Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hijacking your comment, sorry.

I just downloaded the app and went hunting. It indeed connect to some service, more specifically it creates a webview (think iframe but better separated) with url "https://www.diigo.com/account/thirdparty/openid?openid_url=h... (which you should totally not access with a logged in google account, or in any other way).

It then adds several callbacks one of which handles loading stopped which causes the app to send a command "handshake" to the app. I have so far found two, one of which is a response to the handshake and the other is a command "launch" which opens the index.html command with a given title and data url.

This shit has China written all over it - and I mean so literally because the bg.js file has the following user information at the top, with a Chinese date:

/ * User: xiaoge * At: 14-5-19 5:52δΈ‹εˆ * Email: abraham1@163.com */

Will keep digging. So far I haven't found out what it is it sends, but it does request access to both your google drive account and (most worringly) to your EMAIL.

This is definite no install.

_Edit_: Remember what I said about your email info? Awesome screenshot can upload your screenshots to your gdrive, it does so using oauth2, which tells us the client that has access to it. In this case the app signs in as awesomescreenshot.com/client, but use https://secure.diigo.com/kree as the actual signin url - which means that they now have access to your gdrive files.



Would you consider putting the URL in a code block (double indented), or in some way mangling the URL so that it's not auto-hyperlinked?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: