Hacker News new | ask | show | jobs
by Tyr42 4858 days ago
That's the problem though, isn't it? They don't do password specific permissions, so any leak escalates up to taking over the whole account.
1 comments

No, ASPs can only be used to access account data available over imap, smtp, xmpp, and other non-web protocols that don't allow cookies/asking for the OTP.
Not true. Read the article :)
The article says it's fixed.
The fix that Google rolled out blocks ASP-based logins from accessing a few highly-sensitive pages on https://accounts.google.com, but otherwise, little has changed. With a quick API request, you can still use an ASP to skip just about any other Google web-based login anywhere on the web. Google might have to completely eliminate their Chrome/Android auto-login feature to actually prevent this sort of thing...