Question Is TLOPO genuinely not secure?

Status
Not open for further replies.

JessieTT

Honorable Pirate
Hello.

FIrst of all, I didn't know where to put this as I have not located a sub-set of forums for technical safety issues as regards to malicious software being in the game.

I've played TLOPO since beta keys were a thing, and to be fair, the team is comprised of novice coders and developers, so I never expected the game to be perfect. The first few times I launched TLOPO, my anti-virus flagged the execute file of the game when I would fill in my log in details and try to launch, however after manually reviewing the files on my own, I concluded that it was just my anti-virus being extra careful, and I allowed the files to run.

This has never really stopped, and frankly never really been an issue for me. I've always taken my computer security seriously, and every time that my anti-virus would flag these files I'd just allow them because they were benign.

Just today, however, I tried to log in to the game and I find this.
1586695697374.png

This is the first time where my anti-virus has flagged a file as actually being a credible threat (trojan, with the file itself being malware.) Before it just merely stated the files were suspicious / could be harmful. Keep in mind I regularly scan, defragment, virus scan, full scan, update windows, clean caches, do anything and everything to make my computer clean and safe.

I've put up with a lot of this from TLOPO over the years. I've played dozens of alpha phase games and get no warnings about potentially bad apples in the forms of files, and these games always run fine for me... but I'm not willing to play TLOPO anymore with there now seemingly being malicious software within the game.

To add onto all of this, there are reports from other players being keylogged on the TLOPO launcher that have been surfacing extremely recently.

It's not worth the risk to me to play, but the point of this thread is to ask if you are aware that this is in the game / execute file, and are you working on it? I don't want to have to stop playing, however every time I try to relaunch the game, the launcher tries to specifically re-download this file, and so every time I try to launch I have to disallow the file and so I cannot play as it seems to be in the execute file.

I hope this gets fixed, I've only brought this up recently because before it was just warnings of files that were harmless in the game, and I assumed my anti-virus was only flagged because, being frank, the people who develop this game are just not experienced coders, and it's understandable that loopholes are present, but recently (today) is when it has become a malicious problem.

Thanks.

EDIT: Just yesterday, I was very busy doing lawn work, and so while I was out, I set up my computer and did virus scans, full scans of all the files, I did an optimization after all of that, did Windows updates, updated chrome, cleared the cache, and now I get this flag from my anti virus, ONLY when I open TLOPO.
 
Last edited:
This is what's known as a false-positive.

What's occurring here is we do not have an official certificate signing the tlopo.exe download. So when the launcher downloads the game, your computer's anti-virus is confused what tlopo.exe is.

This never really occurred previously because before the Pypperoni update, when we updated the game we would update a file called "phase_1.mf" and rarely had to update tlopo.exe. So because tlopo.exe was largely unchanged, anti-virus software had the time to realize it was a legit file. Now, because we need to update tlopo.exe every single update, anti-virus software isn't able to catch up fast enough and realize it's legit.

A certificate would fix this issue. We are in the process of getting a certificate to sign the exe, after we do that this warning should never occur again.

In the meantime, click the "add to whitelist" button. As more people do that, eventually the anti-virus software will realize it's a legit file.
 
This is what's known as a false-positive.

What's occurring here is we do not have an official certificate signing the tlopo.exe download. So when the launcher downloads the game, your computer's anti-virus is confused what tlopo.exe is.

This never really occurred previously because before the Pypperoni update, when we updated the game we would update a file called "phase_1.mf" and rarely had to update tlopo.exe. So because tlopo.exe was largely unchanged, anti-virus software had the time to realize it was a legit file. Now, because we need to update tlopo.exe every single update, anti-virus software isn't able to catch up fast enough and realize it's legit.

A certificate would fix this issue. We are in the process of getting a certificate to sign the exe, after we do that this warning should never occur again.

In the meantime, click the "add to whitelist" button. As more people do that, eventually the anti-virus software will realize it's a legit file.
Thanks for the fast response. However I'm curious, if this has happened because the TLOPO exe file is now an unrecognised file as it is changed, why is the name of the false-positive trojan attack a malware gen? is that a coincidence or something?
 
Thanks for the fast response. However I'm curious, if this has happened because the TLOPO exe file is now an unrecognised file as it is changed, why is the name of the false-positive trojan attack a malware gen? is that a coincidence or something?
 
Thanks for the fast response. However I'm curious, if this has happened because the TLOPO exe file is now an unrecognised file as it is changed, why is the name of the false-positive trojan attack a malware gen? is that a coincidence or something?
That's just because of how that specific brand of anti-virus software works. I can't really give you a concrete answer without knowing what the anti-virus software is getting concerned about.

Every time we update the game, we recompile the game code into a new EXE. So each update is a brand new file that the anti-virus software has never "seen" before (even though it's like 99% the same). Anti-virus software, by design, is very paranoid. Thus, it triggers alerts the moment it is even the slightest concerned about something.

After we begin signing the EXE with a certificate, I feel like this issue will go away. Because at that point, the EXE will have a verified publisher associated with it -- which is an additional layer of accountability for the anti-virus that'll make it less paranoid.
 
That's just because of how that specific brand of anti-virus software works. I can't really give you a concrete answer without knowing what the anti-virus software is getting concerned about.

Every time we update the game, we recompile the game code into a new EXE. So each update is a brand new file that the anti-virus software has never "seen" before (even though it's like 99% the same). Anti-virus software, by design, is very paranoid. Thus, it triggers alerts the moment it is even the slightest concerned about something.

After we begin signing the EXE with a certificate, I feel like this issue will go away. Because now the EXE will have a verified publisher associated with it, which is an additional layer of accountability for the anti-virus that'll make it less paranoid.
Thanks for the response, I appreciate the help. I will test and see if my computer is still alive tomorrow :D you may lock this thread.
 
Status
Not open for further replies.
Back
Top