Skip to content
Search AI Powered

Latest Stories

Coding Error In Popular Pokemon Go Game Leaves Nintendo Scrambling To Reassure Users

Coding Error In Popular Pokemon Go Game Leaves Nintendo Scrambling To Reassure Users

[DIGEST: CNN, The Guardian]

Niantic Labs, the developers of augmented reality game Pokemon Go, made emergency fixes to the game after discovering the app inadvertently had been granted full access to users’ Google accounts. The permissions appeared to affect players who signed up with their Google accounts on Apple devices. According to Google, “full access” means Pokemon Go "can see and modify nearly all information in your Google Account." This includes access to email. Nintendo of America, which owns the Pokemon brand, declined comment. Pokemon Go’s release last Thursday shattered industry records and sent Nintendo’s stock soaring. To date, the game has been downloaded on Android and Apple devices more than 5 million times.


The news sparked fears that playing the game would allow its developers to not only read and send email, but edit and delete documents in Google Drive and Google Photos and access individual browser and map histories. In a statement Monday night, Niantic assured users it only sought minimal information, specifically a user’s unique player ID and email address and that it was working to reduce the user permissions required to play the smartphone game. The company admitted, however, that “the Pokemon Go account creation process on iOS erroneously requests full access."

Credit: Source.

It does not appear Niantic intentionally sought access to users’ personal data––Ingress, Niantic’s other augmented reality game, only requests minimal information from its users––but the company uses an outdated version of Google’s shared sign-on service. This approach is favored by app developers because it makes sign-up quicker and easier for players. It negates the need to create another online account using credentials already stored on their phones. Ideally, shared sign-ons should ask the user what permissions they want to grant the app. In this case, the permission-granting step was skipped because Niantic used an unsupported and out-of-date version of the sign-on process. This error then prompted Google to default to warning users that Pokemon Go had “full access” to their accounts.

It is difficult to ascertain just how much of the blame for the security scare can be apportioned between both parties, but it appears Google may have presented

the limited permissions granted as full access. “Once we became aware of this error, we began working on a client-side fix to request permission for only basic Google profile information, in line with the data that we actually access,” Niantic said. “Google has verified that no other information has been received or accessed by Pokémon Go or Niantic. Google will soon reduce Pokémon Go’s permission to only the basic profile data that Pokémon Go needs, and users do not need to take any actions themselves.”

Adam Reeve, a computer security expert at cybersecurity firm RedOwl, claimed he discovered the security vulnerability. In a blog post written Monday, Reeve said, "This is probably just the result of epic carelessness. I don't know how well they will guard this awesome new power they've granted themselves... I really wish I could play, it looks like great fun, but there's no way it's worth the risk." Mark Nunnikhoven, a computer security expert with cyber security firm Trend Micro, echoed Reeve’s concerns. "A game shouldn't require this amount of access to your data,” he said.

Credit: Source.

However, fellow cyber security expert and Trail of Bits CEO Dan Guido cast doubt on Reeve’s claim after reaching out to Google tech support. Google assured him that “full account access” does not mean a third party can read or send email, let alone access files. In a statement, Google said that “In this case, we checked that the Full account access permission refers to most of the My account settings. Specific actions such as sending emails, modifying folders, etc, require explicit permissions to that service (the permission will say "Has access to Gmail").” Reeve has since backtracked on his claim, saying he wasn’t “100 percent sure” his blog post was true. Reeve, a former senior engineering manager at Tumblr, admitted he had never built an application that uses Google account permissions and had never tested the claims he makes in his blog post.

More from News

James Charles
@jamescharleslol/TikTok

YouTuber James Charles Sparks Backlash For Berating Former Spirit Airlines Worker Who Sent Him GoFundMe Link After Losing Her Job

The thing about being a rich influencer is that you're only a rich influencer in the first place because the fans who watch your content made you one.

Makeup content creator James Charles seems to have forgotten this simple fact and has turned himself into the internet's latest Marie Antoinette because of it.

Keep ReadingShow less
bedazzled MAGA hat
Timothy Hurst/MediaNews Group/The Denver Post via Getty Images

Threads User's Epic Rant Ripping MAGA Fans Who Now Claim They 'Always Had Doubts' About Trump Has The Internet Applauding

As prominent MAGA minions, like QAnon conspiracy peddler and former Georgia Republican Representative Marjorie Taylor Greene, have come out against MAGA Republican President Donald Trump, so too are some lesser known individuals.

Whether it's his Iran War, his continuing saga with the Epstein files, his utter failure to keep any of his campaign promises that they banked on helping them, or the abject incompetence of his hand-picked personnel, some members of MAGA are distancing themselves from the cult.

Keep ReadingShow less
Donald Trump
Kevin Dietsch/Getty Images

Trump Ripped For Somehow Making His 'Happy Mother's Day' Post All About Himself Without Any Mention Of Melania

President Donald Trump was criticized after he "honored" mothers on Mother's Day by attacking Democrats in a self-absorbed post on Truth Social, never mentioning his wife, First Lady Melania, who is the mother of his youngest son Barron.

Instead of acknowledging her and mothers around the country, Trump gloated about the economy and accused critics of having "Trump Derangement Syndrome," targeting Democrats and Jerome Powell, the Federal Reserve Chair he's been trying to push out of his administration.

Keep ReadingShow less
Screenshot of Zach Galifianakis; Donald Trump
Conan O'Brien Needs a Friend; Jim Watson/AFP via Getty Images

Zach Galifianakis Expertly Lays Into Comedians Who Refuse To 'Challenge' Trump When He's A Guest On Their Podcasts

Actor and comedian Zach Galifianakis called out comedians who have had President Donald Trump on their podcasts and didn't "challenge" him, noting that they've effectively abdicated their role by not making jokes at Trump's expense or pushing back against things he says.

Galifianakis made that argument during a recent episode of Conan O’Brien Needs a Friend, where host Conan O'Brien remarked that few, if any, people have challenged a sitting president the way Galifianakis did when he interviewed then-President Barack Obama in 2014 on his satirical series Between Two Ferns.

Keep ReadingShow less
Screenshot of Sean Duffy
Fox News

Sean Duffy Ripped After Encouraging Americans To Take 'Road Trips' As Gas Prices Continue To Soar

Transportation Secretary Sean Duffy was called out after he encouraged Americans to take "road trips" as gas prices continue to rise as a result of President Donald Trump's war in Iran.

Republicans have faced pressure from constituents nationwide to address the rising cost of living, but Americans are feeling pain at the pump now that the Iran war, which the Trump administration kicked off in late February, has prompted a spike in gas prices.

Keep ReadingShow less