Open ssl issues...

119 views
Skip to first unread message

Rob

unread,
Apr 1, 2016, 3:23:51 AM4/1/16
to Game Closure DevKit

Hello Dev team,


I got an email from google which is give below


Hello Google Play Developer,

Your app(s) listed at the end of this email utilize a version of OpenSSL that contains one or more security vulnerabilities. If you have more than 20 affected apps in your account, please check the Developer Console for a full list.

Please migrate your app(s) to OpenSSL 1.02f/1.01r or higher as soon as possible and increment the version number of the upgraded APK. Beginning July 11, 2016, Google Play will block publishing of any new apps or updates that use older versions of OpenSSL. If you’re using a 3rd party library that bundles OpenSSL, you’ll need to upgrade it to a version that bundles OpenSSL 1.02f/1.01r or higher.

The vulnerabilities were addressed in OpenSSL 1.02f/1.01r. The latest versions of OpenSSL can be downloaded here. To confirm your OpenSSL version, you can do a grep search for ($ unzip -p YourApp.apk | strings | grep "OpenSSL").

To confirm you’ve upgraded correctly, submit the updated version to the Developer Console and check back after five hours. If the app hasn’t been correctly upgraded, we will display a warning.

The vulnerabilities include "logjam" and CVE-2015-3194. The Logjam attack allows a man-in-the-middle attacker to downgrade vulnerable TLS connections to 512-bit export-grade cryptography. This allows the attacker to read and modify any data passed over the connection. Details about other vulnerabilities are available here. For other technical questions, you can post to Stack Overflow and use the tags “android-security” and “OpenSSL.”

While these specific issues may not affect every app that uses OpenSSL, it’s best to stay up to date on all security patches. Apps with vulnerabilities that expose users to risk of compromise may be considered in violation of our Malicious Behavior policy and section 4.4 of the Developer Distribution Agreement.

Apps must also comply with the Developer Distribution Agreement and Developer Program Policies. If you feel we have sent this warning in error, contact our policy support team through the Google Play Developer Help Center.

Regards,

Message has been deleted

Rob

unread,
Apr 4, 2016, 9:04:21 AM4/4/16
to Game Closure DevKit

Any Update ??


I try to it myself but there is an issues with libssl.a and libcrypto.a  both file has build but after run ndk-build in jin folder getting an error :


/Desktop/android/android-ndk-r10d/toolchains/arm-linux-androideabi-4.6/prebuilt/darwin-x86/bin/../lib/gcc/arm-linux-androideabi/4.6/../../../../arm-linux-androideabi/bin/ld: /Users/appypie/Downloads/TeaLeaf/jni/lib/libcurl.a(curl_ntlm_core.o): in function Curl_ntlm_core_lm_resp:curl_ntlm_core.c(.text+0x288): error: undefined reference to 'DES_ecb_encrypt'


make ***[ ../TeaLeaf/obj/local/armeabi/libtealeaf.so] Error 1

Jishnu

unread,
Apr 4, 2016, 9:55:27 AM4/4/16
to Rob, Game Closure DevKit
Hi Rob,
I was able to upgrade openssl 1.0.1s.

Follow https://wiki.openssl.org/index.php/Android to build libssl.a
and libcrypto.a
then, use https://github.com/gcesarmza/curl-android-ios to build libcurl.a.
--
Regards,
Jishnu

http://j15h.nu

rawan rakshash

unread,
Apr 4, 2016, 10:14:57 AM4/4/16
to Jishnu, Game Closure DevKit
Hi Jishu,

I have follow these step for android, but getting an error 

make depend

making depend in crypto...

../util/domd: line 30: makedepend: command not found

mv: Makefile.new: No such file or directory

make[1]: *** [local_depend] Error 127

make: *** [depend] Error 1

if you have build these file then please share us..


rawan rakshash

unread,
Apr 5, 2016, 1:56:48 PM4/5/16
to Jishnu, Game Closure DevKit
Thanks Jishnu,

Now My Open SSL issue has fixed, I have upgrade my SSL Version now its 1.0.1s

Thanks

Jishnu

unread,
Apr 12, 2016, 6:45:16 AM4/12/16
to rawan rakshash, Game Closure DevKit
There is a huge file size difference between the curl cross compiled
for android and the one that is being used in gameclosure.

