Console logs contain pseudo-PII and enumeration info

While there is nothing red-hot in these logs, I find it a bit sketchy you’re encouraging users to upload them unredacted here with links for anyone else to download them at will. They include hardware enumeration for their CPU, GPU, all network adapters, Windows build info and Machine UUID. As well as their user install path for the game, steam name, etc. This could be used to collate more information about a user.

Which some or all of them are then available from an unsecured AWS S3 bucket as follows: (Google search)

site:cdck-file-uploads-europe1.s3.dualstack.eu-west-1.amazonaws.com “atoma.cloud”

Several thousand are found via that search…

3 Likes

We’ll sort it out. :slight_smile:

Np. That probably came across more intense than I intended. I just figured data in the open on public S3 buckets is less than ideal, given the stories in the news about them over the years. And you guys need a break from potential bad PR these days :sweat_smile: