.

Keep ReadingShow less
transgender pride flag in front of Supreme Court
Heather Diehl/Getty Images

Republicans Slammed For Soulless One-Word Response To Democrats' Trans Day Of Visibility Tweet

According to research by the Williams Institute at UCLA School of Law, transgender people in the United States were over four times more likely than cisgender people to be victims of violent crime based on statistics from 2017-2018. A study by the non-profit Everytown for Gun Safety found the number of trans people murdered in the U.S. nearly doubled between 2017and 2021.

In the last 5–9 years, those figures have only increased as the Republican Party has made trans people the target of many of their political campaigns and legislative actions.

Keep ReadingShow less
Pete Hegseth; Screenshot of Kid Rock during Army helicopter fly-by
Mandel Ngan/AFP via Getty Images; @KidRock/X

Pete Hegseth Slammed After Calling Off Investigation Into Army Helicopter Fly-By At Kid Rock's House

Defense Secretary Pete Hegseth was criticized for calling off the U.S. Army's investigation after MAGA musician Kid Rock posted a video of an Army Apache helicopter doing a fly-by at his Nashville home.

The video shows Kid Rock saluting as the aircraft hovers near his property, standing next to a replica Statue of Liberty by his pool. In the brief clip, a helicopter that appears to be an AH-64 Apache—an attack helicopter used by the U.S. Army and National Guard—flies at low altitude near his estate in Whites Creek.

Keep ReadingShow less