Google+ API: affected 52.5 million users

Google has discovered a new bug in the Google+ API. According to the company's announcement, personal information from 52,5 seems to have been affected users after the reported bug was disclosed in October of 2018.

GoogleWhat had happened:

Η εταιρεία δήλωσε τον Οκτώβριο ότι το σφάλμα εντοπίστηκε στο API του Goοgle+ People. Από προεπιλογή, οι χρήστες του Goοgle+ μπορούσαν να δώσουν πρόσβαση στα δεδομένα του προφίλ τους σε εφαρμογές τρίτων κατασκευαστών. Όπως με το and Twitter, Google+ users could allow third-party apps to obtain information from the public profile of the user's friends.

However, in a post on the company's blog, Ben Smith, Google Fellow and Vice President of Engineering, stated that the bug allowed third-party applications to access user data that was classified as private and not just public data that was allowed to Applications "see".

Google said at the time that it could not determine exactly which users were affected by the error and reported around 500.000 accounts, so today the company said:

We have confirmed that the bug was approximately 52.5 million users in connection with a Google+ API.

"Upon discovery of this new bug, we've decided to accelerate the shutdown of all Google+ APIs, which will happen within the next 90 days," said David Thacker, VP of G Suite Product. .

Read the new announcement of the company.

"In addition, we have decided to accelerate the expiration of consumer Google+ from August 2019 to April 2019."

Google discovered the error in the Google+ People API during the standard testing process that started a week after the problem was discovered.

According to the company, there is no breach in its systems and no indication was found that a developer was aware of the error or the API was abused.

However with this API, the applications that were requesting to view profile information, they had access to the user's name, email address, occupation, and age, even if he did not allow them to be viewed publicly.

Applications that had access to that data were also able to view personal data that was privately shared by other Google+ users.

According to the company, no password, financial data, IDs or other similar sensitive data were leaked.

"We have begun the process of notifying consumers and corporate customers affected by this error. Our investigation is ongoing into other possible implications of the Google+ APIs. ”

______________________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).