Launched in broad beta on Wednesday, closed for inviting Thursday and now spam potential discovered Friday. One has to wonder what else will surface over the weekend. Hey, maybe there will be real fireworks Monday!
Thursday night while playing with Google’s new toy – okay is way more important than that, but to me just another thing to play with – I discovered you could do some serious bulk emailing inside the system.
I wanted to see if my thinking was off so I reached out to Michael Gray, Rae Hoffman and Dave Naylor – we had discovered the flaw in Google’s real time search launch a couple of years ago in Chicago during an SES conference. Dave’s crew must have been on it already as they posted about it later that day.
So what is the problem? Well if you import a large list of contacts in to your Gmail account and then port some to your circle in Plus, any not contacted people can potentially be emailed any time you make a post. See the nice radio button asking you if you are ready to spam below.

“The fact that Google Plus allows non Google Mail accounts to be placed into the contacts list within the site has opened up a huge security issue for email users based on the fact that Google have allowed you to share anything that you wish with huge contact lists, regardless of whether they use Gmail or not,” Alex Graves posted on Dave Naylor’s blog.
Actually it can include any Gmail accounts that have yet to join Google Plus or you may not share a circle with. No doubt this will disappear some time soon. One of the commenters on Dave’s blog asked if it was reported to Google yet, to which Dave replied “I used the form on google+ that count”.
Interestingly, if you are not using Gmail and receive messages from Plus, trying to unsubscribe cannot be done – you get a 404 page at the moment.

It is unfortunate this happened this weekend, no doubt many Google employees are off celebrating the July 4th long weekend. Matt Cutts I am hoping this does not interfer with your celebrations.


