![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
加密貨幣新聞文章
Google's "Sign in with Google" Authentication Flow Flaw Lets Attackers Access Sensitive Data by Purchasing Failed Startups' Domains
2025/01/15 00:08
A "deficiency" in Google's "Sign in with Google" authentication flow has been uncovered by new research, exploiting a quirk in domain ownership to gain access to sensitive data.
"Google's OAuth login doesn't protect against someone purchasing a failed startup's domain and using it to re-create email accounts for former employees," Truffle Security co-founder and CEO Dylan Ayrey said in a Monday report.
"And while you can't access old email data, you can use those accounts to log into all the different SaaS products that the organization used."
The San Francisco-based company said the issue has the potential to put millions of American users' data at risk simply by purchasing a defunct domain associated with a failed startup and gaining unauthorized access to old employee accounts related to various applications like OpenAI ChatGPT, Slack, Notion, Zoom, and even HR systems.
"The most sensitive accounts included HR systems, which contained tax documents, pay stubs, insurance information, social security numbers, and more," Ayrey said. "Interview platforms also contained sensitive information about candidate feedback, offers, and rejections."
OAuth, short for open authorization, refers to an open standard for access delegation, allowing users to grant websites or applications access to their information on other websites without having to give their passwords. This is accomplished by making use of an access token to verify the user's identity and allow the service to access the resource the token is intended for.
When "Sign in with Google" is used to sign in to an application such as Slack, Google sends the service a set of claims about the user, including their email address and the hosted domain, which could then be utilized to log users into their accounts.
This also means that if a service is solely relying on these pieces of information to authenticate users, it also opens the door to a scenario where domain ownership changes could allow an attacker to regain access to old employee accounts.
Truffle also pointed out Google's OAuth ID token includes a unique user identifier – the sub claim – that could theoretically prevent the problem, but that has been found to be unreliable. It's worth noting that Microsoft's Entra ID tokens include the sub or oid claims to store an immutable value per user.
While Google initially responded to the vulnerability disclosure by stating that it is intended behavior, it has since re-opened the bug report as of December 19, 2024, awarding Ayrey a bounty of $1,337. It has also qualified the issue as an "abuse-related methodology with high impact."
In the meantime, there are no protections that downstream software providers can take to protect against the vulnerability in Google's OAuth implementation. The Hacker News has reached out to Google for further comment, and we will update the story if we hear back.
"As an individual, once you've been off-boarded from a startup, you lose your ability to protect your data in these accounts, and you are subject to whatever fate befalls the future of the startup and domain," Ayrey said. "Without immutable identifiers for users and workspaces, domain ownership changes will continue to compromise accounts."
免責聲明:info@kdj.com
所提供的資訊並非交易建議。 kDJ.com對任何基於本文提供的資訊進行的投資不承擔任何責任。加密貨幣波動性較大,建議您充分研究後謹慎投資!
如果您認為本網站使用的內容侵犯了您的版權,請立即聯絡我們(info@kdj.com),我們將及時刪除。
-
-
- 比特幣(BTC)的恢復繼續顯示動力,當前資產交易
- 2025-04-26 19:10:13
- 比特幣的恢復繼續表現出勢頭,在過去24小時內增長1.6%後,資產交易目前為94,288美元。
-
- 隨著加密貨幣市場的恢復,比特幣(BTC)的價格超過$ 90k
- 2025-04-26 19:05:13
- 隨著市場情緒的改善,加密市場在結束週的結束周中已有顯著的複蘇。比特幣和索拉納是一些表現最好的專業
-
- 如果您本週眨了眨眼,您會錯過很多。有一陣混亂!
- 2025-04-26 19:05:13
- 加密和華爾街比以往任何時候都更加艱難。從繫繩支持的比特幣巨頭從公開露面到Solana突然成為企業的痴迷
-
- Ada Cardano Price進入了一個強大的集會階段,現在正在關注$ 1
- 2025-04-26 19:00:13
- 在越來越多的看漲情緒,改善技術和零售和機構圈子的重新關注的驅動下。
-
- 比特幣價格集會再次捕獲頭條新聞
- 2025-04-26 19:00:13
- 比特幣價格集會再次佔領了頭條新聞,因為BTC損失了94,000美元,從而在加密貨幣市場上引起了興奮。
-
-
- 今天的PI新聞混雜,因為有積極的發展和負面發展。
- 2025-04-26 18:55:13
- 積極的事件可以幫助增強社區情緒並提高PI價格,與DAPP開發有關。
-