Tech

A flaw in Google OAuth system is exposing millions of users via abandoned accounts

Share
Share


  • Buying domains from businesses that shut down could grant access to their SaaS accounts, research finds
  • Google argues it’s not a vulnerability, and that businesses should make sure they’re not leaving sensitive information behind
  • Researchers propose additional safeguards

Experts have found a vulnerability in Google’s OAuth “Sign in with Google” feature which could allow malicious actors to access sensitive data belonging to businesses that have shut down.

Google acknowledged the flaw, but is not doing much to address it, rather saying that it is up to the businesses to ensure the security of the data they are leaving behind.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Email pioneer says SaaS needs to make sustainability part of its DNA
Tech

Email pioneer says SaaS needs to make sustainability part of its DNA

SaaS sector lags behind others in sustainability awareness and industry Digital emissions...

Jessica Jones is back – Krysten Ritter’s hard-hitting PI joins Daredevil: Born Again season two
Tech

Jessica Jones is back – Krysten Ritter’s hard-hitting PI joins Daredevil: Born Again season two

Jessica Jones is making a comeback in Daredevil: Born Again season two...

This new ChatGPT feature solves the most annoying thing about Deep Research
Tech

This new ChatGPT feature solves the most annoying thing about Deep Research

ChatGPT’s Deep Research feature can now export reports as PDFs The PDFs...