Unity is acquiring a company who made a malware installer
pcgamer.com
pcgamer.com
The way this software worked (as far as I can recall): The installer bundled a DLL from which only a few minor functions were exposed to display offers within the host process. Usually, the only thing the client portion of this DLL needed was a HWND. During initialization, the DLL stored a copy of itself in the user's temp directory. The host application unknowingly then used rundll32 to load this copy as a separate (also elevated) process. This process would run at least as long as the calling process would. Once in place, the process would scan the user's computer for specific use patterns (geoinformation; MS Office presence; what language; etc.). In order to retrieve the latest advertising "offers", the DLL called home with this information over a secure pipe and checked for updates. This data was stored and referenced if the same user invoked the DLL again at some point. Only at this point would any actual targeted ads be displayed in the client application's window.
Things may have changed since then - these were the pre-Windows 10 days - but if it's anything like this, it's wise to avoid the Unity installer.
What "Unity installer"? Games nowadays are all distributed on steam / epic / app store / etc.
If you are talking about the editor, this makes no sense they would bundled it up with malware (their target is the games made with it).
I'm not thrill about the announcement at all but there is a lot of unfounded fear.
E.g. for Steam see the Install Script section here: https://partner.steamgames.com/doc/sdk/goldmaster
That is only your interpretation of the purchase. Unless you have insider information you don't know what their true intentions are.
They could have purchased a more reputable company with the same goal you mentioned.
Malware isn't really a uniform category of software. They can be harmful in a lot of different ways. Something like a kernel level anti-cheat is malware in almost every sense of the name except the developer's promise that it's not doing anything nasty. And there's a long list of DRM that affects the performance, security, or stability of the system while most users aren't aware this is happening or why. They install a game, everything else that comes with it is realistically hidden just like any malware.
So while you could group them in different categories, many forms of DRM are malware in form and function.
How would you call a "Malware" as describe above versus a "Malware" DRM / Anti-cheat. There is a clear separation between the two for those platforms.
But sticking with a philosophical defintion, malware is a very fuzzy category, and that line is so blurred as to essentially not be there in the case of anti-cheat programs and services, which effectively spy on the user (malware behavior) for financial gain (having a gaming platform that doesn't have a large number of cheaters) and often employ malware tactics like rootkits, VM detection, process inspection, etc.. Similairly Google Analytics definitely meets the criteria we generally use to define malware (spyware in that case) if you raise the bar a bit for things running in the browser.
No matter how we define those at the end of the day there is a difference between them, so maybe "malware" is the wrong word here as this seems to irk many, but seeing all the replies that group DRM / anti-cheat / analytics / ads (interstitial) and malicious software that get sneakily installed to add toolbar / popups to a computer all being grouped together as one and the same is just wrong because in the practical world those companies makes a clear distinction between them.
So my question is, if the correct word is not "malware" to uniquely specify that subset of software that is clearly banned from those store and won't at large also includes stuff that are OK like analytics. What is it?
Personally, in the real world, I would never specify something like analytics or ads (interstitial) as "malware" (even if philosophically they are) because to me, the way I've seen it used was to identify software that get sneakily installed and add malicious stuff to the user's computer (popup / toolbar / crypto mining).
DRM / Anti-cheat, even tho they are "bad" (I get that), are not going to suddenly start showing ads popup (and if they did and they totally can, the stores would banned those games and would classify it as malware not just DRM).
Making a word too broad means we loose the meaning. There has to be a specific word that describes the exact type of software that I am desperately trying to specify. And I know you know what I'm referring to, and I'm sure everyone understood what I meant, and I get that it isn't "malware" but what is it?
I do not agree and I really don't see you being able to support this. They are just different categories of malware. Malware is defined by its characteristics, not the "platform's" (developer's?) definition.
Even if we don't have an absolutely clear, rock solid and immutable definition of what malware is, it's generally accepted that if a piece of software is affecting the stability, security, or performance of a system, while the owner may not even be aware of the presence, function, or impact of that software, then it's malware. More generally performing actions to the detriment of the owner and without the owner's knowledge.
White-hat software that infected routers to fix backdoors and eliminate black-hat malware (so to improve the security, stability, or performance of the system) was in practice still considered malware.
