Easter Egg Hidden in VMWare Fusion and Workstation
misc.name
misc.name
The way this is implemented, I can't see any harm: Instead of getting something along the line "BLEEP LOADER NOT FOUND AT 0" (and you'll still get this if len(floppyimg)>0 ) you get pong.
I think one should be amused here.
If you're worried about code doing things you don't know about then there's a heck of a lot more to VMWare that you could be concerned with. It's a huge, complex application. A few KB for a hidden game is irrelevant - you don't know what hundreds of MB of it actually does. If you're worried about things being hidden in apps then you run them in a trusted environment on tested hardware after you're audited the code (and removed the easter egg).
The only reason this should worry anyone is because VMWare potentially lost sales to organisations who do need to run audited code. I imagine they would have been supplied a version without the Easter Egg though.
You won't be laughing if $RANDOM_EASTER_EGG has a bug that allows for remote code execution.
Thing is, everyone seems to think the place and time is everywhere but not here and now. Companies today tend to have inflated sense of importance and gloominess stemming from what I believe is a mistaken understanding of professionalism.
> You won't be laughing if $RANDOM_EASTER_EGG has a bug that allows for remote code execution.
Hell yes I'll be laughing, I always laugh from remote code execution bugs ;). Anyway, you can argue that for any piece of code. Sure, an easter egg increases the surface of attack... by 0.1% or something.
So you're running on seL4 right now? How's that going? Did you program the userspace yourself?
I'm impressed.
$ man tunefs
System Administration Commands tunefs(1M)
NAME
tunefs - tune an existing UFS file system
...
NOTES
You can tune a file-system, but you can't tune a fish.So I see it as both an indicator of good work and a positive thing.
Yes, other's believe that Easter eggs are bad I assume you're referring to the famous http://blogs.msdn.com/b/larryosterman/archive/2005/10/21/483...
It has good points but I believe it to be wrong in conclusion, there's lots of real issues to care about before this one.
Excel 95 had a "Doom"-like 3D game. Excel 97 had a basic flight simulator. These were fun and weren't buggy, but here's the problem:
How much time do you think was lost in classrooms in particular after all the kids discovered there were games they could be playing instead of working? All of the built in Windows games were removed, and Flash/Java weren't installed. But you cannot remove these if you need Excel.
This was a legitimate issue in the 1990s. So much so that the school I attended gave anyone detention caught playing these games during class time(!). Yet every class there would be someone sitting in the corner playing away.
That's exactly the opposite of what I said, I said I liked Easter Eggs in principle but then gave an example of when they went wrong. The first line of my comment was: "I agree with Easter Eggs in products."
Easter Eggs are good, you just really have to consider the impact they're going to have (in terms of perception, usages, and bugs).
However it is unfortunate that they decided to conflate a product needed in a classroom (namely the Office suite) and a feature which is not (namely a game).
Microsoft's only responsibility is that their software is fit for purpose, and in this scenario it is not.
edit: 4 people downvoted, not a single reply? This place is turning into Reddit. Pathetic behaviour.
I'm also concerned about the development process itself. Design reviews? Code reviews? Automated testing? CI/CD? What is the impact of an easter egg on these things? Were the eggs noticed and tacitly approved? What does this tell us about the process?
Do I want to rely on the product of that process?
Or are we saying we don't care?
I appreciate the idea behind the easter egg, the little human touch, the little flourish that says "look what I built", I really do. But, fundamentally, the software I use becomes part of the machine - and I want it to behave that way, like a reliable machine that does exactly what I expect and only what I expect. If I want a human touch, I'll reach out to a human. If I want a surprise, I'll read a book or play a game.
Imagine an easter egg in your car's navigation system. Won't that be cool! Not.
Easter eggs, especially in software that should be part of the machine, strike me as the height of unprofessional irresponsible behaviour. An f-u to management and to users that deserves its own resounding f-u, I'll use someone else's professional, reliable tools, thank you.
It doesn't tell us anything about the production process at VM because we don't know if they were noticed and approved or not noticed. Don't assume either way.
Imagine an easter egg in your car's navigation system.
No need to imagine it.. http://www.gpsinformation.org/dale/secret.htm
Personally I like it. It's a fun little touch
Having said that, putting an easter egg in there denotes some kind of love for the product. I like that.
My guess would be the reason small/new shops have deadlines like that is because they're more likely to have less experienced managers. If it bothers you that much perhaps you should work at a larger company where the managers understand nine women can't make a baby in one month.
Couldn't malware attempt to locate potential easter eggs in order to determine if they are in a honeypot?
No. This is a key combination against the UI. If the VM could send key combinations to the UI of the VMC then the software running on the VM could determine if it was in a "honeypot" (VM) with or without this easter-egg (e.g. send CTRL-ALT-INSERT and see if CTRL-ALT-DELETE is triggered within the VM's context, restart the VM, alter connected devices, and so on).
Also, yes, I think Easter Eggs are fine in a VMC. Particularly when they're only UI deep as is this case. The only software I wouldn't put easter eggs into is software which is "life-death critical" (aircraft control systems, industrial equipment, et al). But these kind of systems are sometimes designed to be mathematically proven safe with no possible conflating variables in the execution (so putting in easter eggs would be HUGELY expensive and likely wouldn't happen for that reason).
https://twitter.com/travisgoodspeed/status/50224961576974745...
[1]http://www.virtuallyghetto.com/2013/09/vmware-nested-easter-...
The virtualghetto.com article is referring to that second easter egg (i.e. the Pride mode) and telling you how to "unlock" it.
The post linked to here on HN is by M. Elizabeth Scott who created the Pong OS easter egg while at VMware.
A version of the code of the Pong OS can be found here: http://sourceforge.net/p/vmware-svga/git/ci/master/tree/exam...
From a cursory look, I don't think it has the Pride mode.
...are a rainbow, a symbol of gay pride[1].
i originally came across it here: https://twitter.com/scanlime/status/502239009595461632