It seems that you're using an outdated browser. Some things may not work as they should (or don't work at all).
We suggest you upgrade newer and better browser like: Chrome, Firefox, Internet Explorer or Opera

×
Some of the exploits' effects have been noticed and cleaned up (by moderators?). I am not in touch with any of them as of now but "they" are probably aware of at least one of the issues - I'll wait for the coming working days.
Post edited November 05, 2017 by neophile1980
You have to crack SHA1 hash first
"exploits' effects"?
Are my games in danger?!?
avatar
timppu: Are my games in danger?!?
Please don't let this shift into a wrong direction. Nothing is in danger. I am trying to responsibly disclose security vulnerabilities to gog.com. There's no real need to further discuss the issues here. All I am asking for is an official contact from gog.com to discuss these issues with. Please don't reply to this thread any longer, thank you :)
low rated
avatar
timppu: Are my games in danger?!?
avatar
neophile1980: Please don't let this shift into a wrong direction. Nothing is in danger. I am trying to responsibly disclose security vulnerabilities to gog.com. There's no real need to further discuss the issues here. All I am asking for is an official contact from gog.com to discuss these issues with. Please don't reply to this thread any longer, thank you :)
Not trying to be difficult here but:

If nothing is in danger, why do you need to talk to GOG about it? And, if you have something which warrants concern, which you must have or you wouldn't be trying to contact them, don't you think that WE the users, the people giving all of our money to GOG, need to know about it sooner rather than later?

If my account, or my personal information is in danger being here, then I want to know about it now, not when GOG gets around to reading your ticket.
Post edited November 06, 2017 by tinyE
avatar
tinyE: If my account, or my personal information is in danger being here, then I want to know about it now, not when GOG gets around to reading your ticket.
So do I. But if there's nothing we (the users) can do, and only GOG staff can fix it, the way to go is not making the vulnerabilities public so any random malicious hacker can exploit them.
avatar
tinyE: If my account, or my personal information is in danger being here, then I want to know about it now, not when GOG gets around to reading your ticket.
avatar
muntdefems: So do I. But if there's nothing we (the users) can do, and only GOG staff can fix it, the way to go is not making the vulnerabilities public so any random malicious hacker can exploit them.
good point.
avatar
tinyE: If nothing is in danger, why do you need to talk to GOG about it?
You run a hotel. I, as a guest, find out that by taking the keycard to my room and pressing it on a specific point to the side of the soda vending machine on the lobby I can turn my keycard into a skeleton key that can open any of the hotel rooms. Do I contact you, the hotel owner about it, or do I tell each and every one of the guests, so they can better protect their valuables?
There are cases when it's better to inform the users, and cases where it's better to not (immediately) inform them but allow the exploit to be fixed first.
avatar
tinyE: If nothing is in danger, why do you need to talk to GOG about it?
avatar
JMich: You run a hotel. I, as a guest, find out that by taking the keycard to my room and pressing it on a specific point to the side of the soda vending machine on the lobby I can turn my keycard into a skeleton key that can open any of the hotel rooms. Do I contact you, the hotel owner about it, or do I tell each and every one of the guests, so they can better protect their valuables?
There are cases when it's better to inform the users, and cases where it's better to not (immediately) inform them but allow the exploit to be fixed first.
I run a B&B in the middle of nowhere. We don't even have locks on the doors. XD No one up here does.
avatar
tinyE: I run a B&B in the middle of nowhere. We don't even have locks on the doors. XD No one up here does.
Hotel related example, not specific to you. After all, you don't even have a soda vending machine in the lobby (or do you?).
But no worries either way.
avatar
tinyE: I run a B&B in the middle of nowhere. We don't even have locks on the doors. XD No one up here does.
avatar
JMich: Hotel related example, not specific to you. After all, you don't even have a soda vending machine in the lobby (or do you?).
But no worries either way.
We don't have a vending machine but our guests have full use of the house, including everything in it, be it coffee, tea, soda, beer, wine, food, free of charge.

Sometimes I get a little pissed when some asshole comes in and drinks all my Coke, but I'd rather have a happy guests than a thirsty one. :P
If this is about the forum, all I can say is that it's a leaky roof and GOG already has plenty of buckets in place. Will they fix the roof? Probably not. It needs to be replaced anyway.
avatar
tinyE: I run a B&B in the middle of nowhere. We don't even have locks on the doors. XD No one up here does.
So anyone can just march into my room nekkid, and start doing helicopter with their dick? What kind of business exactly are you running there?!?
avatar
tinyE: I run a B&B in the middle of nowhere. We don't even have locks on the doors. XD No one up here does.
avatar
timppu: So anyone can just march into my room nekkid, and start doing helicopter with their dick? What kind of business exactly are you running there?!?
Probably one where guests who complain end up like in Bates Motel.