Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Gabrielite
Apr 24, 2008
Well, this is unfortunate.

PC Gamer - Euro Truck Simulator 2 developer gets one-year Steam ban for demonstrating security flaw

quote:

A big update to Euro Truck Simulator 2 is adding three new cities to its lineup of places you can keep on truckin' through, as well as truck-specific speed limits to the GPS route adviser and the hotly anticipated "Seat Adjustement" feature. But perhaps even more interesting than any of that is that Tomas Duda, one of the developers on the game, was banned from Steam for a year for using a "Daily Deal" announcement to bring a potentially serious security vulnerability to Valve's attention.

If you hit yesterday's announcement that Euro Truck Simulator 2 was the Steam Daily Deal, you might have found yourself redirected to an unexpected place: the Harlem Shake video. The idea, according to Duda, was to force Valve to take notice of the security flaw in community announcements, and then fix it, but what happened instead was a one-year ban "for violations of the Steam Subscriber Agreement."

Duda said he went with the ill-advised Harlem Shake redirect after talks about the vulnerability with "a Valve guy (a) few months ago" went nowhere. "I was talking about the script tag vulnerability multiple times. No one fixed it. Now I did Harlem Shake for fun (yay for #steamdb)," he wrote. "Imagine if someone used the vulnerability to steal users' session IDs? Redirected to a phishing site?"

He also claimed that he didn't want to make the vulnerability public, but said it's hard to avoid widespread attention when you post something funny. "People then just share it and it spreads," he wrote. "Had like 100 people at the time on the announcement page a few minutes after doing that."

Duda and his supporters are working on an open letter to Valve appealing the ban, and an "Unban Timmy" user group (in reference to his Steam ID) has also popped up. You can also keep track of his status at istimmystillbanned.info, which for now remains at an unhappy "Yes."

Nothing on the official blog yet. At the moment there's about ~120 people in the unban Timmy group. I would hope Valve gets the message especially if other game media outlets pick up the story.

Edit> Timmy's responses can be seen in a couple of threads on reddit.

Edit 2> Kotaku has the story as well with slightly more insight into what happened. Kotaku - Kid Developer Pranks Steam, Gets Suspended From Steam

Gabrielite fucked around with this message at 10:02 on Jun 17, 2014

Adbot
ADBOT LOVES YOU

Apple Craft
Mar 8, 2012
Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray :cry: Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray
He could have simply resubmitted the bug report. He decided to be immature about the issue and is suffering the repercussions for his actions. I am finding it difficult to be sympathetic to his cause.

ovaries
Nov 20, 2004

It was mentioned in that very quote that he told Valve about it months ago but no action was taken. The important thing is that he's now forced Valve's hand and they have to do something about it.

jadebullet
Mar 25, 2011


MY LIFE FOR YOU!
So does anyone know of a good mod that replaces the sound busses make when they pass you? Having what sounds like an idling diesel playing through my speakers while a bus passes is starting to get old.

Edit: Also, in the idea of there being a prototype for everything, where I currently live we have a real life version of an offramp where you can't go down the road at the bottom.

https://www.google.com/maps/place/Bridgeport,+PA/@40.1059761,-75.3536912,529m/data=!3m1!1e3!4m2!3m1!1s0x89c696003b684205:0x8c9fc675f954f808

Apparently this was a failed bypass from the 1970s that just serves as a very short access road to the center of town.

jadebullet fucked around with this message at 14:43 on Jun 17, 2014

duz
Jul 11, 2005

Come on Ilhan, lets go bag us a shitpost


Apple Craft posted:

He could have simply resubmitted the bug report. He decided to be immature about the issue and is suffering the repercussions for his actions. I am finding it difficult to be sympathetic to his cause.

Except Valve is terrible about fixing security flaws, especially in things that arn't Source Engine. This is pretty much the only way to get them to do something about it. I'm sure the main issue with getting them resolved is their free form structure causing the report to not get to the proper people.

IAmTheRad
Dec 11, 2009

Goddammit this Cello is way out of tune!
Steam developers are expected to not put exploits in their community messages. They trust them to not use exploits. If a developer did something even more malicious with the exploit, would they get any sympathy even if they reported the bug? I don't think they would.

