More

    A flaw in Google OAuth system is exposing millions of users via abandoned accounts




    • Buying domains from businesses that shut down could grant access to their SaaS accounts, research finds
    • Google argues it’s not a vulnerability, and that businesses should make sure they’re not leaving sensitive information behind
    • Researchers propose additional safeguards

    Experts have found a vulnerability in Google’s OAuth “Sign in with Google” feature which could allow malicious actors to access sensitive data belonging to businesses that have shut down.

    Google acknowledged the flaw, but is not doing much to address it, rather saying that it is up to the businesses to ensure the security of the data they are leaving behind.

    https://cdn.mos.cms.futurecdn.net/dEpz5LV5PYpqYBngLd6omi-1200-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img