So keep in mind that an attacker punching you in the face doesn't get to decide whether it's assault or actually just percussive transmission of information. It's the characteristics of the action which define it.
https://www.polygon.com/2018/6/20/17485762/red-shell-spyware...
The concern here is hyperbolic. This is about ads, not malware. There is no rational reason Unity would want to get close to malware.
Unity game dev will, willingly, include ads into their games, no need to sneakily force malware on users computer for that.
I get the fear, "unfounded" was perhaps the wrong word, most articles want to push the narrative this way, but despite their previous sketchy background, IronSource is one the leading mobile gaming ads company, they don't only make malware and clearly this merging is about "ads" and not installing malware.
Edit: Nowadays they take it a step further, like Vanguard. It’s a boot kit that injects a kernel mode driver right at the beginning of OS initialization,
The best part is they likely had an EV code signing certificate with instant SmartScreen reputation while all the indie and open source developers are sitting around locked out of the system due to cost and the absolute clown show of security theatrics baked in to the the trust industry's identity verification processes.
I get games from GOG.com, because they do not have DRM and are generally not evil.
But the unity games on the platform - they all phone home and send back detailed telemetry on what you do in-game. plus probably other stuff.
Thankfully the GOG terms allow you to install and run the games offline without requiring these shenanigans to play your game.
This type of going public and chasing shareholder, share selling, cash infusion (sorry for the word salad, I couldn't think of a better way to put it) - which is often needed for growth past a certain point - how does a company not compromise their vision and bow to the shareholders once they go public, when their directive then becomes "Maximize stock value for the shareholders"?
NOTE: I'm an engineer who graduated with an art degree, so this is way out of my wheel house. I've always built things, and have not been privy to the business side of the show. It's a bit foreign to me.
CEOs use the excuse of "shareholders" because it sounds better than "I wanted to maximize my bonus." That isn't all bad-- seriously everyone wants to maximize their bonus, including me!
As as an aside, I really doubt Unity is planning on installing malware even if they could through the Steam or Apple stores (which they probably can't). They probably just want to do better ad tracking. Is this ethical? I don't know enough to say. But a mom and pop or private company could do the same thing.
Games cost money to make. If people don't want to pay money up front for them, well then as they say: the user can be the product.
All the while, the already paying customer base is frustrated.
So any company's "soul" will be lost through time by mergers and acquisitions. The company that played the game of make-the-most will end up with a treasury large enough to buy those companies who tried the path of ethics.
Take a look at beloved Costco. Blackstone took over the board and has been putting the screws on their staff, and hard selling customers on Executive Memberships. Their hot dog is on the ropes and we'll see if it remains a loss leader.
As profit growth declines due to market saturation, drastic measures will be taken to keep profit growth high. Workers and customers will be squeezed for next quarter growth.
If you think I'm wrong then please take a look at your favourite fortune 500 company and tell me who is going to pay for this quarter's inflation, the shareholders or the customers?
> Unity already has Unity Ads, "our monetization solution for mobile games that enables game developers to monetize their entire player base", but obviously there are benefits to combining that with IronSource: "Unity and ironSource's complementary data and product capabilities will give creators access to better funding for user acquisition (UA) and monetization to successfully scale their games and accelerate their economic performance."
0. https://venturebeat.com/2017/08/10/pc-gaming-weekly-watch-ou...
A game engine company cannot ask for much money at all without the people holding the purse strings turning around and asking "Why don't we just use an open source engine or build our own?" So Unity is stuck with a huge foot-in-the-door problem regarding their game engine business: their direct competition is their customers.
To their credit, I have been consistently impressed with their approach to addressing that challenge, but that challenge makes the whole space of game development support tooling hard to persevere in.
It’s very difficult to justify the expense of developing your own engine, especially if you intend to release for multiple platforms.
Now you have to ask how many of those games would have happened absent a Unity, and the answer is "Most would not." But it's a chicken-egg problem: without Unity, the games wouldn't have existed, but if Unity asks for too much money to publish the game with their engine, the game also doesn't exist.
