Jump to content

freaked out by my child's phone logging in to my Evernote account


Recommended Posts

Hi! My child has a brand new android phone and installed Evernote because he's seen me use it. It instantly automatically logged in to my personal Evernote account on start-up. There may have been a few confirm-this and confirm-that taps involved, I wasn't watching carefully, but it was near instant. I'm seriously freaked out. There is no way my child knows my Evernote password or my Google account password and there is no way I have logged into my Google account on his phone.

The reason I mention Google accounts is that this must have happened through Evernote's "Sign in with Google - sign in to Evernote with 1 click" function. I know this because under the settings of Evernote in Android on the phone I can find that box ticked, and a message "Signed in as xxx.xxx@gmail.com" (my Google ID). My child has logged into the phone with his Google account, but I reiterate that none of us have ever put any of my Google account details anywhere in the phone.

I suspect therefore that this might be some kind of Google account issue rather than Evernote issue, but I have no idea how to get help from Google about this kind of thing so I'm hoping someone here can help. Can my child's Google account somehow have gotten some kind of authority over my personal Google account and therefore Evernote managed to use that indirect link? I'd much appreciate if someone can help me diagnose this and close off this terrible security breach, because like I said it's really freaking me out!

Link to comment
  • Level 5*

Hi.  When you set up a new Android phone,  you're asked for an email address to register the phone,  and that address also drives access to the Play store from which your child presumably got Evernote.  Did you set up the phone with your child's email address,  or with your own?  Because if it was yours,  then when the software was downloaded from the Play store it would have been 'pre-registered' with your Google email details.  Thinking this phone is also yours,  the account would have opened automatically.

There are several things you can do. 

  1. Log out of Evernote on the phone and set up a new account for your child.  Not permanent,  because presumably s/he could log out of that account and back into yours easily. So -
  2. Enable a 'passcode lock' (via settings on your phone) on your own account so it won't open without a 4-digit number.
  3. Go into your account online and block your child's phone from access to the account.

Hope that helps...

Link to comment

Thanks for the suggestions! However, as I said it's definitely not the case that I have ever logged into my Google account on this phone. So I just don't understand how Evenote can have got approval via my Google account, it just doesn't make any sense. I should definitely implement your suggestions but they seem to be sticking plasters rather than getting to the root of the problem...

Link to comment

Thanks for your help! This is not really solved in the sense of knowing exactly what happened, and probably never will be, but this summarises the final chapter (sorry I'm cutting and pasting from my Facebook hence the different tone):

OK so here is the final chapter on this probably. It's still a total mystery how this happened but I suspect it might have something to do with Google Smartlock. Google accounts remember passwords for other accounts, this is called Smartlock. When we looked at the passwords saved under my child's account, it had a whole bunch of log-ins from both me and my wife and other child. Evidently what happens is that my child is logged into chrome on our home computer, someone sits down at that computer and logs in to their account on some site, and then without anyone realising my child's Google account has remembered this login. If you are using chrome, have a look here: chrome://settings/passwords. You might be surprised at the passwords that are stored there. The really weird thing is that although some of my accounts were there, Evernote was NOT. In fact Evernote was listed under the "Never saved" list. My new prime theory is that one of my accounts that my child's Google account did have log-in for was itself somehow linked to my Evernote. Having deleted all my different log-ins from my child's Google account, and getting him to log-out and log-in again from Google on his phone, his phone could no-longer access my Evernote account. Something is very wrong here with Google's permission system, but it's not my job to find out what, as I think I'm safe as long as I make sure my children's accounts get none of my log-ins. Thanks for your help everyone, and may this be a cautionary tale to all of us. This "one account knows all your passwords" thing is clearly not without risk.

Link to comment

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...