Dilan Rona Posted 10 hours ago Report Posted 10 hours ago 10 minutes ago, MKMoose said: Yes, it's entirely safe. It has always been safe* if you weren't also using a select few mods that had obfuscated code (most notably VS Radio and Caves and Caverns, apparently). *Note that the current version is 1.13.2 (September 2nd release). If you haven't updated to it and are running a multiplayer server, then it is strongly recommended to do so, as it includes an important security fix. There is no practical reason to stop using it as of now, as it remains fully functional and safe. There is no substantiated reason to believe it will either stop working or become unsafe anytime in the near future, but if it does, it will be the result of an update, so you might simply want to be a bit more careful about updating it past 1.13.2. That horse has bolted allready, mod was forked as of today. 2
icesharkk Posted 10 hours ago Author Report Posted 10 hours ago 2 hours ago, Rainbow Fresh said: It wasn't obfuscated, just hidden, which is your previous point. No. Hiding it from the public repo, cover its tracks in the log, and delaying execution of the crashcodes to hide attribution to configlib are all obfuscation tactics. 20 minutes ago, Jhoryn said: Howdy. I'm a quiet lurker and been reading everything in the hopes of reassurances, and understand a lot of the anger comes from the lack of clarity and loss of trust. Please note, the following is questioning the code/mod itself and not Mal/the mod dev. I won't attack a person I don't know and have never interacted with. Bold is for TLDR From a User/Player standpoint, the two biggest questions needing reassurance are 1. Is ConfigLib safe to use in its current version? This event is a reminder that mods are code, and that code is shared on a basis of mutual trust. We players trust the mods to do exactly what they say they do and nothing more. Right now, that trust is shaky at best. In hindsight, Mal should have released the Anti-Cheat as a stand-alone download option. Let servers choose to use it, and it probably would've been as popular as the other mods. But, because that's not what happened here, people are understandably upset that a mod did way more than what they were told it did. Now, the safety of the code is being questioned. Can we trust a mod's code to do what it says it does? 2. If ConfigLib is safe, should we still use it, or should a new branch under new ownership be created? Because ConfigLib (and the other mods) have become such a core feature of other mods, it can't simply be removed without adversely affecting other mod devs who have come to rely on it. It is, or was, a well built, useful mod. But, because trust has been lost, should a new forced branch of these questioned mods be created? the author of packrat released a replacement mod that uses the existing json config file formats already in most mods. its called configkit use that instead since its written by a dev committed to transparency and safe code attestation. 3
Nossin Posted 10 hours ago Report Posted 10 hours ago 24 minutes ago, Jhoryn said: 2. If ConfigLib is safe, should we still use it, or should a new branch under new ownership be created? Ultimately it will be forked or independently remade since Maltiez cannot be trusted given they had removed and re-added their malware. Also keep in mind in addition to Config, overhaul and PML, Maltiez admitted they also contain the malware. It is in your best interest to wait until those mods have been rebuilt, if not for the malware, but because there are reports of performance issues 1 1
MKMoose Posted 9 hours ago Report Posted 9 hours ago (edited) 4 hours ago, Vesk Aida said: Obfuscating the code shows further proof this author knew their behavior was unethical. 50 minutes ago, icesharkk said: No. Hiding it from the public repo, cover its tracks in the log, and delaying execution of the crashcodes to hide attribution to configlib are all obfuscation tactics. Obfuscation in software has a very specific meaning, and the controversial code does not meet the definition. I would expect you to respect that when trying to argue about technical details, especially in a context where actual obfuscation is a critical part of the equation as that is what Maltiez' code was detecting. Edited 9 hours ago by MKMoose 1 1
icesharkk Posted 9 hours ago Author Report Posted 9 hours ago (edited) 36 minutes ago, MKMoose said: Obfuscation in software has a very specific meaning. I would expect you to respect that when trying to argue about technical details, especially in a context where actual obfuscation is a critical part of the equation as that is what Maltiez' code was detecting. apologies. My background deals in concealment and obfuscation but at the user behavior level. e.g. hackers. his actions overall are a combination of concealment and obfuscation from a technique standpoint. but i see how it does not meet the definition of code obfuscation now. still consider the overall behavior obfuscation. This is the sort of behavior I have seen APTs do when poisoning repositories and attempting to maintain persistence/establish a foothold on a network. Edited 9 hours ago by icesharkk 1
Teh Pizza Lady Posted 9 hours ago Report Posted 9 hours ago 4 hours ago, Zaldaryon said: Just an fyi, while it's what people think, there is no proof he was hired to touch the combat system. afaik I've read in the public Discord, it's not about combat at all. Well I was sourcing this from here: Quote 6. The 1.23 update This it the big one. Believe it or not lads, the team has decided that Combat should be a focus for the next big update. Here's what we want to look into: Tighter, more visceral hit detection; More varied attack animations; Possibly rework of armor- and weapon tiers; A few more types of weapons; and more! The combat changes will be in good hands - we have Maltiez, author of the mod Combat Overhaul, on our team to advise us, we abducted the infamous SaltyWater to help us with animations and conveniently we just received new combat hit detection tech from the Glint team as they are also currently working on combat \o/ (For clarity, we will not integrate Combat Overhaul into the vanilla game. CO will still have a reason to exist after this update) So maybe a lot of us misunderstood Tyron on this, but I definitely took it to mean that Maltiez was hired into an advisory role to direct the combat update, not necessarily have a direct input on the code itself. If someone from the VS Dev team could clarify this, it would help immensely to know instead of assuming. 3
Dilan Rona Posted 8 hours ago Report Posted 8 hours ago Emphasis would then be on advice. Not that he is a part of the vs team itself. But because of what happened, any existing code he contributed will be checked again, and all future contributions will be picked with a fine tooth comb.
MKMoose Posted 8 hours ago Report Posted 8 hours ago 9 minutes ago, Teh Pizza Lady said: So maybe a lot of us misunderstood Tyron on this, but I definitely took it to mean that Maltiez was hired into an advisory role to direct the combat update, not necessarily have a direct input on the code itself. If someone from the VS Dev team could clarify this, it would help immensely to know instead of assuming. The conversation @Zaldaryon is referencing may be this: It's not crystal clear exactly what Balduranne meant here, but my guess is that Maltiez might be working on combat broadly, but not on the armor overhaul specifically.
LadyWYT Posted 8 hours ago Report Posted 8 hours ago 3 minutes ago, MKMoose said: It's not crystal clear exactly what Balduranne meant here, but my guess is that Maltiez might be working on combat broadly, but not on the armor overhaul specifically. Redram's comment in the wishlist thread may shed some light here. Specifically: Quote What we will *not* be doing is dozens of individual armor locations in the style of combat overhaul.
icesharkk Posted 8 hours ago Author Report Posted 8 hours ago 17 minutes ago, Dilan Rona said: Emphasis would then be on advice. Not that he is a part of the vs team itself. But because of what happened, any existing code he contributed will be checked again, and all future contributions will be picked with a fine tooth comb. there's a lot of contradictory information. multiple staff have referenced his future code commits. some staff say he's advisory. i dont feel comfortable assuming one way or the other until the official statement or post mortem explains wtf his actual impact to the game will be moving forwards. As well as validate whether he has had any impact on 1.22. everything else is supposition for unreliable statements.
Vesk Aida Posted 8 hours ago Report Posted 8 hours ago 4 hours ago, Rainbow Fresh said: Source? I re-read this entire supposed "ground truth mega thread" and didn't find any mention of this yet. Its been mentioned a number of time, though from what I've seen even Maltiez has never attempted to implement any such feature. Though, given the inherent lack of transparency about code being present, maybe 'that' should be taken with a grain of salt: but I've yet to see any evidence it was ever acted upon: merely mentioned as a possibility. 1
Grish Posted 7 hours ago Report Posted 7 hours ago Announcing a suspension from the team may have legal issues for them and that part is understandable. There is absolutely nothing wrong with them announcing his ban from moddb, but They have not addressed anything because they knew about it, its there in the messages ,and they still trusted him. This is actually the most concerning part of the whole matter for me. They did not care about allowing us to download malware,and quite frankly our privacy and safety. I don't care what happens to this game at this point,the lack of integrity lets me know exactly what they think of me. 3
Vesk Aida Posted 7 hours ago Report Posted 7 hours ago (edited) I hope it doesn't have an impact on Vintage Story's development, sales or reputation (e.x. "that game which had malware in it"). Overall I feel this crash code situation would not have been serious or even worth mention had Maltiez been honest and transparent about documenting the code and its function, or even making it as a feature for a stand-alone mod (e.g. "Maltiez's Anti-Cheat"). The deliberate lack of documentation to hide this 'feature', and by his own admission with the purpose of the code 'being' crash code is pretty inexcusable. My fear from all this drama and nonsense is that many/all of Maltiez's excellent mods (e.g. Maltiez's "Firearms" mod) might never get updated as VS continues to receive patches and support, and will inevitably fall by the wayside. Hopefully Maltiez either is allowed back into the community with more scrutiny/code checking, or a more transparent maintainer is able to keep the mods functioning. Edited 7 hours ago by Vesk Aida 1
Zaldaryon Posted 7 hours ago Report Posted 7 hours ago 1 hour ago, MKMoose said: The conversation @Zaldaryon is referencing may be this: It's not crystal clear exactly what Balduranne meant here, but my guess is that Maltiez might be working on combat broadly, but not on the armor overhaul specifically. Exactly that. I only referred to this public info. 1
imtsubaki Posted 7 hours ago Report Posted 7 hours ago Maltiez was brought onto the team primarily as a Mod API programmer. A very large portion of his work has been bug fixes and changes to the API, either extending what mods are able to do or making certain things easier to accomplish without having to work around the existing API. Because most of that work is in the API, the actual source involved is also publicly available through Anego Studios' GitHub. This isn't code that only exists inside some private build where nobody outside the dev team can see what is actually being shipped. He also isn't overseeing or directing some large part of the combat update. Given his experience with his previous combat overhaul mod, it shouldn't be surprising that he has helped with parts of it or offered input where relevant, but much of his earlier work was focused more around bug fixing and changes or additions involving entities, animal AI, and the modding API in general. I don't really want to get into internal development specifics beyond what is already publicly visible, but I do think there is a fairly distorted picture forming of what his role on the team actually was 3
OBAMFSpike Posted 6 hours ago Report Posted 6 hours ago Accountability and trust are major concerns the whole world wide right now everywhere a person OR seraph could chose to go. There are a lot of wise individuals in this thread.
icesharkk Posted 6 hours ago Author Report Posted 6 hours ago 46 minutes ago, imtsubaki said: Maltiez was brought onto the team primarily as a Mod API programmer. A very large portion of his work has been bug fixes and changes to the API, either extending what mods are able to do or making certain things easier to accomplish without having to work around the existing API. Because most of that work is in the API, the actual source involved is also publicly available through Anego Studios' GitHub. This isn't code that only exists inside some private build where nobody outside the dev team can see what is actually being shipped. He also isn't overseeing or directing some large part of the combat update. Given his experience with his previous combat overhaul mod, it shouldn't be surprising that he has helped with parts of it or offered input where relevant, but much of his earlier work was focused more around bug fixing and changes or additions involving entities, animal AI, and the modding API in general. I don't really want to get into internal development specifics beyond what is already publicly visible, but I do think there is a fairly distorted picture forming of what his role on the team actually was citation required 1
Paruza Posted 6 hours ago Report Posted 6 hours ago 1 hour ago, Vesk Aida said: I hope it doesn't have an impact on Vintage Story's development, sales or reputation (e.x. "that game which had malware in it"). It will unfortunately. But that can be mitigated by ultimately taking a hard line on this kind of abuse. Quote Overall I feel this crash code situation would not have been serious or even worth mention had Maltiez been honest and transparent about documenting the code and its function This is 100% of the issue. You can make an anti-cheat mod if you would like, VS can add anti more official cheat measures if they want, All of this is fine as long as you are disclosing this activity and your customers are agreeing to it via a EULA. But stuffing malware "anti-cheat" into a mod that has nothing to do with that? That is straight up illegal and is a serious offence against supply chain trust. However much people like his mods, the right answer here is additional transparency and banning him from moddb. Followed up with a review of moddb policy as well if needed. 1 hour ago, Grish said: They have not addressed anything because they knew about it, its there in the messages ,and they still trusted him. I don't care what happens to this game at this point,the lack of integrity lets me know exactly what they think of me. I wouldn't go quite so far as that yet. It's hard to know really how many people knew, and if at the time they really understood the gravity of these actions. I totally understand and forgive the disjointed response so far, it's easy to see how that can happen. Some team members knowing about a thing, but not really connecting with the problem, isn't the same as an official response by the company. Let them sort through it, and we will judge their actions after. 1
VANTABlack2000 Posted 6 hours ago Report Posted 6 hours ago 2 minutes ago, Paruza said: It will unfortunately. But that can be mitigated by ultimately taking a hard line on this kind of abuse. This is 100% of the issue. You can make an anti-cheat mod if you would like, VS can add anti more official cheat measures if they want, All of this is fine as long as you are disclosing this activity and your customers are agreeing to it via a EULA. But stuffing malware "anti-cheat" into a mod that has nothing to do with that? That is straight up illegal and is a serious offence against supply chain trust. However much people like his mods, the right answer here is additional transparency and banning him from moddb. Followed up with a review of moddb policy as well if needed. I wouldn't go quite so far as that yet. It's hard to know really how many people knew, and if at the time they really understood the gravity of these actions. I totally understand and forgive the disjointed response so far, it's easy to see how that can happen. Some team members knowing about a thing, but not really connecting with the problem, isn't the same as an official response by the company. Let them sort through it, and we will judge their actions after. At this point I think the best thing to do is try not to get too emotional and give the team a chance to explain themselves. it's easy to get emotional over the whole thing which is justified to an extent, but we need to have some trust in the team. I got really emotional at first, but gave them benefit of the doubt that somehow this would end well and I think Tyron tried to keep things calm and now this thread is allowed to exist and even have a mod fact checking some things, so I think things are starting to calm down and in time we will know who knew what and things will get resolved. Just have to have some faith in the team IMO. 3
