6 ms·
Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now
by orastor 8y ago
Seems odd to me that they would encourage allowing 3rd party sites to read all your email, but I guess this is where we're at right now
- ceejayoz 8y agoThe inclusion of that one kinda baffled me. No way for me to tell whether the app that's connecting would be one I'd want reading emails (I wasn't familiar with it) and without an address bar, hard to tell if it's a spoof or the real thing.
- wetpaste 8y agoYeah, I mean it doesn't say the context very well, so I assumed it I clicked on a link. Like if it said you signed up for a service and clicked on a link to do something very specific. If I accidentally clicked on a link in my email and it brought that page up, could you call it phishing? Also the email from the person with the PDF. Like, why is that phishing? What if I trusted the sender? People send pdfs all the time. are there no secure ways to read pdfs?
- rnotaro 8y agoI think it was mostly due to the fact that it was from a different TLD. The TLD of the context was .EDU and the one from the email was a .ORG.
- cbanek 8y agoYeah, anyone asking for that, even if it's not a phishing attempt would never get the OK from me. That's just crazy.
- jopsen 8y agoI suppose it might make sense if you were installing a 3rd party gmail application on your desktop. I'm no oauth expert, but I would imagine an app would go through a flow like this.
- cbanek 8y agoI believe you can connect gmail to your local email client using IMAP/POP3, but I don't think that uses the oauth flow to do that (you just type in the password). I've never used any other kind of 3rd party gmail apps though.
- Gaelan 8y agoApple Mail uses that dialog.
- yellowapple 8y agoNewer email clients do indeed often use Google's OAuth flow for email logins.
- cbhl 8y agoAmusingly, Google doesn't let its own employees allow TripIt to access corporate email accounts. (But personal ones? Go for it...)
- nhumrich 8y agoThat's just about compliance. In order to stay hippa compliant they can't let 3rd party read emails. Period.
- dddddaviddddd 8y agoCould understand if it was a desktop or mobile email app using the API though.
- mattigames 8y agoYeah, baffled me for a bit but then I remembered that question is whether is phishing attack or not; not if you gonna click "Allow". Then again there is no URL address bar to look for so it _might_ be some sort of phishing attack.
- CM30 8y agoYeah, that's the only reason I got a question 'wrong'. Sorry, but no third party app is getting access to my email for obvious security reasons. Doesn't matter how 'legit' the company is or what not.
- nixpulvis 8y agoNot that I disagree with you but, do you... - host your own email... - on your own hardware... - with your own software (hopefully doing end to end encryption) Even then your surely not running your own fiber, though things like STARTTLS help mitigate this vector. I only mean to say, some level of trust is assumed. But yea, you should aim towards less buggy, evil corporate dependencies.
- CobrastanJorji 8y agoI've used TripIt. Reading your email is central to their "magic." The idea is that whenever you get any sort of travel confirmation, they automatically ingest it and compile all the info into trips, then handle stuff like reminding you to checkin, auto-filling up your checkin code, suggesting seats, etc. They also have an alternative for the privacy-minded where you just forward any confirmation emails you want them to know about and the same stuff happens, but for the email address I was using for this, there wasn't anything I was worried about them accessing, and this was easier.
- mrcodedude 8y agoMy workaround for this is to set up a dummy email address that I use for all travel. That email address then forwards the emails to both plans@tripit.com and my personal email address.
- nhumrich 8y agoYou could also use gmails + feature. My.name+travel@gmsil.com and have those forward to trip it.
- drusepth 8y ago
- ahmedfromtunis 8y agoI got that answer wrong too. But I guess they were asking specifically about phishing. I think the rationale is that the page has to be a real permissions page to give the attacker access to your data. A fake page won't have any power in that regard. And on a real permissions page, an attacker won't be able to fake the requesting app's link. So: legit page + legit link = no phishing ... even though it is by no means a safe situation.
- pvorb 8y agoThe barrier to setting up a "legit" request for permissions for my phishy app is not that high. Yes, you can't phish for Google passwords that way, but you can get access to all other accounts of a person that are not protected by 2FA and can reset passwords via email.
- dawnerd 8y agoI wish the quiz had a fake url bar, that one I got right just out of a pure guess. Without the url bar and just assuming the html is legit, theres no way of really knowing.
- jpl56 8y agoThey should have proposed three answers for this one :- [_] phishing [_] legit [X] legit, but there's no chance I will accept that!
- ahoka 8y ago[X] Legit phishing
- drewmol 8y agoI consider this grooming by google