A brief note about Pokemon Go security by CISSReC

img

1. According to the research results from research institute CISSReC, when play Pokemon Go at first, the game application will be directed to https://stats.unity3d.com which is is a engine game use by Pokemon. Servers are located in California.

Then proceed to https://appload.ingest.crittercism.com, also in California. Crittercism is a mobile application performance management (APM) used by Pokemon Go.

Further, when the game is played, the data will be sent to https://pgorelease.nianticlabs.com.

2. In terms of permissions, Pokemon Go does not ask to run at startup, where the most malware is definitely trying to run at startup.

For Pokemon trainer club's, authentication are sent to https://sso.pokemon.com/sso/. So the data are sent to the developers server, not to suspicious parties.

3. From the research that is done by CISSReC, data that sent to the server Niantic are no more than 50 KB. The data file of this size is not enough for the good quality photo.

For comparison, when capture photo on full HD screen, the size of the resulting image can range up to 3 Mb. When compared with the data sent every time we catch Pokemon, no more than 50 Kb.

So there is impossible that our photo location are sent to Niantic server.

4. If you want to install the Pokemon Go game on mobile device, please download the APK (Android Package Kit) file from a trusted web.

If still in doubt, try to join in Pokemon Go community in online forums or Facebook. Usually there are information of which APK file is safe to install.

If absolutely in doubt and does not know which APK files are safer, it is better to wait for the official release of Pokemon Go in the country.

5. While technologically considered safe to be installed, Pokemon Go still has a social impact in society.

The emergence of new technologies or applications will undoubtedly certain social implications.

Therefore, the Pokemon Go players are expected to keep order and in good manner which applies to all locations of playing area.

If necessary, government or private agencies may impose specific rules during the working hours as well as the rules that apply in the workplace.

 Likewise, the government can provide special pleading not to play Pokemon Go near vital objects such as the Presidential Palace or military and police installations.

6. When it was released officially in Indonesia, the Ministry of Tourism can also request Nintendo's to put the Poke Stop and Gym in the places that have potential of tourism and historical aspects.

So that it could be a tourist center that has a special appeal to attended by community, especially the Pokemon Go players in Indonesia as well as overseas players.