Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why has not a single person mentioned that TC is just wrong? The problem is not that it gets your email address... it looks like it's likely that the website isn't even getting the gmail address.

It's much worse. The blog author is able to send emails through an API that appear to be from "noreply@gmail.com" with the proper headers. So instead of getting a funny little email, you get a phising email that even gmail isn't smart enough to block.

But, I mean, sure, let's act scared that some website can get my gmail. You want it? I'd be happy to give it to anyone, spam or otherwise.



Yup:

Update 4: Google says the issue is now resolved: “We quickly fixed the issue in the Google Apps Script API that could have allowed for emails to be sent to Gmail users without their permission if they visited a specially designed website while signed into their account. We immediately removed the site that demonstrated this issue, and disabled the functionality soon after. We encourage responsible disclosure of potential application security issues to security@google.com.”




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: