Demoncyborg Posted September 3 Report Posted September 3 it's insanely sad to me how little trust people put into the devs who have been making this game for 10 years. like all of the sudden everything they stand for is going to come crashing down because of one person hired not even a full year ago. 14 2
williams_482 Posted September 3 Report Posted September 3 7 hours ago, Trace said: Just got word of all this, and decided to uninstall VS. If this dev team is going to circle the wagons over this extremely shady behavior, well, it's been fun but my free time is short and my backlog of games is long. I'll seek my entertainment elsewhere from more reputable sources. 6 hours ago, lizardsprint said: Same. I've bought so many copies of the game for people, too, which is sad. I ran a server for all those friends, but have decided to shut it down tonight after learning of this, will warn all of them and others, and uninstall the game myself. I'd advise anyone to wait until they actually "circle the wagons" around this guy before deciding that this dev team (and by extension their game) are disreputable. This is a small team, likely lacking anyone with real public relations training, who just stumbled into an unexpected and very tricky situation. Here we have: - A recently hired employee, and also creator of a large number of very popular, functionally load-bearing mods, who did something which is clearly bad and ill advised but with apparent good intentions, and reacted very poorly when this came to light. - A large group of people who are justifiably angry, but have also whipped themselves into a frenzy over exaggerated claims of exactly what this guy did and why, and are demanding immediate and harsh action against them. Anego knows this is a serious situation and they are taking time to get all the facts and make a careful, considered decision of what to do. Taking that time to make the best decision possible is clearly the correct process here. Judge them for their final decision when they've actually made one. 7
williams_482 Posted September 3 Report Posted September 3 11 hours ago, Nossin said: Maltiez distributed a malware through VS's mod database to thousands of users with malicious intent to target a specific group with little concern for any victims caught in the crossfire. (Emphasis mine) I want to be clear on something which is being obscured in this statement and others like it: that "specific group" which Maltiez targeted were the developer and users of a *paid* mod designed for the purpose of cheating on multiplayer servers. A "specific group" who either paid money for the ability to harm other players, or were happy to earn money facilitating that harm. The mod and developer have not been named because they are a cancer on the community and advertising for them does us all a disservice. Maltiez's actions were, in my opinion, ill-considered and both legally and ethically dubious. I am not defending the actions or the person. But I also think understanding the motives here is useful. 3
Paruza Posted September 3 Report Posted September 3 6 hours ago, Vratislav said: Even experienced moderators and Tyron himeslf may make mistakes if there is not clear guidance. That's why I am not angry much, as what I see from the studio's people reactions, there is no bad intent, they are just desperately trying to keep situation under control, when missing proper tools or guidance. I agree completely with this. I'm not angry with the VS studio *yet* . It's easy to see how this can happen, it's easy to understand how the communication thus far could be misguided and fragmented. It's not optimal, but I'm fine with that. What matters is what they ultimately decide to do. Fortunately there's plenty of past examples of how you deal with this kind of thing, and the consequences for the studio if they don't handle it well. 2 2
lizardsprint Posted September 3 Report Posted September 3 (edited) 33 minutes ago, williams_482 said: who just stumbled into an unexpected and very tricky situation. ... Anego knows this is a serious situation and they are taking time to get all the facts and make a careful, considered decision of what to do. Taking that time to make the best decision possible is clearly the correct process here. Judge them for their final decision when they've actually made one. It's really not a tricky situation at all, and their actions so far have been showing the exact opposite of this, that they don't really think this is a serious situation. I don't deal with games, or developers of games, that intentionally harm/degrade the experience of players because of their own grudges or insecurities, whether it's with DRM like Denuvo, always-online connections/spyware, rudimentary "malware" like this one, or of course actual malware in games. The "motive" does not really matter. The "motive" behind Flock/Axon cameras is to "stop criminals" but they are routinely abused for cop's or random 3rd party individuals with access own personal interests/motives. I have plenty of other games in my library whose developers let me play how I want that don't have a track record of endorsing, or downplaying, harmful software in their game/mods, especially by one of their own developers. No need to bother with wannabe-arbiters of gameplay. Edited September 3 by lizardsprint 6
