Hacker News new | ask | show | jobs
by tart-lemonade 494 days ago
It downloads and executes a Python script to update the store page? Log4j/log4shell, anyone?

Just build a JSON API! It's not that hard! You don't need to RCE your game every time it launches just for microtransactions.

1 comments

> Just build a JSON API! It's not that hard!

I agree that a JSON API is a better approach, but it's possible for AAA game developers to screw that up too: https://arstechnica.com/gaming/2021/03/developers-to-update-...