Slashdot Mirror


Adult Themed VR Game Leaks Data On Thousands (securityledger.com)

chicksdaddy writes from The Security Ledger: Somebody deserves a spanking after personal information on thousands of users of an adult virtual reality game were exposed to security researchers in the UK by a balky application. Researchers at the firm Digital Interruption on Tuesday warned that an adult-themed virtual reality application, SinVR, exposes the names, email and other personal information via an insecure desktop application -- a potentially embarrassing security lapse. The company decided to go public with the information after being frustrated in multiple efforts to responsibly disclose the vulnerability to parent company inVR, Inc., Digital Interruption researcher and founder Jahmel Harris told The Security Ledger. Jahmel estimated that more than 19,000 records were leaked by the application, but did not have an exact count.

SinVR is a sex-themed virtual reality game that allows players to navigate in various adult-themed environments and interact with virtual characters in common pornographic themes including BDSM, cosplay, naughty teacher, and so on. The company discovered the data after reverse-engineering the SinVR desktop application and noticing a function named "downloadallcustomers." That function called a web service that returned thousands of SinVR customer records including email addresses, user names, computer PC names and so on. Passwords and credit card details were not part of the data dump, Harris said.

41 comments

  1. Could be worse by Anonymous Coward · · Score: -1

    Adult Themed VR Game Leaks Juice On Thousands

    1. Re:Could be worse by Anonymous Coward · · Score: -1

      I'd "leak" my juice on these girls!
       
      -creimer

    2. Re:Could be worse by Anonymous Coward · · Score: -1, Offtopic

      Ah, 19 year old "senior editors" spamming trash about porn is what Slashdot has become. I don't know what's worse. THAT or the parent actually posting porn.
       
      So much for news for nerds and stuff that matters. This place is dead. And Beau and BIZX, please DIAF.

  2. Seymour Butts? by Anonymous Coward · · Score: -1

    What ever happened to the simpler days of playing Seymour Butts?

    1. Re:Seymour Butts? by Anonymous Coward · · Score: -1

      A Minus One Score? That's a real game from the 1990s, you insensitive clod. It's relevant to the topic.

    2. Re:Seymour Butts? by Anonymous Coward · · Score: -1

      More of a fan of the Ben Dover series.
       
      Remember when the rips were coming out on KaZaA and you got to see your first DP and creampie in JUST ONE CLIP?

  3. Naughty teacher? by 110010001000 · · Score: 2

    Is the naughty teacher theme the one where they teach Evolution?

    1. Re:Naughty teacher? by rmdingler · · Score: 2

      The rather obligatory teaching theme ought to be:

      If you enter your genuine personal information into a porn site's data base, you're taking a silly risk.

      --
      Happiness in intelligent people is the rarest thing I know.

      Ernest Hemingway

    2. Re:Naughty teacher? by Ol+Olsoc · · Score: 2

      Is the naughty teacher theme the one where they teach Evolution?

      No, it's the 35 year old female boinking her underage students.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    3. Re:Naughty teacher? by Ol+Olsoc · · Score: 1

      The rather obligatory teaching theme ought to be:

      If you enter your genuine personal information into a porn site's data base, you're taking a silly risk.

      Depends on whether you are worried about it or not, I guess. If a person is concerned about their data leaking out, they should never use computers at all..

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    4. Re:Naughty teacher? by Anonymous Coward · · Score: 0

      You're using a computer, so you must not be worried. Feel free to post your real name, address, date of birth, mother's maiden name, first pet, city of birth and last four of your social security number here.

      After all, there's nothing for you to be worried about, right?

    5. Re:Naughty teacher? by Anonymous Coward · · Score: 0

      No, it's the 35 year old female boinking her underage students.

      I wish I had been one of those students.

    6. Re: Naughty teacher? by Anonymous Coward · · Score: 0

      That someone is 35, female and a teacher is good enough for you to say ok? That's a nice threshold.

    7. Re:Naughty teacher? by Ol+Olsoc · · Score: 2

      You're using a computer, so you must not be worried. Feel free to post your real name, address, date of birth, mother's maiden name, first pet, city of birth and last four of your social security number here.

      After all, there's nothing for you to be worried about, right?

