Jump to content

icesharkk

Vintarian
  • Posts

    110
  • Joined

  • Days Won

    5

Everything posted by icesharkk

  1. bzzzt false. there is some technical truth in what you are saying that is conveniently misleading and sidestepping the fact that you absolutely can have a secure ci/cd pipeline and you can have verification that compiled code is based on the repository. we cant garuntee that the code isnt malicious until it is thrid party verified. but at least it stops the sideloading that maltiez was doing. which undermined the suposed safety of the exiting transparancy
  2. Sure but I was expecting a more solid stance like: "he will not have access to the code" or we are terminating his employment effective immediately. instead what we got is we'll keep an eye on him, trust us (just like you trusted us from november till now when we didnt keep an eye on the situation we apparently knew about), And we told him not to talk on discord anymore. im going off how tyron is framing the consequences. and anego has run out of goodwill for me to give benefit of the doubt on this. they need to be clear and firm or i am going to assume anything not explicitly covered will continue as it has up till this point. And how it has been up till this point is unacceptable. Ah yes, censor all who disagree with you! with that take you sound more American than i do
  3. so what you are saying is the standard code review is sufficient risk management to account for the employment of someone who has already demonstrated the capability and motivation to circumvent Anego studios terms of Use and rules regarding the code quality/safety of their user base? Code review is only one part of proper risk reduction. another step in risk reduction is not employing personnel with a track record of lying, evading detection, and injecting malicious code. and doing so out of spite when called out by the community.
  4. the cheat mod in question was just the most recent instance of this. and with the huge spotlight on this situation i expect there to a resurgence. I cant honestly recommend any server owner do anything except what your are planning or have dedicated in world moderation staff checking for cheat activities like they do in Rust.
  5. Its the spin on the explanation that I am uncomfortable with. especially in the context of the rest of the post that doesnt address the ways his action negatively affected the community. Nor does effectively address consequences. Maltiez already stopped working on the majority of his mods by this point, there ae forks and refactors out for configlib now, tyron already oversees all code commits so that s a nothing consequence, and Maltiez keeps his intellectual rights.
  6. "Maltiez decided to interrupt the effectiveness of this mod.... as a result all game servers using [his mods] were effectively protected from malicious users..." queue the I Need a Hero Shrek montage
  7. enable the ability publish mod libraries directly from github to moddb, or enable hash checking between the two and put a green check mark on the moddb page for mods releases that match their public github. no middle man injection opportunity.
  8. Tyron didnt criticize maltiez, He spent 1/3 of the statement justifying the actions against the cheat author and painting it as successful. Then Tyron omitted any mention of users affected by false positives or users who had the code installed and didnt know it.
  9. it should also be pointed out that there is no official statement on Anego's website or forums. They put it on reddit where it will sit only until it is unstickied. so only people who are in the reddit or discord spaces and already drowning in the offopic channel have been notified officially. The majority of the customer base can only find out through this unofficial set of threads in discussion. Most people only pay attention to teh devlog/news forum and nothing else for games like this. Seems like Anego is hoping the majority of the player base never finds out. including anyone whos still running poisoned versions of those mods for older compatibility reasons. that doesnt sit right with me either.
  10. we can see how many downloads of the compromised configlib code occurred and a quick look shows its north of 300,000. i didnt bother checking the other two mods download counts 300,000 was way more than I thought and just staggers me.
  11. a pointless quibble. they are still choosing to retain an proven bad actor that they never would have hired if the order of events were reversed. the fox ate some hens so he is band from the yard but he is still allowed in the henhouse under supervision.
  12. I completely agree with op. People are absolutely nuts defending Anego for choosing to retain a developer guilty, by admission and analysis, of distributing malicious code to the company's userbase, covering it up, and lying by omission to them about it. If this had occurred before he was hired by Anego would they have chosen to employ him? Latvian employment law accounts for the ability to fire an employee who is a technical risk to your company without waiting the 30 days, I'm sick of seeing the latvian employment excuse.
  13. looks like the moniker malwarestory is popping up in areas completely unconnected to the actual game now. I can't even in good conscious disagreee with them if tyron is going to retain him. ask yourself this: If maltiez had applied for a job at anego studios after he was caught distributing malware through their moddb, and compromising thousands of systems leading to thousands of manhours of troubleshooting and server maintenance, would they have hired him? no. I think not.
