Jump to content

Eruannon

Very supportive Vintarian
  • Posts

    2
  • Joined

  • Last visited

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

Eruannon's Achievements

Wolf Bait

Wolf Bait (1/9)

10

Reputation

  1. Fun fact - there's such a thing as 'disciplinary termination of employment', in case of egregious violations, such as... malware distribution. As per 'no chance' - please, I'd honestly appreciate if You at least made half-reasonable claims. npm, PyPi, Go and Packagist, few of bigger linux packages, far more widely used than VS, verified by multiple expert programmers, managed to be targets and vectors of supply chain attacks in 2026, but somehow, a one-person validation turns it into 'no-chance' for violations?
  2. Frankly I think it is high time I added my two cents here, as frankly I'd like to double check if I understood the statement by TyronX correctly. 1. Maltinez performed what could be argued illegal acts as per Directive 2013/40/EU, by adding malware to his library mods. And yes, I am using Malware with full intent and meaning behind it - specifically code which intentionally interferes with whole or part of information system (in this case - client) without right (i.e. without user's authorization, as each and every single of those mods were listed as library mods, rather than anti-cheat mods, which is classic example of supply-chain attack, recently shown also in one of linux libraries, where additional payload was added after normal commits by same user), more than that - code was reportedly NOT included in official source files for the mods, making the deception and intent extremely clear. Also - before this argument is used - no, 'but other mod was worse' is NOT an excuse in civilized world. Whitelisting of both users and mods is possible, and creation of mods that would facilitate it is possible as well. Vigilantism, unlike what comic books would like people to believe - is not legal in most, if not all, of Europe. 2. Worse yet - Dev team KNEW of the illegal acts in question, at least partially, and never bothered to check if by chance the 'anti-cheat' measures don't cross from 'ok, good, let's address it' to 'dude, you are aware it's literally illegal right?' 3. Even given benefit of the doubt completely, and ignoring the point 2 for now - once the scope, scale and manner was made quite clear to the community, including Maltinez' own admission of it being effectively malware - the Anego Studios will STILL continue cooperating with known malicious actor, under supposed supervision (which already has failed given moddb was supposedly curated as well) on the main codebase, rather than just on mods [ironically - I'd be willing to make a claim that You have the reaction backwards. He should've been removed completely from main project first and foremost as known malicious actor, and maybe consider removing him from mod projects, as his own reputation would follow him, rather than other way around]. 4. The official perspective of TyronX is that the execution in question (malware) is 'no big deal, as the correct targets were affected'. And here, I'd like to confirm, with TyronX preferably, whether his official stance is 'as long as correct targets were affected' it was fine with infecting large number of computers with malware via supply-chain attack, thus performing literal cybercrime, just because other malicious actors (with admittedly worse code effects, though again - we're talking malware here) were hit by it? Whether Anego studio styles themselves as group of nerds or a company, it does not change the fact that as it stands currently - representative of the company/group is condoning criminal (malware distribution via supply-chain attack) acts, just because the excuse is noble. Honestly speaking I am fed up with how many people in various communities seem to consider that 'not a big deal', whenever this, or something similar happens. people try to excuse effectively criminal behaviour. Every single covert and semi-covert supply-chain attack begins as 'fix', 'security update' 'anti-tampering', 'testing kit' etc. Once the presence of such code is expected and stops being verified, the actual payload is then inserted, OR users get tricked into installing that update by claims of benign code. It baffles me, how much people give allowance to those actions, as long as the perpetrator gives good enough story to cover his back after they get caught. Usually by messing something up - such as here - giving a ton of false positives. It is especially egregious due to Maltinez being official part of the team working on the VS. I will be watching further updates from the studio regarding the incident, and I honestly hope You get your stuff together and address the incident comprehensively. 'Tee heee, whoopsie' is not really acceptable response in my opinion, nor is 'yo he did good; he did it via malware, but he did it good, he got the worse guys', especially when we talk potentially criminal conduct as could be argued this incident is.
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.