<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8787108</id><updated>2011-11-27T16:14:14.128-08:00</updated><category term='unknown account'/><category term='security issue'/><category term='account'/><category term='google'/><category term='swap'/><title type='text'>Priyadarsan V</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://priyadarsan.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8787108/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://priyadarsan.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Priyan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8787108.post-5882467620067011564</id><published>2009-05-22T04:32:00.000-07:00</published><updated>2009-05-22T05:00:46.102-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security issue'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><category scheme='http://www.blogger.com/atom/ns#' term='unknown account'/><category scheme='http://www.blogger.com/atom/ns#' term='account'/><category scheme='http://www.blogger.com/atom/ns#' term='swap'/><title type='text'>Google providing access to other user accounts</title><content type='html'>I have been facing issues with google accounts for months, which is posted by Philipp on his &lt;a href="http://blogoscoped.com/archive/2009-05-19-n84.html"&gt;blog post&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Below is the email content I &lt;span style="font-weight: bold;"&gt;wrote to Google on April the 28.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;For the past one month, I am facing an issue wherein, when i access the help forum and the google profile (Update: Affected Services Google Notebook, Google Docs, Google Profile, Google , &lt;span class="text_exposed_show"&gt;Google Analytics,  Google Alerts,  Google Finance, Google Friend Connect, Google Maps, Google Map Maker, Google Video, Google Code, Google iGoogle, Google Feedburner&lt;/span&gt;), the account that i logged in (&lt;a href="mailto:" target="_blank"&gt;priyadarsan****@gmail.com&lt;/a&gt;) is swapped with another account. I am able to access the account holder's personal information and his contacts. (Later i contacted the persons involved to share this matter).&lt;br /&gt;&lt;br /&gt;In my knowledge, all the users involved are based in Singapore, So far there are five people which i identified. I have collected a bunch of screen shots and some writeups, which i will be attaching with this email. Please do something about it, we don't want others to access our account and happily use our contact information.&lt;br /&gt;Please go through the below content. It's bit lengthy, but it will help you to trace the issues, i believe. The forum links are still there.&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-=-=&lt;/div&gt;&lt;div style="font-weight: bold;"&gt;April 3rd: Mail i dropped to philipp of blogoscope&lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: collapse;"&gt;&lt;div&gt;Today, while i was browsing the Google Apps help centre. Suddenly, i realized that instead of my email ( &lt;a href="mailto:" style="color: rgb(42, 93, 176);" target="_blank"&gt;priyadarsan***@gmail.com&lt;/a&gt; ), the interface is showing &lt;a href="mailto:" style="color: rgb(42, 93, 176);" target="_blank"&gt;Maximilian.***&lt;wbr&gt;gmail.com&lt;/a&gt;. I thought it's some kinda minor bug and it will be prompting for my account once i refresh. It didn't happen. I tried posting a message in one of the &lt;a href="http://www.google.com/support/forum/p/Apps+Partner/thread?tid=6b522565387b8bea&amp;amp;hl=en&amp;amp;fid=6b522565387b8bea000466a2bab1e1c4" style="color: rgb(42, 93, 176);" target="_blank"&gt;thread&lt;/a&gt; and to my surprise, the post came in as Maximilian's. I dropped an email to the account holder as well.&lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I was using chrome at first. Then I tried accessing from a different browser (firefox). It was the same Maximilian's account in firefox as well. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I was asked to login when i accessed the following&lt;/div&gt; &lt;div&gt;* Gmail&lt;/div&gt;&lt;div&gt;* My Account&lt;/div&gt;&lt;div&gt;But many other services were browsable..&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I am not using a Proxy&lt;/div&gt;&lt;div&gt;I cleared the firefox relogged into my account, but it changed to Maximilian, while i was navigating, to be exact: Login, &lt;a href="http://www.google.com/support/forum/p/Apps+Partner?hl=en" style="color: rgb(42, 93, 176);" target="_blank"&gt;Google Apps Help Centre&lt;/a&gt; , &lt;a href="http://www.google.com/support/forum/p/Apps+Partner/user?hl=en&amp;amp;userid=00042855154822523658" style="color: rgb(42, 93, 176);" target="_blank"&gt;My Profile&lt;/a&gt; &lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;What do you think the problem might be?