Valve did the right thing by banning TimmyCZ for using the exploit. They trust developers to not pull this type of stuff. If a developer uses an exploit, they should get punished regardless. If they stole important things like passwords or credit card information, legal action would be taken against them. Timmy is lucky to just get banned for a year.

sellouts
Apr 23, 2003

Yeah trust, that always works out

FredMSloniker
Jan 2, 2008

Why, yes, I do like Kirby games.

ovaries posted:

It was mentioned in that very quote that he told Valve about it months ago but no action was taken. The important thing is that he's now forced Valve's hand and they have to do something about it.
And now that they've done something about it, they can go back to business as usual.

wolrah
May 8, 2006
what?

Apple Craft posted:

He could have simply resubmitted the bug report. He decided to be immature about the issue and is suffering the repercussions for his actions. I am finding it difficult to be sympathetic to his cause.

Are you really supporting a zero tolerance approach? Valve ignored his report, so he made a literally harmless proof of concept on an old page of his own.

Yes he technically did something wrong, but in terms of actual harm it scores a big fat zero.


Ban him for a day, a week, some token amount of time that says "you broke the rules so we have to do something". Don't punish someone who makes public a flaw you've ignored in a harmless way.

PureRok
Mar 27, 2010

Good as new.

IAmTheRad posted:

Steam developers are expected to not put exploits in their community messages. They trust them to not use exploits.

This is rather naïve, especially considering how untrustworthy quite a few of the indie developers appear to be.

CJacobs
Apr 17, 2011

Reach for the moon!

IAmTheRad posted:

Steam developers are expected to not put exploits in their community messages. They trust them to not use exploits. If a developer did something even more malicious with the exploit, would they get any sympathy even if they reported the bug? I don't think they would.

Valve did the right thing by banning TimmyCZ for using the exploit. They trust developers to not pull this type of stuff. If a developer uses an exploit, they should get punished regardless. If they stole important things like passwords or credit card information, legal action would be taken against them. Timmy is lucky to just get banned for a year.

This post would make sense if he said how to do the exploit in his post. But he didn't, so it's still bullshit.

ovaries
Nov 20, 2004

CJacobs posted:

This post would make sense if he said how to do the exploit in his post. But he didn't, so it's still bullshit.

It's just a script tag. No instructions are necessary because anyone with even the slightest familiarity with HTML would recognize how that could very easily be exploited. I agree that Valve's ban was bullshit, although your reasoning is stupid and it's all largely beside the point anyhow -- the important thing is that Valve needs to get this fixed ASAP.

There's a good reason why forums like this one use BBcode and it's pretty nuts that Valve is allowing this kind of thing, especially given that they soon plan on opening the floodgates to anyone who wants on their service.

ovaries fucked around with this message at 00:06 on Jun 18, 2014

Kilonum
Sep 30, 2002

You know where you are? You're in the suburbs, baby. You're gonna drive.

The ban got reversed

http://istimmystillbanned.info/ has a no

Apple Craft
Mar 8, 2012
Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray :cry: Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray

wolrah posted:

Are you really supporting a zero tolerance approach?
I support Valve's right to enforce their rules. At the same time, I am happy to see that Valve has chosen to review the issue and that his ban has been lifted.

track day bro!
Feb 17, 2005

#essereFerrari
Grimey Drawer
In other news, TSM 5.0 has been released apparently the whole of spain and portugal has been redone. Which is good seeing as most of spain was pretty much the uk.
https://bitly.com/bundles/thomastsm/G
Please feel free to complain that you cant download it.

Feindfeuer
Jun 20, 2013

shoot men, receive credits

Megadyptes posted:

Spintyres is pretty fun, getting stuck in mud all day erry day. hosed around in mp and some dude helped me out when I got stuck. camera controls are loving meh but it's pretty decent. There's a poo poo ton of mods for the old tech demo, dunno if they work for the full game but I imagine a lot will be ported over.

:toot:

It's pretty fun, I just wish tere was a mod that allowed me to probe puddles for depth before traversing them. I now just try to avoid them completly after this happened a few times.



This is not somewhere in the wilderness, that is the centre of a crossroad on one of the roads... or what passes as a road in that part of russia.

Zeether
Aug 26, 2011

Spintires sounds cool but what it really needs is a William Friedkin's Sorcerer mod where you have to transport nitroglycerin and the slightest shock will blow up the truck.

