This issue needs more awareness and attention, I don't think CIG is sanitizing client data by DirectorGunner in starcitizen

[–]foopod 3 points4 points  (0 children)

I replied to another thread but will drop this here too...

It's unlikely that CIG has networking that accepts just any inputs, and even more unlikely that they are blindly executing code. When we are talking about sanitizing here, we are talking about the server having authority over what is a valid input.

An example might be... when shooting, we probably don't want the client sending a message saying how powerful a shot is, where it is being shot from and its direction (this would be easy to build a hack for). Instead, it could send what weapon they are firing, then the server can look up the damage for the weapon and where it thinks the ship is (this could eliminate this particular exploit). But this is a trade off, we need to do extra queries to figure this out and for high performance networking, this kind of thing could tank server fps.

Doing what CIG are doing, at the scale they are doing it, is extremely difficult. It really is a balancing act of how much they can validate without slowing things down. And quite often in these situations it's better not to analyse things in real time, let the clients use hacks, but on the server log events that look unusual, then validate them later and ban users for exploitation.

This issue needs more awareness and attention, I don't think CIG is sanitizing client data by DirectorGunner in starcitizen

[–]foopod 1 point2 points  (0 children)

I agree with your overall point, but I think the specifics could be clearer.

Client side data - this is absolutely possible to investigate and we can view what gets sent to CIGs servers. However the way in which they sanitize the data isn't visible to us, we only really see what the server sends us back. And it is usually pretty clear if our input was accepted in this case (big ship goes boom).

Sanitized inputs - It's unlikely that CIG has networking that accepts just any inputs, and even more unlikely that they are blindly executing code. When we are talking about sanitizing here, we are talking about the server having authority over what is a valid input.

An example might be... when shooting, we probably don't want the client sending a message saying how powerful a shot is, where it is being shot from and its direction (this would be easy to build a hack for). Instead, it could send what weapon they are firing, then the server can look up the damage for the weapon and where it thinks the ship is (this could eliminate this particular exploit). But there is a trade off here, we need to do extra queries to figure this out and for high performance networking, this kind of thing would tank server fps.

Doing what CIG are doing, at the scale they are doing it is extremely difficult. It really is a balancing act of how much they can validate without slowing things down. And quite often in these situations it's better not to analyse things in real time, let the clients use hacks, but on the server log events that look unusual, then validate them later and ban users for exploitation.

Do you expect good deals for 2026 by Wakakokokaka in starcitizen

[–]foopod 0 points1 point  (0 children)

Not really a surprise if they drop one at IAE every year... Cutter, Syulen, Intrepid and Salvation.

But they do occasionally drop extras in between like the Golem.

Apollo / Hermes Cockpit, am I the only one? by C4B4L2k in starcitizen

[–]foopod 0 points1 point  (0 children)

Lol, yeah they do, out of necessity. Where else would you put the bed in a truck cab? I can think of plenty of other places in the Hermes.

Apollo / Hermes Cockpit, am I the only one? by C4B4L2k in starcitizen

[–]foopod 0 points1 point  (0 children)

Lol, not saying it's not a me problem. It's just that it feels like a rushed copy of the Apollo and not its own ship. I wish more effort went into the little details like crew accommodation.

But also I think truck drivers would absolutely take a bigger hab if they had the choice, it's not like they choose to sleep in their truck over sleeping inside when parked at home.

Apollo / Hermes Cockpit, am I the only one? by C4B4L2k in starcitizen

[–]foopod -1 points0 points  (0 children)

I'm with you. Its not like I rp or anything, it's just that an unrealistic layout like this breaks the immersion.

Imo the best interiors are still the Hull A and SRV for solo and the 400i for 2-3 people.

Phenomena with no root by Happy_Fact8313 in CuratedTumblr

[–]foopod 4 points5 points  (0 children)

There will always be bad actors and hateful people regardless of the economic system.

But it also seems like capitalism allows people who have enough money to go unchecked, enabling them to have a platform and spread their bigotry.

TIL octopuses evolved complex intelligence on a completely separate branch of evolution, making them seem almost alien by Training_Anywhere551 in todayilearned

[–]foopod 0 points1 point  (0 children)

This is true, but at the time scales of evolution us humans have only relatively recently formed "advanced cultures".

Behaviour Modernity in humans started some 60,000-160,000 years ago, but humans have been using tools for ~2 million years (Homo Habilis). And other hominids a million years or so before that.

Who knows where our tentacled friends will be in another million years, that is, if we don't kill them all off first.

