Twitch source code, passwords, SDKs, and more made publically available in major leak

asddasad.png

Earlier this week saw Facebook, Whatsapp, and Instagram all go down in a supposed hacking incident. However, that wasn't the only major thing to happen this Monday; apparently, Twitch was hacked, with an anonymous source posting a 125GB torrent onto 4chan today that contained user data and other sensitive information from the website. Reportedly, this data dump contains a wide variety of different things, such as the source code for Twitch, private SDKs, information about payouts that live streamers receive, clients for various platforms that Twitch is available on, and even data pertaining to other websites that Twitch owns such as IGDB and CurseForge.

Beyond that, there also appears to be an unreleased PC storefront for digital games, with the codename of Vapor, intended to compete against Steam and the Epic Games Store. As for the leaked passwords, they are reportedly encrypted. Regardless, it would be wise to change your password, or even turn on two-factor authentication for Twitch if you haven't already.

According to news outlet VGC, who broke the initial story, the following is in the torrent:

  • The entirety of Twitch’s source code with comment history “going back to its early beginnings”
  • Creator payout reports from 2019
  • Mobile, desktop and console Twitch clients
  • Proprietary SDKs and internal AWS services used by Twitch
  • “Every other property that Twitch owns” including IGDB and CurseForge
  • An unreleased Steam competitor, codenamed Vapor, from Amazon Game Studios
  • Twitch internal ‘red teaming’ tools (designed to improve security by having staff pretend to be hackers)

According to the 4chan post, the hacker uploaded the leak in order to cause disruption and competition for Twitch, as they find the community to be toxic. While nothing else has been uploaded quite yet, the user claims that they will be leaking even more files soon in the future.

:arrow: Source
 

deinonychus71

Well-Known Member
Member
Joined
Sep 12, 2008
Messages
912
Trophies
1
Location
Chicago
XP
2,877
Country
United States
What's fascinating to me is how their excuse always sound so childish.

"Toxic community". EVERY community once it reaches a certain size has toxic elements. That's no excuse.
 

FAST6191

Techromancer
Editorial Team
Joined
Nov 21, 2005
Messages
36,798
Trophies
3
XP
28,403
Country
United Kingdom
What's fascinating to me is how their excuse always sound so childish.

"Toxic community". EVERY community once it reaches a certain size has toxic elements. That's no excuse.
I would usually opt instead for the game makes the community; if better performance is gained by being an elitist arsehole then you will generate elitist arseholes, even from those without a particular disposition to being one, even more so if being elite requires secret knowledge or non obvious knowledge. See also the DOTA/MOBA scene where things are non obvious (people insist on having jank made because it was a mod that retooled another quite different game), a bad player will tank your team and thus rankings (which are the only things people see about you)...
As the game of twitch does not reward cooperation (literally if they are watching someone else they are not watching you and big numbers if the only way to roll both mechanically for the host and the player, and more pragmatically), will inevitably trend towards the flashy (as a great song once said "I'm in a ratings system here, and the key factor is sensationalism") or very least trendy. Wind in some further serious monetary incentives, worse still those that can speak to laziness, and it gets more fun still. This is also saying nothing about agendas and whatnot from various parties involved.

Couple that with https://knowyourmeme.com/memes/greater-internet-fuckwad-theory (though anonymity is good stuff so might be a have to take the pain scenario) and yeah.

Granted I am not sure I see a way to making it work without all that, even as a loss leader for a company but especially if it is supposed to turn a profit/vaguely break even.
 

RatherSimple

Active Member
Newcomer
Joined
Feb 10, 2021
Messages
39
Trophies
0
Age
54
XP
271
Country
South Africa
I don't care and really dislike twitch as many of you do but this is a massive breach! Now there are going to be million copycat twitch clones lmao. I also don't like they're trying pretend they're not hosting softcore porn but banning people just because they're earning too much than others. Either admit that you're now a zero-nudity chaturbate (lol) or actually do host support gaming content other than call of duty.

I'm prepping a huge bulk of popcorns for the upcoming dramas and inside jobs. I always wondered why disrespect got banned from twitch out of no where.
 

FAST6191

Techromancer
Editorial Team
Joined
Nov 21, 2005
Messages
36,798
Trophies
3
XP
28,403
Country
United Kingdom
I'll never understand why they store that sensitive shit online to begin with. It's like they're just BEGGING to have it stolen.
Most of that would be the sort of thing I expect those with access to whatever code storage to have access to.

