Fabien Chebel, an editor for the French gaming site, Vossey.com, has brought to our attention that a backdoor may have been purposely left in to recent builds of the Insurgency Mod. The allegations of this issue arose some weeks ago when one of the mod's developers was able to kick another player on a public server. The developer allegedly had no admin access and did not have the server's rcon password.
Subsequent complaints on the matter to the Insurgency Mod team went ignored and were ultimately deleted. A short while after, the mod's project lead, "Dr. Spielmann" issued the following statement.
The developer backdoor is slated to be removed "in the following weeks." In case anybody has caught wind of this issue, we felt compelled to share the story with you to reassure you that nothing malicious will happen on your server. Well, nothing malicious will happen on your server provided the mod's developers play nice.
We'd like to give a special thanks to Fabien "heffebaycay" Chebel and the Vossey.com site for bringing this to our attention. The original story and letter from Dr. Spielmann can be found at NoFrag.
Please note that without this appearing on an all-English website, it is hard to confirm or validate some of these claims. As such, we have taken the precaution of tagging this as a potential rumor.
Subsequent complaints on the matter to the Insurgency Mod team went ignored and were ultimately deleted. A short while after, the mod's project lead, "Dr. Spielmann" issued the following statement.
However, as a consequence there's been some public discussion regarding the existence of « backdoors » in our mod. We believe that the issue has been artificially magnified and taken out of context, causing unnecessary alarm among a few communities of INS players. There is no malicious code of any kind in Insurgency.
What is still present in the code, as this is a non-commercial and non-profit project in beta stage, are some debug, development and testing tools that can be used by the developers of the mod to work in the game. Our tools only allow registered developers to execute code that has been approved and accepted by all of you when using Source-engine related software, such as rcon commands.
When addressing malicious attacks in the past we have been repeatedly asked by server admins to implement anti-cheating measures. To work on those measures we have also had the need in the past to exceptionally execute rcon commands such as kicking a player from a server, particularly in servers without server admins, test servers or promotional servers (such as the ones we've grown used to setting up for free for our community when releasing major updates). That's the only reason why those tools are present.
We are convinced that this policy has enabled you to have a better online experience until now. However, we are ready to revise it and change / remove some of its functionality.(...)
While we still believe the tools are useful for that purpose, it's true that they have been incorrectly used in this particular case, so we have decided to remove them in the next update scheduled for mid-August. From now on we will fully and exclusively rely on server administrators to execute those commands and keep their servers free from exploits, aggressive behavior, racist insults or well-known cheaters.
What is still present in the code, as this is a non-commercial and non-profit project in beta stage, are some debug, development and testing tools that can be used by the developers of the mod to work in the game. Our tools only allow registered developers to execute code that has been approved and accepted by all of you when using Source-engine related software, such as rcon commands.
When addressing malicious attacks in the past we have been repeatedly asked by server admins to implement anti-cheating measures. To work on those measures we have also had the need in the past to exceptionally execute rcon commands such as kicking a player from a server, particularly in servers without server admins, test servers or promotional servers (such as the ones we've grown used to setting up for free for our community when releasing major updates). That's the only reason why those tools are present.
We are convinced that this policy has enabled you to have a better online experience until now. However, we are ready to revise it and change / remove some of its functionality.(...)
While we still believe the tools are useful for that purpose, it's true that they have been incorrectly used in this particular case, so we have decided to remove them in the next update scheduled for mid-August. From now on we will fully and exclusively rely on server administrators to execute those commands and keep their servers free from exploits, aggressive behavior, racist insults or well-known cheaters.
The developer backdoor is slated to be removed "in the following weeks." In case anybody has caught wind of this issue, we felt compelled to share the story with you to reassure you that nothing malicious will happen on your server. Well, nothing malicious will happen on your server provided the mod's developers play nice.
We'd like to give a special thanks to Fabien "heffebaycay" Chebel and the Vossey.com site for bringing this to our attention. The original story and letter from Dr. Spielmann can be found at NoFrag.
Please note that without this appearing on an all-English website, it is hard to confirm or validate some of these claims. As such, we have taken the precaution of tagging this as a potential rumor.
Comment