Nossin Posted September 3 Report Posted September 3 8 minutes ago, williams_482 said: (Emphasis mine) I want to be clear on something which is being obscured in this statement and others like it: that "specific group" which Maltiez targeted were the developer and users of a *paid* mod designed for the purpose of cheating on multiplayer servers. A "specific group" who either paid money for the ability to harm other players, or were happy to earn money facilitating that harm. The mod and developer have not been named because they are a cancer on the community and advertising for them does us all a disservice. Maltiez's actions were, in my opinion, ill-considered and both legally and ethically dubious. I am not defending the actions or the person. But I also think understanding the motives here is useful. If you want to go further: Maltiez actually went to Anego and suggested an "anticheat". Ultimately this was not feasable for Anego and it was up to server hosts to manage their servers, whitelist, ban bad actors, etc. Then Maltiez added a malware to their mods after being told no. According to Maltiez themself, the malware was successful and the cheat mod maker had given up and discontinued their mod. So then why keep the malware in? Why create a blacklist after other modmakers contacted Maltiez after figuring out their mods were causing issues instead of removing the malware? Then Maltiez started doubling down and justifying themself. There is a reason vigilante behavior is not good, because ultimately taking down the "bad guys" became more important that protecting the victims 3 1
Paruza Posted September 3 Report Posted September 3 10 minutes ago, williams_482 said: Maltiez's actions were, in my opinion, ill-considered and both legally and ethically dubious. I am not defending the actions or the person. But I also think understanding the motives here is useful. It's not useful because it's not the important part of this. I don't care what his motives were, literally at all. What he claims his motives to be, cannot be taken at face value at this point. His actions are costing a lot of people a lot of time auditing his code, forking it, etc. To say nothing about the admins having to do extra work removing his mods and dependencies, cleaning up their worlds, debating this on forums. And the damage and efforts the dev team themselves will have to go through to resolve this situation as well. 9
lizardsprint Posted September 3 Report Posted September 3 5 hours ago, Angius said: One of the reasons the whole ConfigLib conundrum feels so malicious, is that the "anticheat" code did not exist in the public repository. This time it was something somewhat benign, yes, but what's stopping someone from uploading a zipbomb? Some sort of provenance system is, IMHO, necessary. It feels so malicious because this is what a lot of software developers that end up torching their reputation and putting actual malware (ones that will encrypt all your shit in exchange for Monero, and/or steal your wallet keys, ID documents, bank login credentials, etc.) into their software do. He's literally following in their footsteps, and it's likely he would've escalated had he not been caught. 2
Jhoryn Posted September 3 Report Posted September 3 Howdy. I'm a quiet lurker and been reading everything in the hopes of reassurances, and understand a lot of the anger comes from the lack of clarity and loss of trust. Please note, the following is questioning the code/mod itself and not Mal/the mod dev. I won't attack a person I don't know and have never interacted with. Bold is for TLDR From a User/Player standpoint, the two biggest questions needing reassurance are 1. Is ConfigLib safe to use in its current version? This event is a reminder that mods are code, and that code is shared on a basis of mutual trust. We players trust the mods to do exactly what they say they do and nothing more. Right now, that trust is shaky at best. In hindsight, Mal should have released the Anti-Cheat as a stand-alone download option. Let servers choose to use it, and it probably would've been as popular as the other mods. But, because that's not what happened here, people are understandably upset that a mod did way more than what they were told it did. Now, the safety of the code is being questioned. Can we trust a mod's code to do what it says it does? 2. If ConfigLib is safe, should we still use it, or should a new branch under new ownership be created? Because ConfigLib (and the other mods) have become such a core feature of other mods, it can't simply be removed without adversely affecting other mod devs who have come to rely on it. It is, or was, a well built, useful mod. But, because trust has been lost, should a new forced branch of these questioned mods be created?