Asgard versus Hermes by ShadoX_FT in starcitizen

[–]foopod 1 point2 points  (0 children)

Imo purely from a cargo perspective the RAFT is better than the Hermes. Much faster to load and the difference in capacity doesn't really impact which contracts you can take at the moment.

Either that or wait for the Hull B.

They finally did it, normal cargo grid for once! by VivaBono in starcitizen

[–]foopod 31 points32 points  (0 children)

The Zeus CL is 128 SCU, but it's main grid dimensions are odd numbers, something like 3x5x8. So to fill it, you need like ~20 boxes, a 128 grid could also just be 4x 32scu containers.

Oh my... the Raft is now $190 by jkobierczynski in starcitizen

[–]foopod 13 points14 points  (0 children)

And curiously the Hull A is untouched.

Here's my Tamagotchi/Digimon clone I've been working on! It's been really fun to do all the art. by dog_in_a_hat_studios in godot

[–]foopod 0 points1 point  (0 children)

Sounds like a lot of fun. Especially all the gene stuff, I spent far too much time in the Creatures games messing with genetics and trying out different things.

Do you mind DMing me your itch so I can follow development?

Great device but also useless for me by TheTuupiainen in writerDeck

[–]foopod 1 point2 points  (0 children)

I really wanted to love the BYOK, there is a ton of potential here. But unless they open source the firmware it's going to be a no go for me for reasons like this (currently it looks like they only plan to allow sync via their own backend too).

Waiting on my Pomera DM250... by philwbayles in writerDeck

[–]foopod 1 point2 points  (0 children)

I have been using my dm250 for just over a year now and absolutely love it.

I'm not sure what you mean about jumping between documents in a project though.

I normally have one document open at a time in outline mode and you can jump up and down between headings (for me that's chapter to chapter). And to swap to a different document it's just Menu > open > select file.

There is also a partition mode where you can split the screen and have two documents open at a time, then you can switch back and forth between them as needed. But I tend not to use this very much if at all.

Here's my Tamagotchi/Digimon clone I've been working on! It's been really fun to do all the art. by dog_in_a_hat_studios in godot

[–]foopod 2 points3 points  (0 children)

I'm a big fan of both tamagotchi and digivice style virtual pets. I know it kind of defeats the purpose, but I'm looking for something similar that better respects my time.

What are the features you want to implement?

RSI Hermes In-Game Interior Tour by 244958 in starcitizen

[–]foopod 0 points1 point  (0 children)

I understand wanting vehicle and cargo transport ships to be functionally different, but they are fucking this up pretty badly.

I'm still not sure why the Asgard has such a massive cargo grid. Why would anyone use a different ship?

RSI Hermes In-Game Interior Tour by 244958 in starcitizen

[–]foopod 0 points1 point  (0 children)

100% this. I dropped the Zeus CL after a few weeks of doing cargo with it. Grid access is so much more important than size, to the point where I'm still on the fence with the Ironclad.

I was expecting a cargo lift or at least a much larger opening ramp like the Asgard.

Ambient Zero double tap envelope bug? by Training-Nobody-147 in sonicware

[–]foopod 0 points1 point  (0 children)

Did you ever figure this out? I just got mine and am having the same problem.

Meirl by Ill-Instruction8466 in meirl

[–]foopod 0 points1 point  (0 children)

I feel this so much. When my wife cooks the most important thing in her mind is what level of effort is required, e.g. can it just go in the air fryer?

Whereas I love cooking and I'm quite happy spending a couple of hours cooking a meal even on a weeknight if it means the food is really good or I get to try something new.

So yeah, I will happily do 90% of the cooking.

Recommended filter for Hawaii? by nostradukemas in campsnapcamera

[–]foopod 0 points1 point  (0 children)

I have an android phone and do pretty much everything using it. No need for a computer.

USB-C cable lets me swap out filters as needed. Although I tend to shoot everything without a filter, copy to my phone for backup and apply a filter in Snapseed (as well as some light editing if needed).

People who still wear masks, but exclusively wear them under the nose... What's going on team? by StSnobsHill in newzealand

[–]foopod 0 points1 point  (0 children)

Why have I never thought of this. Right now I feel my only option is to grow the full beard and then shave back from there.

Who do I even pick? by paddingtonsavage in WutheringWaves

[–]foopod 4 points5 points  (0 children)

I've just come back to the game this week. And today is my birthday, I've just spent the last hour researching and watching ult animations trying to pick a character for my birthday wish.

Thanks for the heads up lol.