Live data from Hacker News

CD Projekt Red has been subject to a cyber attack and ransom demand

twitter.com

21–30 of 252 posts

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#21
post #9

Now the 2077 source is public, can we crowdsource the bug fixes?

If the code is released then CDPR could obtain it as well. So why pay the ransom? The threat in a hostage situation is not “give me money or I release a hostage.”

But selling or leaking the source code is exactly the threat used in the email as seen in the screenshot image on the linked the Twitter post.

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#23
post #15
post #5

Earlier quoted context omitted.

It's not a given that the hacker will even release the source code. With the ransom threat rebuffed publicly, they might not be bothered to actually distribute the files, or they might choose to keep them privately for bragging rights. And then it's entirely possible the source code might not be in a compilable state without lots of work. But the biggest problems are the copyright issues. CDPR will be well within the…

> publishing unofficial builds of the source code You could patch installed files and/or at runtime, no? With patches being wholly original work? I'm not actually sure how IP law works for something like that.

Presumably antything based in stolen IP is tainted.

Not an exact analogy, but if you translate a copyrighted piece of work, you own the copyright to the translation, but cannot e.g. publish that without the original work’s copyright holder’s consent.

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#24
post #16

The note makes it seem like the attackers got access to their internal network; but the (admittedly little) information I have on the subject indicates that the perforce server was hosted on the internet with username/password access (not cert based authentication as is recommended by Helix these days). I suppose the IT team got overwhelmed with requests to open up the firewall for people working from home during the…

This may be a stupid question, but isn't it standard practice to require that employees use VPN? Why would they expose servers to the internet?

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#25
post #16

The note makes it seem like the attackers got access to their internal network; but the (admittedly little) information I have on the subject indicates that the perforce server was hosted on the internet with username/password access (not cert based authentication as is recommended by Helix these days). I suppose the IT team got overwhelmed with requests to open up the firewall for people working from home during the…

Sorry. What year is it?

Must be somewhere in the 1990s since you've mentioned perforce multiple times.

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#26
post #25
post #16

The note makes it seem like the attackers got access to their internal network; but the (admittedly little) information I have on the subject indicates that the perforce server was hosted on the internet with username/password access (not cert based authentication as is recommended by Helix these days). I suppose the IT team got overwhelmed with requests to open up the firewall for people working from home during the…

Sorry. What year is it? Must be somewhere in the 1990s since you've mentioned perforce multiple times.

I've been told that a lot of game development uses Perforce as it handles large media assets quite well.

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#27
post #25
post #16

The note makes it seem like the attackers got access to their internal network; but the (admittedly little) information I have on the subject indicates that the perforce server was hosted on the internet with username/password access (not cert based authentication as is recommended by Helix these days). I suppose the IT team got overwhelmed with requests to open up the firewall for people working from home during the…

Sorry. What year is it? Must be somewhere in the 1990s since you've mentioned perforce multiple times.

Perforce is an excellent source control system if you can afford it, much better than Git for centralized repos (i.e. most companies).

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#28
post #24
post #16

The note makes it seem like the attackers got access to their internal network; but the (admittedly little) information I have on the subject indicates that the perforce server was hosted on the internet with username/password access (not cert based authentication as is recommended by Helix these days). I suppose the IT team got overwhelmed with requests to open up the firewall for people working from home during the…

This may be a stupid question, but isn't it standard practice to require that employees use VPN? Why would they expose servers to the internet?

An employee could have got hacked, or defected

They’re the ones getting screwed over the most here imo

Re: CD Projekt Red has been subject to a cyber attack and ransom demand

#30
post #6

Now the 2077 source is public, can we crowdsource the bug fixes?

I had one "I need to reload the game or else it won't work"-type of bug in 100 hours of gameplay. I have seen games that have been much much worse 4 years after the release than this game in it's current state.

played 80 hours PC version, only crash was on the release version, about 10 minutes in. after that it was solid. not enough meat in the main story, but pretty excellent otherwise.
Post reply on HN