16 comments

  • client4 a day ago ago

    This talk was a hit at Districtcon's junkyard talks -- outstanding work; and hilarious to see Doom inside of C&C.

  • joe_mamba a day ago ago

    >After initial discovery and creation of the PoCs, we reached out to EA Games in August 2025 to report these issues. EA was helpful but confirmed that the issues were not within scope of their support.

    Man, I gotta respect the balls on the author for reaching out to EA, and with a straight face, expecting them to push a bug fix for a ~23 year old game. Someone at EA who got the email probably got a chuckle out of it.

    Also happy to see this classic RTS is still being played and even developed by the community. I'd be curious to know what the age of people this invested into the game is, if it's all 30+ year old boomers with nostalgia and knee pain, or if Generals also found its way to the current generation of players. "Can I have some shoes?"

    • charcircuit a day ago ago

      https://store.steampowered.com/app/2229870/Command__Conquer_...

      They are still selling it. Selling games you know have such dangerous security issues is not good.

      • joe_mamba 20 hours ago ago

        >They are still selling it.

        Good, very good! Better to still be able to own it legally in its original form, even if it's not been updated. Because otherwise the alternative for most people would be downloading it from some shady piracy site which would be even more risky.

        > Selling games you know have such dangerous security issues is not good.

        I assume in the EULA they are selling it "AS IS", so the risks are up to you, especially given that the game does not run on modern OSs out of the box so it's not like your average grandma is gonna get hacked from this. It's a niche product for enthusiasts and tinkerers at this point. Is ID software also pushing security fixes to Doom so you don't get hacked from running a 30 year old piece of SW?

        • charcircuit 18 hours ago ago

          I don't care if it's legal or not. It's unresponsible behavior. At the very minimum they should be adding a disclaimer for the danger of using the software.

          • joe_mamba 18 hours ago ago

            OK, let's have the game removed from storefronts so nobody can have it, this way we're keeping the 38 playerbase safe from a potential exploit for malware that doesn't exist in the wild of a 23 year old game.

            Better now?

    • skhr0680 a day ago ago

      > Also happy to see this classic RTS is still being played and even developed by the community. I'd be curious to know what the age of people this invested into the game is, if it's all 30+ year old boomers with nostalgia and knee pain

      There's enough of a community to support a yearly World Series with $25K cash awards in 2025!

      • joe_mamba 19 hours ago ago

        IIRC 25k is not that much by major e-sports standard of today. Do you know if they're playing the original gold release of the game or some modded variant?

        • skhr0680 7 hours ago ago

          It’s not too shabby for an abandoned 20+ year old game

          The source code release changes everything, but they used to play on a mod (GenTool) with the ruleset from the final retail release.

          The current meta is almost balanced so most attempts to improve it generally fail

    • protocolture a day ago ago

      They have a tendency to rerelease the full stack every few years.

    • ajsnigrutin a day ago ago

      It would be a lot more cool if they actually fixed it and showed how they care about their customers even if the games are very old.. it's good PR, compared to eg. the most downvoted reddit comment ever.

      • joe_mamba 20 hours ago ago

        >It would be a lot more cool if they actually fixed it

        Damned if you do, damned if you don't. Getting hate for stuff like this is why most games companies will just say 'fuck it', and not bother releasing classic games to the public anymore, let alone their source code, if the bar they now have to clear is to also actively supporting their classic games for which their OG devs lave long retired from the company.

        How many games companies are actively patching their 23 year old games?

        Unlike other people, I don't let perfect be the enemy of good, and I appreciate them giving us the source code, that's already more than most game companies do. The community can take it from there.

  • hexasquid a day ago ago

    Atredis has detected wormsign

  • OsamaJaber a day ago ago

    Surprised it took this long for someone to write it up properly