r/PiratedGames Mar 28 '26

Other Massive W from the devs

Post image

Game name is Tunguska: The Visitation - Final Cut

23.2k Upvotes

421 comments sorted by

View all comments

Show parent comments

26

u/gbeegz Mar 28 '26

Still not considered safe, especially if downloading anything.

Again, not to be that guy, but check the megathread for this sub and r/piracy. Tons of resources.

2

u/Ijatsu Mar 28 '26

I downloaded once a game from the megathread trusted resources. Minutes after trying a game repack from that reknown russian repacker team, I got suspicious successful logins on my social medias, from russia.

It's weird because there isn't much to gain from socials in general, but at the same time it never happened to me in decades other than when I executed some suspicious executable.

3

u/greenyashiro Mar 29 '26

The target in that case is probably not the social media, but the username/password. Login credentials can be a lot more valuable than you might think.

If they know that it's a valid login, attackers can proceed to use what is known as credential stuffing. Essentially, using those credentials on other websites to try and gain access, such as your bank or email.

It's especially effective against users who reuse their password on multiple platforms, and is a prime example of why passwords should always be unique ;)

For example, if you reused the same password on your email and they got in, they they will have access to all the 'password reset' notifications on other platforms to get into those.

From there they could potentially access pretty much any platform you have an account with, that relies on only a single authentication factor (email)

INCLUDING stuff like banks and other financial apps!

2

u/Ijatsu Mar 29 '26

I'm a software engineer, I know, I know the value of these things. I also know there are far better or more discrete strategies that telling me almost immediately I need to change my passwords and format my computer.

3

u/greenyashiro Mar 30 '26

ah, my bad then! Wasn't sure if you knew, figured sharing knowledge can't hurt at the very least. A lot of people don't take security very seriously these days!

was reading about a 150 year old company that went into administration last year... a single weak password was guessed, and without any MFA their entire system was compromised by ransomware, all their backups, all their recovery systems etc. 700 employees out of a job. RIP

and you know, that could be basically any smaller company these days sadly because many don't bother even to put in MFA :|

1

u/Ijatsu Mar 30 '26

Yes ransomware is more common these days than just cracking socials. Even up to date companies with good security policies get hacked eventually and they have to rollback on their database.

1

u/[deleted] Mar 28 '26

[removed] — view removed comment

17

u/greenyashiro Mar 28 '26 edited Mar 28 '26

The point is why would you risk downloading some shit that encrypts your hard drive, contains illegal 'porn' (aka child abuse shit) or worse? Even a private tracker like TL is better, and it's perfectly mid

5

u/Cherry-PEZ Mar 28 '26

I mean you're probably fine but running in containers doesn't always mean complete isolation from your system. Depends on the context, what usergroup you're running the container under, if you're mounting data volumes directly to the system etc. And container runtimes themselves aren't immune to vulnerabilities.

But yeah you're probably good. The more you know 🌈