

This commit was the refactor commit from the private dev flow to the open source repo. The process basically added a lot of files and deleted a bunch as well. it was long overdue but I wouldn’t expect constant 11m line code changes
Just your normal everyday casual software dev. Nothing to see here.


This commit was the refactor commit from the private dev flow to the open source repo. The process basically added a lot of files and deleted a bunch as well. it was long overdue but I wouldn’t expect constant 11m line code changes


That would make sense, although I think it’s unlikely that it embeds itself into the mods. It would probably replace itself. Since in order to embed itself into the mod, it would have to know how the mod is made/structured but I guess it would be possible if it was able to completely replace the existing mods with the worm.


I’m glad you added from 2025 there because otherwise it would have been super deceptive.
I definitely thought it happened again, and I was gonna be like, well that was fast. Like we all know it’s going to happen again, but that would have been extremely fast.


Yeah, that’s how I took it, but the developer acted like every system that was on the workshop was infected. They never listed a mod that caused the issue and instead just issued a blanket statement of this is what happened. It’s very weird.


I was originally going to add that usually different services can use the same name as long as there’s no overlap, but you can’t even use that on this one because they’re both blogging platforms.
Yeah, unless they have authorization from the original project this is likely going to require a name change.


I don’t own this game or project or whatever it is, but I’m confused. How does a mod getting hacked on a workshop make it so every player that’s on the workshop has a virus?


Wasn’t Shopify one of the first companies to go all in on an AI infrastructure? I seemed to recall reading that about a year or two ago.
It’s because presale isn’t actually against their policy. What is against their policy is someone putting an inventory up that they haven’t confirmed they are going to have.
So like if they have the email from Valve saying “this is the timeframe you get this” and that timeframe is more less than than 40 days out, as long as they can confirm shipment within 40 days of the item listing it’s allowed.
I wonder if you get a new report option if the page has been active for more than 40 days, or if said issue requires a buyer to report them when they don’t ship within 40
Being said, I think valve should crack down on the resale of their product on platforms like ebay, if they can find a listing that links to a steam account terminate future sales. With how overarching their system is they could likely cite Policy violation and close the entire account as well.
I assume it would be fairly easy to look for identical card numbers across the platform, or require the primary account on the device to be the account that purchased it for at least X amount of days having the system like how phone carriers do with carrier locking.


Said backdoor isn’t possible with the current day key exchange process. Without the servers in use private key, the most law agencies can do without acquiring the private key is force the CA to revoke a cert, which will disallow properly configured clients from accessing and transferring data with the server.
LE doesn’t have enough information to recreate the private key based off the public key, the only key distributed during the CSR process is the servers public key via a certificate signing request which is signed using your private key, which the CA then signs with it’s own intermediate key (which is signed by it’s root server certificate) and hands back to the private server.
The CA doesn’t have the ability to create that private key, and as such doesn’t have a way to decrypt traffic that is using that key. There is no concern for a backdoor in that process.
In order for the “backdoor” to exist, they would need to either copy the private key as part of the signing process (which it doesn’t), or somehow force the server admin to use a new private key (that the CA also holds) or somehow compromise the servers key generation process to allow for an escrow on the private key when it was generated which would allow the CA to be able to recreate the private key using the master & public key.
Now don’t take me wrong, you can still have a MiTM impersonation attack or a full impersonation bypass by the CA issuing a new certificate and having the DNS registrar have the web address go to a new server that is using the new key but, that’s not something the CA alone has the capability of doing, and any traffic that is issued to the original server still wouldn’t be compromised, its just clients visiting your site will end up at the other site and as such will end up using keys that the other side generated instead of your own keys and additionally said new keys would also be appearing in Certificate transparency logs, or modern day clients would refuse to use them.


I don’t think anyone’s going to solve the problem in general, to be honest.
Like, Let’s Encrypts goal is super novel, but also expensive as shit to actually run, and requires a lot of coordination because it needs to be a trust authority. If this ever happened, it would probably be at the backing of some government structure, because I don’t see many people wanting to jump at that as an expense.


Is this accurate? Like, I know what you’re meaning, but I’m pretty sure it’s not ICANN doing it, and more so your domain registrar handing it over to the US government.
I think the most control that ICANN has over it is they could theoretically, if they wanted to, delete an entire top level domain. Since they do control the DNS root, but that is the most that they control from what I understand.
I don’t know if they have the ability to delete or transfer control over an individual domain on legal request. I think that’s outside of what their actual system allows for.


the ironic part of this is in some cases it can. Pirate broadcasts and media boxes are becoming increasingly common to have subscription models for way cheaper than you would having the traditional streaming subs.
We are in a world where even piracy is starting to cost money in some cases fair cause convienence, but its still weird to think about. Everything always goes full circle.
That’s a good idea I haven’t thought of trying. I was working on modifying the ui itself to add an option but that would be way easier!
edit: I was able to add a site##button[aria-label=“Downvote”] to ublock which removed any downvote button. Thanks for the tip!
Yeah, for real. I don’t think this is a Reddit exclusive thing.
The Hive Mind is a scary thing, and while I definitely think that Reddit is one of the worst offenders of it, it’s present on any social media platform with the ability to downvote and also shows the downvote.
Thankfully on Lemmy, most of the major UIs give you the ability to hide down votes in general. I think Photon is the only one I’ve found so far that doesn’t have the ability to hide downvotes, which sucks because it’s also the best UI(imo) that I’ve found so far.


We have… I’m more impressed that you found a toaster that doesn’t. I don’t think I’ve had a toaster in the last ten years that didn’t give a little bit of leeway on the lever to let you pull up a little bit more to be able to grab it.


I wouldn’t sell your gear, put it in a closet, or continue using it without purchasing any more in their ecosystem. But if you sell your gear, you’re going to enable someone else who is willing to purchase into the ecosystem. Where if you just closet it or only play with what you have, then they won’t gain anything else from it.


Yeah, which is why I think it doesn’t make sense that Steam allows it in the first place. Like, it’s actively letting a direct competitor use your platform. You get none of the benefits and all of the upkeep.


Fully agree. I think that Steam should make it a platform requirement that external launchers cannot be used on the platform.
It makes zero sense for me to hit play just to have a third party launcher open, and I have to hit play in that third party launcher as well. and I have to hit play in that third party launcher as well. At that point, I’m better off just buying it through the third party launcher.
The whole third-party launcher update process is also obnoxious… Every gatcha game does it. what’s the point of using steam at that point


Even then, the prompt could be as easy as a “recheck” button that the user sees on age restricted media. Kind of like how their age verification bucket was going to be. Database side all they need to know is a boolean of true or false of if they are a minor or not. or /maybe/ a trinary (0,1,2) system if that wanted a distinguishment of < 13 13-17 and 18+ It doesn’t have to check daily, it only has to check when the user requests access to age restricted stuff.
For perspective, the watch division makes between $35 to $40 billion annually.