lizardsprint Posted September 3 Report Posted September 3 1 hour ago, Demoncyborg said: it's insanely sad to me how little trust people put into the devs who have been making this game for 10 years. like all of the sudden everything they stand for is going to come crashing down because of one person hired not even a full year ago. Maybe they shouldn't have broken that trust ¯\_(ツ)_/¯ They're an employee of the company; their actions, words, doing work on the game or projects related to the game, as a publicly-facing employee of the company can harm the company's reputation if what they're doing is malicious, especially when other employees and even the CEO downplay the situation. Welcome to the real world. 23 5 1
MKMoose Posted September 3 Report Posted September 3 (edited) 16 minutes ago, Jhoryn said: 1. Is ConfigLib safe to use in its current version? Yes, it's entirely safe. It has always been safe* if you weren't also using a select few mods that had obfuscated code (most notably VS Radio and Caves and Caverns, apparently). *Note that the current version is 1.13.2 (September 2nd release). If you haven't updated to it and are running a multiplayer server, then it is strongly recommended to do so, as it includes an important security fix. 16 minutes ago, Jhoryn said: 2. If ConfigLib is safe, should we still use it, or should a new branch under new ownership be created? There is no practical reason to stop using it as of now, as it remains fully functional and safe. There is no substantiated reason to believe it will either stop working or become unsafe anytime in the near future, but if it does, it will be the result of an update, so you might simply want to be a bit more careful about updating it past 1.13.2. Edited September 3 by MKMoose 1 3
Lukas Marty Posted September 3 Report Posted September 3 11 minutes ago, lizardsprint said: Maybe they shouldn't have broken that trust They did not. You are whiny children 2 3 2
Dilan Rona Posted September 3 Report Posted September 3 10 minutes ago, MKMoose said: Yes, it's entirely safe. It has always been safe* if you weren't also using a select few mods that had obfuscated code (most notably VS Radio and Caves and Caverns, apparently). *Note that the current version is 1.13.2 (September 2nd release). If you haven't updated to it and are running a multiplayer server, then it is strongly recommended to do so, as it includes an important security fix. There is no practical reason to stop using it as of now, as it remains fully functional and safe. There is no substantiated reason to believe it will either stop working or become unsafe anytime in the near future, but if it does, it will be the result of an update, so you might simply want to be a bit more careful about updating it past 1.13.2. That horse has bolted allready, mod was forked as of today. 2
williams_482 Posted September 3 Report Posted September 3 1 minute ago, Lukas Marty said: You are whiny children Some aspects of this situation may well be blown out of proportion and some people have definitely been overly hasty in their reactions, but what happened is still troubling. Insulting people for their concerns is rude and out of line. 17 4
ImHereToProcrastinate Posted September 3 Report Posted September 3 I'm not on discord, but on reddit a lot of the reactions have been quite counterproductive. Many of them read as people relishing the chance to go full out meltdown on somebody they perceive as allowed target. And ironically, some of the things being said by some people make me sympathize with the devs more. 13
icesharkk Posted September 3 Report Posted September 3 2 hours ago, Rainbow Fresh said: It wasn't obfuscated, just hidden, which is your previous point. No. Hiding it from the public repo, cover its tracks in the log, and delaying execution of the crashcodes to hide attribution to configlib are all obfuscation tactics. 20 minutes ago, Jhoryn said: Howdy. I'm a quiet lurker and been reading everything in the hopes of reassurances, and understand a lot of the anger comes from the lack of clarity and loss of trust. Please note, the following is questioning the code/mod itself and not Mal/the mod dev. I won't attack a person I don't know and have never interacted with. Bold is for TLDR From a User/Player standpoint, the two biggest questions needing reassurance are 1. Is ConfigLib safe to use in its current version? This event is a reminder that mods are code, and that code is shared on a basis of mutual trust. We players trust the mods to do exactly what they say they do and nothing more. Right now, that trust is shaky at best. In hindsight, Mal should have released the Anti-Cheat as a stand-alone download option. Let servers choose to use it, and it probably would've been as popular as the other mods. But, because that's not what happened here, people are understandably upset that a mod did way more than what they were told it did. Now, the safety of the code is being questioned. Can we trust a mod's code to do what it says it does? 2. If ConfigLib is safe, should we still use it, or should a new branch under new ownership be created? Because ConfigLib (and the other mods) have become such a core feature of other mods, it can't simply be removed without adversely affecting other mod devs who have come to rely on it. It is, or was, a well built, useful mod. But, because trust has been lost, should a new forced branch of these questioned mods be created? the author of packrat released a replacement mod that uses the existing json config file formats already in most mods. its called configkit use that instead since its written by a dev committed to transparency and safe code attestation. 5
