Sunday, December 30, 2018

Authenticate once against YouTube at your iPhone and you are always authenticated.

There is a security hole in the way the iPhone interacts with YouTube. It has been there since at least the iPhone4S. If you upload one movie to YouTube you will always be able to push up movies to that account, even after you change your password at Google. Just now I was able to push up this:

To see the ghetto phenomenon for yourself, just make a movie on your iPhone and then go into the settings for the video clip at your photos. The canned YouTube app from the early versions of the iPhone has long been removed but the canned push-to-YouTube option at your photos yet lingers... and it is sick.

https://m.youtube.com/watch?v=LAQlbqVIllQ was pretty easy for me to make even after I had changed my password. I guess Google and Apple are not infallible. I remember Paul Hammant calling me on a Sunday and blowing up at me because he let this fact slip out of his mouth at this tech talk when he maybe wasn't supposed to and I in turn blogged of it. Funny!

 
 

Addendum 12/8/2019: This is no longer the reality! This hole has been plugged!

No comments:

Post a Comment