This week’s raging controversy involves the premature release of source code to a hotly anticipated game into the wild by an unknown cracker. The game, of course, is Half-Life 2, and its developer, Valve. Well, it seems that Valve has sprung a leak, so to speak…
See this statement from chairperson Gabe Newell. Apparently, the attacker(s) used a custom-written trojan to infiltrate development machines at Valve HQ, gaining access to the coveted source code without their knowing.
Around 9/19 someone made a copy of the HL-2 source tree. […]
At some point, keystroke recorders got installed on several machines at Valve. Our speculation is that these were done via a buffer overflow in Outlook’s preview pane. This recorder is apparently a customized version of RemoteAnywhere created to infect Valve (at least it hasn’t been seen anywhere else, and isn’t detected by normal virus scanning tools).
[…] Well, this sucks.
This is any game developer’s worst nightmare, but the impact is likely to be limited. It seems unlikely to ruin the game or reduce demand. Paradoxically, it may even increase game/engine sales, and might lead to better code security by the time of launch.