haven512 Posted Wednesday at 11:54 AM Report Posted Wednesday at 11:54 AM "Hello! After one of Vintage Story's developers (Maltiez) added malware into game's modifications, and other members of dev team didn't do anything to prevent that or remove that code, and kept hiding that before it became public, i'm asking you to please delete my in-game account. After what's happened and how it was handled by the devs, i can't trust any code or software made by Vintage Story's developer team, so i'm compelled to stop using it. I'm not going to ask for a refund, but i don't want to deal, in any way, with people approving and covering someone adding malware in their code and software." This is the request i've sent to Vintage Story's customer support. Please treat it as my official position towards the game and it's developers. 3 1
Stoney Martyr Posted Wednesday at 12:12 PM Report Posted Wednesday at 12:12 PM Bump and photo for more context
Diff Posted Wednesday at 02:07 PM Report Posted Wednesday at 02:07 PM 1 minute ago, PhotriusPyrelus said: What did this 'malware' do, exactly? Appreciate you asking, there's an awful lot of misinformation about the situation. I'm not a fan of what happened, but we don't help anything by drifting further away from the actual facts. There is a paid cheat client for Vintage Story. This is a product that has real users, it obfuscates its code, and it lets people cheat in multiplayer servers. Maltiez, who originally was just a modder but was actually hired by Anego later on, added code to 3 of his mods, including ConfigLib, that attempts to detect this hacked client and mess with them. When ConfigLib detects the cheat client during a multiplayer session, it will set random timers to disconnect the client, crash the game, or close the game normally. It does this in ways that hide that it's the one responsible for the crashes in the logs. From what I understand, Maltiez's detection paid attention mostly to variable names, whether they contained unprintable characters or whether they were consistently too short to be humanly readable, both signs of obfuscated code. I believe there was also some searching for specific strings associated with the cheat client. This has affected one innocent mod that I have heard of, Caves and Caverns, who obfuscated their code to prevent other people from stealing their tuned cave generation. There may be more, but like I said ConfigLib wasn't making it easy to identify it as the source. 1 5
icesharkk Posted Wednesday at 02:48 PM Report Posted Wednesday at 02:48 PM 35 minutes ago, Diff said: Appreciate you asking, there's an awful lot of misinformation about the situation. I'm not a fan of what happened, but we don't help anything by drifting further away from the actual facts. There is a paid cheat client for Vintage Story. This is a product that has real users, it obfuscates its code, and it lets people cheat in multiplayer servers. Maltiez, who originally was just a modder but was actually hired by Anego later on, added code to 3 of his mods, including ConfigLib, that attempts to detect this hacked client and mess with them. When ConfigLib detects the cheat client during a multiplayer session, it will set random timers to disconnect the client, crash the game, or close the game normally. It does this in ways that hide that it's the one responsible for the crashes in the logs. From what I understand, Maltiez's detection paid attention mostly to variable names, whether they contained unprintable characters or whether they were consistently too short to be humanly readable, both signs of obfuscated code. I believe there was also some searching for specific strings associated with the cheat client. This has affected one innocent mod that I have heard of, Caves and Caverns, who obfuscated their code to prevent other people from stealing their tuned cave generation. There may be more, but like I said ConfigLib wasn't making it easy to identify it as the source. theres also a lot of rug sweeping and minimization going on. bottom line maltiez pushed known malicious code to thousands of computers. Thankfully there was not credit card theft/ransomwhere/etc highly illegal consumer exploitation but that doesnt change the definition of "malware". the fact that his intent was noble is completely irrelevant to the impacted users. We cant even properly assess how many were impacted because his code deliberately obfuscated its contribution to the crash reports and runtime errors in order to remain hidden in the first place. Furthermore this shows maltiez is willing to violate of ethics, moddb terms of use, and several laws in pursuit of his own version of the greater good. someone who chooses not follow rules they dont believe in is one comfy justification away from repeat offense. 3 1
Recommended Posts