If we are all supposed to be remote working these days and not in offices with air gapped networks and patted down for USB drives on the way out. Whether they have some valve style "everybody can work on anything" or just failed to compartmentalise I don't know.
The payouts thing has me curious, usual bet there is if this is not some kind of in through a small hole approach then someone decided to play database checker with some real data (why I imagine it is 2019 data rather than something more current) and "don't need to anonymise it", that or if it did include red team tools and such then maybe it was the prize.

Now there are going to be million copycat twitch clones lmao.
I doubt it. If the opening post is accurate then it is wound fairly tightly into Amazon's services (some of which may not even be available to the public), most generally avoid using code stolen from others and anybody that could sensibly anonymise it and make it more generalised can probably happily make a RTMP/RTSP server -- the principle is not hard, just needs a fair chunk of bandwidth.
 

Dr_Faustus

Resident Robot Hoarder
Member
Joined
Mar 25, 2021
Messages
680
Trophies
0
Age
34
Location
The Best State on The Best Coast
XP
826
Country
United States
I would rather a youtube leak but I will take this.

+1 for wishing it was Youtube as well. I would have loved to see what is being used to screw around everyone and just have the community cannibalize the system by eternally fucking with the algorithms. If nothing else, at least the internal workings brought to light will show just how awful they are as a system.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BigOnYa @ BigOnYa:
    If your internet speeds are fast enough. Streaming 4k takes alot. I used to only have 20mb sec, and 4k struggled. Now I have 300mb sec and 4k plays fine.
    +1
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, i only have like 1 or 2 mb sec
  • BigOnYa @ BigOnYa:
    Did you feed the hamster in your internet router? It prob died and is running slow now.
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, why did you start saying my pc has a hamster in the first place?
    +1
  • BigOnYa @ BigOnYa:
    Its actua!ly just a old joke, meaning its slow. Was just kidding around with you.
    +1
  • BigOnYa @ BigOnYa:
    I bet @AncientBoi has some hamsters hidden somewhere tho....
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    I think Game streaming should work like this.... Local Hardware able the run the game fine, game engine and common assets stored locally, all FMV and music and textures could be streaming
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Some temporary storage
  • Xdqwerty @ Xdqwerty:
    also @BigOnYa im making some progress on my gdevelop project, implemented various mechanics
  • Psionic Roshambo @ Psionic Roshambo:
    They went all in on streaming, should have been more of a hybrid approach
    +1
  • BigOnYa @ BigOnYa:
    Or free government supplied high speed internet be nice also. Like Obama care. Xdqwerty that's cool, its time consuming but rewarding once done or playable, to see what you've made from scratch. Animations take forever, but worth it.
    +1
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, although the bullets are a bit buggy
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Not to mention this would be a massive pain to pirate
  • Xdqwerty @ Xdqwerty:
    @BigOnYa,
    and the visual aspect of the game is quite crude (the sprite that looks best is that of the protagonist just because he is a stickman with sunglasses)
    +1
  • BigOnYa @ BigOnYa:
    There is a bullets behaviour you assign to your character, that makes the code easier, under "behaviours"
  • Xdqwerty @ Xdqwerty:
    i meant that when the character is pointing to the right, the bullets spawn where they should, but when he is on the right, they move to the right but the spawn point is incorrect
  • BigOnYa @ BigOnYa:
    Itch.io has lots of free assets also. Under the bullets behavior tab, there is a "rotate bullets" option, can try that. Or in the code can try
    - fire bullet Player.X(PlayerDirection)
  • Xdqwerty @ Xdqwerty:
    im taking a break for today anyway
    +1
  • BigOnYa @ BigOnYa:
    YEa gotta after a while, looking at code for long periods will bug your eyes.
    +1
  • BigOnYa @ BigOnYa:
    That's cool tho, I'm proud of you going back to it, not giving up. It is difficult at first to learn, but fun once you get the hang of it. I think I've watched every tutorial video there is, but I still struggle sometimes to get stuff to work right. But gotta keep trying dif things, and eventually you will get it right.
    +1
  • K3Nv2 @ K3Nv2:
    Lol McDonald's has a grandma mcflurry
  • Xdqwerty @ Xdqwerty:
    @K3Nv2, furry grandma?
    Xdqwerty @ Xdqwerty: @K3Nv2, furry grandma?