      I'm always concerned. But the intertoobz is not a secure place, and was never designed to be a secure place. I have whatever protections there are, and don't worry about it that much. Just use good care.

      My point is that if a person wants to use masturbatory aids on the intertoobz, and would feel embarassed or worse if the knowledge that he or she is using those aids, they shouldn't use a service that requires personal info. It's just the same thing with people who want to do criminal acts. The intertoobz is the worst place to do that. Because even with encryption, they are drawing attention to themselves.

      It's like someone using a skywriting service to send encrypted messages. The powers that be might not know what is in those messages, but they can follow the plane, find where it lands, and have anice chat with the pilot, his boss, and eventually the people who paid for the encrypted can be found.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    8. Re:Naughty teacher? by Ol+Olsoc · · Score: 1

      No, it's the 35 year old female boinking her underage students.

      I wish I had been one of those students.

      Just remember, she can say you victimized her, https://www.thestar.com/news/w... , and http://www.dailymail.co.uk/new... , and https://nypost.com/2017/12/20/...

      One of these days, and it won't be long, a female teacher will screw a little boy, and he'll be the one arrested.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    9. Re:Naughty teacher? by grep+-v+'.*'+* · · Score: 0

      If you enter your genuine personal information into a porn site's data base, you're taking a silly risk.

      This is of course not the same thing, but OK Cupid is now asking for first names. I've heard of people actually entering them -- that and their actual pictures have led to some users actually being located in real life.

      That being said, when they asked me I entered "Nope". Now they've begun sending me emails with Dear Nope, ...

      I might tell a potential date my first name during the first conversation, but i'm sure NOT telling the entire world. (That, and it's fairly unique. My first name is enough to narrow it down to easily less than 50 people, any other information and you've pegged me. That's great and all, but dating information is a two-way street.)

      --
      If the universe is someone's simulation -- does that mean the stars are just stuck pixels?
  4. Why would it have data by Anonymous Coward · · Score: 0

    Why would the game even have data, or connect online?

    1. Re:Why would it have data by GrumpySteen · · Score: 2

      Because it's profitable to harvest customer data and sell it. Duh.

  5. Backdoor? by Anonymous Coward · · Score: 0

    The company discovered the data after reverse-engineering the SinVR desktop application and noticing a function named "downloadallcustomers."

    Why would such an api be in the application?

    1. Re:Backdoor? by jarkus4 · · Score: 1

      Most likely it uses common library with some company tools and this function comes from there. Still no authentication for such a function...

  6. Why the fuck... by Anonymous Coward · · Score: 0

    Do they have a function to download All customer data, from a customer client. Just why.

    1. Re:Why the fuck... by Anonymous Coward · · Score: 0

      Likely a bunch of fake names and burn mail addresses but why is right,when porn uses DRM i don't need porn any more.

  7. Shocker! by demonlapin · · Score: 2

    Porn VR game has bad security? Who knew?

    1. Re:Shocker! by Anonymous Coward · · Score: 0

      Find out their insurance company, or ring a few and list the directors that carry enhanced 'risk'. Were legal council involved?
      Now take that list and find out who live in the EU - data protection laws
      Repeat for USA - any lawyers as customers?
      I'm sure the directors won't mind having their personal information well published, which can be given to some wimmins social justice groups.

  8. Example by Anonymous Coward · · Score: 0

    Another example of a company(InVR Inc) not listening and believing they know best blah blah blah.

  9. needs better headline by Anonymous Coward · · Score: -1

    - data squirts past protection?
    - leaks prematurely?
    - looses data via all 3 input methods ?

    Comeon, community, help me here ...

  10. OH NOES. I like porn! by Anonymous Coward · · Score: -1

    So does literally every single person on this planet!

    *Especially* religious people.
    Even apes. Even dolphins!

    So the problem lies purely in those who shame or scold others for it. They are the perverts. And usually, they are the ones raping children. That's precisely why they associate sex with something bad!

  11. "Balky" by Anne+Thwacks · · Score: 0

    What does that mean? its not English, so you can't blame the spelling corrector, and bulky my be true, but is not relevant here.

    --
    Sent from my ASR33 using ASCII
    1. Re:"Balky" by Anonymous Coward · · Score: 0

      One assume's it's the American spelling of Baulky.

