Trying to get synced animations in the editor is somehow really hard even though the objects are created AND updated in the same ticks... I have no clue why (also really do ignore the ghost object I somehow made an object which is a dupe of an existing object on save)
@ZURC_99 I mean you're surprised?
This would be far from the first time encryption methods had a universal key. By now I've just come to expect this from tools which aren't public source.
Gotta love it when you spent 5 days debugging just to find out that your hook was partially inlined on Windows making it pretty much useless (images shown is the uses of the method on Windows VS Android)
#GeometryDash So considering RobTop never did the due diligence he should have as a European company to report what was leaked. I may as well just reveal one thing I kept secret for quite a while to not immediately soil his reputation.
In the DB leak were unencrypted passwords.
If you think about it. Some of the most critical logins on the web (sftp & ssh which are the protocols to remotely communicate with a server) don't support 2 factor authentication. Kind of a scary thought).
@33YYYYYYY@chrissvector@RobTopGames 1) 2 way obfuscation is useless
2) Nah, most apps use a one time access token which can be revoked at any time when it's compromised. Besides no party involved should have any reason to leave a password 2 way encrypted/encoded since you should test against the hash.
@ArcadiacManiac@ClingingBogGMD@tricipital14 Anyone confirmed compromised through this person's messages was already informed. But unless RobTop goes through the SQL logs (which sadly he isn't doing) I have no way to confirm the scale of the exploit abuse.
@ArcadiacManiac@ClingingBogGMD@tricipital14 Due to sensitivity on this topic I'm not providing anything identifiable but please refer to my reply on the top comment in this thread to explain how non temp this really is.
@ArcadiacManiac@ClingingBogGMD@tricipital14 This same person also got into a bunch of accounts at the time, so there's a high likelihood that they used this same table or used a login bypass trick you can execute when you have read access to the DB.
@ArcadiacManiac@ClingingBogGMD@tricipital14 Currently the person from who we found evidence of knowing about this exploit before pen testers got to it has been inactive. I've always said that it's currently unknown to what extend the breach was abused. Just that the possibility of this data was leaked.
@tricipital14 Basically rob seems to have made this table to find common passwords bots check for so that he can blacklist these. However, he just straight up captures raw login inputs from anyone to achieve this. This table has also existed for years.
@greyogd He did in the sense that he immediately patched it once it was reported. But when I told him that others had also found it and that he legally has to disclose that publicly he completely ignored it.