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;I don't know Maximilian, until this event happened. I am not able to read his emails as i am been redirected to the login page. Mostly the problem lies around the help pages. To add, this is my personal laptop, only I myself uses this computer. Not even a guest account is enabled in it.&lt;/div&gt; &lt;div&gt;Attachment: &lt;span&gt;priyangooglesecuri&lt;wbr&gt;tyissue.zip&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;-=-=&lt;/div&gt;&lt;span style="font-weight: bold;"&gt;April 9th: Mail i dropped to Peter Breitkreutz&lt;/span&gt;, whose account was the next one which i got access to&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span style="border-collapse: collapse;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;span style="border-collapse: collapse;"&gt;Hi Pete,&lt;br /&gt;I don't know you yet. Sorry for pulling you in. We are facing a problem with Google Profile. Since your name is involved, i want you to be here. Hope you won't mind.&lt;br /&gt;&lt;br /&gt;Hi Philipp,&lt;br /&gt;&lt;br /&gt;This is getting serious. I am now able to see Max's address book (Names and Emails in his addressbook) , account information [Even the Account Name, Address is Editable]. I am able to browse through his picasa album from the profile, but clicking on any photo leads me to picasa's login screen. Clicking on My account leads to login screen (same with Google Reader, Gmail). I won't be surprised when one day i am writing from Max's Gmail.&lt;br /&gt;(Screen Shot attached)&lt;br /&gt;&lt;br /&gt;Maximilian wrote to me this morning saying that his account name has changed to "Aussie Pete". I googled only to find that Pete is in Singapore as well (I got his email from his &lt;a href="http://www.blogger.com/profile/04893185575367843149" style="color: rgb(42, 93, 176);" target="_blank"&gt;blogger profile&lt;/a&gt;). This problem might be facing by everyone who is under same ISP who shares single public IP.&lt;br /&gt;&lt;br /&gt;The surprising thing is that all 3 of us are google apps user's (I am using It, Max told me he is using and Pete's &lt;a href="http://jaimezheng.com/" style="color: rgb(42, 93, 176);" target="_blank"&gt;domain&lt;/a&gt; points here)&lt;br /&gt;&lt;br /&gt;I use Google for anything and everything. Lot and lots of sensitive data are present in various tools like notebook and docs. I can't imagine that position, If i loose those.&lt;br /&gt;&lt;br /&gt;Why am i writing this to you?, is 'cuz you can influence them and could bring their attention here. (or tell me where i can report it).&lt;br /&gt;&lt;br /&gt;Expecting your reply.&lt;br /&gt;&lt;br /&gt;I got to see this thread, where Pete says he is seeing Maximilian's account:&lt;br /&gt;&lt;a href="http://www.google.com/support/forum/p/Google+Apps/thread?tid=7a12c06200f1387e&amp;amp;hl=en" style="color: rgb(42, 93, 176);" target="_blank"&gt;http://www.google.com/support/&lt;wbr&gt;forum/p/Google+Apps/thread?&lt;wbr&gt;tid=7a12c06200f1387e&amp;amp;hl=en&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Attachment: &lt;span&gt;repriyangooglesecu&lt;wbr&gt;rityissue.zip&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-style: italic;"&gt;Reply from Peter:-&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;div&gt;&lt;span style="font-style: italic;"&gt;Hi - yes it was very strange when I posted my question on google help... because there was no profile created, I went in and edited it, thinking that it was my profile (didn't notice the email address at the top of the page was showing Max's address and not mine).&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span style="font-style: italic;"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-style: italic;"&gt;Once I noticed, I went back and logged in as myself with my email address and created my own profile.&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span style="font-style: italic;"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-style: italic;"&gt;At the time, I though perhaps google was somehow defaulting to a 'pretend' person until my own profile was created... obviously this mustn't be the case.&lt;/span&gt;&lt;/div&gt; &lt;div&gt;&lt;span style="font-style: italic;"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="font-style: italic;"&gt;Thanks for looping me in - very strange occurrence indeed. I also use googleapps for many things... including more than just this one domain.&lt;/span&gt;&lt;/div&gt; &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-=-=&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: collapse;"&gt;&lt;span style="border-collapse: collapse; font-weight: bold;"&gt;April 25th: &lt;/span&gt;&lt;/span&gt;&lt;span style="border-collapse: collapse; font-weight: bold;"&gt;Mail i dropped to Chang Morgan&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Dear All,&lt;br /&gt;&lt;br /&gt;The issue is still around.&lt;br /&gt;&lt;br /&gt;Now more people are involved. Marking them as well.&lt;br /&gt;&lt;br /&gt;@&lt;a href="http://www.google.com/support/forum/p/gmail/user?userid=09976660229725728312&amp;amp;hl=en" style="color: rgb(42, 93, 176);" target="_blank"&gt;Chang Morgan&lt;/a&gt;,&lt;span&gt;&lt;/span&gt; - Pulling you in to inform about this security issue.