+

Cookies on the Business Insider India website

Business Insider India has updated its Privacy and Cookie policy. We use cookies to ensure that we give you the better experience on our website. If you continue without changing your settings, we\'ll assume that you are happy to receive all cookies on the Business Insider India website. However, you can change your cookie setting at any time by clicking on our Cookie Policy at any time. You can also see our Privacy Policy.

Close
HomeQuizzoneWhatsappShare Flash Reads
 

Hackers Could Have Been Abusing This Bug To Get Gmail Addresses For Years

Jun 12, 2014, 06:15 IST

REUTERS/Carlos Barria

A major bug in Google's Gmail service was recently patched, but until now, all it took to find potentially every Gmail address in the world was a few keystrokes, Wired reports.

Advertisement

Tel Aviv-based security researcher Oren Hafif discovered the bug and helped Google fix the problem. Before he did that, he experimented, setting up a program that uncovered 37,000 Gmail addresses in about 2 hours, he told Wired.

"I have every reason to believe every Gmail address could have been mined," Hafif told Wired. He added that any business using Google to host its emails was also vulnerable.

The bug involved an account-sharing feature that lets users delegate access to their accounts. Discovering email addresses is as simple as changing a few characters in a URL. Hafif uploaded a how-to video to his YouTube channel.

Advertisement

Hafif reported the bug to Google, who fixed it after about a month. The company paid the security researcher $500 under its bug bounty program, which Hafif thought was a little low.

"Being a good person is not very profitable these days," he said with a smiley face on Twitter.

Next Article