Nossin Posted September 3 Report Posted September 3 24 minutes ago, Jhoryn said: 2. If ConfigLib is safe, should we still use it, or should a new branch under new ownership be created? Ultimately it will be forked or independently remade since Maltiez cannot be trusted given they had removed and re-added their malware. Also keep in mind in addition to Config, overhaul and PML, Maltiez admitted they also contain the malware. It is in your best interest to wait until those mods have been rebuilt, if not for the malware, but because there are reports of performance issues 1 1
lizardsprint Posted September 3 Report Posted September 3 (edited) 13 minutes ago, Lukas Marty said: They did not. You are whiny children Pot. Kettle. Black. 8 minutes ago, williams_482 said: Some aspects of this situation may well be blown out of proportion and some people have definitely been overly hasty in their reactions, but what happened is still troubling. Insulting people for their concerns is rude and out of line. It's whatever, it's the Internet. People love to insult and project. Reasonable people simply just don't like developers of games deciding what mods they're allowed to use and hiding the code to do so, and lying about it being there, and other devs of the games downplaying that. Edited September 3 by lizardsprint 3 1 1
Lukas Marty Posted September 3 Report Posted September 3 This is not what happened. You are a false snake 1 1
LadyWYT Posted September 3 Report Posted September 3 10 minutes ago, williams_482 said: Some aspects of this situation may well be blown out of proportion and some people have definitely been overly hasty in their reactions, but what happened is still troubling. Insulting people for their concerns is rude and out of line. Incidentally, this is usually why the ban hammer ends up coming down so harshly sometimes. When the community remains calm, there's not a need for strict moderation, because most everyone is being civil and you don't have a bunch of wild speculation leading to fights and rumors. When the community gets whipped into a frenzy, however, speculation and rumors run wild, people get upset and give into emotion, and some of them end up being abusive towards others they disagree with. And that's when it goes too far and moderators have to step in to get everything back under control before more damage is done. That doesn't mean that it's not okay to be upset at what happened or raise concerns about it. There's just a big difference between politely raising concerns and starting fights with those who don't hold the same opinion on the matter. 7 2 1
ImHereToProcrastinate Posted September 3 Report Posted September 3 (edited) 4 minutes ago, Lukas Marty said: false snake As opposed to a ... true snake? Edited September 3 by ImHereToProcrastinate 2
HalfAxd Posted September 3 Report Posted September 3 4 minutes ago, LadyWYT said: That doesn't mean that it's not okay to be upset at what happened or raise concerns about it. There's just a big difference between politely raising concerns and starting fights with those who don't hold the same opinion on the matter. Exactly... well said. 1
MKMoose Posted September 3 Report Posted September 3 (edited) 4 hours ago, Vesk Aida said: Obfuscating the code shows further proof this author knew their behavior was unethical. 50 minutes ago, icesharkk said: No. Hiding it from the public repo, cover its tracks in the log, and delaying execution of the crashcodes to hide attribution to configlib are all obfuscation tactics. Obfuscation in software has a very specific meaning, and the controversial code does not meet the definition. I would expect you to respect that when trying to argue about technical details, especially in a context where actual obfuscation is a critical part of the equation as that is what Maltiez' code was detecting. Edited September 3 by MKMoose 1 2
williams_482 Posted September 3 Report Posted September 3 1 minute ago, ImHereToProcrastinate said: As opposed to a true snake? Herpetology error. Their username clearly indicates that they are a lizard. 1
lizardsprint Posted September 3 Report Posted September 3 1 minute ago, Lukas Marty said: This is not what happened. You are a false snake I've bought 16 copies of the game, one for myself and 15 for my friends. I ran a server for those friends. I'd say my concerns are valid. That is literally what happened. They've even admitted it themselves once caught. And this is only what we know of. Look, I'll even cut the rest of the team some slack and play ball with the idea that Maltiez is solely responsible, and that he did in fact lie to the rest of the team (what they're now claiming) in order to get these API changes into the game so that Config Lib could use those changes (hiding the Config Lib code that does this from the public git repo is another issue). What other changes of his got past code review into the game itself, that doesn't do exactly what he said it did? As a software developer myself, this raises HUGE concerns for me considering the game, and server software, has been running on my machines. 6
Recommended Posts