GHIRBI, the Gatekeeper

Cultist Simulator

Seize forbidden treasures. Summon alien gods. Feed on your disciples. Cultist Simulator is a game of apocalypse and yearning. Play as a seeker after unholy mysteries, in a 1920s-themed setting of hidden gods and secret histories.

There are now a hundred and forty mods on the [url=https://steamcommunity.com/app/718670/workshop/][i]Cultist Simulator[/i] Steam workshop[/url]. The number’s exploded since we enabled DLL modding – that is to say, we allowed modders to run their own code as part of a mod, changing fundamental game behaviour rather than just adding new narrative content and images. Four of the top five mods are DLL mods. Any time you run someone else’s code on your machine, there’s a risk. In theory, a modder could include malicious code in a DLL mod. The risk is very low – AV programs may notice it, Steam will block malicious modders – and the same applies to games anyway – there’s nothing in principle to stop a game developer from putting malicious functionality in their work. But there was [url=https://www.kaspersky.co.uk/blog/cities-skylines-malicious-mods/24257/]an incident earlier this year[/url] where a modder [u]did[/u] include malicious code in a [i]Cities: Skylines[/i] mod. It was trivial – it just interfered with other mods as part of some sort of community drama, it wasn’t ransomware or anything. It was spotted within days. And it only affected about fifty people. But [url=https://www.kaspersky.co.uk/blog/cities-skylines-malicious-mods/24257/]it did happen[/url]. (A few months later we got an email from a security researcher pointing this out.) [img]{STEAM_CLAN_IMAGE}/31397842/0bcc7c72f8158d9a08c0e2334bef366f469a8577.png[/img] So from the beginning of next year, we’re making it slightly harder to enable DLL mods. All you’ll need to do is [url=https://steamcommunity.com/sharedfiles/filedetails/?id=2901287611]install a gatekeeper mod, Ghirbi[/url], and all Ghirbi does is show you a notice making you aware of the theoretical risk. This is basically the same as making the user tick a box to say ‘I am OK with this’ – but most people tick most checkboxes without reading the notice, especially when they’re playing games. [i][You won’t need to download or install Ghirbi to use DLL mods until after our next patch, NEMESIA, but you can [url=https://steamcommunity.com/sharedfiles/filedetails/?id=2901287611]install him now to save hassle[/url]. If you don’t use Steam, [url=https://www.dropbox.com/s/dt7yesst1hvkiy3/Ghirbi.zip?dl=0]you can download Ghirbi here[/url].][/i] Honestly I think the risk here isn’t traffic-accident low, it’s hit-by-a-meteorite low. But if someone was hit by a meteorite [i]because they’d installed our game[/i], then even if it was a bizarre accident, we’d feel bad about it. So we’re adding a meteorite warning it’s impossible to ignore. Happy Christmas.