Ubisoft games security risk!

This topic is locked from further discussion.

Avatar image for agpickle
agpickle

3293

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#1 agpickle
Member since 2006 • 3293 Posts

Apparently Uplay installs a plugin on your web browser that has a huge security risk. ThisRPS article lists affected games and how to disable the plugin on Chrome, Firefox and Opera.

Avatar image for skrat_01
skrat_01

33767

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#2 skrat_01
Member since 2007 • 33767 Posts
Interestingly enough I have a few of those said games installed and don't have the Chrome plugin. Either way this is ****ing ludicrous.
Avatar image for trastamad03
trastamad03

4859

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#3 trastamad03
Member since 2006 • 4859 Posts

Interestingly enough I have a few of those said games installed and don't have the Chrome plugin. Either way this is ****ing ludicrous. skrat_01
Check plugins, not extensions. A lot of people made that mistake.

chrome://plugins/

It's also odd they didn't mention Anno 2070... I have that installed and it uses Uplay. Got the news while on the bus today so can't check if I have the plugin or not... I'm guessing I do.

Avatar image for Everiez
Everiez

1946

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#4 Everiez
Member since 2006 • 1946 Posts

I have Anno 2070 and I've this plugin in my FF and Chrome too. I'm surprised to see there are other plugin like Yahoo, Nvidia, Pando and whatnot installed without my permission (or maybe because I can't be arsed to read long boring T&A).

Avatar image for skrat_01
skrat_01

33767

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#5 skrat_01
Member since 2007 • 33767 Posts

[QUOTE="skrat_01"]Interestingly enough I have a few of those said games installed and don't have the Chrome plugin. Either way this is ****ing ludicrous. trastamad03

Check plugins, not extensions. A lot of people made that mistake.

chrome://plugins/

It's also odd they didn't mention Anno 2070... I have that installed and it uses Uplay. Got the news while on the bus today so can't check if I have the plugin or not... I'm guessing I do.

Oh I did, buried away and nested in all those advanced settings, crazily enough it actually isn't there - which is baffling me.
Avatar image for MW2ismygame
MW2ismygame

2188

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#6 MW2ismygame
Member since 2010 • 2188 Posts

Thankfully I dont have any ubi games on my PC, but this is bullsh*t all the same. would not be surprised if they hid this in the TOS or ELUA that are so long that nobody in their right mind would read. hopefully this comes to light and damaged ubi.

Avatar image for Macutchi
Macutchi

10483

Forum Posts

0

Wiki Points

0

Followers

Reviews: 4

User Lists: 0

#7 Macutchi
Member since 2007 • 10483 Posts

if this is true i'll be playing any future ubisoft games on the xbox.

bad enough splinter cell conviction kept chucking me out of the game back to the desktop; now i find out us paying customers have been rewarded with a nice security exploit too. awesome

Avatar image for lucfonzy
lucfonzy

1835

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#8 lucfonzy
Member since 2008 • 1835 Posts
[QUOTE="trastamad03"]

[QUOTE="skrat_01"]Interestingly enough I have a few of those said games installed and don't have the Chrome plugin. Either way this is ****ing ludicrous. skrat_01

Check plugins, not extensions. A lot of people made that mistake.

chrome://plugins/

It's also odd they didn't mention Anno 2070... I have that installed and it uses Uplay. Got the news while on the bus today so can't check if I have the plugin or not... I'm guessing I do.

Oh I did, buried away and nested in all those advanced settings, crazily enough it actually isn't there - which is baffling me.

same, not there for me even though i have a few ubisoft games that make use of uplay
Avatar image for DanielDust
DanielDust

15402

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#9 DanielDust
Member since 2007 • 15402 Posts
Another +1 for not having such a thing, AC Rev, Driver, Anno 2070 and Settlers 7 installed.
Avatar image for Davulao
Davulao

1042

Forum Posts

0

Wiki Points

0

Followers

Reviews: 6

User Lists: 0

#10 Davulao
Member since 2007 • 1042 Posts

I have Heroes of M&M installed. Checked plugins and there they were. Disabled now. Thanks for the news TC.

Avatar image for Baranga
Baranga

14217

Forum Posts

0

Wiki Points

0

Followers

Reviews: 4

User Lists: 0

#11 Baranga
Member since 2005 • 14217 Posts

It was fixed.

if this is true i'll be playing any future ubisoft games on the xbox.

Macutchi

But are you still using Steam?

Valve has fixed a man-in-the-middle vulnerability in the Windows Steam client, which would have allowed a correctly-positioned attacker to divert and decrypt HTTPS traffic without the victim's knowledge. This made sensitive payment details, such as PayPal credentials, vulnerable to eavesdropping.

---------------

The way Steam handles authorisation is with a cookie named steamLogin, however when a user signs out the token is not destroyed. That would be bad enough however, the same token is used in subsequent logins.

Steam handles credit card information and allows you to store it server-side. Thus if a malicious user gained a copy of someones cookie, they could make charges to an already registered credit card and max it out very easily.

Avatar image for kozzy1234
kozzy1234

35966

Forum Posts

0

Wiki Points

0

Followers

Reviews: 86

User Lists: 0

#12 kozzy1234
Member since 2005 • 35966 Posts

Thanks for the info, glad Anno is not affected

Avatar image for MythPro1
MythPro1

2746

Forum Posts

0

Wiki Points

0

Followers

Reviews: 4

User Lists: 0

#13 MythPro1
Member since 2003 • 2746 Posts
Uplay has a new update that addresses this issue.
Avatar image for INF1DEL
INF1DEL

2083

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#14 INF1DEL
Member since 2006 • 2083 Posts
I didn't know this until earlier today when firefox told me it was disabling the plugin due to stability issues. Total BS that it didn't even tell me about it. Like we needed another reason to hate uplay.
Avatar image for ssvegeta555
ssvegeta555

2448

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#15 ssvegeta555
Member since 2003 • 2448 Posts
Anno 2070 didn't give me the plugins so I'm happy. But I will be very wary of any future Ubisoft purchases from now on.
Avatar image for Darkslayer16
Darkslayer16

3619

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#16 Darkslayer16
Member since 2006 • 3619 Posts

Wonder if that has anything to do with the fact after it installed for me I had like 40 trojan pop ups.

Avatar image for Tidal_Abyss
Tidal_Abyss

857

Forum Posts

0

Wiki Points

0

Followers

Reviews: 17

User Lists: 0

#17 Tidal_Abyss
Member since 2010 • 857 Posts

I've had ubi blacklisted for years now, since ac2 and on- that's when their 'always online drm even for sp' started- and I'm a single player. THeir drm gets worse and worse, I see I was right to do so. They've lost a lot of money over the years, I"m hardly the only one not giving them a dime while they're like this.

Avatar image for Planeforger
Planeforger

19583

Forum Posts

0

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

#18 Planeforger
Member since 2004 • 19583 Posts

I've had ubi blacklisted for years now, since ac2 and on- that's when their 'always online drm even for sp' started- and I'm a single player. THeir drm gets worse and worse, I see I was right to do so. They've lost a lot of money over the years, I"m hardly the only one not giving them a dime while they're like this.

Tidal_Abyss

They fixed the problem the day after people noticed it.
They've also patched the always-online DRM out of their major titles, and their most recent games haven't used that at all.

So...I don't think it's fair to say that it's getting worse and worse. Ubisoft does actually seem to be trying to listen and improve - it's just that the mindless gaming horde will villify them no matter what they do.