Security
Last updated: 2026. Contact: massimo@eordea.it
Reporting a vulnerability
If you find a security problem in this site, in the API or in the game's integration with it, write to massimo@eordea.it with enough detail to reproduce it. We will confirm receipt and keep you informed.
Please do not access accounts that are not yours, do not degrade the service for other players, and give us a reasonable window to fix the issue before publishing it.
How accounts are protected
- Passwords are stored as scrypt hashes. They are never written to logs and cannot be read back by anyone, including us.
- Website sessions are opaque server-side records, revocable instantly from "sign out everywhere".
- The game receives a short-lived access token and a refresh token that rotates on every use. A reused refresh token revokes its whole family.
- Password resets and email changes invalidate every session and every linked game installation.
- Login, registration and recovery are rate-limited per address and per account, and never reveal whether an email address is registered.
How results are protected
- Races are opened as sessions on the server before they are driven.
- Results are signed with a key issued for that one session; there is no shared secret inside the game build.
- Lap totals, sector times and the elapsed session window are checked against each other before a result counts.
- Suspicious results are quarantined for human review rather than silently dropped, so the evidence survives.
What we do not claim
No system is perfectly secure, and a determined attacker with control of a game client can always try to submit plausible-looking times. The design goal here is to make that expensive, detectable and reversible — not to claim it is impossible.