Largepotato
Jan 18, 2007

Spurd.

smelly cabin filter posted:

In other news, TSM 5.0 has been released apparently the whole of spain and portugal has been redone. Which is good seeing as most of spain was pretty much the uk.
https://bitly.com/bundles/thomastsm/G
Please feel free to complain that you cant download it.

Looks good, think I will wait until after the 1.11 patch is released before trying it though.

Snowy
Oct 6, 2010

A man whose blood
Is very snow-broth;
One who never feels
The wanton stings and
Motions of the sense



Zeether posted:

Spintires sounds cool but what it really needs is a William Friedkin's Sorcerer mod where you have to transport nitroglycerin and the slightest shock will blow up the truck.

I was reminded of that too, I love that idea!

IAmTheRad
Dec 11, 2009

Goddammit this Cello is way out of tune!

PureRok posted:

This is rather naïve, especially considering how untrustworthy quite a few of the indie developers appear to be.
In extreme cases, Valve will pull the developer's games off Steam and issue refunds for people who bought them. These are very rare cases, and they won't happen everyday.

Well, Valve did fix the bug and also reversed the ban. Probably because of the outcry for support for TimmyCZ since he didn't do anything really malicious. Just proof of concept. Valve still needed to ban Timmy regardless, to show a zero tolerance policy for exploiting bugs in Steam.

Which also puts into the spotlight of other companies with known issues and not fixing them.
GM with their faulty ignition switches, only deciding to actually fix the issue after knowing about it for 10 years because of the fatalities, and people wanting answers for the massive recall.
The Heartbleed bug with OpenSSL is also somewhat a known thing, but the time they revealed the bug, the fixed version of OpenSSL was released.

tater_salad
Sep 15, 2007


Is there a spintires demo somewhere, I'd love to give it a try, but not sure if my low spec comp will run it, I'm crossing fingers for steamsale goodness.

track day bro!
Feb 17, 2005

#essereFerrari
Grimey Drawer

tater_salad posted:

Is there a spintires demo somewhere, I'd love to give it a try, but not sure if my low spec comp will run it, I'm crossing fingers for steamsale goodness.

Yeah theres one on their website if you google it.

Can anyone tell me if this truck works and is it actualy fully sick?
http://ets2.lt/en/kamaz-4410-6450/

tater_salad
Sep 15, 2007


smelly cabin filter posted:

Yeah theres one on their website if you google it.

Can anyone tell me if this truck works and is it actualy fully sick?
http://ets2.lt/en/kamaz-4410-6450/

Is the tech demo a good representation of the game and load required for a PC instead of just a proof of concept, seeing that it's only 145MB it seems small compared to the 10GB game req on steam.

Overwined
Sep 22, 2008

Wine can of their wits the wise beguile,
Make the sage frolic, and the serious smile.

tater_salad posted:

Is the tech demo a good representation of the game and load required for a PC instead of just a proof of concept, seeing that it's only 145MB it seems small compared to the 10GB game req on steam.

I have a similar question: I just downloaded the tech demo and played around and it ran surprisingly well on my ageing machine. How much more taxing is the most recent version? I exceed the min system requirements, but am a little shy of the recommended.

ovaries
Nov 20, 2004

^^^ I haven't tried the tech demo, but the full version seems optimized incredibly well and I've experienced no slowdown on my system (FX-4100 @ 4.4 ghz, 7870). I was experiencing some pretty wretched graphics glitches on AMD's 14.6 beta drivers but they went away once I rolled them back.

tater_salad posted:

Is the tech demo a good representation of the game and load required for a PC instead of just a proof of concept, seeing that it's only 145MB it seems small compared to the 10GB game req on steam.

The full game is ~550 MB. It's listed as 1 GB on its store page but that almost definitely just accounts for compressed data.

ovaries fucked around with this message at 18:21 on Jun 18, 2014

tater_salad
Sep 15, 2007


Confused it's req's with my other wishlist of DayZ..
Come on Gaben Dont' let me down, I've got an addiction to fuel, but I'm cheap.

PureRok
Mar 27, 2010

Good as new.
I'm holding off on buying it until they add a cockpit view. Supposedly they said they plan to, but I'll wait until I see it happen.

