Jump to content
IGNORED

Account Info in Plain Text


Recommended Posts

I posted this in the AtariVCS subreddit, thought some here would find it interesting.

 

Well digging around trying to add some open source games to the Dashboard I found that the account info is stored in plain text in a json file.

 

The file is located at /home/user/.config/unity3d/Atari/Dashboard/Production/GameDoc/LocalDB/Session.json

I found it using a Fedora live disk, on Fedora its mounted in /run/media/liveuser/storage instead of /home

 

It includes email, pin, password, nick name, and date of birth.

It appears the password is something generated and used for creating an authorization token for the store. The token is also listed in the file.

 

The Session.json file appears to store the info for anyone with an account on the system.

  • Like 2
  • Haha 1
Link to comment
Share on other sites

I suggest you prevent the console from being stolen, in that case. ?
Thank goodness for SSL, in regard to communication with the server. I believe that information is per-console, though?
I don't know yet if it's possible to login to another console with account details from another machine. I think accounts are local at this time.
I am looking forward to looking more deeply into the differences between AtariOS versions as they come along, if it's still possible.

Link to comment
Share on other sites

20 minutes ago, Cebus Capucinis said:

LMFAO, better hope your Netflix box isn't wide open to the interwebs and that you aren't re-using passwords ? 

 

Does it store credit card data anywhere and can I get your IP? "Asking for a friend!"

 

The Netflix "app" for it is just a bookmark for Chrome that launches the address directly in Chrome, so should be alright.

 

I don't know about credit card info, the thing is so weakly implemented I don't trust it to enter one.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...