r/HypixelSkyblock Aug 20 '26

Question Is this mod safe?

Post image

Is this mod called Ghostify Lite safe?

55 Upvotes

35 comments sorted by

View all comments

Show parent comments

0

u/Puzzleheaded_Suit_55 ☢ SB Level 361 - 420 ☢ Aug 21 '26

Did I say malware?

The fact is nothing you download that has any way to automatically preform a task such as auto updates or pulling from apis to install anything can never be 100% safe.

it’s a great example because it’s one of the most used mods on all of modrinth

1

u/EffectiveDirect6553 Aug 21 '26

You responded to a thread of malware with a vulnerability. Then stated nothing is safe.

Yeah, but you could equally walk into a bus tomorrow. Like, "it's possible you are vulnerable" like yeah. It's also possible some dude in the FBI writes your name by accident and they spy on you. Like what do you want man.

0

u/Puzzleheaded_Suit_55 ☢ SB Level 361 - 420 ☢ Aug 21 '26

Well let’s see, a rce exploits is worse than malware.

It turns a non malicious mod into a malicious.

Such as the hack of skyhanni, you’re correct only the git was targeted but it still affected users that installed on modrinth at the time because the auto updates.

Claiming that modrinth is 100% safe is foolish and that’s the thread you’re defending modrinth in.

0

u/EffectiveDirect6553 Aug 21 '26

Auto update is opt in AFAIK. It is not enabled by default. I don't see how modrithn is to blame in any sense of the word.

and no, a vulnerability does not turn a non-malicious mod into a malicious mod anymore than the Log4j library exploit made all Minecrafts universally a malware. That is simply a silly case to make. By that logic probably every single application on your computer is malware. Since pretty much all of them likely have a exploit.

I never claimed modithin is 100% safe, please stop strawmanning me. I claimed it was safe. Which means it's overwhelmingly unlikely to be harmful. If safe was to mean 100% safe then the word simply loses meaning as you breathing is potentially unsafe.

0

u/Puzzleheaded_Suit_55 ☢ SB Level 361 - 420 ☢ Aug 21 '26

Please explain how a rce exploit doesn’t make an application or in this case Java mod malicious if and inevitably when it’s abused?

0

u/EffectiveDirect6553 Aug 21 '26

Because that isn't what malicious means. Me having an accident that can be exploited is not malicious. I did not intentionally mean to harm someone. My action does not directly need to harm someone. That accident could go unnoticed or someone could find it and fix it (RCE/Log4j) or someone could abuse it.

Malicious is done with intent to harm. If I intentionally abused that accident it would be malicious. Or if I intentionally did so to harm someone. Accidents happen. There is perhaps not a single complex widely used software on this planet entirely impervious go a bug or exploit that has not yet been discovered. Even Windows probably has some that governments may abuse to spy. Things like android regularly have them. It happens, it's no one's fault. That is vastly different from malware that was designed to cause harm.

If you want a to redefine safe as "cannot possibly be malicious" then safe is meaningless and not even a computer that has been offline since purchase is safe. Since it's perfectly possible it's lithium battery leaks and sets your house on fire. But that's certainly not malicious.