6 ms·
Game launcher installs Root CA certificate on your machine (2024)
- deleted 1y ago[deleted]
- sneak 1y agoThe entitlement of application authors to do whatever the fuck they want on your machine is astounding to me. Root CAs, background processes 24/7, uploading of the full process list, clipboard spying, local network scanning, surveillance (aka telemetry) - when did developers decide that our machines aren’t ours anymore?
- Bluecobra 1y agoThis appears to be a server emulator for the defunct MMO Need for Speed World. My guess is that need they need to spoof the TLS certs and install local host entries to get the original game client to work.
- vandalism 1y agoThe certificate is used for nothing more other than checking whether the launcher is "signed". The whole scheme is full of security holes, the certificate check mostly seems like it was a programming exercise for the author. There is no need for the certificate installation with regards to any emulation functioning. Also, worth noting that this is an ongoing issue: this reboot of the game still has a decent daily player count and the CA installation concern has not been addressed, the launcher still does this. (It's also not a server emulator, it's just a launcher for the game client, used by players of the game.)
- reactordev 1y agoCodesigning is expensive. You have to purchase a $500 cert and renew it every year. Or, you can issue your own CA capable of code signing and sign your own stuff. But the OS won't think it's really signed unless the OS also has the CA in it's trust store. This is just a case of them wanting to save money on code-signing certificate renewal fees.
- hamandcheese 1y ago[flagged]
- calcifer 1y ago> criminal negligence Can we stop with this kind of hyperbole, please? It's an open-source project for a dead game. It does not come pre-installed with any hardware, nor is it required by any employer or government to be installed on your device. It's something you actively have to seek and install, and not even the person reporting the bug saw anything malicious happening. Criminal negligence is a legal term with a specific meaning, and it is far removed from... whatever you think is happening here.
- jdjdhdbdndbsb 1y agoCan you think a little bigger about the implications here?? Please understand the root key for this cert has absolute mother fuckton of power ... Someone who has this key can sign certs and pretend to be your bank, your crypto provider, anything you visit!!!! You need to understand that a root ca key is generally stored offline , in shamir secret sharing pieces, likely in some vaults... if this dude is just keeping this on his computer with a shitty router in front of it, they are being criminally negligent. This isn't hyperbole. Edit: missed a word
- reactordev 1y agoExcept this is just a single validation root ca, not a wildcard across the whole internet CA. I agree that this is complete hyperbole and everyone is making a fuss about nothing. To remind the viewers, in order for a certificate to be considered “valid”, at least an intermediate CA (certificate authority) certificate needs to be trusted by the OS. At work, we do this. When I release games, I do this. I give you my CA, so you can verify and guarantee my software was written by me, my org, and hasn’t been altered. I get the perspective of letting end users know, but I don’t agree with giving them a choice. The same intermediate CA is used by us for encryption of communications as well. So, we want to remove that? Make everything plain text binary? No. Get over yourself.
- deleted 1y ago[deleted]
- chmod775 1y ago[flagged]
- VoidWhisperer 1y agoThe work being OSS and done free of charge doesn't excuse them from putting their users at unnecessary risk, especially when it is done so with only a one line mention in their github README and no mention on their website, which doesn't point towards the README at all
- chmod775 1y agoIt should not, but they still don't owe it to you or anyone to change anything. You're not paying them. There's no transaction. They're not even giving the software specifically to you, rather they're saying "this is free for anyone to pick up" - with no warranty of any kind. When you pick up some free furniture from the roadside, it's on you to determine whether it meets your safety standards. If the free table you picked up has some defect, you most certainly don't ring someone's doorbell and demand rectification.
- benreesman 1y agoNah, distributing rootkits under false pretenses is a dick move. That's not even a little controversaial. You put a thing on the web that says "Just a harmless XYZ" and it roots TLS forever? Malware. Black and white.
- vandalism 1y agoThis assumes that all users are informed enough to make such decisions. You cannot expect the average player of an online game to have the technical knowledge necessary to discern whether a piece of software is safe to use or not. Even if you could, you'd also be expecting them to take the time to do a proper analysis of such software, which I do not think is a reasonable premise. What's more, this is open-source software we're talking about and you can actually relatively easily perform meaningful security checks; imagine if this were not the case.
- deleted 1y ago
- guessmyname 1y agoAdd to the list exfiltration of $ENV (environment variables), which often include secret keys and app tokens. I have seen many young developers expose their $ENV on GitHub when other developers asks them to share their “go env”, or similar commands, while debugging a problem.
- askvictor 1y agoThe alternative being a walled garden like Apple or (increasingly) Android, where they don't have access to anything (at least without a prompt asking if you grant said permission). If you run a system that lets you do what you want to it, you need to accept that others might try to do what they want to it, too.
- 01HNNWZ0MV43FF 1y agoPrompts are completely fine. I am happy with the prompts GrapheneOS offers me
- hackernoops 1y ago[dead]
- diath 1y agoIt would be nice if desktop software had to explicitly request access to different APIs on the system (network, filesystem, etc) as well as only request access to specific filesystem paths, then give us prompts that list the permissions that the app wants. Something like pledge (https://man.openbsd.org/pledge.2 https://man.openbsd.org/pledge.2) from OpenBSD/Serenity but integrated into the desktop systems GUI.
- drodgers 1y agoMacOS has been moving more and more in this direction, and it’s good.
- to11mtm 1y agoThat would indeed be very nice, compared to the current standards out there for desktops... Ironically, I -think- UWP tried to 'solve' this in some ways but OTOH adds new problems instead... I also know Microsoft had a different idea when it came to .NET before core, where libraries could be run in 'Partial trust' but with 'Link Demands'... And I've never seen a shop actually do that right vs just YOLOing with 'full trust' and/or abuse of AllowPartiallyTrustedCallersAttribute... Which I guess is a roundabout way of saying I feel like Microsoft has tried twice but completely lost the plot early on and failed to deliver a usable product (What even is the state of UWP questionmark, and .NET Code Access Security was given up in Core....)