#Issue Resolved
1 messages · Page 1 of 1 (latest)
This addon is very heavily obfuscated. Your reasoning "it's to prevent spammers" makes no real sense, since as you acknowledge in a steam comment on the dependency:
Thanks, the obfuscation is to prevent spammers from reading it, but it didn't work for long.
If the obfuscation didn't work as you say, remove it. It serves literally no purpose
Atleast it will stop some people
But it'll remain like that, you can check for malicious code if you want to there's none
Security by obscurity is just inherently flawed
Would you provide a deobfuscated version or are you expecting anyone wishing to audit the addon to manually deobfuscate it?
Sure
To you?
Sounds good
But the GIC is also obfuscated, at first it wasn't but now yes, and there's no backdoors
But you know what, I'll unobfuscate it
the steam workshop version of GIC doesn't seem to be
Yes it does
I'm at work currently (waiting for someone else so im not just slacking too bad) so I had to get someone else to send me the extracted version lol, but it doesn't seem to be obfuscated
it doesnt look bad except from the fact that it uses HTTP connections and doesn't seem to actually have any validation / authentication for sent messages
why would you have the clients send the messages and not the server?
Because It's rudimentary
It's POST requests
After I updated it, can you remove this channel? Thanks, I don't want people thinking I do backdoors
Check POST request the addon does and you'll see
If the obfuscation is removed then yeah sure
done
ur high or something? Obfuscation it's always the answer smh
jokes aside, i always would liked to do something like this, but realistically people will just find a way to ruin it
well I don't really have any other choice and it's too late
but I'll repost the addon when the
be done
looks good man, thanks for updating
I don't think I can delete the thread unless im dumb, so ill rename it
Issue Resolved
k thanks
also just to make sure
i meant you're using HTTP instead of HTTPS (insecure), I should've worded it better
its not terrible since you're not really sending any sensitive data really but its something you should maybe look into
00qzMprY8XsjaX7 here's a code for marvel snap, you earned it 🫰
free host, no choice
I already know that, but if you see flaws, it's that I don't have the choice