Posted June 04, 2019

instaboy
Me™
Registered: May 2013
From Norway

Maxvorstadt
I is more stronger than Darth Vapour!
Registered: Apr 2014
From Germany
Posted June 04, 2019
Hm, so this happens only when one uses an android phone? Hm, now I´m curious, shall I try to go to GoG with my phone?
Nah, I guess I would end up as Tiny E. Hm....
But to be serious: This is really a bit scary.
Nah, I guess I would end up as Tiny E. Hm....
But to be serious: This is really a bit scary.
user deleted
Gaming on Linux
Registered: Apr 2009
From Norway
Posted June 04, 2019
Does two-factor login even help against this?
That this has been going on for years is ridiculous and reason enough to consider closing down the account. If this is the security breach that is painfully visible to us, I don't wanna know what's going on under the hood without our knowledge.
That this has been going on for years is ridiculous and reason enough to consider closing down the account. If this is the security breach that is painfully visible to us, I don't wanna know what's going on under the hood without our knowledge.

fronzelneekburm
I'm back!
Registered: Apr 2012
From China, People's Republic of
Posted June 04, 2019
Well, there's a comforting thought! At least they didn't manage to break it further.
1000+ games + a license to shitpost sounds like a pretty sweet deal TBH.
1000+ games + a license to shitpost sounds like a pretty sweet deal TBH.

Clairsentient
Mostly Tired
Registered: Nov 2017
From Singapore
Posted June 04, 2019
If someone has access to your account, is that mean your saved card details also exposed?

Fortuk
New User
Registered: Aug 2015
From Other
Posted June 04, 2019
Post edited June 04, 2019 by Fortuk

ZocomMAX
Indeed!
Registered: Oct 2012
From Canada

fronzelneekburm
I'm back!
Registered: Apr 2012
From China, People's Republic of
Posted June 04, 2019
I don't see how. Like I said, I didn't even have to log in, gog just gave me immediate access.
I dunno, since I never saved any payment details here. You can check it out yourself: Check what you can do on your own account once logged in without entering any further details. If you can just add games to our cart, select your credit card and hit pay and it actually works, then ANYONE who gets access to your account via this bug could do that.
I dunno, since I never saved any payment details here. You can check it out yourself: Check what you can do on your own account once logged in without entering any further details. If you can just add games to our cart, select your credit card and hit pay and it actually works, then ANYONE who gets access to your account via this bug could do that.

Fortuk
New User
Registered: Aug 2015
From Other
Posted June 04, 2019
I'm assuming the bug is that it misattributes the session of the account somehow and that's how you log in. The two-step check should trigger somewhere along the line of that process and if it doesn't that makes for even bigger security hole.

immi101
User
Registered: May 2010
From Germany
Posted June 04, 2019

see here
When making any purchase with a credit or debit card, you can now select the option to save your card for later use.If your payment is successful, that card will be remembered for later use. You'll be able to select it during your next checkout without retyping the info every time. Simple, straightforward, and probably very familiar.
We're taking advantage of tried and tested industry-standard solutions used across the world today. Among other things, this means your entered payment data isn't actually kept anywhere on GOG.com. Once your bank approves the purchase, your entered card number is replaced with a unique, encrypted token that can be used only by us to process your future payments, and which cannot be reverse engineered to resolve your card number and data. From time to time, we'll also ask you to verify your information based on a number of security factors, like if you haven't used that card in a long time
might still be worth a thought to remove that for the time being.
Post edited June 04, 2019 by immi101

GamezRanker
Disagreement Verboten!
Registered: Sep 2010
From United States
Posted June 04, 2019
low rated

PS: I'd like some sort of explanation from gog how such an issue is even possible. How am I just in random person's account when all I did was visit gog from my phone's browser? It would also be nice if gog were to get in touch with Xiaozhuzi and let him know about this issue and issue an apology for this mess.
I only ask as it'd seem far more easier to do than being logged into someone else's account.
Though if you are genuine(and I don't see why you wouldn't be) this is a problem.
Yes, many giveaways are us giving gifts to ourselves to get praise also from ourselves....it;s a vicious loop. :D
Post edited June 04, 2019 by GameRager

tiredliger
New User
Registered: Apr 2018
From Samoa
Posted June 04, 2019
Hope the 2FA will protect my account.

GamezRanker
Disagreement Verboten!
Registered: Sep 2010
From United States
Posted June 04, 2019
low rated



paladin181
Cheese
Registered: Nov 2012
From United States

Fairfox
New User
Registered: Sep 2010
From United States
Posted June 04, 2019
low rated
quick, someone write like me