-
Posts
110 -
Joined
-
Days Won
5
Content Type
Profiles
Forums
Blogs
News
Store
Everything posted by icesharkk
-
@IAmMoss it is not illogical or unreasonable so see Anego's willingness to omit and lie, to paint a better picture, as evidence that they will continue to do so or that other statements they make may be suspect. Oh look this is the only thread left. Anego has deleted every other megathread even if it was cooling down on its own. PR before transparency. Merged That's still it for me folks. I have shit to do irl finally and no more motivation to argue.
-
per maltiez own admission this was not about protecting the community it was him vs the the cheat developer. Furthermore, just because the target is justified does not make the action acceptable. --edit: removed an analogy that will just piss people off and not be productive-- What maltiez did is wrong. The target doesn't change the legality, ethics, or correctness of the action. and thats even if you believe he did it for the right reasons. which based on his own words I do not.
-
i think what i want out of this situation is a sfer environment that reduces teh individual burden on the end-user by implementing a more trustable pipeline between public reviewable code and compiled hosted mod. Its not even about what i would or would not have gotten hit by based on my verification steps, its about what i expect the average user to do. the average user was exploited by maltiez towards his own ends and I want Anego to improve the supply chain so that is not as easy to perform for the sorts of users who are not going through all of the steps thorfinn outlines. because it isnt about us. its about the community as a whole. And im not willing to say its the user's fault for maltiez criminal actions or that the user is responsible for preventing this in the future. i.e. I guess the user shouldn't have dressed like that...
-
Presumed by myself and several others discussing it. Conspicuously and conveniently absent from accountability by Tyron. on a rough order of magnitude comparison between the official statement number of cheaters and the total number of potential impacts between the two mods we know of at this time. and frankly I place significantly more weight behind the harm/impact done to the innocent users than the cheaters.
-
Perhaps. I am hardly perfect and it has been a long few days. I cannot simply read something without bias and to insinuate that i haven't taken the time to read it as neutrally as possible is a bit obnoxious. just because i do not agree with you does not me that my conclusion is as a result of bias. We do not agree on Tyron's response.
-
it is true that the malicious code did not write to the filesystem. whether it wrote to the filesystem or no it engineered an outcome that ensured attribution of the crash to its code would be difficult to achieve as a result of the evasive action it took. whether it wrote to the filesystem or not it still disrupted the availability of the application it had no authorization or responsibility impacting. The harm it caused is not mitigated by whether it touched the filesystem or not. if it had written to the filesystem it might have been "worse" but so too it might have also stolen credit cards, which it didnt so that line of reasoning isnt really fruitful. call it concealment, call it evasiveness, call it obfuscation, call it a logic bomb. I see how each of can apply to what maltiez did.
-
about half of the arguments the last 36 hours are sacrificing overall clarity to instead pursue detail specificity. To me the hair splitting has begun to feel pedantic but i understand that for the people who think this is no big deal they want to minimize the severity of the language used. And some people are genuinely trying to hell make sure clear correct terms are being used. However, in the case you're replying to, that is just rejection of the reality to split hairs on a lower level technicality that doesnt change the overall truth.
-
this is simply not true and dismissive of the situation. one of the most trusted mod authors on the site using one of the most popular mods on the site did harm for personal purpose and gain. that isnt the first person you would distrust and want to verify the code of. and even if you did verify all of the mods before adding them to your game Maltiez omitted the code from his github to conceal his actions. it is one thing to say that you should not trust mods from disreputable sources. Its another thing entirely to say that you should decompile and reverse engineer every piece of code that you install, and its completely unacceptable to expect the userbase to simply accept the tepid response from Anego that doesnt even address or improve the supply chain problem that maltiez exploited to put the malicious code in after the public repo was clean that detonated the trust teh community had in the process.. Your argument dismisses the problem and shuffles all of the blame onto the consumer instead of the bad actor and apathetic and now disingenuous studio. for the record i dont actually think Anego should have had to review all mod code to prevent this. But i do think the pipeline for mods could have some easy atestation and hash checking built in to protect the consumer. and its obvious now that is a vulnerability of this moddb implementation. and of course since this wouldn't have affected you all of the transgressions committed should be dismissed.
-
this isnt really the issue that has people upset with tyrons response. Its that this risk is unnecessary and choosing to continue risking it is at the expense of the community trust they claim to want to build. stacked on top of lying about hte nature of the code, lying about the impacted users, and applying consequences that are just how they were going to do business regardless. even the PR training isn't for our benefit. its to teach his people to keep their mouths shut so he doesnt have to clean up after skelsta or T.read again.
-
its the only argument they have. between this and tyring to debate the definition of malware in increasingly convoluted ways. The incident as a whole is indifensible so they have to resort to small technicalities where "winning" the technicality can make the passive observer feel like the arguer won the argument. let me put this another way to outline a common problem with human nature in large debates like this. if you give someone 10 reasons why they should wear sunscreen at the beach a bad faith opposing party will not tackle your most convincing argument. they will pick your weakest argument, defeat it with rhetoric or hair splitting and then declare that you reasoning is flawed. a less canny audience will then feel that they have a point and your debate position has weakened far more than the simple loss of your weakest argument. Something like" well you said the suns rays are harmful but the suns rays are our primary source of vitamin D. Vitamin D is critical vitamin that your body needs to survive, without it you will die!