It's a conundrum that caused Unity's predecessors to mostly try and fail (with a few exceptions that are still around), and I've been impressed by their ability to thread the needle on this market. But it's a delicate market... lacking a Unity out there, I doubt OnlyCans Team would have rolled their own engine, but I also doubt they'd have paid money to Unreal to execute on their novelty idea. They just... Wouldn't exist. Unity has to pull far, far less revenue from developers of a game project than Unreal does to maintain the existence of the ecosystem they grew around themselves.
While I think your point still holds, I think it should be noted that 2005 was 2 years after steam released. And still primarily a distribution platform for valve’s first party games. There were many more games available via other distribution channels.
Unreal has technology moats like Lumen and Nanite to justify the royalty while Unity doesn't.
On Steam, it seems to be about 20% - pretty much the same share as Unreal's: https://www.gamedeveloper.com/business/game-engines-on-steam...
There's also a difference between rolling your own in-house engine like Frostbite or REDengine, and making a game on your own with no general-purpose engine using something like SDL. There's little point in doing the former nowadays, but there's plenty of titles that still successfully take the latter approach. General-purpose engines make this whole field obviously more approachable and for some kinds of projects are the only viable option, so the percentage share of no-engine games will likely continue going down, but I don't expect absolute numbers to drop significantly.
Those people should be fired
Unity has always had a pretty predatory business model. And has basically never made money from successfully shipping games.
This would also help Unity's image of being an engine for bad games; currently, bad games use the free version of Unity, meaning they show the Unity logo splash screen, while all good games built on Unity use the paid version which allows customizing the splash screen.
If there was only one version of Unity, which was free up-front but took a 5% royalty, it seems like a lot of problems would be solved for both Unity and developers.
This _seems_ like an attempt to shore up that part of the business.
Speculation: They know the returns from the game engine/vr-ar future will take a long time to arrive. So they need — given they’re a publicly traded company - to ‘show them the money’, and they fell down the ‘ads!’ hole, and I’m not sure they’ll get out of it.
Those pesky consumers, who have explicitly chosen not to be tracked.
When Apple Tracking Transparency first came about, many of my clients had a hard time grasping the situation. They couldn't understand why we couldn't track them anyway, even though within the agreements between all parties it was clear that the consumer has not allowed you to track them. The attitude for some business owners is that their engagement with their consumers is not an agreement between two parties, consumers are just feedstock for their advertising apparatus.
1. Unity only grabs the Indie especially the mobile market.
2. Unity cannot compete with UE without a huge investment.
So the only solution is to go down the ads road. Sorry I really don't see a second option. Only with ads can Unity makes more money to afford more editor development. Editor development needs very expensive people (those senior and staff engineers with large TC) and has no way to prove that it can be profitable so far.
So, they're going where the money is. They're pivoting to mobile games, and to make bank in that, they partner with a spyware company that installs shit on your phone and is neck deep in helping with predatory pricing and abusive psychological manipulations.
Unity is a sinking ship, and the captain is a rat.
I'm quite surprised that nobody is talking about anti competition - ironsource's rise and unity ads are, together, a very large mobile advertising network. Two that are often vying for the same customer. App developers that depend on those two competing are now shit out of luck. I'm really surprised this deal snuck through anticompetition oversight and it doesn't seem like it would have if google wasn't at the same table.
Anyway, ironsource STILL runs this slippery desktop install network - it's not like this was way back in the past and they've moved on. Hit the download button on any streaming/torrent website or keygen installer and you'll find ironsource.
And there are many other competitors in this field.
It really felt like I was printing money. Whenever I needed to pay tuition I would just work for like 8~10 hours and the next month a check arrived that paid all of my costs as a student.
Looking back it wasn't the best but neither was being forced to pay a few thousand dollars every semester to buy the same textbook but with an updated cover and table of contents so they can call it the 18th edition.
For a corporation that is trading publicly to do this, I have to wonder who is running it and whether they have its best interest.
I see many indie developers starting to ditch Unity and opting for Godot or other game engines. This is unlikely to impact Unreal Engine, as it very much is aimed at a different demographic (namely studios with at least 5 FTE)
And Epic took pains to hide where this shit was coming from.
Wake up.
https://www.epicgames.com/help/en-US/epic-games-store-c73/la...
No relationship to Godot - just an impressed user.
