A recent study has revealed a loophole in Google’s authentication process known as “Sign in with Google,” which capitalizes on a peculiarity in domain ownership to infiltrate and obtain confidential information.
According to Dylan Ayrey, the co-founder and CEO of Truffle Security, “Google’s OAuth authentication is inadequate in preventing an individual from acquiring a failed startup’s domain and leveraging it to recreate email accounts belonging to past employees.”
According to Dylan Ayrey, the co-founder and CEO of Truffle Security, “Google’s OAuth authentication is inadequate in preventing an individual from acquiring a failed startup’s domain and leveraging it to recreate email accounts belonging to past employees.”
