Ubisoft UPlay may accidentally contain web plugin exploit, Ezio would not approve (update: fixed)

Assassin's Creed 2 - Ezio Auditore da Firenze

If you’ve played Assassin’s Creed 2 (or other Ubisoft games), you may have installed more stealthy infiltration than you bargained for. Some snooping by Tavis Ormandy around Ubisoft’s UPlay looks to have have discovered that the service’s browser plugin, meant to launch locally-stored games from the web, doesn’t have a filter for what websites can use it — in other words, it may well be open season for any maliciously-coded page that wants direct access to the computer. Closing the purported, accidental backdoor exploit is thankfully as easy as disabling the plugin, but it could be another knock against the internet integration from a company that doesn’t have a great reputation for online security with its copy protection system. We’ve reached out to Ubisoft to confirm the flaw and learn what the solution may be, if it’s needed. For now, we’d definitely turn that plugin off and continue the adventures of Ezio Auditore da Firenze through a desktop shortcut instead.

Update: That was fast. As caught by Geek.com, the 2.0.4 update to UPlay limits the plugin to opening UPlay itself. Unless a would-be hacker can find a way to compromise the system just before you launch into Rayman Origins, it should be safe to play.

Filed under: ,

Ubisoft UPlay may accidentally contain web plugin exploit, Ezio would not approve (update: fixed) originally appeared on Engadget on Mon, 30 Jul 2012 10:02:00 EDT. Please see our terms for use of feeds.

Permalink TechDirt  |  sourceSeclists.org  | Email this | Comments

Droid X360 goes for the KIRF prize, antagonizes Microsoft, Motorola and Sony at the same time (video)

Droid X360 PS Vita clone goes for the KIRF prize, antagonizes Microsoft, Motorola and Sony at the same time

Can we establish a KIRF award for Most Likely to Invite Multiple Lawsuits? If so, Long Xun Software would have to claim the statuette for its Droid X360, at least if it dared set foot in the US. This prime example of keepin’ it real fake is even more of a PS Vita clone than the Yinlips YDPG18, but goes the extra mile with a name that’s likely to irk Microsoft, Motorola, Verizon and George Lucas all at once. That’s even discounting the preloaded emulators for just about every pre-1999 Nintendo, Sega and Sony console. Inside, you’ll at least find a device that’s reasonably up to snuff: the 5-inch handheld is running Android 4.0 on a 1.5GHz single-core Quanzhi A10 processor, 512MB of RAM, 8GB of built-in space, a 2-megapixel camera at the back and a VGA shooter at the front. If the almost gleeful amount of copyright and trademark violation isn’t keeping you from wanting this award-winner, you’ll have to ask Long Xun for pricing and availability.

Continue reading Droid X360 goes for the KIRF prize, antagonizes Microsoft, Motorola and Sony at the same time (video)

Filed under: ,

Droid X360 goes for the KIRF prize, antagonizes Microsoft, Motorola and Sony at the same time (video) originally appeared on Engadget on Tue, 24 Jul 2012 15:44:00 EDT. Please see our terms for use of feeds.

Permalink MIC Gadget, Talk Android  |  sourceShanzhaiben  | Email this | Comments