EionRobb / purple-hangouts

47 stars 4 forks source link

Outh code / simulated Hangouts device seemed to be used for requesting archive from Google account #228

Open nekromoff opened 3 years ago

nekromoff commented 3 years ago

I disabled it, but still a weird message from Google received.

nekromoff commented 3 years ago

image

Unknown device shown to have requested the archive. Unknown device equals Oauth device for Pidgin Hangouts.

security

EionRobb commented 3 years ago

The hangouts plugin shows up as "purple-hangouts on ios", rather than as an unknown device.

I'm not sure how to trigger a Google account checkout using the hangouts APIs, or whether that's even possible. Do you have two-factor auth enabled on your account? Does the Google security page say you're logged in from somewhere else?

nekromoff commented 3 years ago

Well, the funny thing was, that it actually showed the same location as I am at. I have 2FA enabled for sure. It might as well be some Google bug as another archive was just recently exported for me. But it showed as a different request. Weird. And I know it used show as an iOS device before.

Anyway, maybe it's not the best to even authorize a simulated device that will have access to lots of peoples' hangout contacts in the developers console (I understand your key/simulated device gets the access through the developer's console). I will have to rethink the use of it, specifically since Hangouts are going to be phased out soon and replaced by Google Chat.