![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
![]() |
|
加密货币新闻
Google's "Sign in with Google" Authentication Flow Flaw Lets Attackers Access Sensitive Data by Purchasing Failed Startups' Domains
2025/01/15 00:08
A "deficiency" in Google's "Sign in with Google" authentication flow has been uncovered by new research, exploiting a quirk in domain ownership to gain access to sensitive data.
"Google's OAuth login doesn't protect against someone purchasing a failed startup's domain and using it to re-create email accounts for former employees," Truffle Security co-founder and CEO Dylan Ayrey said in a Monday report.
"And while you can't access old email data, you can use those accounts to log into all the different SaaS products that the organization used."
The San Francisco-based company said the issue has the potential to put millions of American users' data at risk simply by purchasing a defunct domain associated with a failed startup and gaining unauthorized access to old employee accounts related to various applications like OpenAI ChatGPT, Slack, Notion, Zoom, and even HR systems.
"The most sensitive accounts included HR systems, which contained tax documents, pay stubs, insurance information, social security numbers, and more," Ayrey said. "Interview platforms also contained sensitive information about candidate feedback, offers, and rejections."
OAuth, short for open authorization, refers to an open standard for access delegation, allowing users to grant websites or applications access to their information on other websites without having to give their passwords. This is accomplished by making use of an access token to verify the user's identity and allow the service to access the resource the token is intended for.
When "Sign in with Google" is used to sign in to an application such as Slack, Google sends the service a set of claims about the user, including their email address and the hosted domain, which could then be utilized to log users into their accounts.
This also means that if a service is solely relying on these pieces of information to authenticate users, it also opens the door to a scenario where domain ownership changes could allow an attacker to regain access to old employee accounts.
Truffle also pointed out Google's OAuth ID token includes a unique user identifier – the sub claim – that could theoretically prevent the problem, but that has been found to be unreliable. It's worth noting that Microsoft's Entra ID tokens include the sub or oid claims to store an immutable value per user.
While Google initially responded to the vulnerability disclosure by stating that it is intended behavior, it has since re-opened the bug report as of December 19, 2024, awarding Ayrey a bounty of $1,337. It has also qualified the issue as an "abuse-related methodology with high impact."
In the meantime, there are no protections that downstream software providers can take to protect against the vulnerability in Google's OAuth implementation. The Hacker News has reached out to Google for further comment, and we will update the story if we hear back.
"As an individual, once you've been off-boarded from a startup, you lose your ability to protect your data in these accounts, and you are subject to whatever fate befalls the future of the startup and domain," Ayrey said. "Without immutable identifiers for users and workspaces, domain ownership changes will continue to compromise accounts."
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。
-
-
- 比特币(BTC)的恢复继续显示动力,当前资产交易
- 2025-04-26 19:10:13
- 比特币的恢复继续表现出势头,在过去24小时内增长1.6%后,资产交易目前为94,288美元。
-
- 随着加密货币市场的恢复,比特币(BTC)的价格超过$ 90k
- 2025-04-26 19:05:13
- 随着市场情绪的改善,加密市场在结束周的结束周中已有显着的复苏。比特币和索拉纳是一些表现最好的专业
-
- 如果您本周眨了眨眼,您会错过很多。有一阵混乱!
- 2025-04-26 19:05:13
- 加密和华尔街比以往任何时候都更加艰难。从系绳支持的比特币巨头从公开露面到Solana突然成为企业的痴迷
-
- Ada Cardano Price进入了一个强大的集会阶段,现在正在关注$ 1
- 2025-04-26 19:00:13
- 在越来越多的看涨情绪,改善技术和零售和机构圈子的重新关注的驱动下。
-
- 比特币价格集会再次捕获头条新闻
- 2025-04-26 19:00:13
- 比特币价格集会再次占领了头条新闻,因为BTC损失了94,000美元,从而在加密货币市场上引起了兴奋。
-
-
- 今天的PI新闻混杂,因为有积极的发展和负面发展。
- 2025-04-26 18:55:13
- 积极的事件可以帮助增强社区情绪并提高PI价格,与DAPP开发有关。
-