-
the cheat could be countered with server rollback and standard moderation procedure but the collateral damage could not be. the crashcodes could not troubleshot successfully until caves and caverns discovered the malicious code and many hundreds to thousands of man hours have been spent chasing these ghost crashes prior to that. I am hesitant to say the collateral damage is presumed minor. collateral damage is unknown but presumed significantly higher than cheater impact. people keep willfully ignoring the wasted time spent troubleshooting and chasing the crashcodes.
-
anecdotal personal evidence for your consideration: could not care less about AI use in coding, Once paid patreon subscriber to maltiez (ended months before this), absolutely consider his community interactions to indicate high levels of disdain towards the community, absolutely think that retaining and defending a confirmed malware developer and supply chain risk with a proven track record of violating your own policies to distribute malicious code using your own infrastructure is the wrong call on many levels.
-
Either They value his personal situation more than that of thousands of customers, they endorse his actions now, or they have no ability to fire him because they endorsed/okay'd the action in the first place and a wrongful firing lawsuit would expose them. I'm not sure i see another option beyond the catch all "because dumb" and i dont think that's it/dont really want to insult them either. they're doing enough damage to themselves as it is.
-
there are three bee mods now and i think they are all cool and i want all of their functionality at once. /dies from bee overdose/ I like the langstroth hives in FGC the best. FGC feels the most balanced in terms of progression integration to the existing ages. their pollination is specifically incompatible with wild farming revival for reasons that no one has been able to track down and FGC author decided was WFR's problem to resolve unfortunately. the animated bees from one of the other two is wonderful and so is the smoker mechanics from the last one. i just want FGC progression with the smoker and animated bees.
-
no I can hold them accountable for his continued employment especially since this campaign continued during his employment there. Furthermore Tyron and other devs on the team have admitted that Anego were inform by maltiez, and simply declined to look deeper. They shouldnt have to check code from the moddb unless there are concerning reports regarding the mod in question. But in this case there were reports and maltiez had already asked to add this anti cheat into the game itself. it is not unreasonable to expect them to put two adn two together. even if they didnt taking decisive action now that it has all come to light would still be acceptable. It is not the community's fault that Matliez chose to violate the law, ethics, and ToS and it is not the communities fault that Anego has chosen to stand by his employment, justify his actions, ignore and lie about the collateral damage done, and praise the success of his operation.
-
sigh. see this is my point. If the best defense available is "wikipedia is unreliable" that isn't really even interacting with the point I'm making. its argumentative distraction. I do get you're bringing up that maybe they brushed the argument off for this reason but i dont think so. The arguments i've seen range from "the degree of harm is insufficient", "the intent wasnt malicious/target was justified", "i made up my own definition that deliberately excludes this case as malware", "its PUP", using the term malware makes it sound worse than it actually was, to "yUo MuSt Not WoRk iN iT". Sufficient harm simply isn't criteria in the the definitions of malware, justification of targe is not in the definition and it was malicious by both definition and admission the third argument is for trolls and fools, either it can be PUP and still be malware or it isnt PUP. PUP is just another quibble to minimize how it sounds because of the definition it meets is not relevant and the last argument is ad hominem so irrelevant. Incase you need them here are some concrete sources: If someone cant accept the NIST definition then I simply cannot help them. i.e. I can explain things to you I cannot understand them for you.
-
i think pushing back on the "um actually its not obfuscated code" arguers is important because their quibble is, either intentionally or not, distracting from the overall suite of behaviors and circumstance that show Maltiez as an actor was deliberate, evasive, malicious, and unrepentant. most of all he felt morally justified to act unethically. thats a very bad combo at least thats why i keep pushing back against it. its the same reason i push back against the definition of malware nitpicks. Both of these arguments are simply the only good arguments people have to minimize the situation and if you strip those away defensibility of the situation goes out the window. again in my opinion. clearly if that sentence could magically change peoples minds there wouldn't be a debate to be had.
-
its not bad faith to see their justification of his actions, lies by omission, and "consequences" that are just status quo dressed up as extra safeguards for what they are. Tyron's response does not increase my faith in the company, it does not take accountability for the situation that has occurred, it covers their ass and protects the perpetrator. It shows me that PR is more important than resolution or accountability.
-
Good question. Honestly im not sure there is, i would like to simply forget about him. All most all of my frustration has shifted to Anego for retaining and defending him. I just cant easily explain why im frustrated with Anego without framing maltiez actions since that is the core everything else stems from. I have been making an effort in my posts to either focus on or connect this to Anego's stance and how they are representing themselves now. if you ask me what Anego could do to for me to accept their [repentance] or sincerity? My answer is three things remove the malware dev, be honest about the actual ramifications of his actions instead of praising them and omitting the victims, and make a commitment to improve the available certification pipeline for the moddb (no garuntee of safety but protections against sideloads is a big start and much less problematic to tackle).