I stole the data in millions of people’s Google accountsethanblake4.medium.com81 points·by ethanblake4·6 năm trước·19 comments
ethanblake4·năm ngoái·discussAll of the major carriers use Google Jibe as their RCS backend anyway though, so it's pretty irrelevant.
ethanblake4·6 năm trước·discussAuthor here, the exact same thing that I did is possible for any 3rd party SSO on mobile apps. It's not a Google exploit, it's an exploit in the idea of SSO.
ethanblake4·6 năm trước·discussI only had to click 'allow device' because I had 2FA enabled on that account. For anyone who doesn't, that step is not required.