imtsubaki Posted 6 hours ago Report Posted 6 hours ago (edited) 13 minutes ago, icesharkk said: citation required Well there isn't really a public source I can cite for individual repo permissions and what not, you can see on the Discord channel 'rules-and-info' what his title is. But most of what else I said comes from looking through the repo myself and talking with other developers over time. I am actively contributing to the game as well, so I do have some direct context here. Edited 6 hours ago by imtsubaki 2
icesharkk Posted 5 hours ago Author Report Posted 5 hours ago (edited) 14 minutes ago, imtsubaki said: Well there isn't really a public source I can cite for individual repo permissions and what not, you can see on the Discord channel 'rules-and-info' what his title is. But most of what else I said comes from looking through the repo myself and talking with other developers over time. I am actively contributing to the game as well, so I do have some direct context here. then redact the unconfirmed information from your post here and on the other thread. we have absolutely zero information on his contribution to 1.22 and only vague and contradictory on 1.23. he has transgressed more than enough with the documented malicious code that there is no reason to falsify additional speculative involvement. it muddys the water and fearmongers. Edited 5 hours ago by icesharkk 2
MKMoose Posted 5 hours ago Report Posted 5 hours ago (edited) 33 minutes ago, icesharkk said: then redact the unconfirmed information from your post here and on the other thread. we have absolutely zero information on his contribution to 1.22 and only vague and contradictory on 1.23. Tsu is a code contributor with access to Anego's private repositories, but even that barely matters in this case as virtually everything they have said is publicly available information. Maltiez' role of the dev team is listed on Discord as "Mod API Programmer" and in game credits as "Bug fixing, Mod API". Tyron has stated that Maltiez advises them on the combat rework. Anything beyond that about his specific contributions is generally information private to Anego which they are under no obligation to share - they know what he contributed to and can investigate it themselves if they deem it as necessary. Although, inspecting his activity on GitHub would allow you to at least get an idea about which bugs he worked on. There is no reason to paint a small extra crumb of information from another contributor about what Maltiez has worked on as "falsified", "muddying the water" or "fearmongering". Code going through review prior to merging is a practice fundamental to modern software development. The core mods and modding API (which are also what most bugfixing is centered on) are publicly visible, so all changes to it made for the public releases can be inspected freely. The remaining code which is not in the public repositories can be decompiled and inspected easily as well, as it is not obfuscated. Edited 5 hours ago by MKMoose 2
imtsubaki Posted 4 hours ago Report Posted 4 hours ago 1 hour ago, icesharkk said: then redact the unconfirmed information from your post here and on the other thread. we have absolutely zero information on his contribution to 1.22 and only vague and contradictory on 1.23. he has transgressed more than enough with the documented malicious code that there is no reason to falsify additional speculative involvement. it muddys the water and fearmongers. I was inbetween customers IRL, so I apologize my answer was not the greatest and was a bit quick, MKMoose's reply right after hit's the nail on the head for what I was trying to cover.
Meiiolri Posted 3 hours ago Report Posted 3 hours ago The whole situation started and moved poorly, from some part of community outrage, to Maltiez "i did the right" and doubling down deleting, readding and deleting the malicious code again. To the whole incidents on discord server (idk how it is there i do not use discord anymore). The main issue as of now is the wait from the dev team to address the issue. I understand that getting the facts right and checking everything is a good thing. Though the longer we do not get the official response there will be issues. 1
Recommended Posts