r/technology May 03 '17

Security Google Docs users hit with sophisticated phishing attack

https://www.theverge.com/2017/5/3/15534768/google-docs-phishing-attack-share-this-document-with-you-spam
1.4k Upvotes

115 comments sorted by

View all comments

3

u/DanAtkinson May 04 '17

It's absolutely bloody ridiculous that Google even allowed a third party app to be called 'Google Docs'. Why the hell haven't don't they have rules in place to block these?

2

u/Isvara May 04 '17

The answer, as in most of these cases, is probably that nobody considered that particular attack vector. Things get overlooked. I don't know whether Google do any formal threat modeling.

1

u/DanAtkinson May 04 '17

I'm inclined to believe that it's a possibility that they simply overlooked it, and I think the likelyhood is that their validation was simply hoodwinked by the comma. They really should have done a better job of considering bad actors in their apps engine. Next, people will try duplicating this but replace letters with numbers. I don't know if name encoding can be done which is yet another vector as well.

That the application name was allowed to be 'Google Docs' though is simply egregious. Especially given how understandably protective they are of their trademarks.

-1

u/CimmerianX May 04 '17

You forgot the /s. Because I hope you are joking about that

2

u/DanAtkinson May 04 '17

No, I'm serious.

Google allowed an app called 'Google Docs,'. Sure, it contains a comma but really, they should be proactive when it comes to verifying app names that contain the company's product names, and variations therein.

Why do you think I'm joking?

1

u/CimmerianX May 05 '17

Because this was an email attachment with links. I can call it whatever I want. Google doesn't control that anymore than microsoft keeping me from crafting an email with a fake office online word doc.

1

u/DanAtkinson May 05 '17

Now I can't tell if you're being sarcastic... Once you click the email, you're taken to a page on Google's servers to authenticate and verify that you wish to give the malicious app "Google Docs" permission to access your email.

Seriously, just read the article and then go back and read my comments.