Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

  > This issue is still a serious matter. I would have still been able
  > to access the person's Amazon account using a wildcard email
  > address.
That's just a general 'loss of domain' issue. It would also be much harder. This Google Apps issue allows you to exploit everyone using that domain without any prior knowledge. Without access to the previous Google Apps accounts, you would have to be specifically targetting someone. (Note: This is the same for any service similar to Google Apps.)


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: