Search Unity

  1. Welcome to the Unity Forums! Please take the time to read our Code of Conduct to familiarize yourself with the forum rules and how to post constructively.
  2. Dismiss Notice

Possible Scam: Received an email regarding faulty Unity IAP

Discussion in 'Android' started by LandonC, Sep 10, 2021.

  1. LandonC

    LandonC

    Joined:
    Dec 20, 2012
    Posts:
    83
    I received an email regarding a flaw in Unity IAP, it does not seem legit but I thought of sharing it here.

    Email came from s3.gameresearch@gmail.com
     
    Last edited: Sep 14, 2021
  2. mgear

    mgear

    Joined:
    Aug 3, 2010
    Posts:
    8,992
    Are those your games? Sounds like a realistic bug/vuln though..

    still bit strange that they didn't use school email.
     
  3. LandonC

    LandonC

    Joined:
    Dec 20, 2012
    Posts:
    83
    Yeah, those are my games. I believe this is a scam as the versions mentioned are very much outdated. I am using the latest IAP available to me too, so if the IAP is flawed, wouldn't everyone who uses Unity IAP be affected too?
     
  4. JeffDUnity3D

    JeffDUnity3D

    Unity Technologies

    Joined:
    May 2, 2017
    Posts:
    14,446
    We believe the email is well intentioned and likely not a scam. Our IAP receipt validator performs a local checksum and does not validate with Google servers as correctly stated. However, we have not heard of widespread use of the bypass that this researcher has mentioned in actual practice, but it is possible. No validation is ever 100% effective, and we do not make that claim. We are discussing improved server-side receipt validation in a future release. In the meantime, you might consider a service like ChilliConnect or PlayFab to verify receipts server-side. Our documentation is linked below and states:

    "Important: While Unity IAP provides a local validation method, local validation is more vulnerable to fraud. Validating sensitive transactions server-side where possible is considered best practice"

    https://docs.unity3d.com/Manual/UnityIAPValidatingReceipts.html
     
    LandonC likes this.
  5. LandonC

    LandonC

    Joined:
    Dec 20, 2012
    Posts:
    83
    Thank you so much for clarifying!
     
  6. Mauri

    Mauri

    Joined:
    Dec 9, 2010
    Posts:
    2,657
    Also, searching the name in that email brings up quite a few entries that confirm the legitimacy - eg. this and this one.
     
  7. albert8716

    albert8716

    Joined:
    Nov 14, 2019
    Posts:
    8
    We also received this message even though we are already using server-side validation.

    We are doing: purchase -> success -> local validation (Unity IAP Validator) -> server validation -> server unlocks content.
    1. Does this mean we don’t have an issue? We assume we were notified because we are also using the local validation first
    2. Is there any reason for us to do the local validation (as we are validating with the server anyway)?

    We implemented it based on the example project but we note there's no local validation in this diagram:
    https://docs.unity3d.com/Packages/c...72.1425503656.1632354011-576983215.1551664329

    Or in this description of server validation:
    https://docs.unity3d.com/Manual/UnityIAPValidatingReceipts.html

    Many thanks,
    Albert
     
  8. Voxel-Busters

    Voxel-Busters

    Joined:
    Feb 25, 2015
    Posts:
    1,832
    Always validate your receipts on your backend server to be fail proof!
     
  9. JeffDUnity3D

    JeffDUnity3D

    Unity Technologies

    Joined:
    May 2, 2017
    Posts:
    14,446
    No solution, even on the server, is fail proof.
     
  10. JeffDUnity3D

    JeffDUnity3D

    Unity Technologies

    Joined:
    May 2, 2017
    Posts:
    14,446
    More validation would never hurt! But typically if you are doing server side validation, local validation is not needed
     
  11. Voxel-Busters

    Voxel-Busters

    Joined:
    Feb 25, 2015
    Posts:
    1,832
    I see. Wasn't aware of the hacks even with server validation.