Stories
Slash Boxes
Comments

SoylentNews is people

Submission Preview

Link to Story

Valve Confirms Code Leak for Two Online Games [Updated]

Accepted submission by upstart at 2020-04-24 22:42:14
News

████ # This file was generated bot-o-matically! Edit at your own risk. ████

Valve confirms code leak for two online games [Updated] [arstechnica.com]:

A major source code leak for Valve's biggest competitive PC multiplayer games—Counter-Strike: Global Offensive and Team Fortress 2 [arstechnica.com]—began making the rounds [reddit.com] late Tuesday. Amid worries that this code leak for active online games would lead to hackers finding exploits and developing remote code executions (RCEs), Valve issued a statement on Wednesday that such worries were moot.

There's a catch, however. In an emailed statement to Ars Technica about the nature of the leak, Valve only offered a statement about CS:GO:

We have reviewed the leaked code and believe it to be a reposting of a limited CS:GO engine code depot released to partners in late 2017, and originally leaked in 2018. From this review, we have not found any reason for players to be alarmed or avoid the current builds (as always, playing on the official servers is recommended for greatest security). We will continue to investigate the situation and will update news outlets and players if we find anything to prove otherwise. In the meantime, if anyone has more information about the leak, the Valve security page (https://www.valvesoftware.com/en/security) describes how best to report that information.

(To clarify: Valve's Source Engine emerged in 2004 as the framework for a different version of Counter-Strike. Before Valve launched any games with that engine, its source code leaked [arstechnica.com]. This week's news is about an entirely different leak, which Valve claims first took place in 2018.)

Valve's representatives did not answer our questions about the lack of TF2 in this statement—or whether existing TF2 players should be concerned or change their play patterns in any way. In terms of Valve's official social media channels, its official @csgo account posted the above statement on Wednesday as a thread [twitter.com], while the official @teamfortress [twitter.com] account hasn't posted an update since August 2019.

Thanks to this vacuum of official word on TF2's state, fans are left to refer to panicky responses from major voices in the TF2 community. In particular, two popular community-run server hubs, Redsun.tf and Creators.tf [twitter.com], have temporarily shut down their operations due to "the uncertainty surrounding security of our infrastructure, as well as a potential for damage to be caused to your computer." In Redsun's case, a widely circulated comment from one of its moderators [imgur.com] says that their team is waiting for "Valve [to] give us the clear" before resuming operations.

Valve could go a long way toward dispelling fears by speaking directly to the leaked code's references to TF2. Valve's Source Engine base breaks into various branches, and while this leaked branch is, as Valve describes, a CS:GO code depot, it includes references to TF2—which one Ars Technica source claims dates back to a 2011 build of TF2. Whether that dated TF2-specific code could be exploited for the sake of RCEs in the current build of TF2 is unclear.

By Wednesday evening, online chatter about possible live TF2 exploits came and went without apparent proof of anything in the wild. This prompted Garry's Mod creator Garry Newman to cast doubt on any major vulnerability in the root Source engine [twitter.com]—which would affect his popular mod—and asked fans to reach out if they learned of any major vulnerabilities or exploits.

In the meantime, the best bet for interested TF2 players is to operate with an abundance of caution and keep your eyes tuned to server hubs like the ones mentioned above. Until those fans are ready to resume TF2's hotly contested Payload matches, you should probably look elsewhere.

Update, April 24: Late Wednesday evening, Valve's Team Fortress social media channel posted an update about the 2018 code leak [twitter.com], and it reads nearly identically to the one seen on its CS:GO account. It reads in part: "From our review, we have not found any reason for TF2 players to be alarmed or avoid the current builds (as always, playing on the official servers is recommended for greatest security)." The tweet does not offer clarity about which portions of the 2018 code leak were TF2-specific, nor whether they were as old and potentially deprecated as we hinted in our original report.

After this official update, the operators at TF2 hub Creators.tf turned their services back on and advised fans to return [twitter.com].

&larr Previous story [arstechnica.com]Next story &rarr [arstechnica.com]


Original Submission