• Aceticon@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    2
    ·
    edit-2
    9 hours ago

    Oh, man, yes.

    I’ve spent more of my career doing server-side stuff than other areas and it’s like night and day when it comes to IT security between server-side dev and gamedev, probably because server-side is networked and generally is done for much more important targets (valuable data and even actual financial assets of big companies, rather than an individual’s game state or machine) so there a big expectation that the best external attackers (and a veritable army of script kiddies) will be hammering at anything a server-side component exposes via a network interface, trying to hack it.

    Mind you, I still bitched and moaned at the lack of IT Security awareness of some of my colleagues when I was doing server side stuff :)

    • JustAnotherKay@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      9 hours ago

      And that’s exactly the thing, the threat model is so different. In gamedev, they’re thinking about those networking issues for sure but man oh man are they WAY more worried about RCE in those drivers you mentioned earlier.

      Why? For the same reason Emacs is a text editor, internet browser, and Spotify client. For the same reason that “will it run doom” is even a question. Because their game got hacked before they even opened the first text file to make the game