Hacker News new | ask | show | jobs
by boilerupnc 1121 days ago
I would have thought that being "added" to anything is a two-way confirmation:

1. One from the party wanting to add the group to their account. Based on a prior comment, sounds like you are prompted to confirm an external group being added as admin.

2. One from the party administering/owning an external google group being requested to be added. Is there any confirmation here?

Without the 2nd confirm, I start imagining security exposures in the family of Ransomware - let's call it "RansomAdd". You randomly add external google groups until you get someone to poke around "too much" and then threaten them with legal action unless they pay up. Ugh.

1 comments

Hah, probably wouldn’t work well though. The types of folks who have money AND would be fooled by something like that would almost never have the time or curiosity to go poking around.