Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Pokemon GO – The Scary Stuff Of Augmented Reality Games
Articles

Pokemon GO – The Scary Stuff Of Augmented Reality Games

ISBuzz TeamBy ISBuzz TeamNovember 4, 2016Updated:November 6, 20165 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

I remember back in the 1990s the small characters from Pokemon inundating our world. It was a whole world of cuteness, in fact, the Pikachu being my favorite. Fast forward 20 years and the Pokemon phenomenon has become digitized to within an inch of their little lives in the form of the augmented reality mobile app, Pokemon GO.

Augmented reality is software that overlays the real world, with the digital one. In the case of Pokemon GO, it uses the phone’s GPS to show local maps which guide players around their locale to find hidden Pokemon characters. Pokemon GO is a massive success, with over 100 million downloads in the first month after release. Pokemon GO’s success has been attributed to the fact it gets people out of the house, to hunt down sweet little cartoon characters and even meet new people – so, what’s not to like?

Is a Mewtwo Stealing Our Data?

Augmented reality technology that superimposes a computer-generated image on a user’s view of the real world, thus providing a composite view. In the case of Pokemon GO, the actual data is the location of the player at any given time. This could be the street, local gym, park, or in fact anywhere in the world. The overlaid, computer-generated data comes in the form of the Pokemon creatures, the trainer (player) has to hunt. They hide in the locale you are “hunting” within. To work, the game has to know where the user is during play. This process occurs while tracking the player, using geo-location data from the GPS service of the mobile device on which the app is installed. In addition to the geo-location data, the app had already collected user information when the player created an account. What the game knows, the host knows too, aka Niantic, Inc. who developed the game.

In regards the data shared for the Pokemon GO account. This can either be using the app account itself directly or by using a Google Sign-in account. The current version of Pokemon GO is 1.3.0. There have been some privacy improvements since the first release. In the first version of the game, V1.0., there was an outcry when it was discovered that Niantic was able to effectively have full access to your Google account if you used your Google Sign-in to sign up with (which most users did as it sped up the account creation process). Now admittedly the user has to consent to share these data points during Google Sign-in usage. However, having full access in the first place raises legitimate privacy concerns – the technology behind Google Sign-in (OAuth 2.0 / OpenID Connect) allows developers to set limits on what data access is allowed and shared. It can also set consents that allow the user to set the share level they feel comfortable with if so coded. To Niantic’s credit, they closed off that hole within a week by updating to version 1.0.1 – which asks for permissions to function. However, it appears that Niantic didn’t regard user privacy as a chief concern. It takes an outcry by privacy and security professionals and players to implement privacy details and after the fact.

This isn’t just the fact that Niantic has the potential to read our Google mail. One of the potential outcomes of compiling details of our every movement is that criminals hacking into a Pokemon GO account could cause certain personal privacy and safety issues, similar to issues with other apps like Waze and WhatsApp. In an extension of this, terrorists could also use this same information to identify Pokemon GO hotspots and target those places to cause mass chaos. In a twist to this last scenario, a Ukrainian website which is known to identify ‘Russian military criminals’ is allegedly developing a technology based on the Pokemon GO concept (nicknames Pokemon Ru) to help in the hunt for their Russian targets.

Will The Pokemon Respect Our Privacy?

A month or so since launch, Niantic have taken steps to show an improvement towards protecting user privacy. They have a section in the Pokemon GO Trainer Guidelines called ‘Respect Privacy’ which encourages the players to respect other users privacy stating that:

“In addition to making smart choices about how you choose to reveal your identity…don’t post, repost, or reveal other information about another user’s identity, including their name, phone number, email address, or physical address,…Violations can result in the loss of your account.”

This is all well and good, and in fairness, we all have to take responsibility for privacy and security. However, privacy and security should begin at the design and development stage of the app itself. Putting the onus of privacy respect into the hands of the user is unfair when the game itself lacks privacy as a fundamental feature. Game designers and architects need to, themselves, respect privacy, to the extent that it is part of their design goals and as important an aspect of the app as the gamification itself. Only then can we have some reasonable level of assurance that the data we share within our augmented reality will be as safe as that Dragonite you just can’t quite catch.

[su_box title=”About Avani Desai” style=”noise” box_color=”#336588″][short_info id=’90644′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}