Naked Bear
Apr 15, 2007

Boners was recorded before a studio audience that was alive!
The game is pretty sweet, but fuckin' a, the camera is a pain in the rear end. The real difficulty is not in getting stuck, but getting the camera to quit loving off.

Kilonum
Sep 30, 2002

You know where you are? You're in the suburbs, baby. You're gonna drive.

Updating TSM fixed the issue I was having :woop:

EDIT: Also cleaning 9GB of unused mods out of the mods folder.

Kilonum fucked around with this message at 01:20 on Jun 19, 2014

Pornographic Memory
Dec 17, 2008

JDAMS CURE PASHTUN posted:

The game is pretty sweet, but fuckin' a, the camera is a pain in the rear end. The real difficulty is not in getting stuck, but getting the camera to quit loving off.

Yeah I'm gonna be pumped when they add a first person view just so I don't have to worry about the camera. I don't play most driving games first person but for Spintires I think I'll make an exception just because you can't see in front of you without swinging the camera way to the side. Cool game though, would be neat to play MP with goons or something so we can all get muddy and stuck together and tug on each other.

StarkRavingMad
Sep 27, 2001


Yams Fan
Spintires is pretty great. Scratches a whole different itch than ETS2 (definitely not a relaxing driving sim, more of a "gently caress get up that hill you bastard don't dig in AH poo poo" simulator). If no one else does, I may have to make a separate thread for it when I get time, maybe this weekend.

ovaries
Nov 20, 2004

You should. I'd certainly like one and I've seen a couple people asking for it in the Steam thread.

Hexenritter
May 20, 2001


So, my dad drives freight all over Europe, and I got an email from him yesterday saying he'd wrecked his truck in Belgium a week or so prior, and the insurance company had just paid out for the totalled vehicle plus personal effects (they just left the poo poo in his truck in Belgium and said "eh, we'll replace it"). He sent me a picture of his new 18-wheeler and my first thought (and what I told him) was "there aren't enough lights, you should be blinding people with the power of a thousand suns or you're not doing it right."





edit: Also, I should have told him to get an FH16

Apple Craft
Mar 8, 2012
Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray :cry: Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray Gaile Gray

CitrusFrog posted:




edit: Also, I should have told him to get an FH16

Eh, while I agree about the lights, that's a pretty nice looking truck. Tell him to stay safe out there.

Hexenritter
May 20, 2001


Apple Craft posted:

Eh, while I agree about the lights, that's a pretty nice looking truck. Tell him to stay safe out there.

Thank you, I will. :)

It really is, and it's 3 model years newer than the one he was driving, he's really happy about it and I'm deeply relieved that he didn't get hurt in the crash. I'm not sure what exactly caused it, but he's a drat fine driver (and used to drive amphibious assault vehicles off cliffs into lakes to terrify newbies in the Grenadier Guards, which is :black101: as gently caress) so it was probably an enemy car.

StarkRavingMad
Sep 27, 2001


Yams Fan
I made a Spintires thread here: http://forums.somethingawful.com/showthread.php?threadid=3644539

I used your gif, Feindfeuer, and gave you credit for it. Hope you don't mind.

tangy yet delightful
Sep 13, 2005



CitrusFrog posted:

edit: Also, I should have told him to get an FH16

Unfortunately in the real world the price difference matters because you don't actually get paid $40+/mi even as an O/O. I know you know this but still that does look nice and I like the paintjob (should have gotten flaming skulls).

IAmTheRad
Dec 11, 2009

Goddammit this Cello is way out of tune!
Jazzycat added a few new trailer packs in recent times.

http://jazzycat.ucoz.net/ is his webpage.

Syrian Lannister
Aug 25, 2007

Oh, did I kill him too?
I've been a very busy little man.


Sugartime Jones
Quick question.

I downloaded an environmental mod, and it has dds files. Where are these installed within ETS2?

Thanks.

Adbot
ADBOT LOVES YOU

MyFaceBeHi
Apr 9, 2008

I was popular, once.
Was the .dds file part of the download or is it within the .scs file? Really any mod would be the .scs file as that is the mod file format. Anything else (except .zip I think) won't work.

Also :siren:THIS GAME IS ON FLASH DEAL RIGHT THE gently caress NOW AT 85% OFF GET IT NOW!:siren:

MyFaceBeHi fucked around with this message at 16:43 on Jun 20, 2014

  • Locked thread