Mark Kraus's Avatar

Mark Kraus

@markekraus.com

I do code things with infra stuff and sometimes dabble in game dev things. I <3 Sunnyvale #csharp #powershell #devops #gamedev

278
Followers
431
Following
144
Posts
02.11.2023
Joined
Posts Following

Latest posts by Mark Kraus @markekraus.com

Just trying to make us both better, luv. <3

06.03.2026 19:31 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

If you had asked, "This isn't my area of expertise, but is this a possible security risk?" I wouldn't be coming on hot. I would have just answered your question.

06.03.2026 19:26 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

You didn't ask a question, though. You said, "I have some slight security concerns that could be mollified if it were open source." as a respected technologist with a platform.

06.03.2026 19:23 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0

You are free to believe whatever you want. But we should not be vibe scaring people.

06.03.2026 19:13 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

But they don't have to! It's literally not any different. The game can just do the bad stuff itself. the game code on disc can be manipulated out-of-process to be malicious... save-file injection is a risk for all games.

06.03.2026 19:11 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

No.. There really is 0 difference between this and any other game that, by necessity, needs to access files on your system and execute code within them. It just has the vibes of being less safe.

06.03.2026 19:08 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

The same concern exists with every game, though. This is not positioned any differently. They all need to read files from disks, including assets, libraries, and save files. They all have to process strings etc.

06.03.2026 19:07 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Are you worried about the player code injecting their own system???? Are you worried about another malicious piece of software launching the game and reaching a loot box to perform code injection??? You have already been successfully compromised before either of these scenarios.

06.03.2026 19:04 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

bad wording... instead of "worry about," I should say "impliment."

06.03.2026 18:49 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I can sympathize with a non-tehncial player being concerned. But you and I are technologists. We shouldn't add to their anxiety.

06.03.2026 18:47 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

If a game pops up a terminal, it's no less secure than a game that just does all its nefarious stuff directly in the game code without a terminal.
The developer doesn't need to worry about command injection... you are already running their code.

06.03.2026 18:46 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 3 ๐Ÿ“Œ 0

By focusing on a game that "looks" less secure based on vibes, you give a pass to all the other games. You draw undue scrutiny for a game that does nothing different from others.

06.03.2026 18:38 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 0

We don't base security posture on what "looks" less or more secure.

06.03.2026 18:35 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

This game has no increased risk over others. They all access your filesystem. A game without a folder gimmick doesn't mean it isn't scraping your hard drive for data.

Law #1: If a bad actor can persuade you to run their program on your computer, it's not solely your computer anymore.

06.03.2026 18:34 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

o_O Why would it be a particular security concern with this game and say... every game?

06.03.2026 17:10 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0
The Mario 64 intro scene with a letter from Princess Peach, reading:
Dear Mario. Please come to the castle. I'm down bad. Yours truly-- Princess Toadstool (Peach)

The Mario 64 intro scene with a letter from Princess Peach, reading: Dear Mario. Please come to the castle. I'm down bad. Yours truly-- Princess Toadstool (Peach)

CATS from the video game Zero Wing (the All Your Base Are Belong To Us game), saying: "I am Locutus of Borg. Resistance is Futile"

CATS from the video game Zero Wing (the All Your Base Are Belong To Us game), saying: "I am Locutus of Borg. Resistance is Futile"

Dracula from Castlevania: Symphony of the Night, saying to Richter "Get out of my house"

Dracula from Castlevania: Symphony of the Night, saying to Richter "Get out of my house"

The transportation advisor from SimCity 2000, saying "YOU CAN'T STAY ON TWITTER! YOU WILL REGRET THIS!"

The transportation advisor from SimCity 2000, saying "YOU CAN'T STAY ON TWITTER! YOU WILL REGRET THIS!"

My big project: The Death Generator.
It's a tool for making fake video game screenshots, just fill in new text and it'll give you a (generally) pixel-accurate image back, the correct fonts and everything.

deathgenerator.com

08.12.2024 07:17 ๐Ÿ‘ 22110 ๐Ÿ” 8544 ๐Ÿ’ฌ 1256 ๐Ÿ“Œ 3391

But what if that person is my emotional support politician, and I live my entire life by a team sports mentality and dogmatic tribalism? Surely I can defend them without repercussions!

04.03.2026 23:25 ๐Ÿ‘ 6 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

So yea... I subscribed to this labeler: bsky.app/profile/join..., then took a long browse through the Discover tab. Every bad lib take, or "orange man bad" meme, is coming from a Nov '24 account. Wild.

03.03.2026 21:04 ๐Ÿ‘ 1 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

Awesome. I kind of suspected it was some of that, especially with the election timing, but I'd never seen it actually articulated anywhere. Thank you for taking the time to explain!

03.03.2026 18:44 ๐Ÿ‘ 10 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

I guess now we will have to stop calling them Spanish Flies and start calling them Freedom Flies.

03.03.2026 17:47 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I have seen multiple people call out the Nov '24 join date as a thing, but I don't know the reason. Can someone enlighten me as to why so many of these accounts suck?

03.03.2026 17:30 ๐Ÿ‘ 7 ๐Ÿ” 0 ๐Ÿ’ฌ 2 ๐Ÿ“Œ 1
Epstein, Me Too, and the Justice We Never Got (ft. Lyz Lenz)
Epstein, Me Too, and the Justice We Never Got (ft. Lyz Lenz) YouTube video by Cancel Me, Daddy

You're not going to want to miss this important discussion with @lyz.bsky.social about the Epstein survivors' struggle for justice. It is one of the most important episodes we've ever recorded.

Now out only on YouTube. Tomorrow morning everywhere else.

youtu.be/UjDdFwgIdAU

25.02.2026 21:54 ๐Ÿ‘ 33 ๐Ÿ” 22 ๐Ÿ’ฌ 3 ๐Ÿ“Œ 3

I'll go with ไธƒไบบใฎไพ (1954) (Seven Samurai)

25.02.2026 00:25 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0
Video thumbnail

This guy gets it.

23.02.2026 20:42 ๐Ÿ‘ 23660 ๐Ÿ” 5747 ๐Ÿ’ฌ 453 ๐Ÿ“Œ 805

The Shadowban labeler bsky.app/profile/did:...

22.02.2026 21:32 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I'm begging news outlets to include at least the name of cases when quoting decisions/orders/etc. Ideally, also include the case ID and courtlistener link if available. I really dislike having to sleuth my way to the source when it is public and accessible.

20.02.2026 22:25 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

That's just lame. I'm not extremely well-read on Marxism, but when I read Lenin's "Imperialism, the Highest Stage of Capitalism" I was constantly blown away by how much of what he was describing back then was still so painfully relevant now.

13.02.2026 22:09 ๐Ÿ‘ 17 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

I used "botty" as a shorthand for that, and it was a poor choice of words.

13.02.2026 17:01 ๐Ÿ‘ 0 ๐Ÿ” 0 ๐Ÿ’ฌ 0 ๐Ÿ“Œ 0

I should say that it doesn't seem organic. Whether it's bots, coordination, foreign influnce, right-wing psy op... whatever. It just has the stench of not being a bunch of people with deeply held beliefs, organically finding these conversations to insert themselves into.

13.02.2026 17:00 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0

Oh... I mean, there are definitely some real people in the mix.. and I wasn't making a claim about this specific individual. But I've seen pile-ons happen to accounts with fewer than 50 followers. If it's not bots, then it's at least coordinated.

13.02.2026 16:55 ๐Ÿ‘ 2 ๐Ÿ” 0 ๐Ÿ’ฌ 1 ๐Ÿ“Œ 0