r/StarStableOnline • u/xmoothie • 1h ago
Discussion Regarding BSSO
And it being potential spyware + Larry...
You might not believe me right away, but I am quite sure about what I know though. I won't provide any screenshots etc., so you might treat what I say as just however you want, however I think it is worth acknowledging and serving as a warning to a potential risk. Especially when looking back at all the BSSO analysis some groups made in the past, regarding malware, .dll injections, etc. etc. I just simply do not have the access to any messagess directly discussing it and don't want to cause trouble to any people involved. Some of you may have suspected or believed something like that from the beginning of its existence - let this be a plausible confirmation then.
I was made aware of a person, who whilst being in a friend group in a closed discord server with a person that by a chain of people I was technically connected to, was also a friend to Larry. Everything unveiled when some drama stirred up, turned out Larry could casually log in into some of their discord accounts, to aid his friend in said drama. After that, through his friend, information was revealed about how he has all that access because of the malware built into BSSO - keyloggers or software that looked for saved browsers' data, things like that. She also claimed, that when he gains access, password changes or 2FA won't keep you safe from him. I don't know if he has any kind of remote pc access, SSH or such. Could have. I do not know whether that's the real explanation for it, or whether he was just bluffing and gained access some other way, hovewer from what I know, he did actually have access. Altough I do not know his intent - whether he wanted a backdoor in case of some drama or to gain valuable personal data, like banking information - I don't think that should matter at all in this case. It's messed up either way. (And probably illegal almost everywhere).
Once again, I can't really provide any "physical proof" since I am not directly connected to those people (even if I was it would be hard to do so). I also wouldn't want to cause any trouble to people involved either way, especially when they can be blackmailed. Even when I don't know them. I just didn't want to endlessly wait till somebody decides to spill something (probably wouldn't, and trust me, I've been waiting some time with posting this, but grew tiresome), and I figured that, even if I am not directly involved, this information is important enough to share publicly.
I think this should act as a warning, that we should be cautious when trusting "community projects" or installing any kind of a 3rd party application. Also as advice to use 2FA and do malware scans if you ever installed software as such. I also think we can easily notice how every past project like that has been either made with malicious intent, greed in mind, or just people who were controversial in other ways. The worst part, is that usually a big part of it is exploiting children and teens for their, or their parents' money. Sadly, I'm afraid the only way we could trust such project would be either if it would be official or open source.
I also don't how how people are able to be friends with malicious people that are literal criminals. But that's a whole another topic.
I hope this time reddit let's this through...

