smuggly: I totally agree whoever is running this project is screwing up. It lacks basic features. They bit-off more than they can chew!
ftfy: It's worse than lacking basic features; see the post and link above yours. It literally is a security risk and shouldn't be used. I'm done with Galaxy, any version.
You are right, and thanks for the link(s)!
Two things i noticed:
1. GOGs handling of security vulnerabilities seems to be on par with the rest of the communication.
2. Either they don't understand the problem, or they are deliberately fucking it up: "After an investigation, it was found that GOG simply updated the signing key used for verifying messages. This key has been recovered, and the proof-of-concept has been updated with it." (cited from your link, edit: whoops, i mean melanko's link) Both explanations are disturbing.