Skip to content
Search AI Powered

Latest Stories

Coding Error In Popular Pokemon Go Game Leaves Nintendo Scrambling To Reassure Users

Coding Error In Popular Pokemon Go Game Leaves Nintendo Scrambling To Reassure Users

[DIGEST: CNN, The Guardian]

Niantic Labs, the developers of augmented reality game Pokemon Go, made emergency fixes to the game after discovering the app inadvertently had been granted full access to users’ Google accounts. The permissions appeared to affect players who signed up with their Google accounts on Apple devices. According to Google, “full access” means Pokemon Go "can see and modify nearly all information in your Google Account." This includes access to email. Nintendo of America, which owns the Pokemon brand, declined comment. Pokemon Go’s release last Thursday shattered industry records and sent Nintendo’s stock soaring. To date, the game has been downloaded on Android and Apple devices more than 5 million times.


The news sparked fears that playing the game would allow its developers to not only read and send email, but edit and delete documents in Google Drive and Google Photos and access individual browser and map histories. In a statement Monday night, Niantic assured users it only sought minimal information, specifically a user’s unique player ID and email address and that it was working to reduce the user permissions required to play the smartphone game. The company admitted, however, that “the Pokemon Go account creation process on iOS erroneously requests full access."

Credit: Source.

It does not appear Niantic intentionally sought access to users’ personal data––Ingress, Niantic’s other augmented reality game, only requests minimal information from its users––but the company uses an outdated version of Google’s shared sign-on service. This approach is favored by app developers because it makes sign-up quicker and easier for players. It negates the need to create another online account using credentials already stored on their phones. Ideally, shared sign-ons should ask the user what permissions they want to grant the app. In this case, the permission-granting step was skipped because Niantic used an unsupported and out-of-date version of the sign-on process. This error then prompted Google to default to warning users that Pokemon Go had “full access” to their accounts.

It is difficult to ascertain just how much of the blame for the security scare can be apportioned between both parties, but it appears Google may have presented

the limited permissions granted as full access. “Once we became aware of this error, we began working on a client-side fix to request permission for only basic Google profile information, in line with the data that we actually access,” Niantic said. “Google has verified that no other information has been received or accessed by Pokémon Go or Niantic. Google will soon reduce Pokémon Go’s permission to only the basic profile data that Pokémon Go needs, and users do not need to take any actions themselves.”

Adam Reeve, a computer security expert at cybersecurity firm RedOwl, claimed he discovered the security vulnerability. In a blog post written Monday, Reeve said, "This is probably just the result of epic carelessness. I don't know how well they will guard this awesome new power they've granted themselves... I really wish I could play, it looks like great fun, but there's no way it's worth the risk." Mark Nunnikhoven, a computer security expert with cyber security firm Trend Micro, echoed Reeve’s concerns. "A game shouldn't require this amount of access to your data,” he said.

Credit: Source.

However, fellow cyber security expert and Trail of Bits CEO Dan Guido cast doubt on Reeve’s claim after reaching out to Google tech support. Google assured him that “full account access” does not mean a third party can read or send email, let alone access files. In a statement, Google said that “In this case, we checked that the Full account access permission refers to most of the My account settings. Specific actions such as sending emails, modifying folders, etc, require explicit permissions to that service (the permission will say "Has access to Gmail").” Reeve has since backtracked on his claim, saying he wasn’t “100 percent sure” his blog post was true. Reeve, a former senior engineering manager at Tumblr, admitted he had never built an application that uses Google account permissions and had never tested the claims he makes in his blog post.

More from News

Screenshots from @realprogressive11's TikTok video
@realprogressive11/TikTok

Rural Michigan Woman Speaks Out About 'Dystopian' Grocery Costs In Eye-Opening Video

TikToker @realprogressive11, a rural Michigan resident, is tired of dancing around the subject and is ready to call it like it is: according to her, grocery shopping has become a "dystopian" experience.

And based on other TikTokers' experiences, this isn't specific to Michigan.

Keep ReadingShow less
Andrew Rannells Just Dished On How Dating Anderson Cooper At 25 Directly Inspired 'Girls' Storyline—And Our Jaws Are On The Floor
Daily Beast/Obsessed; Gary Gershoff/Getty Images

Andrew Rannells Just Dished On How Dating Anderson Cooper At 25 Directly Inspired 'Girls' Storyline—And Our Jaws Are On The Floor

After years of speculation, the tea has finally been spilled about who inspired Elijah Krantz and Dill Harcourt's relationship.

In case you missed it, the hit TV show Girls aired for six seasons from 2012 to 2017, and followed the lives of four young women making their way through early romance and career moves in New York City.

Keep ReadingShow less
Tom Holland and Zendaya
Pablo Cuadra/WireImage/Getty Images

Tom Holland Just Confirmed The Months-Long Rumors That He And Zendaya Got Married—And His Comments Have Fans Swooning

American actor and singer Zendaya and British actor and dancer Tom Holland first met in 2016 during the screen test and casting process for their roles in the 2017 Marvel made/Sony approved movie Spider-Man: Homecoming. The pair, both born in 1996, were successful child actors transitioning into adults, but still playing teens on camera.

They became fast friends, but didn't begin dating until sometime later, even if fans thought the attraction happened much sooner. They finally confirmed their relationship in 2021.

Keep ReadingShow less
Billy Porter; Elisabeth Hasselbeck
CBS Mornings

Elisabeth Hasselbeck Is Getting Some Major Side-Eye After Making Bizarre Dig At Billy Porter During Interview

Conservative TV host Elisabeth Hasselbeck first gained public notice in 2001 as a contestant on the second season of the CBS reality show Survivor, then she furthered her fame by marrying NFL player Tim Hasselbeck the following year.

After that, she became the conservative voice on The View for a decade (2003-2013), frequently clashing with her co-hosts and garnering animosity from viewers. Portraying herself as a trad-wife while in reality being a working mother, her next stint was on Fox News' Fox & Friends from 2013 to 2015 before being replaced by Sean Hannity paramour Ainsley Earhardt.

Keep ReadingShow less
Screenshots of JD Vance and Whoopi Goldberg
Fox News; The View

JD Vance Ripped After Running To Fox News To Whine About Whoopi Goldberg Supposedly Calling Him 'Racist' On 'The View'

Vice President JD Vance was criticized after he complained on Fox News that The View moderator Whoopi Goldberg had called him a "racist" during his appearance on the program.

While on The View, Vance sidestepped a question from Goldberg about concerns that the Trump administration was marginalizing Black history and communities.

Keep ReadingShow less