[SOLVED] IMPORTANT: PC version vulnerability

+
@-PixelRick- Just wanted to thank you for creating your editor! Saved me from some pretty nasty bugs that one. GUI is nice and all, but I've always preferred being as close to the bare metal as possible. Live long and prosper!
Post automatically merged:

[...]
This launch and the events that happend afterwards, drive me personally more and more into resignation.
This comes from a quite frustrated and sad long term member of this community.

The old dogs are gone man. I feel your pain but that's how it always ends.
Either the youngsters learn to swim before they drown or we raise our glasses for a final salute and move on... The next couple of months will show.
 
mode = the cyber engine tweaks mod?

Yep it was the mode in question I had taken it on nexus to test but I quickly removed it because at home I was losing in graphics quality and fluidity, after I am on RTX 2060, I think on the other hand that for a card smaller graphic, this mode had to be better. Thank you for your answer. :)
 
I'm now just waiting for the patch to come, to end all this bad press. I love the game and will continue to dev tools for it.
I wish the world wasn't constantly waiting for any excuse to burn.

Then they should start that process in good faith.

Yet here we are, in a thread buried in the "PC" sub-forum of the tech section. If the vulnerability affects ALL platforms, wouldn't it be more sensible to PIN the announcement on the main tech forum for ALL to see, regardless of platform, rather than hoping it gets obscured among other threads? And where's the correction statement to take the heat off modders who are STILL getting the blame?

A simple Google search clearly shows what many people believe is to blame for this latest mess:


So how about starting there? Maybe pin this thread to the main tech forum, along with an HONEST and TRUTHFUL explanation of the vulnerability? Or is this how they intend to handle everything going forward? Pretend it's not a problem, or it's somehow someone else's fault?

Seems par for the course so far.....
 
Thank goodness that the modders have already fixed this issue, something that they shouldn't of had to do .. :shrug:
 
Last edited:
Thank goodness that the madders have already fixed this issue, something that they shouldn't of had to do .. :shrug:

Except it's not "fixed" for anyone who doesn't use Cyber Engine Tweaks as I understand it. Like ANY console user who uses downloaded cloud saves. Or PC users who download saves to skip some of the content or check out other endings rather than play through the whole game again. Not to mention the countless mods that don't require CET to run.

And according to the author of CET, the vulnerability is from a process the game engine runs in excess of 100 times. I don't think there's any "quick hotfix" that can eliminate something that deeply embedded into the game. If it were, you would think there would have been a hotfix within hours of it's discovery.

Have to wonder if they gave any notification at all to Microsoft and Sony so they could warn their customers.
 
Except it's not "fixed" for anyone who doesn't use Cyber Engine Tweaks as I understand it. Like ANY console user who uses downloaded cloud saves. Or PC users who download saves to skip some of the content or check out other endings rather than play through the whole game again. Not to mention the countless mods that don't require CET to run.

And according to the author of CET, the vulnerability is from a process the game engine runs in excess of 100 times. I don't think there's any "quick hotfix" that can eliminate something that deeply embedded into the game. If it were, you would think there would have been a hotfix within hours of it's discovery.

Have to wonder if they gave any notification at all to Microsoft and Sony so they could warn their customers.

Actually, I'm using the fixes, and some perks still break the game, but you have a hotkey to turn them on and off when that happens.

Also, this is the item list which is barely touched.. Updated today.
 
Knew there was a reason i never touch mods, spam mail, and Facebook adverts :)
Mods are fine if you see download counts and obviously new games are fresh targets for malware I don't plan on touching mods till like a year from now because I had a feeling it would be unsafe and I guess I was right

but a year from now I'll download all the top ones that seem worth it and have 10K plus downloads etc
 
Actually, I'm using the fixes, and some perks still break the game, but you have a hotkey to turn them on and off when that happens.

Also, this is the item list which is barely touched.. Updated today.

What fixes are you talking about? I'm talking about the security vulnerability fixes in CET, not fixes provided by other mods for stuff in the game that doesn't work.
 
Mods are fine if you see download counts and obviously new games are fresh targets for malware I don't plan on touching mods till like a year from now because I had a feeling it would be unsafe and I guess I was right

but a year from now I'll download all the top ones that seem worth it and have 10K plus downloads etc

XD Um, the exploits can be done to consoles which never use mods, so, you're not safe unless you play with the Cyber Engine Tweaks fixes, because CDPR hasn't touched the fix, we modders, did..
 

Ziffa

Forum regular
Mods are fine if you see download counts and obviously new games are fresh targets for malware I don't plan on touching mods till like a year from now because I had a feeling it would be unsafe and I guess I was right

but a year from now I'll download all the top ones that seem worth it and have 10K plus downloads etc

There was cases of mods uploaded on Nexus with malicious intent (keylogger).
While download counts most of the time is a sign of a trustworthy mod, like torrents votes, doesn't mean it's 100% safe.
 
I explained the issue with some details in the readme of my save editor project here:
https://github.com/PixelRick/CyberpunkSaveEditor/blob/main/README.md

I have put the proof of concept on github too but it is currently held private for the usual 45+ days of non-disclosure as half of the issue concerns a microsoft library.


I added a mini-comment in the readme to prove that yamasushi is indeed yamashi.
I want to apologise for passing by as a jerk and making fun of you guys, I have the utmost respect for what you are doing.
Keep up the good work 👍 (y)
 
the modders do in weeks what the company takes years to do. For Free. The modders actually listen to players and make stuff we want instead of totally ignoring us and saying they are listening. This is of course making CDPR look bad because instead of listening they want to ignore people. i'm seeing tons of stupid 1 line responses happy to jump on the modders for the issue when the modders found and warned them ages ago. it is literally the modders that saved every last pc playing person and they have the nerve to jump on them yeah this is what these people you are tryng to help are like so the next time there is an issue SAY NOTHING COVER YOUR PC TELL YOUR FRIENDS TO COVER THEIRS AND WATCH THE COMPANY BURN BECAUSE THEY ARE HAPPY TO THROW YOU ON THE FIRE FIRST.
 
Top Bottom