video.twimg.com

nuggie_ss, do games w Block Blasters: Theft of $32k in crypto from a stage 4 cancer patient due to valve’s incompetence in allowing malware on their platform

All the average gamer-intelligence in this thread is reassuring.

Glad I still see no reason to take most of you people seriously on anything related to technology.

MellowYellow13, do games w Block Blasters: Theft of $32k in crypto from a stage 4 cancer patient due to valve’s incompetence in allowing malware on their platform

The only country in the world that this repeatedly happens, just like school shootings. Gee I wonder how you could ever fix this??

t3rmit3, (edited ) do gaming w Block Blasters: Theft of $32k in crypto from a stage 4 cancer patient due to valve’s incompetence in allowing malware on their platform

They were contacted by an unknown person who requested they play their video game demo (downloadable from Steam). In exchange for RastaLand playing their video game demo on stream, they would financially compensate them.

Unfortunately, it’s extraordinarily easy to hide malware in any application that is expected to have online components, because you can add the malicious, “staged” malware after install. Also, depending on what the code is doing, it may not even appear malicious to malware scanners.

Crypto-stealers often don’t even need to elevate privileges or access system components or create backdoors in order to operate, they’re just sending info out, so from a behavioral perspective they often don’t really “act” maliciously.

Sadly, this is less about Valve not preventing something, and more about someone falling for targeted phishing.

Edit: Looking through the tweets, the only references to it being malicious all appeared within the past day, and the claims of the dev being compromised within the last week, so I’d guess the game was updated with malicious components in the last couple days.

theangriestbird,

The thing is, Valve could go back to their old model where they review and approve 100% of new games on Steam. It would be significantly more expensive than it used to be for them, but they have more than enough money to staff a team for this process. They could do this, and they would still be plenty profitable. They just choose not to because they have no financial reason to do so, and they would rather keep that extra money as profit. Unfortunately, their choice to leave Steam as an unmoderated hell scape has had real consequences in the real world on real people.

TehPers,

While this would be nice, it’s not that hard to design malware that hides itself in certain environments. It’s actually extremely common for more advanced malware to disable itself in sandboxes, for example.

For other reasons, that might be nice though. It at least enforces some level of quality and playability.

bless,

For the curious, stuxnet is a prime example of software altering behaviour under different environments en.m.wikipedia.org/wiki/Stuxnet

t3rmit3,

What people overlook is how Valve removing those barriers to listing directly brought about the indie revolution that’s happened.

Blisterexe,

Exactly, greenlight was good for the time but sucks compared to what we have now

Blisterexe,

Except that wouldn’t prevent a lot of scams like that, what if the game’s cryptodrainer only activates like 2h in

t3rmit3,

They already scan all submitted games with malware scanners. Manual approval wouldn’t be any different, they weren’t doing binary analysis or source code review before. Their AV scanners back then would have given them the same result as their AV scanners now.

theangriestbird,

that’s fair! maybe I am overestimating, IDK. I just think that if such a process still existed, the approval process would be lengthy enough that people wouldn’t even bother with trying to sneak by malware submissions.

KairuByte,
@KairuByte@lemmy.dbzer0.com avatar

This would be expensive, time consuming, and utterly useless.

Automated scans are going to be just as useful, if not more useful, than manual auditing. Not to mention, manual auditing is useless in 99% of cases unless you’re also submitting source code. And even then, if you offer any sort of streaming of assets, you can simply not turn on the exploit download until after the review process. That isn’t even mentioning the issues with uploading source code.

This simply isn’t an issue you can throw money or manpower at. Really, users need to be more educated, which is something valve can do.

Megaman_EXE, do gaming w Block Blasters: Theft of $32k in crypto from a stage 4 cancer patient due to valve’s incompetence in allowing malware on their platform

People lacking empathy really messes with me. Stealing is obviously morally wrong, but to steal from someone who is obviously very sick is next level fucked up. I’m glad people helped this guy out in the end. Really sad story

skozzii, do games w Block Blasters: Theft of $32k in crypto from a stage 4 cancer patient due to valve’s incompetence in allowing malware on their platform

America is the only country where this could occur, look yourself in the mirror…

ibot, do games w Block Blasters: Theft of $32k in crypto from a stage 4 cancer patient due to valve’s incompetence in allowing malware on their platform

No discussion, it is super shitty that someone stole the money.

But the real scandal is, that anybody needs to raise money, to get a cancer treatment.

  • Wszystkie
  • Subskrybowane
  • Moderowane
  • Ulubione
  • test1
  • ERP
  • Technologia
  • tech
  • rowery
  • Gaming
  • esport
  • healthcare
  • FromSilesiaToPolesia
  • krakow
  • fediversum
  • muzyka
  • turystyka
  • NomadOffgrid
  • Psychologia
  • Cyfryzacja
  • Blogi
  • shophiajons
  • informasi
  • retro
  • Travel
  • Spoleczenstwo
  • gurgaonproperty
  • slask
  • nauka
  • sport
  • warnersteve
  • Radiant
  • Wszystkie magazyny