Minecraft modding platforms Curseforge and Bukkit compromised
Minecraft modding platforms Curseforge and Bukkit compromised
Oh wow, I haven't heard about Sandboxie in a long while. I tried using it years ago, but I didn't understand the documentation and gave up. Maybe I should try it out again sometime.
I personally like flatpaks, but sometimes even with Flatseal it's hard to figure out which permissions are needed for things to work. (For example, I tried making flatpak Calibre open PDFs using another flatpak program, but I never got that working.)
Sandboxing is always a good idea, but depending on what game you play, it might not help, unless you mean sandboxing the entire game.
Take World of Warcraft for example. I don't use any addon manager, I manually install addons tho I do download them from CurseForge.
They compromised the accounts of developers, so even if you don't use any app to manage your addons, you're still at risk because malicious code could be inside the addons themselves. WoW addons are not mentioned in this specific case, but they (potentially) are at risk as well, it wouldn't be the first time (not the last either).
Not sure it's possible to sandbox WoW addons, they're source code and they're compiled by the WoW client when loaded, you should sandbox the entirety of WoW but I have no idea what impact it has on the gaming experience, nor if it's feasible at all.
If sandboxing is not possible, better to avoid any update of any kind, until they fix the breach, and follow their instructions to check if you're affected and how to fix that.
unless you mean sandboxing the entire game
Sandboxie actually automatically opens any processes/dependencies the sandboxed app opens, under the same sandbox, so it should be fine. The entire game will be sandboxed. The game still runs smoothly on my machine regardless of the sandbox as well.
Curseforge with the malware again? It's not the first time I've heard this, suspect it's not the last. It seems that they specify Minecraft, which makes sense as it's a JAR game with all the vulnerabilities that brings, but could this potentially affect other games they host mods for?
At least we have Modrinth as a functional alternative in the meantime. Modrinth has been my first choice but it's still missing a lot of big-name projects.
I looked up on here and holy shit. Thankfully I installed on Flatpak so my filesystem should be unaffected(the app only has read only access to downloads).
Maybe this is a good moment to clear my PC from sensitive information xD
nix run.