Seems like GC is using code from Tealeaf/jni/deps/curl.

google duck

unread,
May 5, 2016, 6:30:43 AM5/5/16
to Game Closure DevKit
Will Gameclosure solve this issue in next build? OR fix in any PR?

Davide Aimone

unread,
May 7, 2016, 5:58:52 AM5/7/16
to Game Closure DevKit
The real question is... is gameclosure still alive???

Game Ninja

unread,
May 7, 2016, 6:00:13 AM5/7/16
to Davide Aimone, Game Closure DevKit
Such a beautiful framework should not be dead. We all should promote it. Whats your thoughts???

Davide Aimone

unread,
May 7, 2016, 6:13:34 AM5/7/16
to Game Closure DevKit
I think that this group is not monitored anymore: you can see the spam message and nobody delete them.

The last update of the core was 1 month old and I think the SSL problem is still not solved, but I think this is a blocking issue! And the last version of the core is absolutely broken!

I tried to get the access to weeby.co a lot of times but I've never get an answer.

Last but not least, GC team is very poor about marketing things: if someone discover this framework nowadays, they can find only outdated info.

I started my game with GC one year ago, and I'm not planning to move away since it is quite done, but if nothing will change, the next one will be based on something else!


Il giorno venerdì 1 aprile 2016 09:23:51 UTC+2, Rob ha scritto:

Game Ninja

unread,
May 7, 2016, 6:17:19 AM5/7/16
to Davide Aimone, Game Closure DevKit
I agree with you. I am going through same situation. They are poor in support and marketing. They need to invest to make it stable and for support. 

Hope it got take over by some big company and they make this product stable and famous too.


On Saturday 7 May 2016, Davide Aimone <aimo...@gmail.com> wrote:

Davide Aimone

unread,
May 7, 2016, 6:17:53 AM5/7/16
to Game Closure DevKit
Another point: integration with iOS gamecenter was broken since the release of iOS 9. I solve the problem and created a pull request on 21-nov-2015... Do you think my fix was merged? https://github.com/gameclosure/gamekit/pull/5


Il giorno venerdì 1 aprile 2016 09:23:51 UTC+2, Rob ha scritto:

Game Ninja

unread,
May 7, 2016, 6:20:38 AM5/7/16
to Davide Aimone, Game Closure DevKit
Upper management of game closure team should see this posts atleast. They are not taking benefits of our PR also.


On Saturday 7 May 2016, Davide Aimone <aimo...@gmail.com> wrote:

David King

unread,
May 7, 2016, 7:19:30 PM5/7/16
to Game Ninja, Davide Aimone, Game Closure DevKit
My instinct is that, while their open-source initiative was well intentioned, they've re-focussed all their efforts in weeby.co and partnerships with larger gaming studios.

This feeling was a major factor in our abandoning Button Up! which we developed on the GC platform. The early conversations were really positive, but I think at that point they were still feeling out the landscape...


Kind Regards,
David King

Tel: +44(0)7939273963

Davide Aimone

unread,
May 8, 2016, 9:07:35 AM5/8/16
to Game Closure DevKit
I agree with you, David.
May I ask what was your next choice for the game engine? Did you rewrite Button Up! in another framework?
I'm considering phaser.io, unity and cocos2D for the  next projects...


Il giorno venerdì 1 aprile 2016 09:23:51 UTC+2, Rob ha scritto:

David King

unread,
May 8, 2016, 1:57:42 PM5/8/16
to Davide Aimone, Game Closure DevKit
Nah, Button Up! was a folly at bet, I've gone on to freelance work for some steady income. I like to keep my mind moving!! Phaser.io looks pretty fun though...


Kind Regards,
David King

Tel: +44(0)7939273963

Jimmy Griffith

unread,
May 8, 2016, 4:38:01 PM5/8/16
to David King, Davide Aimone, Game Closure DevKit
Hey guys,

I'm sorry it's been tough to keep up the open source support. We have a lot of other projects in the works, keeping us busy to the max - the good news is they're going very well. We'll have more bandwidth soon, so I'm thinking about hiring a community focused dev to help keep devkit up-to-date across all our stacks, even the documentation. If you know anyone who might be interested, feel free to send me their info.

I'll check on the status of the issue in this thread tomorrow, and post back.

