Friday, 21 February 2025
30 C
Singapore
32.3 C
Thailand
21.7 C
Indonesia
25.9 C
Philippines

Employees of failed startups risk data theft through Google logins

Former employees of failed startups face risks of data theft due to a Google login flaw. Learn about the issue and how to protect yourself.

Losing your job at a failed startup is hard enough, but now thereโ€™s a growing concern about a hidden threat: the potential for your personal data to be stolen. This includes sensitive details like private messages, Social Security numbers, and bank account information.

A discovery with alarming implications

Security researcher Dylan Ayrey, co-founder and CEO of Truffle Security, uncovered this vulnerability. Ayrey is recognised for creating TruffleHog, an open-source project that monitors data leaks involving API keys, passwords, and tokens. After notifying Google and the affected companies, his findings were presented at the ShmooCon security conference.

The vulnerability lies in how Google OAuth, used for โ€œSign in with Google,โ€ handles domain-level access. If cybercriminals purchase failed startups’ expired domains, they could log in to cloud-based software linked to those domains. These apps, ranging from Slack to HR systems, often hold critical employee data.

Ayrey tested his theory by acquiring the domain of a defunct startup. Using it, he gained access to applications such as ChatGPT, Zoom, and an HR platform that contained Social Security numbers. He noted that the biggest threat is the monetisable data stored in HR systems, such as banking information.

Thankfully, Google confirmed that data stored in personal Gmail accounts or Google Docs is not at risk. However, startups are particularly vulnerable because they often rely heavily on Googleโ€™s tools and cloud-based services. Ayrey estimates that tens of thousands of former employees and millions of accounts could be affected, given the 116,000 startup domains currently available for sale.

Limited solutions to a significant problem

Googleโ€™s OAuth configuration includes a feature called a โ€œsub-identifier,โ€ which uniquely identifies each Google account. This mechanism should, in theory, prevent unauthorised access, even if hackers recreate email addresses.

However, Ayrey found issues with this system. Collaborating with an affected HR provider, he discovered that sub-identifiers occasionally changed, albeit in a tiny percentage of cases (0.04%). This inconsistency could lock out hundreds of users weekly for large platforms, leading some providers to forgo the feature.

Google disputes these findings, claiming that sub-identifiers do not change. However, as the HR provider reported the issue and not directly through Ayreyโ€™s bug report, it remains unresolved.

Googleโ€™s response

Initially, Google dismissed Ayreyโ€™s findings, calling the issue a โ€œfraudโ€ risk rather than a bug. Ayrey acknowledged this perspective, noting that Googleโ€™s OAuth system worked as designed, but the vulnerability highlighted broader data privacy concerns.

Three months later, Google reconsidered and awarded Ayrey a US$1,337 bounty for his discovery. This wasnโ€™t the first time his findings were reconsideredโ€”he faced a similar situation in 2021 when a talk at Black Hat prompted Google to acknowledge his work and award him third prize in their annual security research competition.

Despite recognising the issue, Google has not released a technical fix. The company has updated its guidance, encouraging cloud providers to use sub-identifiers, but has not announced further plans.

You may be at risk if youโ€™ve worked at a failed startup. Ayrey advises employees to secure their accounts by updating passwords and unlinking old โ€œSign in with Googleโ€ connections from inactive domains. Being proactive can help mitigate these risks as the tech world waits for broader fixes.

Hot this week

Apple Intelligence could come to Vision Pro in April

Apple could bring Apple Intelligence to Vision Pro in April, but a long-awaited Siri upgrade may face delays due to engineering issues.

Baidu embraces DeepSeek AI to enhance search experience

Baidu integrates DeepSeek AI into its search engine, following Tencentโ€™s move with Weixin. Chinaโ€™s AI race heats up as DeepSeek gains popularity.

MOVA unveils innovative smart cleaning solutions in Singapore

Experience the future of smart home cleaning with MOVAโ€™s latest innovationsโ€”the Z50 Ultra robot vacuum and X4 Pro wet & dry vacuum. Unveiled at Jewel Changi Airport, these cutting-edge appliances redefine effortless cleaning with AI-driven intelligence, advanced mopping, and powerful suction.

Perplexity introduces its own deep research tool

Perplexity launches its Deep Research tool, offering fast, professional-grade AI research with accurate citations.

Kahoot! partners with Hello Kitty and Sanrio characters for free educational games in Singapore

Kahoot! partners with Sanrio to launch free educational games featuring Hello Kitty and friends, making learning fun for children and families in Singapore.

Google expands in-car apps, turning vehicles into mobile entertainment hubs

Google is expanding its in-car apps, bringing more streaming and gaming options to vehicles with built-in Google services, starting with Volvo and Polestar.

Singapore businesses embrace AI to boost efficiency

Singapore businesses and government agencies use AI to improve efficiency, reduce costs, and enhance productivity, as shared at Microsoftโ€™s AI Tour.

Sonar acquires AutoCodeRover to boost AI-powered software development

Sonar acquires AutoCodeRover to enhance AI-powered coding, automating debugging, improving security, and speeding up software development.

ASUS launches ZenScreen Duo OLED MQ149CD, a portable monitor with dual OLED displays

ASUS unveils the ZenScreen Duo OLED MQ149CD, a portable dual-screen monitor with OLED technology, delivering stunning visuals and flexible work setups.

Related Articles