Google Account Security Hole Allows Account Hijacking
Google January 12th, 2007 - By Haochi
Philipp Lenssen over at Google Blogoscoped report that Tony Ruscoe, who revealed many secret Google services, has found a security flaw that allows some one to have partial access to many of your Google services: “reads parts of your Google emails, views your docs, modifies your spreadsheets, checks out your reading habits on the Google personalized homepage or Google Reader, and goes through your search history”, according to Philipp. In such a situation, we should probably thank Google for not showing our passwords.
The problem seems to be fixed now, Tony said a few hours ago, but he can’t tell you for sure. He “think it took them around 3 hours 30 minutes or so from emailing them”, and as usual, he hasn’t receive any response from Google.
This is pretty much your “worst nightmare” with the Google accounts, other than letting some malicious hacker know your password. Bad bad bad Google, no donut for you.
