{"id":11401,"date":"2023-01-27T20:01:04","date_gmt":"2023-01-27T19:01:04","guid":{"rendered":"http:\/\/plus.maciejpiasecki.info\/index.php\/2023\/01\/27\/this-popular-android-rpg-just-leaked-a-ton-of-player-information\/"},"modified":"2023-01-27T21:01:33","modified_gmt":"2023-01-27T20:01:33","slug":"this-popular-android-rpg-just-leaked-a-ton-of-player-information","status":"publish","type":"post","link":"https:\/\/plus.maciejpiasecki.info\/index.php\/2023\/01\/27\/this-popular-android-rpg-just-leaked-a-ton-of-player-information\/","title":{"rendered":"This popular Android RPG just leaked a ton of player information"},"content":{"rendered":"<p>The mobile software industry is no stranger to large-scale leaks. A popular RPG on the Google Play Store Guidus just leaked data on a ton of its sizable user base. This leak, according to Cybernews, was avoidable, and it could have been a lot worse.<br \/>\nGuidus isn\u2019t quite Genshin Impact, but it was able to garner a decent user base. The app has over 100k downloads, and the 4.2-star rating is the icing on the cake. It\u2019s a nice-looking pixelated RPG with solid gameplay. Looking at it, we can tell that the app is legit, so what about the leak?<br \/>\nGuidus allowed players\u2019 data to be leaked<br \/>\nStarting off, the situation sounds worse than it actually is, but it still needs to be highlighted. As per the source, the developers, Izzle, hardcoded sensitive data into the client side of the app. This meant that this data was accessible to just about anyone.<br \/>\nOn the scale of leaked data, this information wasn\u2019t bad at all. The information that people could access all pertained to the player\u2019s progress. This includes their in-app currency and their progress through the game. If a bad actor got access to that information, they could erase that data and cause a player to lose their progress. That\u2019s frustrating in and of itself, but it gets worse.<br \/>\nThe developers also left keys hardcoded to the client end of the app. The Cybernews research team said that \u201cHardcoding sensitive data into the client side of an Android app is a bad idea\u2026In most cases, it can be easily accessed through reverse engineering.\u201d If a bad actor does access those keys, they might be able to get ahold of even more sensitive data on a player.<br \/>\nIzzle was told that Guidus leaked the data, but the company has yet to fix the problem. We\u2019ll have to wait to see if the company does issue some sort of patch.<br \/>\nThe post This popular Android RPG just leaked a ton of player information appeared first on Android Headlines.&#013;<br \/>\n<img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/plus.maciejpiasecki.info\/wp-content\/uploads\/2023\/01\/Guidus-Title.jpg\" width=\"1600\" height=\"900\">&#013;<br \/>\nSource: ndroidheadlines.com&#013;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The mobile software industry is no stranger to large-scale leaks. A popular RPG on the Google Play Store Guidus just [&hellip;]<\/p>\n","protected":false},"author":27,"featured_media":11402,"comment_status":"false","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-11401","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bez-kategorii"],"_links":{"self":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts\/11401","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/comments?post=11401"}],"version-history":[{"count":1,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts\/11401\/revisions"}],"predecessor-version":[{"id":11403,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/posts\/11401\/revisions\/11403"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/media\/11402"}],"wp:attachment":[{"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/media?parent=11401"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/categories?post=11401"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/plus.maciejpiasecki.info\/index.php\/wp-json\/wp\/v2\/tags?post=11401"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}