I stole the data in millions of people’s Google accountsethanblake4.medium.com81 points·by ethanblake4·6 jaar geleden·19 comments
ethanblake4·vorig jaar·discussAll of the major carriers use Google Jibe as their RCS backend anyway though, so it's pretty irrelevant.
ethanblake4·6 jaar geleden·discussAuthor here, the exact same thing that I did is possible for any 3rd party SSO on mobile apps. It's not a Google exploit, it's an exploit in the idea of SSO.
ethanblake4·6 jaar geleden·discussI only had to click 'allow device' because I had 2FA enabled on that account. For anyone who doesn't, that step is not required.