&lt;br /&gt;&lt;br /&gt;The private information that i got has been send to Chang's personal account.&lt;br /&gt;&lt;br /&gt;Guyz... We should do something about it.&lt;br /&gt;&lt;br /&gt;Priyan&lt;br /&gt;-=-=-=&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;May 19th: Mail to Derick&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Dear Derick,&lt;br /&gt;&lt;br /&gt;Just wanted to inform that when i opened &lt;a href="http://google.com/notebook" target="_blank"&gt;google.com/notebook&lt;/a&gt;, instead of seeing my notes, it showed your account (See attached), like the way you see it. If you carefully read the below thread, this security issue is not just to google notebooks, but also google profile, google contacts and google help (So far).&lt;br /&gt;&lt;br /&gt;Guyz, The danger has come and i am gonna delete all of my google account except the email (for which i need few months).&lt;br /&gt;&lt;br /&gt;I posted the issues at &lt;a href="mailto:security@google.com" target="_blank"&gt;security@google.com&lt;/a&gt;, which went unanswered. Google was a god given gift for me, but they are not caring about security issues.&lt;br /&gt;&lt;br /&gt;Somebody here if you can help, it would be grateful.&lt;br /&gt;&lt;br /&gt;Priyan&lt;br /&gt;-=-=-=-=&lt;br /&gt;&lt;br /&gt;Alast, i got a &lt;span style="font-weight: bold; color: rgb(255, 0, 0);"&gt;response from Google on 22nd of May&lt;/span&gt; (Nearly a month later after my email to security@google.com)&lt;br /&gt;&lt;br /&gt;Hi Priyan,&lt;br /&gt;&lt;br /&gt;The issue you're describing was reported by a small number of users&lt;br /&gt;visiting a Google Help Center page from your ISP. As you described, those&lt;br /&gt;users could become partially logged into the account of a recent viewer of&lt;br /&gt;the same page from the same ISP. We have fixed the issue completely, and&lt;br /&gt;we apologize for any inconvenience.&lt;br /&gt;&lt;br /&gt;Thanks very much for reporting it to us.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;Manuel for&lt;br /&gt;The Google Security Team&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Response:&lt;br /&gt;&lt;/div&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8787108-5882467620067011564?l=priyadarsan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://priyadarsan.blogspot.com/feeds/5882467620067011564/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8787108&amp;postID=5882467620067011564' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8787108/posts/default/5882467620067011564'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8787108/posts/default/5882467620067011564'/><link rel='alternate' type='text/html' href='http://priyadarsan.blogspot.com/2009/05/google-providing-access-to-other-user.html' title='Google providing access to other user accounts'/><author><name>Priyan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8787108.post-3602098513219933876</id><published>2008-07-04T21:45:00.001-07:00</published><updated>2008-07-04T21:45:48.033-07:00</updated><title type='text'>jijo vincent</title><content type='html'>&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;avan singaporel ethi..&lt;br/&gt;&lt;br/&gt;bu hu hu hu ha&lt;br/&gt;&lt;br/&gt;entammO..&lt;br/&gt;&lt;br/&gt;enne kollu..&lt;br/&gt;&lt;br/&gt;&lt;br/&gt;avaaara mon&lt;br/&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8787108-3602098513219933876?l=priyadarsan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://priyadarsan.blogspot.com/feeds/3602098513219933876/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8787108&amp;postID=3602098513219933876' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8787108/posts/default/3602098513219933876'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8787108/posts/default/3602098513219933876'/><link rel='alternate' type='text/html' href='http://priyadarsan.blogspot.com/2008/07/jijo-vincent.html' title='jijo vincent'/><author><name>Priyan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8787108.post-115850311389091114</id><published>2006-09-17T07:25:00.000-07:00</published><updated>2006-09-17T07:25:13.956-07:00</updated><title type='text'>DiCE Guyz</title><content type='html'>&lt;a href="http://diceguyz.blogspot.com/"&gt;DiCE Guyz&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8787108-115850311389091114?l=priyadarsan.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://priyadarsan.blogspot.com/feeds/115850311389091114/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8787108&amp;postID=115850311389091114' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8787108/posts/default/115850311389091114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8787108/posts/default/115850311389091114'/><link rel='alternate' type='text/html' href='http://priyadarsan.blogspot.com/2006/09/dice-guyz.html' title='DiCE Guyz'/><author><name>Priyan</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
