Ubisoft UPlay may accidentally contain web plugin exploit, Ezio would not approve (update: fixed)

Assassin's Creed 2 - Ezio Auditore da Firenze

If you’ve played Assassin’s Creed 2 (or other Ubisoft games), you may have installed more stealthy infiltration than you bargained for. Some snooping by Tavis Ormandy around Ubisoft’s UPlay looks to have have discovered that the service’s browser plugin, meant to launch locally-stored games from the web, doesn’t have a filter for what websites can use it — in other words, it may well be open season for any maliciously-coded page that wants direct access to the computer. Closing the purported, accidental backdoor exploit is thankfully as easy as disabling the plugin, but it could be another knock against the internet integration from a company that doesn’t have a great reputation for online security with its copy protection system. We’ve reached out to Ubisoft to confirm the flaw and learn what the solution may be, if it’s needed. For now, we’d definitely turn that plugin off and continue the adventures of Ezio Auditore da Firenze through a desktop shortcut instead.

Update: That was fast. As caught by Geek.com, the 2.0.4 update to UPlay limits the plugin to opening UPlay itself. Unless a would-be hacker can find a way to compromise the system just before you launch into Rayman Origins, it should be safe to play.

Filed under: ,

Ubisoft UPlay may accidentally contain web plugin exploit, Ezio would not approve (update: fixed) originally appeared on Engadget on Mon, 30 Jul 2012 10:02:00 EDT. Please see our terms for use of feeds.

Permalink TechDirt  |  sourceSeclists.org  | Email this | Comments

Adobe confirms it won’t support Flash on Android 4.1, stops new Flash installs from Google Play on August 15th

Adobe Flash Platform

Adobe was very public about dropping mobile Flash last fall. In case that wasn’t clear enough, the developer just drew a line in the sand: Android 4.1 doesn’t, and won’t ever, get certification for Flash. The company is stopping short of saying that Flash won’t run, but it’s evident that Adobe won’t help you if the web browser plugin doesn’t install (or breaks in spectacular fashion) on that Nexus 7. Just to underscore the point, the firm is also halting new installations of Flash from Google Play as of August 15th. Security updates and other vital patches will continue on for existing users. Any fresh downloads after that fateful day, however, will have to come from Adobe’s mausoleum for old versions. The company had already said that HTML5 was the way forward on phones and tablets — now we know just how quickly it’s backing up that claim.

Adobe confirms it won’t support Flash on Android 4.1, stops new Flash installs from Google Play on August 15th originally appeared on Engadget on Thu, 28 Jun 2012 23:55:00 EDT. Please see our terms for use of feeds.

Permalink   |  sourceAdobe  | Email this | Comments