

For perspective, the watch division makes between $35 to $40 billion annually.
Just your normal everyday casual software dev. Nothing to see here.


For perspective, the watch division makes between $35 to $40 billion annually.


This commit was the refactor commit from the private dev flow to the open source repo. The process basically added a lot of files and deleted a bunch as well. it was long overdue but I wouldn’t expect constant 11m line code changes


That would make sense, although I think it’s unlikely that it embeds itself into the mods. It would probably replace itself. Since in order to embed itself into the mod, it would have to know how the mod is made/structured but I guess it would be possible if it was able to completely replace the existing mods with the worm.
edit: Yeah, a post-work summary was posted today, and it basically did exactly that, it replaces all workshop mods created by the user with a copy of the worm, which then spreads. Honestly, I feel like this is also a vulnerability on Steam’s behalf as well because I don’t see any realistic use case of why it shouldn’t require either a 2FA or some form of validation before pushing an update to the game, especially one that changes the entire mod out for something else.
This one happened to be allowing C-sharp integration, which is how the original infection happened, because that allowed for compilation at runtime. However, this vulnerability could technically happen with any Steam Workshop-enabled game. It’s really concerning that there’s no check system in place. The Steam depot should not allow you to be able to do a full mod replacement using a session or with token.


I’m glad you added from 2025 there because otherwise it would have been super deceptive.
I definitely thought it happened again, and I was gonna be like, well that was fast. Like we all know it’s going to happen again, but that would have been extremely fast.


Yeah, that’s how I took it, but the developer acted like every system that was on the workshop was infected. They never listed a mod that caused the issue and instead just issued a blanket statement of this is what happened. It’s very weird.


I was originally going to add that usually different services can use the same name as long as there’s no overlap, but you can’t even use that on this one because they’re both blogging platforms.
Yeah, unless they have authorization from the original project this is likely going to require a name change.


I don’t own this game or project or whatever it is, but I’m confused. How does a mod getting hacked on a workshop make it so every player that’s on the workshop has a virus?


I’m not sure where you are but, around here it’s pretty common to have some kind of hat. As you mentioned it’s usually a baseball cap but, we do have sunblockers(I think thats the name?), fisherman caps and occasionally straw hats.
I have never been a hat guy though, I occasionally will wear a ball cap but it’s only if I’m going to be outside a lot.


If you aren’t looking for a daily, you can also just buy an external hard drive or two and rotate them manually from time to time. That’s my setup I have an external that auto backs up daily and then every couple of weeks I bring the cold storage drive over and rsync it.
Since I visit the location that I store the cold drive in every couple of weeks, I just plan it for when I’m there.
price wise that route would be looking at roughly 40-80 USD a drive vs cloud solutions which would be 3-10$ a month. so it would pay for itself in 8-16 months depending on drive cost


Wasn’t Shopify one of the first companies to go all in on an AI infrastructure? I seemed to recall reading that about a year or two ago.
It’s because presale isn’t actually against their policy. What is against their policy is someone putting an inventory up that they haven’t confirmed they are going to have.
So like if they have the email from Valve saying “this is the timeframe you get this” and that timeframe is more less than than 40 days out, as long as they can confirm shipment within 40 days of the item listing it’s allowed.
I wonder if you get a new report option if the page has been active for more than 40 days, or if said issue requires a buyer to report them when they don’t ship within 40
Being said, I think valve should crack down on the resale of their product on platforms like ebay, if they can find a listing that links to a steam account terminate future sales. With how overarching their system is they could likely cite Policy violation and close the entire account as well.
I assume it would be fairly easy to look for identical card numbers across the platform, or require the primary account on the device to be the account that purchased it for at least X amount of days having the system like how phone carriers do with carrier locking.


the ironic part of this is in some cases it can. Pirate broadcasts and media boxes are becoming increasingly common to have subscription models for way cheaper than you would having the traditional streaming subs.
We are in a world where even piracy is starting to cost money in some cases fair cause convienence, but its still weird to think about. Everything always goes full circle.


Yeah, which is why I think it doesn’t make sense that Steam allows it in the first place. Like, it’s actively letting a direct competitor use your platform. You get none of the benefits and all of the upkeep.


Fully agree. I think that Steam should make it a platform requirement that external launchers cannot be used on the platform.
It makes zero sense for me to hit play just to have a third party launcher open, and I have to hit play in that third party launcher as well. and I have to hit play in that third party launcher as well. At that point, I’m better off just buying it through the third party launcher.
The whole third-party launcher update process is also obnoxious… Every gatcha game does it. what’s the point of using steam at that point


more diversity. currently lemmy predominantly has politics, tech, and memes. Anything else is a little rough around the edges or nonexistent
Particularly, I was a huge fan of the Tales from X-style subreddits. It was entertaining to be able to go into them, read some stories about it and see others responses, even if some of them you could totally tell weren’t actually real. there have been communities made for some of the topics, but they’re dead, and unfortunately, those types of communities aren’t really communities that you can do too much with yourself unless you’re actively in that same field.


I’ll be interested as well, but I don’t think that it is a bad thing so to speak. Both CD PROJEKT and Michal have high values when it comes to DRM-Free and open gaming. Gog is mostly supported by it’s backers and game revenue, I don’t think that will change. I don’t see the co-founder who created both the studio and the storefront performing a pump and dump on GoG. If anything we may end up seeing a more heavy push into DRM free areas now that it’s detached from the game studio. Additionally CD Projekt’s reason seems fully valid. It makes sense they would rather focus more on making games than distributing. Distributing games is no easy task, let alone maintaining an entire storefront that most of the corporate world dislikes due to the core principles of the storefront (I.E the push towards support and DRM-Free).
It could be bad but, I’m not going to be super concerned until actual evidence ends up on the ground for it.
yea 11m changes is quite a bit at once but, I wouldn’t expect a constant change like that. After all, the monorepo itself is a little over 3m lines, 1.37m of it being lang/locale files for every language for its front end, 600k of it is comments, and 1.5m is the rest of it.