Almost Fell For The Google Docs Worm

Almost Fell For The Google Docs Worm

Tech News gmail google oauth phishing security

I almost clicked it. Wednesday afternoon, sitting at the kitchen table with the laptop propped on a stack of old Wired issues I keep meaning to recycle, an email showed up from someone I actually know, a former coworker, someone whose name I'd recognize without even reading the subject line. "has shared a document on Google Docs with you." Perfectly normal. I get three or four of those a week.

I had my cursor sitting right on "Open in Docs" before something made me stop. Maybe it was that the email had no actual document name attached, just the blue button and nothing else. Maybe it was pure luck. I tabbed over to Twitter instead of clicking, and there it was: my whole feed already full of people posting screenshots of the exact same email, warning everyone not to touch it.

That was the Google Docs phishing worm from this past Wednesday, May 3rd, and it's genuinely one of the more clever bits of social engineering I've run across in a while, mostly because it barely resembled phishing at all. There was no fake login page to spot. If you clicked through, you landed on a real accounts.google.com screen, the actual one, asking you to let an app called "Google Docs" read, send, and manage your Gmail and your contacts. It looked like Google because part of it genuinely was Google. Somebody registered a third-party OAuth app, named it "Google Docs," slapped Google's own Docs icon on it, and let the real consent screen do the lying for them. Grant it access and it immediately emailed your entire contact list the same invite, which is how the thing tore through people's inboxes so fast. A friend of mine who works in local government said half her office got hit inside twenty minutes.

Google says they killed it in about an hour, pulled the app, pushed a fix, and by Wednesday evening the wave had mostly stopped. Fine, credit where it's due, that's a fast response for a company that size. But an hour is still a long time on the internet, and I'd bet real money the number of accounts that granted access before anyone figured out what was happening is in the hundreds of thousands, not the low thousands some of the first writeups guessed at.

What's stuck with me since Wednesday isn't really the worm itself. It's the OAuth consent screen it exploited. I use that screen constantly, every time some app wants calendar access or wants to post to my Twitter or whatever, and I could not tell you the last time I actually read one line by line before hitting allow. Nobody does. It's a wall of text with a blue button at the bottom, and the whole design assumes you'll skim it in half a second and click through, which is exactly what happened to probably a million people this week. The permission dialog is doing legal cover, not actual communication. If Google, or Facebook, or anyone else running an OAuth flow, actually wanted people to read these things, they'd look nothing like they currently do. There'd be a giant red banner if the app name doesn't match a verified publisher, not a small gray line of text under the scope list that says "unverified app" in a font size nobody's eyes are built to catch on a phone screen at eight in the morning.

I went and pulled up my own Google account's connected apps page afterward, out of pure paranoia, and it was a little horrifying how long the list was. Some fitness tracker I stopped using two years ago still has access to my contacts. A Chrome extension for RSS feeds I don't even remember installing can read my mail. I spent about twenty minutes revoking things Wednesday night, and I'd genuinely recommend everyone reading this go do the same. It takes five minutes and it's unsettling what's still sitting in there, quietly authorized, doing nothing anyone would notice until it does something.

None of this required me to be careless, and that's the part that bugs me most. I'm reasonably careful about email, I've been running this blog since November 2011 and I've written more "don't click that" posts than I can count over the years. The thing that saved me on Wednesday wasn't skepticism. It was dumb luck and a slow Twitter refresh at exactly the right second. That's not a system worth relying on, and it's definitely not one most people have sitting around waiting to save them.