APXEOLOG wrote:I think loftar should put a disclaimer into the custom client launcher about the potential problems.
APXEOLOG wrote:vatas wrote:My rather layman understanding is that the most realistic attack-vector is limited to just stealing the passwords you input on the client to log in. Which obviously is still rather bad if you have a 1000 dollar hat collection.
Well, you can basically do anything in the system, since you'll be running your own code. But it's not really any different with any other game. Half of the Unity games are modded through the Harmony which is basically code injection. And all those mods are distributed through the steam workshop as well.
I think in the end it will be a matter of trust and name behind the client.
vatas wrote:I managed to forget that Haven is a special case with the open-source client - in other games like WoW you'd be limited to any exploits in the API for injecting malware into an addon.
loftar wrote:vatas wrote:I managed to forget that Haven is a special case with the open-source client - in other games like WoW you'd be limited to any exploits in the API for injecting malware into an addon.
I don't really think Haven is that much of a special case. I don't know about WoW specifically, but my understanding is that many games achieve moddability basically through DLL injection, so such mods would also be entirely free to do whatever they wish. Even for games that perhaps have some higher-level API/scripting language, I doubt they are so thoroughly sandboxed and pentested that a crafty modder wouldn't be able to escape it.
loftar wrote:Even for games that perhaps have some higher-level API/scripting language, I doubt they are so thoroughly sandboxed and pentested that a crafty modder wouldn't be able to escape it.
EnderWiggin wrote:Even for games with official APIs there's pretty much always exists some form of script extender that injects into a game - because for modders any API is not enough.
Users browsing this forum: Claude [Bot] and 77 guests