Live data from Hacker News

CD Projekt Red has been subject to a cyber attack and ransom demand

twitter.com

11–20 of 252 posts

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#11
post #6

Now the 2077 source is public, can we crowdsource the bug fixes?

I had one "I need to reload the game or else it won't work"-type of bug in 100 hours of gameplay. I have seen games that have been much much worse 4 years after the release than this game in it's current state.

Most of the complaints were related to older console version (PS4, Xbox One). PC bugs were mostly solved rather quickly.

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#13
post #6

Now the 2077 source is public, can we crowdsource the bug fixes?

I had one "I need to reload the game or else it won't work"-type of bug in 100 hours of gameplay. I have seen games that have been much much worse 4 years after the release than this game in it's current state.

On PC, I had softlocks, hardlocks, being catapulted at the other side of the map after climbing up a pile of trash, T-posing enemies with disabled AI, dead bodies talking, and plenty, plenty more. Neither your experience or mine is more valid, simply that "it did/didn't happen to me" isn't a good defense.

Additionally, Cyberpunk is also being shat on for lacking mechanics or half-assing them. Cops being the more obvious one, or the complete lack of driving AIs.

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#14

Now the 2077 source is public, can we crowdsource the bug fixes?

I heard it was better already, like key issues addressed

The game doesn't crash that much on PCs and recent consoles. It is unplayable on base PS4 and Xbox One. They manage to add in softlocks in the main story with bugfix patches though. But even then, it remains a very average game.

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#15
post #5

Now the 2077 source is public, can we crowdsource the bug fixes?

It's not a given that the hacker will even release the source code. With the ransom threat rebuffed publicly, they might not be bothered to actually distribute the files, or they might choose to keep them privately for bragging rights. And then it's entirely possible the source code might not be in a compilable state without lots of work. But the biggest problems are the copyright issues. CDPR will be well within the…

> publishing unofficial builds of the source code

You could patch installed files and/or at runtime, no? With patches being wholly original work?

I'm not actually sure how IP law works for something like that.

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#16
The note makes it seem like the attackers got access to their internal network; but the (admittedly little) information I have on the subject indicates that the perforce server was hosted on the internet with username/password access (not cert based authentication as is recommended by Helix these days).

I suppose the IT team got overwhelmed with requests to open up the firewall for people working from home during the pandemic and just opened it for the whole internet.

CI runners (usually Jenkins) require a perforce user to function and those users often have very simple passwords, this is compounded by the fact that perforce itself does not have any backoff for brute force attempts.

Perforce assumes that it's being hosted in a secure environment.

The note indicates HR documents were stolen, but I have not seen any evidence of that, it is most likely posturing.

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#18
post #9

Now the 2077 source is public, can we crowdsource the bug fixes?

If the code is released then CDPR could obtain it as well. So why pay the ransom? The threat in a hostage situation is not “give me money or I release a hostage.”

They do say in the ransom note that "we understand you can most likely recover from backups", so it seems the encryption was expected to be nothing more than an inconvenience, and the extortion of releasing their documents and source trees publicly is the main ransom subject, not denying them access.
Post reply on HN