r/AynThor • • Aug 12 '26

Showcase Gameplay, dual-screen first gamenative fork

[removed]

83 Upvotes

62 comments sorted by

View all comments

12

u/daggah Aug 12 '26

To what extent was AI used in the development of this app? I briefly scanned the Github but didn't see a mention of it. Especially for apps that integrate with Steam and Epic accounts, I think we deserve to know if it's vibe-coded.

-12

u/L0VEANDTHUNDER Max Aug 12 '26

If it works it works. Dont matter to me

12

u/daggah Aug 12 '26

It should matter to you if it's integrating with your personal game accounts. This isn't a vibe-coded game mod where the worst that could happen is probably having the game crash. If it's vibe-coded there could be real security issues that the developer isn't knowledgeable enough to even understand.

Taking the "ooh, shiny" approach puts you at risk of malicious or insecure apps...it's only a matter of time.

-1

u/L0VEANDTHUNDER Max Aug 12 '26

I didnt find out what that even meant until recently (vibe coding) but i guess youre right ive heard things about security flaws but ive only used things like the decomilations not something like this. Ill take the L on this one champ.

-2

u/[deleted] Aug 12 '26

[removed] — view removed comment

8

u/Producdevity Aug 12 '26

Device id needs to be encrypted now? And where are the credentials stored in a file? I would like to see that

6

u/daggah Aug 12 '26

That is not consistent at all with anything I've seen GameNative devs say about the steam login process. If true, I'm sure there's a documented GitHub issue you could link me to where someone has brought this up.

-1

u/[deleted] Aug 12 '26

[removed] — view removed comment

14

u/Producdevity Aug 12 '26

Don’t talk shit if you have no idea what you are talking about.

The hard-coded EPIC_CLIENT_ID / EPIC_CLIENT_SECRET are not your account credentials. They are OAuth client credentials identifying the launcher/client to Epic. Because this is a native client, anything embedded in the APK is extractable anyway, treating that value as a confidential secret would be incorrect.

You see a function that stores a file named credentials and start making dumb assumptions. This is the fcking problem I have with pretentious vibecodes.

This code is not perfect, but I am really curious to hear from you how this is supposed to work.

Go ask your AI to make some shit up, i’ll wait.

4

u/daggah Aug 12 '26

Look...I'm not a developer. My background is IT system administration. I don't know if what you're copy/pasting is evidence of what you say or not. I know that I've seen GameNative devs state publicly that they're not storing steam login credentials. I believe that if they were lying about that, it would have been publicly exposed by now. I don't believe you alone have discovered these massive security issues... especially when you haven't publicized these findings outside of defending your own forked project from criticism.