Jump to content

Regarding the impact of the crashcode put into ConfigLib and the needed clarification and explanation of the code for layman understanding


Recommended Posts

Posted

Welcome to the forums.

Cicadas and icesharkk have two threads with good information in them. Further threads will feed into the problem that happened on Reddit, where there was disjointed conversations and people missing pieces or spreading bad information. There are some good write-ups across these two worth reading, and worth adding to.

https://www.vintagestory.at/forums/topic/22429-concerns-about-supporting-anego-studios-further-on/


https://www.vintagestory.at/forums/topic/22417-the-configlibmaltiez-incident-so-far/

  • Like 4
Posted

i'm not a code writer or mod creator or dev or anything. simply someone who's paid for a few friends to have gift copies of VS and runs two servers. but i'm disgusted by the situation and would like to voice that at least somewhere. sorry for my dumb little comment. i can't in good faith continue to play VS or pay for my servers anymore especially with maltiez on the dev team officially. i think a lot of people are upset about the big shiny optics without realizing this also hurts people who just want to hang out with their friends and such. idk.

  • Like 2
Posted (edited)
41 minutes ago, SabiWasabi said:

i think a lot of people are upset about the big shiny optics without realizing this also hurts people who just want to hang out with their friends and such. idk.

Apologies if this is an impertinent question, but how has this hurt you or interfered with your ability to hang out with your friends?

So much of this talk is about optics mostly for lack of anything else to go over. The only unresolved aspect at this stage is Vintage Story's reputation: there is no longer any malware in play, that malware had an extremely limited and difficult to identify impact on legitimate users, and there is no danger of more malware coming from this developer via mods or Vintage Story itself. 

Edited by williams_482
  • Like 1
  • Haha 1
Posted
1 minute ago, Diff said:

I have lost trust with Anego studios as a whole because of their choice to protect and laude the malware developer. They are not acknowledging or devoting they efforts towards preventing this from happening. They benefited (until he was caught) from the actions he told them he was going to do. The way this stands, with Tyrons response, I do not trust this to be the last shady thing they do. you're right it probably wont be malware. but that kinda misses the point.

4 minutes ago, Diff said:

You observation makes this worse. You are pointing out the obvious fact that the "consequence" of maltiez "having oversight" is just status quo and that Anego isn't taking this serious accountability or changing anything to actually protect the consumer..

  • Like 3
Posted (edited)
1 hour ago, SabiWasabi said:

i'm not a code writer or mod creator or dev or anything. simply someone who's paid for a few friends to have gift copies of VS and runs two servers. but i'm disgusted by the situation and would like to voice that at least somewhere. sorry for my dumb little comment. i can't in good faith continue to play VS or pay for my servers anymore especially with maltiez on the dev team officially. i think a lot of people are upset about the big shiny optics without realizing this also hurts people who just want to hang out with their friends and such. idk.

i agree, vintage story was literally my favorite game behind rimworld.  and i game a lot.  but now eveytime i feel like playing it again, i'm;

1.  having my mind nagged by the malware peddler and the devs and owner's VEHEMENT defense and deciet around this issue AND thier attacks and censorship OF THEIR OWN PLAYERS

2.  wondering what other pieces of malware have been loaded on my laptop from vintage story and its mods.  luckily for anego studios i use a seperate laptop for my work and i handle peoples medical records.  if thier mods infected THAT laptop they would be facing many many many years in prison, because they KNEW the malware peddler infected people's devices with malware.  for a year.  at least i would be cleared cause the peddler hid their malware from the players.  though obviously playing games and downloading sh!t to a laptop wioth sensitive professional data would be a thing only total morons would do lol.  but of course, im not the only vintage story player that has used mods from their official mod database page.  but even if i had downloaded those mods on a brand new computer, i would have at least contacted my attorney on what expert i could contact in order to bring legal action for compensation for my data and potentially laptop.  cause you know... any malware is just open season on god knows what else was compromised.  people keep saying over and over again that "we know what the mod did" but they all said that before the multiple more functions of this malware that the devs have hid have come to light from players, some of those people are just idiots of course, but the rest including the devs and owner have now been proven to have long known, kept the mod up, hired the malware peddler, lied about everything, banned people for asking questions and calling for the malware peddler to be fired, ect., ect.