> A: The definition of the term Open Source is heavily debated. The Open Source Initiative has created a definition of the term Open Source where it must be possible to commercialise the source code. The Defold Foundation has made the decision to prevent commercialisation of the game engine and editor (the Game Engine Product). We want Defold to always be free to use! (You can of course still sell your games and plugins and you can modify the engine as much as you like).
Depending where your moral compass lies this is either even better than open source or worse.
No, the definition of the term isn't heavily debated; it just became a trendy term over years with enough positive connotations to make some people want to use it for marketing even when their projects don't actually match the definition.
When Defold made its source code public, they used the term "open source" across their marketing material and only stopped doing so after community backlash. Their license URL is still "/opensource/". They got a lot of media coverage from people who were mislead into believing that Defold went open source until this got corrected. You should read what they wrote with this context in your head. I find what you quoted to be borderline manipulative.
Also, I don't understand the purpose of non-commercial clauses on such projects. All they do is cause PITA. It makes your project non-free, so it cannot be included in distros that distribute FLOSS only or mixed with code on viral licenses. And nobody is going to buy something they can get for free unless you're adding some real value on your own with your fork. Furthermore, what exactly constitutes of "commercial usage" is often arguable. If you really care about your project staying free, use a viral FLOSS license, with a non-viral exception on the runtime part. Those technically don't prevent commercialization, but still require freedom, so everything stays free to use in practice. Stamping a non-commercial clause on a Apache-like license like Defold did is the worst of all worlds.
Apparently it has some non-native feel issues, but it works better than you'd expect. They had a bunch of custom UI components for recycling views and stuff too.
> The VFX teams at Weta Digital aren’t included in the deal; instead, they will be part of a standalone entity called WetaFX that will still be majority owned by Jackson
https://app.companiesoffice.govt.nz/companies/app/ui/pages/c...
Appreciate it.
Indeed, in my experience, hijacking elements like right click, copy, and back/forward buttons is somewhat commonplace. Some browsers are better at avoiding this, but none I've used are immune to hijacking tricks, especially the back button.
I don't agree that it's a bad idea. What is bad is the amount of user-hostile sites that get promoted on the web. Those should be silenced, not boosted into mainstream by search engines an social media.
Anyway, browsers can improve the feature by grouping the added links and making it easy for users to ignore them. But innovation on the web got it's last and fatal strike when Firefox killed its original extensions API.
Like I said, I'm sure there are "reasons" for doing it. Put your own "back" button in the application then, don't take MY browser button and reconfigure it. The browser back button should go back in my browser history - including leaving an app, not where some web developer decides it should go. This is a giant security concern introduced for web developer convenience.
This is only a security issue because the browser developers want it to be. There's nothing on the standard saying that when you click back, it should go to the previous link inserted by JS, or that there must be a single button for everything, or that every site is treated the same way.
Anyway, removing the quite useful possibility of the browser remembering the history of the usage of an application won't solve the issue of browser innovation being destroyed or of malicious sites using any loophole available to get something out of you. For that we need browsers and basic web infrastructure that are focused on supporting your needs, what the current crop clearly isn't.
> InstallCore was also behind a fake installer for a Windows version of Snapchat, a program that's only ever been available on mobile. It would instead install Android emulator BlueStacks, as well as the usual injection of adware.
This was true in 2015 when the referenced blog post was written.
Nowadays Snapchat is not only available on mobile; there is a web client. Additionally, on Mac OS, there is an officially supported emulation (virtualization?) layer that allows you to run iOS apps (at least in theory; I’ve never tried it).
EDIT: this comment is almost entirely wrong, sorry! I’ll leave it up since people have replied to it. I don’t know why I thought there was a web client - maybe I was thinking of snap map. And I thought that you could run any iOS app on Apple M1, but apparently this is not true. (While I was searching this, I believe I also encountered articles promoting the same malware described in the OP!)
> InstallCore was also behind a fake installer for a Windows version of Snapchat, a program that's only ever been available on mobile. It would instead install Android emulator BlueStacks
That actually sounds like a _real_ installer for a Windows version of snapchat. Just because they had to use some technical trick to make it work doesn’t mean diddly(if it actually works).
This isn't true.