
google hdr+

Earlier this year, Google started a project to review third-party developer access to Google accounts through the use of APIs. It found a security breach surrounding Google+, and is now shutting the service down, at least for consumers.
今年年初,谷歌啟動了一個項目,以審查第三方開發人員通過使用API??對Google帳戶的訪問權限。 它發現了圍繞Google+的安全漏洞,并且目前正在關閉該服務,至少對于消費者而言。
The long and short of the issue is that there was a security hole that allowed third-party developers to access Google+ users’ account data, including name, email address, occupation, gender, and age—even if the account was set as private.. This isn’t?particularly?sensitive data, but regardless, a breach is a breach.
問題的根源在于,存在一個安全漏洞,允許第三方開發人員訪問Google+用戶的帳戶數據,包括姓名,電子郵件地址,職業,性別和年齡,即使該帳戶設置為私人帳戶也是如此。這不是特別敏感的數據,但是無論如何,違規就是違規。
The bug was discovered in March of 2018, but was presumed to have been open since sometime in 2015. To make matters slightly more troubling, Google only keeps this particular API’s data log for two weeks…so the company has no way of knowing which users were affected. Presumably, however, some 500,000 users were on the list.
該錯誤于2018年3月被發現,但據推測自2015年某個時候就已經打開。為了使問題更加麻煩,Google僅將該特定API的數據日志保留了兩周……因此該公司無法知道哪些用戶受了影響。 但是,大概有500,000個用戶在列表中。
As a bit of a bright side, however, there was no evidence that any developer was even aware this bug existed, despite 438 applications using the API. Similarly, there was no evidence that any profile data was stolen, sold, or otherwise misused. That’s good, I guess.
但是,盡管有438個應用程序使用該API,但有一點光明的一面是,沒有證據表明任何開發人員甚至都知道存在此錯誤。 同樣,也沒有證據表明任何個人資料數據被盜,出售或以其他方式濫用。 我猜那很好。
The bug was patched two weeks after it was initially discovered (Google took two weeks to analyze the data before patching the hole), but has now decided to shut down Google+ as a consumer service. In a blog post by the company highlighting its findings, it’s stated that 90 percent of all Google+ visits last fewer than five seconds. Ouch.
該漏洞是在最初被發現的兩周后被修補的(Google在修補漏洞之前花了兩周的時間來分析數據),但是現在決定關閉Google+作為消費者服務。 該公司在一篇博客文章中強調了這一發現,指出90%的Google+訪問持續時間不到5秒。 哎喲。
So, instead of investing time, energy, and money into a clearly dead network, the company is just going to put it out of its misery. The consumers side will be completely closed by August of 2019. From that point forward, G+ will continue on as an enterprise product, where many companies seem to use it heavily.
因此,該公司不會將時間,精力和金錢投入到顯然已死的網絡中,而只是將其從痛苦中解脫出來。 到2019年8月,消費者方面將完全關閉。從那時起,G +將繼續作為企業產品使用,許多公司似乎都在大量使用它。

As another upside, more granular account permissions are going to be available on Google accounts. That means instead of just allowing access to your account with one simple “Allow” button, you’ll get to choose which permissions apps are allowed access to each particular service.
另一個好處是,可以在Google帳戶上使用更精細的帳戶權限。 這意味著您不僅可以通過一個簡單的“允許”按鈕來允許訪問您的帳戶,還可以選擇允許哪些權限的應用訪問每個特定服務。
So, for example, if you’re using your Google account to sign into a new service and it requests access to your Calendar and Drive, you’ll be able to grant or deny that permission on a per-service basis. Think of it like Android’s permission control, just for your Google account. They’re also limiting app’s access to your Gmail account moving forward, so only apps that “directly enhance” email functionality (like email clients and backup services) will be able to access your Gmail messages.
因此,例如,如果您正在使用Google帳戶登錄新服務,并請求訪問日歷和云端硬盤,則可以基于每個服務授予或拒絕該權限。 僅將其視為Google帳戶的Android權限控制。 它們還限制了應用程序對您的Gmail帳戶的訪問權限,因此,只有“直接增強”電子郵件功能的應用程序(如電子郵件客戶端和備份服務)才能訪問您的Gmail郵件。
Finally, app access to Call Logs and SMS on Android are going to be limited moving forward. Google Play will limit the types of apps that are allowed to request these permissions—only your default app for the given situation will be able to access this info. So, for example, your default messaging app will have access to SMS permissions, and the default dialer can access Call Logs. But other apps won’t be able to.
最后,今后對Android上的呼叫記錄和SMS的應用訪問將受到限制。 Google Play將限制允許請求這些權限的應用程序的類型-只有在給定情況下的默認應用程序才能訪問此信息。 因此,例如,您的默認消息收發應用程序將有權訪問SMS權限,而默認撥號程序可以訪問呼叫日志。 但是其他應用程序將無法執行。
All these changes are happening in the coming months, giving users more control over their own data. Google will also work with developers to give them time to adjust the required permissions for apps and services that will be affected by the changes.
所有這些更改都將在未來幾個月內發生,從而使用戶可以更好地控制自己的數據。 Google還將與開發人員合作,讓他們有時間調整受更改影響的應用和服務所需的權限。
Source: Google
資料來源:谷歌
翻譯自: https://www.howtogeek.com/fyi/google-is-dead-survived-by-better-privacy-controls/
google hdr+