3.  troubled that tyron himself has quadrupled down, lied, banned people's voices, and refuses to punish, ban, and fire the malware peddler.  all for what?  a modder that has long has severe mental social issues, has treated players with vitriolic hatred and vile language?  a malware peddler that has now been proven to have KNOWINGLY INFECTED PEOPLES DEVICES WITH HIDDEN MALWARE BY THEIR OWN PUBLIC ADMISSION (which again is an extremely serious crime)

these arent mistakes.  these devs have been and are likely still lying to us.

and we cannot trust anything they will ever tell us.  theyre proven liars.  and they STILL have a proven malware peddler on their official staff.

Edited by Cetasaya
  • Like 1
Posted (edited)
9 minutes ago, Cetasaya said:

i agree, vintage story was literally my favorite game behind rimworld.  and i game a lot.  but now eveytime i feel like playing it again, i'm;

1.  having my mind nagged by the malware peddler and the devs and owner's VEHEMENT defense and deciet around this issue AND thier attacks and censorship OF THEIR OWN PLAYERS

2.  wondering what other pieces of malware have been loaded on my laptop from vintage story and its mods.  luckily for anego studios i use a seperate laptop for my work and i handle peoples medical records.  if thier mods infected THAT laptop they would be facing many many many years in prison, because they KNEW the malware peddler infected people's devices with malware.  for a year.  at least i would be cleared cause the peddler hid their malware from the players.  though obviously playing games and downloading sh!t to a laptop wioth sensitive professional data would be a thing only total morons would do lol.  but of course, im not the only vintage story player that has used mods from their official mod database page.  but even if i had downloaded those mods on a brand new computer, i would have at least contacted my attorney on what expert i could contact in order to bring legal action for compensation for my data and potentially laptop.  cause you know... any malware is just open season on god knows what else was compromised.  people keep saying over and over again that "we know what the mod did" but they all said that before the multiple more functions of this malware that the devs have hid have come to light from players, some of those people are just idiots of course, but the rest including the devs and owner have now been proven liars.

3.  troubeled that tyron himself has quadrupled down, lied, banned people's voices, and refuses to punish, ban, and fire the malware peddler.  all for what?  a modder that has long has severe mental social issues, has treated players with vitriolic hatred and vile language?  a malware peddler that has now been proven to have KNOWINGLY INFECTED PEOPLES DEVICES WITH HIDDEN MALWARE BY THEIR OWN PUBLIC ADMISSION (which again is an extremely serious crime)

these arent mistakes.  these devs have been and are likely still lying to us.

and we cannot trust anything they will ever tell us.  theyre proven liars.  and they STILL have a proven malware peddler on their official staff.

I feel like if you're this paranoid, then you shouldn't use any device unless you've thoroughly vetted or at the very least written the software yourself. No computer, phone, car, game console, etc until you can be sure it doesn't have malware in it. #jussayin At some point you have to accept it was a one-time thing for a single purpose. It wasn't right that it happened, but it did, was reversed and we can all move on from this now.

Also I work in healthcare, too.. if you use your work device to play video games that's a terminable offense. Your work devices are the property of the company you work for. you shouldn't be using them to play video games...

Edited by Teh Pizza Lady
  • Like 2
Posted (edited)
17 minutes ago, icesharkk said:

I have lost trust with Anego studios as a whole because of their choice to protect and laude the malware developer.

Understandable.

17 minutes ago, icesharkk said:

They benefited (until he was caught) from the actions he told them he was going to do.

Not really in any way that really matters to them. Otherwise they would have taken official action against the cheat dev. Some mitigation built into the game, server side validation to catch cheating players. All they bothered to do was ask him nicely to stop.

17 minutes ago, icesharkk said:

You observation makes this worse. You are pointing out the obvious fact that the "consequence" of maltiez "having oversight" is just status quo and that Anego isn't taking this serious accountability or changing anything to actually protect the consumer..

