Content Warning

Content Warning

Build Apr 2, 2024 @ 2:01am
Potential Security Breach?
So after the c*ck hurting thing and the dev confirming that the game was indeed being hacked.
Is anyone else concerned about player security being compromised? It concerns me with the access this game has to the computer (albeit something as simple as sending videos to the desktop), it shows some level of a compromise.
Originally posted by Jake:
Saw you in the Discord server asking about this too.

To put your mind at ease, it was the servers that were compromised. The only thing they changed was the text string when you loaded into the server.

Someone having access to the server does not mean your client (and thus your computer) was compromised.

I assure you that if someone had found an RCE exploit to do things to your computer, they would have done much more than spamming an obscene message on your screen.
< >
Showing 1-10 of 10 comments
Botten Hanna  [developer] Apr 2, 2024 @ 2:04am 
Hi! Someone was hacking the game, it should be fixed now!
Ketzerin Apr 2, 2024 @ 2:05am 
cybersecurity is one of the few things that really spooks me, so im super paranoid rn about this
Build Apr 2, 2024 @ 2:05am 
Originally posted by Botten Hanna:
Hi! Someone was hacking the game, it should be fixed now!
I understand that Botten, but what does this say in terms of player security and safety? Has anything else been compromised because of this?
Botten Hanna  [developer] Apr 2, 2024 @ 2:26am 
Originally posted by jkterjter:
Originally posted by Botten Hanna:
Hi! Someone was hacking the game, it should be fixed now!
I understand that Botten, but what does this say in terms of player security and safety? Has anything else been compromised because of this?

Nothing else should be compromised due to this no, especially now that it has been patched.
The author of this thread has indicated that this post answers the original topic.
Jake Apr 2, 2024 @ 2:31am 
Saw you in the Discord server asking about this too.

To put your mind at ease, it was the servers that were compromised. The only thing they changed was the text string when you loaded into the server.

Someone having access to the server does not mean your client (and thus your computer) was compromised.

I assure you that if someone had found an RCE exploit to do things to your computer, they would have done much more than spamming an obscene message on your screen.
Ketzerin Apr 2, 2024 @ 2:32am 
Originally posted by Jake:
Saw you in the Discord server asking about this too.

To put your mind at ease, it was the servers that were compromised. The only thing they changed was the text string when you loaded into the server.

Someone having access to the server does not mean your client (and thus your computer) was compromised.

I assure you that if someone had found an RCE exploit to do things to your computer, they would have done much more than spamming an obscene message on your screen.

I feel much better now, thanks.
Build Apr 2, 2024 @ 2:33am 
Originally posted by Jake:
Saw you in the Discord server asking about this too.

To put your mind at ease, it was the servers that were compromised. The only thing they changed was the text string when you loaded into the server.

Someone having access to the server does not mean your client (and thus your computer) was compromised.

I assure you that if someone had found an RCE exploit to do things to your computer, they would have done much more than spamming an obscene message on your screen.
Thank you, I appreciate the detailed response :)
Jake Apr 2, 2024 @ 2:33am 
Originally posted by Ketzerin:
I feel much better now, thanks.
It's healthy to be cautious, but not so cautious that you borrow stress from a possibility that may never come.
Botten Hanna  [developer] Apr 2, 2024 @ 2:45am 
Originally posted by Jake:
Saw you in the Discord server asking about this too.

To put your mind at ease, it was the servers that were compromised. The only thing they changed was the text string when you loaded into the server.

Someone having access to the server does not mean your client (and thus your computer) was compromised.

I assure you that if someone had found an RCE exploit to do things to your computer, they would have done much more than spamming an obscene message on your screen.

Thank you for explaining this better than me!
Jake Apr 2, 2024 @ 3:09am 
I don't know if this would make anyone feel better or worse, but it will hopefully give a little perspective.

I can see in jkterjter's game list that they played Counter Strike 2 (formerly CS:GO).
For at least two months from mid-may to mid-july of 2018 (and who knows how long before that), CS:GO had an actual Remote Code Execution exploit by using malformed data that can be reliably reproduced by simply making the player download a custom map (which happens all the time in community servers).

The individual that found it, reported it to Valve, it was fixed, and they were paid a nice bounty.

It goes to show that whilst yes, these things are always possible and yes that's real scary, the amount of knowledge and experience that would be required to find these things is not something the vast majority of people have. And when you find an exploit THAT big, what do you do with it? Well, that depends on what sort of person you are.

If you're a good person, you report it to the devs, and work with them to fix it. You help protect many people and likely get a nice cash bounty for just doing the right thing.

If you're a bad person, well sure there's a lot of things you could do, install crypto miners, steal personal data, whatever. But that only lasts until someone else finds the exploit and reports it. Then they get the bounty, and your exploit no longer works.

Now, with all that in mind, if you were a bad person with an RCE exploit, you definitely would not just go changing random text in the game to some obscene message to mess with people because it means people will know there's a problem, and will start looking for the exploit so they can fix it, which means you have less time to take advantage of it.

So the fact that the only thing that happened is some rude text, it's safe to assume that was the absolute extend to their capability with this exploit, because if they could have done worse, they most likely would have, and wouldn't want you to know something was wrong.
< >
Showing 1-10 of 10 comments
Per page: 1530 50

Date Posted: Apr 2, 2024 @ 2:01am
Posts: 10