Google Calendar Security Hole
It’s entirely possible that this problem exists in all major calendar platforms, and I’ve just called Google out for no reason, but I’ve recently had need to work extensively with the Google Apps platform (which I love, by the way), and came across a couple of interesting bits. Here’s one of them: Other people can accept calendar invitations that they have no business accepting. In other words, with the right link, I can accept an invitation on your behalf. Here’s a quick proof (all done using Google’s web interface): Send your buddy (we will call him Ryan) a calendar invitation to a bogus event. When Ryan gets the email notification, ask him to simply reply to the message. He doesn’t need to write a message, just have him reply to it. Now from his reply in YOUR EMAIL, click “Yes” … Continue reading