No extra oversight is needed. This process works well enough to accept open contributions from the wide open, actually-malicious internet, of course it's good enough here. You're right that it isn't a consequence, it's informational so people can be sure that Maltiez can't just sneak code in. It doesn't work that way. The consequences are separate.

9 minutes ago, Cetasaya said:

"we know what the mod did" but they all said that before the multiple more functions of this malware that the devs have hid have come to light from players

No, it's been pretty consistent and comprehensive since AdditionalStuff.cs was first discovered. Devs never hid aspects of its functions from the public, nor would it have been possible for them to. Anyone can disassemble a DLL. People playing telephone with the information is different from the information evolving or being discovered over time. It's a pretty short file, pretty easy to read in a single sitting.

Edited by Diff
  • Like 3
Posted
2 minutes ago, Diff said:

No, it's been pretty consistent and comprehensive since AdditionalStuff.cs was first discovered. Devs never hid aspects of its functions from the public, nor would it have been possible for them to. Anyone can disassemble a DLL.

Do you not consider hiding it from the public github and sideloading it before hosting it on moddb to be hiding aspects of its function from the public?

  • Like 1
Posted
Just now, Teh Pizza Lady said:

I feel like if you're this paranoid, then you shouldn't use any device unless you've thoroughly vetted or at the very least written the software yourself. No computer, phone, car, game console, etc until you can be sure it doesn't have malware in it. #jussayin At some point you have to accept it was a one-time thing for a single purpose. It wasn't right that it happened, but it did, was reversed and we can all move on from this now.

i feel like if you're this purposefully obtuse then you're not adding anything relevant or valueable to the conversation  #jussayin  At some point you have to accept that loading people's property with malware and being decietful about it is a crime.  the devs have stated many times that the mod didnt have malware.  are you seriously telling us that if apple or google decided to lie and cover up apps that did things they werent disclosed of doing you'd download from the apple store or google play?

okay then.  that's a choice you would have made...

  • Like 1
Posted (edited)
5 minutes ago, Diff said:

No, it's been pretty consistent and comprehensive since AdditionalStuff.cs was first discovered. Devs never hid aspects of its functions from the public, nor would it have been possible for them to. Anyone can disassemble a DLL.

that is just another lie.  are you a dev?  their lies are literally all over discord, reddit, ect.  are you seriously thinking this would work?  genuinely.

Edited by Cetasaya
  • Like 1
Posted (edited)
4 minutes ago, icesharkk said:

Do you not consider hiding it from the public github and sideloading it before hosting it on moddb to be hiding aspects of its function from the public?

Not by the devs, no. When I read "but they all said that before the multiple more functions of this malware that the devs have hid have come to light from players" I read that some functions of the malware were understood, requiring AdditionalStuff.cs to have already been discovered, before additional features were announced that were previously undiscovered. No such features have been unearthed.

  

2 minutes ago, Cetasaya said:

that is just another lie.  are you a dev?

Floor's yours. What's a feature of AdditionalStuff.cs that wasn't first discovered by the community before the devs announced its existence, that the devs had also taken action to cover up?

Edited by Diff
Posted
1 minute ago, Cetasaya said:

i feel like if you're this purposefully obtuse then you're not adding anything relevant or valueable to the conversation  #jussayin  At some point you have to accept that loading people's property with malware and being decietful about it is a crime.  the devs have stated many times that the mod didnt have malware.  are you seriously telling us that if apple or google decided to lie and cover up apps that did things they werent disclosed of doing you'd download from the apple store or google play?

okay then.  that's a choice you would have made...

Oh sorry, I thought we were just going to baseless extremes with our comments, my bad.

Posted (edited)
5 minutes ago, Diff said:

Not by the devs, no. When I read "but they all said that before the multiple more functions of this malware that the devs have hid have come to light from players" I read that some functions of the malware were understood, requiring AdditionalStuff.cs to have already been discovered, before additional features were announced that were previously undiscovered. No such features have been unearthed.

