Adult Themed VR Game Leaks Data On Thousands (securityledger.com)
chicksdaddy writes from The Security Ledger: Somebody deserves a spanking after personal information on thousands of users of an adult virtual reality game were exposed to security researchers in the UK by a balky application. Researchers at the firm Digital Interruption on Tuesday warned that an adult-themed virtual reality application, SinVR, exposes the names, email and other personal information via an insecure desktop application -- a potentially embarrassing security lapse. The company decided to go public with the information after being frustrated in multiple efforts to responsibly disclose the vulnerability to parent company inVR, Inc., Digital Interruption researcher and founder Jahmel Harris told The Security Ledger. Jahmel estimated that more than 19,000 records were leaked by the application, but did not have an exact count.
SinVR is a sex-themed virtual reality game that allows players to navigate in various adult-themed environments and interact with virtual characters in common pornographic themes including BDSM, cosplay, naughty teacher, and so on. The company discovered the data after reverse-engineering the SinVR desktop application and noticing a function named "downloadallcustomers." That function called a web service that returned thousands of SinVR customer records including email addresses, user names, computer PC names and so on. Passwords and credit card details were not part of the data dump, Harris said.
SinVR is a sex-themed virtual reality game that allows players to navigate in various adult-themed environments and interact with virtual characters in common pornographic themes including BDSM, cosplay, naughty teacher, and so on. The company discovered the data after reverse-engineering the SinVR desktop application and noticing a function named "downloadallcustomers." That function called a web service that returned thousands of SinVR customer records including email addresses, user names, computer PC names and so on. Passwords and credit card details were not part of the data dump, Harris said.
Is the naughty teacher theme the one where they teach Evolution?
Why would the game even have data, or connect online?
The company discovered the data after reverse-engineering the SinVR desktop application and noticing a function named "downloadallcustomers."
Why would such an api be in the application?
Do they have a function to download All customer data, from a customer client. Just why.
Porn VR game has bad security? Who knew?
Another example of a company(InVR Inc) not listening and believing they know best blah blah blah.
What does that mean? its not English, so you can't blame the spelling corrector, and bulky my be true, but is not relevant here.
Sent from my ASR33 using ASCII
The name of the game is SinVR - did you expect ethics and/or morality?
'The company discovered the data after reverse-engineering the SinVR desktop application and noticing a function named "downloadallcustomers."'
Demonstration the necessity of stripping all debug information before shipping the applications - DOH!
I've been using Balky (along with my whole family and many others I have met) in the U.S. since I was a kid. Never spelled out though, I admit it does look kind of funny (and I'm not even sure that's how it would be spelled for the U.S.).
"There is more worth loving than we have strength to love." - Brian Jay Stanley
Somebody has failed to deserve a spanking......
Fascism: An authoritarian and nationalistic right-wing system of government and social organization. See also: NAZI's