14 ms·
What is up with the strange sensationalist claims in the article on and Twitter? Source code availability is not a prerequisite to people finding vulnerabilitie
by notaplumber 6y ago
What is up with the strange sensationalist claims in the article on and Twitter? Source code availability is not a prerequisite to people finding vulnerabilities or RCE exploits in games, there are many established games with open source game clients. Security researchers routinely reverse engineer proprietary software.
Bizarre.
- whymauri 6y agoI've been hearing that an RCE for TF2 is confirmed but not for CS:GO or the other leaked code/clients.
- weaksauce 6y agoThe csgo twitter says csgo should be fine. (At least on valve’s servers)
- ocdtrekkie 6y agoSource code availability makes it a lot easier to find vulnerabilities. Open source code is much more likely to already have been audited better. Closed source code often depends more heavily on security by obscurity, and unexpected source release can definitely make vulnerabilities immediately apparent that weren't known prior.
- 3fe9a03ccd14ca5 6y agoEvery statement you just made is speculation and not backed up by any meaningful data. While it’s obviously “easier” to find bugs when you can view the source code, making it one or the other doesn’t bestow any magical protections on the software.
- d1str0 6y ago"Time and effort required" in order to find vulnerabilities is not a magical protection. It is a legitimate protection. Not one that should be relied on, but very much something that factors in. Open sourcing software doesn't immediately improve security, but it drastically lowers the barrier of entry for researchers to start looking into it.
- notaplumber 6y agoI have to believe given the sheer size of these communities, that the source code being available only helped to confirm what was already known. The panic seen here hearkens back to the days when companies made similar ridiculous security claims about open source software compared to proprietary software.
- whylie 6y agoThat seems like quite a stretch. The difference between having the source code and not having it is night and day as far as exploring potential vulnerabilities...which is one of the strengths of open source as you point out, but this code was not intended to be || written as open source hence the panic. Feel like you missed the mark on this one.
- colejohnson66 6y ago> Open source code is much more likely to already have been audited better. Worth keeping in mind this isn’t a silver bullet. OpenSSL with Heartbleed comes to mind.
- MaxBarraclough 6y agoVery true, but OpenSSL in particular is rather infamous. Unfortunate given that so much relies on it. https://news.ycombinator.com/item?id=7556407 https://news.ycombinator.com/item?id=7556407
- rmdashrfstar 6y agoThis is why the assumption that “open source code is more likely to be closely audited for vulnerabilities” is not true (even for incredibly core/important projects with a wide scope) and is potentially dangerous to rely on.
- ngcc_hk 6y agoIt is not 100% and always. But practically. Especially unexpected leak.
- tal8d 6y ago> This is why the assumption that “open source code is more likely to be closely audited for vulnerabilities” is not true... That is a safe assumption, otherwise you'd have to believe that non-open source code is more closely audited - at greater expense, because businesses secretly prioritize security.
- chupasaurus 6y agoShellshock still outperforms any security issue of OpenSSL in terms of time in the wild.
- hitpointdrew 6y ago> Open source code is much more likely to already have been audited better. Common wisdom. I just happens to not be true. People just aren't auditing random code on github for fun. Auditing code is hard, and time consuming. Most vulnerabilities are found by techniques like fuzzing, not by combing through thousands of lines of code.
- _pmf_ 6y ago> People just aren't auditing random code on github for fun No, just the important code that everyone is running.
- deleted 6y ago[deleted]
- josefx 6y agoAfaik it had the opposite effect for OpenSSL. Not only was the code so bad that it would crash if ran with a secure malloc implementation. Due to being free and open source nobody felt the need to donate[1], with only one developer employed to work on it full time. [1] https://arstechnica.com/information-technology/2014/04/tech-giants-chastened-by-heartbleed-finally-agree-to-fund-openssl/ https://arstechnica.com/information-technology/2014/04/tech-...
- _pmf_ 6y agoWell. eventually someone looked at it. And probably Heartbleed has been used a long time before it was published.
- fnord123 6y agoI have to confess that I have run afl on random code on github.
- iforgotpassword 6y agoYou don't have to audit that. It's so popular, someone else must have done a thorough review already!
- baby 6y agoopen source code being more secure is a myth.
- numlock86 6y agoThe whole "open source is audited better than closed source" is nothing but a myth and I am actually quite surprised to see this statement appear on HN.
- 3fe9a03ccd14ca5 6y agoI’m wondering the same thing. Is there any evidence of an RCE bug out in the wild? Or was it just wild speculation because the source code is now available? Unless they specifically hardcoded a back door into the game, I’m dubious a leak would result in an RCE so quickly, if ever.
- whymauri 6y ago>Unless they specifically hardcoded a back door into the game, I’m dubious a leak would result in an RCE so quickly, if ever. AFAIK, parts of the source code have already been leaked since 2018 amongst certain circles outside Valve. It's only been in the past few days that this is now common knowledge.
- trufas 6y agoAllegedly there's already an exploit in the wild that lets you open a popup in game to all other players in a server. You can find screenshots if you look around the /r/tf2 subreddit.
- humaniania 6y ago"allegedly" means nothing and screenshots are so easy to fake, it's 2020. I want to see concrete proof of this alleged exploit.
- moftz 6y agoI remember a custom CSS server doing this. The admin would fire off some command and a typical in-game browser window would show that would immediately go to a site the admins ran that hosted audio files. One would start playing. You could turn it off but they could push out the link again.
- res0nat0r 6y agoI'm assuming that whomever leaked the code modified it and added a remote exploit to the codebase and that's what folks online are referring to. Happens a lot with shady non-scene type of warez.
- deleted 6y ago[deleted]
- russdill 6y agoAs someone who's reverse engineered large portions of a game with similar tech from the same era, I would be absolutely shocked if there were not remote exploits.
- deleted 6y ago[deleted]
- surround 6y agoIf it was open-source from the beginning, there wouldn’t have been this problem.