  

Floor's yours. What's a feature of AdditionalStuff.cs that wasn't first discovered by the community before the devs announced its existence, that the devs had also taken action to cover up?

im too tired to keep track of your shifting goal posts. what argument are you trying to make right now? that Anego didn't hide functions of the malware? Technically maltiez is and continues to be a member of Anego but lets leave that aside. what are you proving by stating that Anego did not hide portions of the malware or take actions to cover up?

Edited by icesharkk
  • Like 1
Posted
4 minutes ago, Cetasaya said:

are you seriously telling us that if apple or google decided to lie and cover up apps that did things they werent disclosed of doing you'd download from the apple store or google play?

Google does this constantly, all the time... Look up the app "DT Ignite." It's an app preinstalled by many carriers that is hidden and installs additional apps on your phone at any time without your permission because it makes the carrier money.

  • Like 2
Posted

okay.  all we're getting are people asking questions, me laying down the reality, and some rando tyron stans that are lying and arguing with us.  as far as i am concerned, this matter is closed, im far too employed to care to argue with people, and I like many other people am leaving vintage story behind.  at least for now.  anego studios will have to work long and hard to regain my trust but whatever.  i had a LOT of fun with this game, and it was well worth the price.

i ask anyone else out there to be prepared seek compensation for any further damage to your devices that may eventually come to light from this game or any of its supported mods.

Posted
Just now, icesharkk said:

what are you proving by stating that Anego did not hide portions of the malware or take actions to cover up?

That Cetasaya, by claiming otherwise, was either being hyperbolic or untruthful?

  • Like 1
Posted (edited)
8 minutes ago, Cetasaya said:

that is just another lie.  are you a dev?

Diff is not a dev or employee of Anego. Diff is very smart and very well versed in the ways of programming however and has been very helpful in explaining exactly what the code did which you can find here: https://hastebin.com/share/uqeyuhirof.markdown

taken directly from that link:

Quote

The confirmed malicious payload is confined to in-memory game-client sabotage. I found **no evidence in this sample** of OS persistence, credential theft, external command-and-control, HTTP/socket exfiltration, process or shell execution, registry changes, native injection, file encryption, save-file deletion, or a downloaded second stage. On the evidence available, an operating-system reinstall is not indicated solely because this DLL was present.

Sometimes reading is important.

Edited by Teh Pizza Lady
  • Like 1
Posted
Just now, Diff said:

Google does this constantly, all the time... Look up the app "DT Ignite." It's an app preinstalled by many carriers that is hidden and installs additional apps on your phone at any time without your permission because it makes the carrier money.

yes.  and it is illegal malware.  even if a ToS says you "give them permission" few judges will allow that ToS to hold any water in court.

difference is.  anego studios aint got the money to bribe judges, lobbyists and pay for high powered lawyers like google does.

Posted
3 minutes ago, Diff said:

That Cetasaya, by claiming otherwise, was either being hyperbolic or untruthful?

ah i think the lies they're referring to are not the coverup you were asking for proof of. I can definitely say the lies i'm talking about are things like Vallen stating "its not malware" in the refund request, Tyron stating only <100 cheat users were affected, and the operation was targeted. Lies by omission and bald faced lies about the targeting mechanism of the code itself.

 

but im tired and i need to get away from this place for a while so i'll check back in the morning if i can sleep.

  • Like 1
Posted (edited)
14 minutes ago, Cetasaya said:

yes.  and it is illegal malware.  even if a ToS says you "give them permission" few judges will allow that ToS to hold any water in court.

False.

"Malware" (malicious software) generally refers to software designed to damage, disrupt, spy on, or gain unauthorized access to a system without the user's knowledge or consent. Things like viruses, ransomware, spyware, or trojans. Carrier-preinstalled apps like DT Ignite don't fit that definition for a few reasons:

  • Disclosed purpose: It's typically used for remote diagnostics, device management, or carrier support features. This is documented functionality, not hidden.
  • Consent, even if buried: Clicking through a carrier agreement or terms of service when you activate a phone is legally treated as consent, even though almost nobody reads those terms and the app was already sitting on the device before you agreed to anything. That's consent in a legal sense, not necessarily in a meaningfully informed sense.
  • No malicious intent: The legal and security-industry definition of malware hinges on intent to harm or deceive. Carrier bloatware is designed for the carrier's or manufacturer's business purposes (support, upsells, data collection for their own use), which can feel invasive, but is a different category from software built to steal your data or damage your device.

