<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Evan Samek's blog &#187; youtube</title>
	<atom:link href="http://blog.evansamek.com/category/youtube/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.evansamek.com</link>
	<description>develop - design - strategy</description>
	<lastBuildDate>Fri, 23 Sep 2011 15:03:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>[UPDATED]Google Security Hole &#8211; YouTube Login Logs You Into Gmail Too</title>
		<link>http://blog.evansamek.com/2009/08/10/google-security-hole-youtube-login-logs-you-into-gmail-too/</link>
		<comments>http://blog.evansamek.com/2009/08/10/google-security-hole-youtube-login-logs-you-into-gmail-too/#comments</comments>
		<pubDate>Mon, 10 Aug 2009 23:35:50 +0000</pubDate>
		<dc:creator>esamek</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[opinion]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[youtube]]></category>
		<category><![CDATA[Account]]></category>
		<category><![CDATA[blog]]></category>
		<category><![CDATA[evan]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[ip log]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[samek]]></category>
		<category><![CDATA[security hole]]></category>
		<category><![CDATA[user names]]></category>
		<category><![CDATA[usernames]]></category>

		<guid isPermaLink="false">http://blog.evansamek.com/?p=216</guid>
		<description><![CDATA[<p><a href="http://blog.evansamek.com/wp-content/uploads/2009/08/blog-post-gy.jpg" rel="lightbox[216]"><img class="alignnone size-full wp-image-217" title="blog-post-gy" src="http://blog.evansamek.com/wp-content/uploads/2009/08/blog-post-gy.jpg" alt="blog-post-gy" width="500" height="141" /></a></p>
<p>So I believe I have found a security hole in Google&#8217;s login systems, and why they need to unlink usernames with YouTube accounts, or they need to at least address this issue.  I&#8217;ll be brief.</p>
<p><a href="http://blog.evansamek.com/2009/08/10/google-security-hole-youtube-login-logs-you-into-gmail-too/" class="more-link">Read more on [UPDATED]Google Security Hole &#8211; YouTube Login Logs You Into Gmail Too&#8230;</a></p>
]]></description>
			<content:encoded><![CDATA[<p><a href="http://blog.evansamek.com/wp-content/uploads/2009/08/blog-post-gy.jpg" rel="lightbox[216]"><img class="alignnone size-full wp-image-217" title="blog-post-gy" src="http://blog.evansamek.com/wp-content/uploads/2009/08/blog-post-gy.jpg" alt="blog-post-gy" width="500" height="141" /></a></p>
<p>So I believe I have found a security hole in Google&#8217;s login systems, and why they need to unlink usernames with YouTube accounts, or they need to at least address this issue.  I&#8217;ll be brief.</p>
<p>Say you have a Google Account.  Say your other friend has a Google Account.  These two accounts are independent of each other, as in they have different User Names and Passwords.  Now, say that one of you, lets say here that its you, who creates a YouTube account to <strong>share with me.</strong></p>
<p>This is a very common circumstance.  I have about 3 different accounts in YouTube that I share with other people, it makes it convenient to maintain the account, especially if its a busy one.</p>
<p>So here is the security hole: if I log into this &#8216;Shared&#8221; YouTube account, all I need to do is head on over to Gmail and waalaa! I&#8217;m now in your Gmail.  I have full access, and I can poke around all you want, without you knowing except for that little IP log at the bottom of the Gmail window.  I could do some real damage  and snooping.</p>
<p>This is a serious issue, please unlink the accounts.  Email is rarely shared, YouTube accounts are.</p>
<p><strong>UPDATE: </strong>This is the response from Google about this issue.  Apparently these accounts were linked, and this is just the nature of the Google Accounts system.  I agree with the security team, there is no large risk, but this is still a problem in my opinion.</p>
<p>From Google:</p>
<blockquote><p>Thank you for the clarification, and for helping me figure out the<br />
nature of the problem.</p>
<p>As you noted, the user in fact disclosed his Google account password<br />
to you, along with an &#8220;alias&#8221; on YouTube. This alias serves simply as<br />
a nickname for his canonical account with Google, and the password<br />
could be readily used to access services such as Google Mail or Google<br />
Docs without the need to rely on YouTube at all.</p>
<p>Although the fact you gained access to all Google services by logging<br />
in via YouTube with this alias may sound somewhat counterituitive to<br />
people less accustomed to a variety of Google services, I believe<br />
there is no security risk. As noted, you could have used the same<br />
password, and his canonical account name, to simply log in at:</p>
<p><a href="https://www.google.com/accounts/Login" target="_blank">https://www.google.com/accounts/Login</a></p>
<p>&#8230;to gain access to the same services. Canonical account names are<br />
not a secret, and could be easily discovered, e.g. through the YouTube<br />
UI itself.</p>
<p>Now, it goes without saying that sharing your password with other<br />
parties is usually not a good idea, for a number of reasons; if this<br />
can&#8217;t be avoided, we would recommend creating a separate Google<br />
account for this purpose.</p></blockquote>
<p>My Short Rebuttal:</p>
<blockquote><p>Absolutely Sir, I will add to my blog post now.  I have to say though, that it would not be a bad idea to give Google Account&#8217;s access permissions.  This would also prevent something confusing like this from happening.  The basic fact is, while your correct there is no large security risk, this user (my friend) had no intention, nor any indication (according to him) that he was allowing me to access his Gmail without his explicit consent.  Just something to consider&#8230;</p></blockquote>
<p>I would like to praise Google right now, for their quick response time, and detail centered approach.  This encounter with them was exciting in its short life span.  Onward&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.evansamek.com/2009/08/10/google-security-hole-youtube-login-logs-you-into-gmail-too/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

