This seems like a strong argument against using open source codes. Should I take this argument seriously and avoid them?
This seems like a strong argument against using open source codes. Should I take this argument seriously and avoid them?
The main issue for leaking source code of _games_, especially _multiplayer games_, is that people learn how to bypass the anti-cheat mechanisms which leads to a degraded online experience for everybody.
I worked on Tom Clancy's The Division and the mantra was always "write code like it will be public one day".
(in their case it meant don't get to persnickety about a library not working how you wanted or swearing about how Windows was batshit insane at times -- but it also applied to making sure you did't just assume the code wouldn't be read by malicious people)
The multiplayer part of some games made the single player section worse, because of the drastic anti-cheating measures.
It's always easier to be on the attacking side of cyber security. If the attackers have good intel, and the defense isn't organized, their work is much easier.
With (popular) open source projects, there are hundreds of eyeballs looking at the source and trying to fix security issues before they can be exploited.
The closed source project is typically less secure, but attackers also have less information to work with. Open source is typically more secure, but attackers have more information. Leaked closed source is the worst of both worlds.
And only if the codebase is routinely looked over and tested, no part of the codebase gets forgotten and becomes unmaintainable because somebody left the company.
Open source has the added benefit that maintainers typically don't disappear complete from the project overnight because they got a new job/were fired.
But even then you have the whole area of protocol reverse engineering and data fuzzing which doesn't require the source at all.
A closed source projects can have thousand of security bugs no-one will never know about. Since it's closed, it's hidden so no problem... until it's leaked.
In contrast, source code of games is a trade secret. It is being worked at by famously overworked developers. And companies in the industry are known to sit on vulnerability reports for months or years.
Don't ever install games on a machine you use for work or identity.
- Banking.
- Insurance.
- Main Google account.
- SSH keys.
- GPG keys.
- Pictures of any important documents.
- Digital copies of any important documents.
Basically: the moment you start installing games on a computer, assume it makes its contents world read/writeable.
His argument is also complete horsesh_t to prop up the firm and to also spread FUD. Just look at this sentence: 'identify deeper flaws for exploit', tells you they don't even understand that you find the vulnerabilities first and THEN you develop an exploit for it.
Another "death sentence" of journalistic quality at the BBC whilst also advertising for firms that have clueless spokespeople.