    2. Re:"Balky" by Anonymous Coward · · Score: 0

      What does that mean? its not English, so you can't blame the spelling corrector, and bulky my be true, but is not relevant here.

      It's just an adjectival form of balk. Perfectly normal English. A balky horse is one that refuses to jump over fences as its rider intends. A balky application is one not doing what its user or designer intends.

    3. Re:"Balky" by hey! · · Score: 1

      Words are like nice new wood chisels that get stored in a common work area. They don't stay sharp long because people keep misusing them.

      "Balky" means "tending to refuse to respond as directed". If you have a car which often fails to start, that is a balky car. Balkiness is a tendency to a particular kind of malfunction, but the submitter here used it as a synonym for "malfunctioning".

      --
      Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
    4. Re:"Balky" by Anonymous Coward · · Score: 0

      Yes, how old are you?

  12. You're the cancer, mate. by Anonymous Coward · · Score: -1

    Seriously?? Such a conservapussy that you actually *complain* about porn??

    Back in the days, it would have been weird and creepy if it *wasn't* porn! So stop acting like a long-term user.

    It's weird how the kids today have become *less* open and modern. The hipsters don't even wear ugly backwards clothes from a shit time and victorian-era beards ironically anymore. They are now fully serious about it, and more conservative amd nostalgic for "simpler times" than the closedted child fuckers with the cross around the neck back when those things used to be worn!
    Of course they *believe* they are modern, because they have an iPhone and go all p.c. and SJW and "gender fluid".

    But fact is: All those things are singns of total pussyfication and of the repressing that comes with it.
    iPhones attract them because they are afraid of being overwhelmed by the " complicated" world. SUVs attract them because they are civilian tanks. And p.c./SJWness is just a form of forcing others into a rigid conformism to a "safe space". While the "gender fluid" bullshit was expressed by priests wearing women's clothes in private, to their perverted sexual orgies with prostitutes, chilren, dogs and horses, back in the times the hipsters are imitating.

    Face it: Your generation are pretend-modern hyper-conservatives.

  13. What else did you expect? by Anonymous Coward · · Score: 0

    The name of the game is SinVR - did you expect ethics and/or morality?

  14. A function named downloadallcustomers by najajomo · · Score: 1

    'The company discovered the data after reverse-engineering the SinVR desktop application and noticing a function named "downloadallcustomers."'

    Demonstration the necessity of stripping all debug information before shipping the applications - DOH!

    1. Re:A function named downloadallcustomers by kqs · · Score: 1

      Demonstration the necessity of stripping all debug information before shipping the applications - DOH!

      That would be step 1, sure, but the more important things would be:
          * Stop putting access functions for internal APIs in public clients.
          * Don't allow access to internal APIs from externally.
          * Don't allow access to internal APIs without proper credentials.

      This is a sign of completely screwed up security and programming. I don't care if this is porn, IoT, finance, or anything else: this is a sign of many deeper problems.

    2. Re:A function named downloadallcustomers by mentil · · Score: 1

      I don't care if this is porn, IoT, finance, or anything else: this is a sign of many deeper problems.

      Not to worry, porn is ALL ABOUT solving 'deeper' problems.

      --
      Corruption is convincing someone that the selfless ideal is the same as their selfish ideal.
  15. It is english by SuperKendall · · Score: 1

    I've been using Balky (along with my whole family and many others I have met) in the U.S. since I was a kid. Never spelled out though, I admit it does look kind of funny (and I'm not even sure that's how it would be spelled for the U.S.).

    --
    "There is more worth loving than we have strength to love." - Brian Jay Stanley
    1. Re:It is english by kqs · · Score: 1

      I've always seen it spelled baulky, not balky, though both seem to be valid spellings according to dictionaries.

  16. Uh oh.... by Anonymous Coward · · Score: -1

    If you need anything beyond a
    porno mag or videos, you might want
    to consider seeking help for your problem.

  17. Shouldn't that be... by meglon · · Score: 1

    Somebody has failed to deserve a spanking......

    --
    Fascism: An authoritarian and nationalistic right-wing system of government and social organization. See also: NAZI's