  14. local labor laws has already been debunked. in latvia you can terminate an employee that poses a technical threat to your company. discovering that an employ is guilty by admission and analysis of distributing malicious code to thousands of your own products users via your own moddb and mislead you as to the nature of his mod is easily grounds for technical threat to the company. ask yourself this: if this had come to light before he was employed would any dev studio have willing hired a developer they themselves had to ban from the moddb for distributing malware to their users? absolutely not.
  15. the question people should ask themselves is if this had happened before maltiez was hired do you think any dev studio, including Anego, would have hired him knowing the illegal thing he did to their user base and that he is already banned from their moddb in perpetuity.
  16. I am severely disappointed with Tyron's response. He spent 1/3 of his statement justifying the actions against the cheat dev, 0% of it is accountability for the impacted collateral damage, plans to continue employing the malware dev. that's it folks. I cannot with integrity fight back against the popular sentiment of "malware story". i hope the door hits my ass on the way out. the only good thing is that maltiez's loses access to moddb and his mods will be transferred to custodianship other than maltiez. The latter doesn't matter the community already forked the code. that's a nothingburger solution. The former is good because we cant trust maltiez. unfortunately he is being retained to contribute on the base game but with oversight. "We have decided to retain the fox who ate your chickens, he no longer has access to the yard. He will however continue to have access to the henhouse. but with oversight!" I cannot in good conscious continue promoting this game or hosting servers for this game at this time. Three other unrelated communities I'm in have been referring to VS as malware story. I wont be sticking my integrity out by correcting anyone spitefully calling it malware story. That is the legacy wrought by these decisions
  17. I also do not support retaining maltiez on the VS team. I do not trust his judgement and his continued involvement is a supply chain risk. He's done significant damage to the brand, the user base, and to the trust the userbase holds in VS and that isnt going to go away while he remains. It is possible that its the Latvian employment legalities that are contributing to this but he needs to have no access to the code. It is also quite disappointing that Tyron conspicuously did not mention any of users or mods harmed by maltiez in the execution of his crusade against one cheat client/mod. This whole uprising you are seeing is about the harm and trust maltiez caused and broke. i have no little in the justification of why he did it or that it was successful. infact the idea that you would dedicate a significant portion of your official statement to justifying his actions and they fail to account for the collateral damage is staggering. three other discord communities that i participate in, that I didnt even know knew about this game have been calling it malwarestory for days. That sentiment cannot be cleaned with the malware author still employed. I cannot in good conscious tell them they are wrong while he remains. I WON'T tell them they are wrong while he remains.
  18. then redact the unconfirmed information from your post here and on the other thread. we have absolutely zero information on his contribution to 1.22 and only vague and contradictory on 1.23. he has transgressed more than enough with the documented malicious code that there is no reason to falsify additional speculative involvement. it muddys the water and fearmongers.
  19. i agree completely. i just want to note its still a bit unclear what specifically was known by whom since February. i think theres a good chance of telephone game coupled with maltiez lying by ommission to them that would significantly reduce my outrage with regard to "them knowing since february." though trust is also a thin commodity right now
  20. there's a lot of contradictory information. multiple staff have referenced his future code commits. some staff say he's advisory. i dont feel comfortable assuming one way or the other until the official statement or post mortem explains wtf his actual impact to the game will be moving forwards. As well as validate whether he has had any impact on 1.22. everything else is supposition for unreliable statements.
  21. apologies. My background deals in concealment and obfuscation but at the user behavior level. e.g. hackers. his actions overall are a combination of concealment and obfuscation from a technique standpoint. but i see how it does not meet the definition of code obfuscation now. still consider the overall behavior obfuscation. This is the sort of behavior I have seen APTs do when poisoning repositories and attempting to maintain persistence/establish a foothold on a network.
  22. No. Hiding it from the public repo, cover its tracks in the log, and delaying execution of the crashcodes to hide attribution to configlib are all obfuscation tactics. the author of packrat released a replacement mod that uses the existing json config file formats already in most mods. its called configkit use that instead since its written by a dev committed to transparency and safe code attestation.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.