What's fair to call it instead:

  • Bloatware -- preinstalled software you didn't choose and often can't fully remove
  • Potentially unwanted program (PUP) or potentially unwanted app -- a real industry term for exactly this gray zone: not malicious, but unwanted and sometimes hard to uninstall
  • A legitimate privacy concern, if it collects more data or has more system access than users realize
Edited by Teh Pizza Lady
clarification
  • Like 4
Posted (edited)
8 minutes ago, Teh Pizza Lady said:

False.

"Malware" (malicious software) generally refers to software designed to damage, disrupt, spy on, or gain unauthorized access to a system without the user's knowledge or consent. Things like viruses, ransomware, spyware, or trojans. Carrier-preinstalled apps like DT Ignite don't fit that definition for a few reasons:

  • Disclosed purpose: It's typically used for remote diagnostics, device management, or carrier support features. This is documented functionality, not hidden.
  • Consent, even if buried: Clicking through a carrier agreement or terms of service when you activate a phone is legally treated as consent, even though almost nobody reads those terms and the app was already sitting on the device before you agreed to anything. That's consent in a legal sense, not necessarily in a meaningfully informed sense.
  • No malicious intent: The legal and security-industry definition of malware hinges on intent to harm or deceive. Carrier bloatware is designed for the carrier's or manufacturer's business purposes (support, upsells, data collection for their own use), which can feel invasive, but is a different category from software built to steal your data or damage your device.

What's fair to call it instead:

  • Bloatware -- preinstalled software you didn't choose and often can't fully remove
  • Potentially unwanted program (PUP) or potentially unwanted app -- a real industry term for exactly this gray zone: not malicious, but unwanted and sometimes hard to uninstall
  • A legitimate privacy concern, if it collects more data or has more system access than users realize

By these definitions, I'm not even sure you can call ConfigLib "malware" in the legal sense, given that it did not intended to cause harm or deceive anyone... dunno.

I'm not even going to argue that PUP is a subset of malware anymore because more importantly: involuntary and deliberate denial of service or disruption of the runtime environment of the users applications is NOT pup. It meets the criteria for intent to harm. the fact that he missed and shot bystanders does not in ANY WAY remove the intent to harm. intent to decieve is met by the techniques used to prevent attribution of the crash to configlib when troubleshooting and delaying the crashcodes to further conceal cause and confuse troubleshooting.

I stand by what i said as it relates to maltiez but @Teh Pizza Lady was talking about DT ignite and i am over here arguing with a chair. beddddd~~~

Edited by icesharkk
  • Like 1
  • Haha 2
Posted
Just now, icesharkk said:

I'm not even going to argue that PUP is a subset of malware anymore because more importantly: involuntary and deliberate denial of service or disruption of the runtime environment of the users applications is NOT pup. It meets the criteria for intent to harm. the fact that he missed and shot bystanders does not in ANY WAY remove the intent to harm. intent to decieve is met by the techniques used to prevent attribution of the crash to configlib when troubleshooting and delaying the crashcodes to further conceal cause and confuse troubleshooting.

I don't think anyone was arguing that what Maltiez did wasn't malware. The goalposts shifted and DT Ignite came under fire as malware and I was just trying to demonstrate that it wasn't. That's all.

Posted
Just now, Teh Pizza Lady said:

I don't think anyone was arguing that what Maltiez did wasn't malware. The goalposts shifted and DT Ignite came under fire as malware and I was just trying to demonstrate that it wasn't. That's all.

ah shit. I am sorry. in that case i have no opinion on DT ignite at this time and i am sorry for jumping in to disagree with you about the wrong thing entirely.

  • Like 2
Posted
2 minutes ago, icesharkk said:

ah shit. I am sorry. in that case i have no opinion on DT ignite at this time and i am sorry for jumping in to disagree with you about the wrong thing entirely.

*gently pats on head*

It's okay. Everyone is drinking stupid juice around this topic, myself included.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.