Best regards,
Jimmy


--
Jimmy Griffith
Studio Head | Weeby.co

Game Ninja

unread,
May 8, 2016, 4:41:13 PM5/8/16
to Jimmy Griffith, David King, Davide Aimone, Game Closure DevKit
Good to hear from Jimmy. We have loved gameclosure and need support from you guys. 

All the best for your all projects.

Davide Aimone

unread,
May 9, 2016, 3:35:13 AM5/9/16
to Game Closure DevKit
Hi Jimmy,
I'm happy to hear you here ;)

I could be interested in your proposal but it depends on what you are looking for exactly.
I think you already have my mail address, let me know some more details



Il giorno venerdì 1 aprile 2016 09:23:51 UTC+2, Rob ha scritto:

Jishnu

unread,
May 16, 2016, 12:05:31 PM5/16/16
to Game Closure DevKit, Davide Aimone
Hi everyone,
We at hashcube [1] have been using GameClosure for our projects for 2 years.

Our game Sudoku Quest[2] was featured last week internationally on
Google Play and we are on the verge of reaching 1 million downloads
there. We were featured on iOS last month in a few countries.

When we were developing, came across several bugs and most of them we
were able to fix it ourselves internally. (Isn't that the beauty of
free and open source software?!). We created several native plugins
based on our neededs, all of them are open source [3] (our main repos
are in bitbucket, github ones can be outdated. if you find anything,
let me know)

We made several updates to gameclosure native-ios and native-android
modules including upgrading to add Android M support, removing
unnecessary permissions, support for low end android devices, iOS 3D
touch support etc. If you guys are interested, you can map devkit-core
in manifest file to our github repo [4] and use it for your project.

Even though there are several important issues we are facing, we
haven't given up yet. Our current game Gummy Pop [5], which is in soft
launch phase right now is using GC. We are committed to GC for at
least one more game. So, for the GC community, we should be able to
provide the help if needed.

At the same time, I believe weeby will be able to release more of
their code and make the project alive.


[1] http://hashcube.com
[2] https://play.google.com/store/apps/details?id=com.hashcube.sudokuquest
[3] https://github.com/hashcube
[4] https://github.com/hashcube/devkit-core
[5] https://play.google.com/store/apps/details?id=com.hashcube.bubble

Davide Aimone

unread,
May 17, 2016, 3:44:11 AM5/17/16
to Game Closure DevKit
Really interesting news! I want to give it a try in next days.

Long time ago, someone suggested a "community edition" of GC and I think it can be an interesting idea, but I think we still need help from GC studio.
If Jimmy is interested we can discuss the various solution here or on Skype.

We need continuity and solidity in GC framework to use it


Il giorno venerdì 1 aprile 2016 09:23:51 UTC+2, Rob ha scritto:

google duck

unread,
May 21, 2016, 1:04:27 PM5/21/16
to Game Closure DevKit
Hi Davide,

I think Jishnu had suggested to start community based GC at that time when commit rate was slowest. 

google duck

unread,
May 21, 2016, 1:07:19 PM5/21/16
to Game Closure DevKit, aimo...@gmail.com
HI Jishnu,

We are glad, we have supportive developer like you in this community. You are always prompt in helping on this forum. You are gem of this forum.

Thanks 

Davide Aimone

unread,
May 29, 2016, 10:06:04 AM5/29/16
to Game Closure DevKit
Thank you Jishnu,
I will give a try to your version but I have a couple of question:
How much is stable? Do you know any blocking bug? Do you accept pull request?


Il giorno venerdì 1 aprile 2016 09:23:51 UTC+2, Rob ha scritto:

Jishnu

unread,
May 30, 2016, 2:03:05 AM5/30/16
to Game Closure DevKit, Davide Aimone
Hi Davide,
All our games in production are using that repo.

I'm trying open source all the projects (gc modules) to github. Will
write an email here once it is done.

Yes. We are happy to accept pull requests.

Jishnu

unread,
Jun 8, 2016, 8:08:58 AM6/8/16
to Game Closure DevKit
Hi everyone,
I just finished moving all out modules to github. Will write a detailed email listing them.

Also, we decided to do all our development related to devkit and devkit module libraries open, on github.

Davide Aimone

unread,
Jun 25, 2016, 6:36:15 AM6/25/16
to Game Closure DevKit
Great!!!
I started to use your fb module and it works like a charm! well done!

I think you should open a new thread here to list your work ;)
Reply all
Reply to author
Forward
0 new messages