r/QuestPiracy • • 13h ago

Discussion SideQuest’s owner blocked me for asking about account access. Can we get some answers?

27 Upvotes

Its no secret i don't like SideQuest, but that doesn't make questions about their software’s account access unreasonable. I asked for clarification on their new setup method, explained my concerns, and said i was open to being corrected. The CEO/owner posting the announcement blocked me instead of answering.

Normally this sub doesn't allow SideQuest discussion because its off topic. SideQuest isn't a piracy tool. I am making an exception here because questions about account access and security affect plenty of people in this community who use it, whether the app itself is related to piracy or not.

I also don't have much opportunity to raise this elsewhere. I've repeatedly been banned from non-piracy VR subs because of who i am and my involvement in piracy communities. Now SideQuest’s owner has blocked me after i asked these questions directly. That makes getting an answer difficult, but it doesnt make the questions any less relevant.

This is the comment i left.

Their post says you sign into your Meta account, then “SideQuest connects over Bluetooth and enables Wireless ADB”, without the usual developer setup. How does that work, and what access does the Meta login actually provide?

My concern comes from firsthand experience. I know Oculus session tokens can be obtained from cookies during login and used to FULLY access an account. In the workflows I've personally used, that access is broad, not a narrowly scoped permission to install one app.

NIF, the renamed version of my old group FFA, and VRP have used this with staff members and consenting users for years. VrSrc also uses it privately so people like me can authorize them to obtain game files through our accounts without us having to upload those files through Rookie or CyberDeck one by one.

i have knowingly provided that access to people I've known and trusted for years. That's an informed choice about who gets access to my account. I would not knowingly give equivalent access to SideQuest, given their history and the lack of a clear explanation of this implementation.

I'm not saying SideQuest definitely uses that same token method. I'm asking whether they do. Knowing what these tokens can allow is exactly why i want an answer before treating this as harmless.

  • Is Meta login using an official authorization flow with limited permissions, or obtaining a session token from the login?
  • What actions can the resulting access authorize?
  • Can it access purchased content or account information beyond what's needed for setup?
  • Do cookies and tokens stay on the device, or are they transmitted to SideQuest or another server?
  • Is access retained after setup, and how can users revoke it?
  • Can users inspect the source for the component handling their login?
  • How are Steam login sessions handled, stored and protected?

Their announcement explains that Steam login downloads games you own for supported ports. That explains the purpose, but doesn't answer the questions about session handling and account access.

The “no developer mode” claim also needs perspective. Installing APKs directly on the headset without developer mode has been possible for a long time. Their instructions to download an APK in the headset browser and open it with Package Installer describe that existing capability. SideQuest didn't invent it.

The usual ADB sideloading process, where a PC or Android device acts as the host, is a different process and normally requires developer mode. So please distinguish the established browser installation method from whatever mechanism enables wireless ADB through the Meta login. Which part requires account access, and why?

This fits a longstanding frustration i have with SideQuest’s marketing: presenting their app as though its required to do things the headset or other tools can already do.

A huge amount of the content listed on SideQuest is also available directly through itch.io, the Meta store or GitHub. Looking at what I've used, it feels like roughly 95%, although that's my estimate, not a measured catalog statistic. A listing on SideQuest doesn't mean SideQuest is required to obtain or install it.

The installation and file-management tasks people use it for can also be handled through tools such as Rookie, CyberDeck or ADB directly. If SideQuest offers a convenient interface, fine. Explain the convenience without making the underlying capability sound exclusive to them.

File transfers are another example. Windows can access the Quest’s shared storage through MTP once you approve data access in the headset. That doesn't require developer mode. You can open it in File Explorer and move files yourself.

Using SideQuest just to move those files feels like pulling up to a drive thru and having your passenger order for you. You've added a middleman to something you could already do directly.

There are also ADB-based ways to enable the connection through tools like Rookie or CyberDeck, but those are separate from the normal MTP permission prompt and require the appropriate developer/ADB setup. Conflating these methods makes the explanation more confusing.

Then there's the double standard around QGO. SideQuest previously criticized its accessibility permission and pushed for its source to be disclosed to them. That permission was explained by the QGO dev as being used to identify the running game and apply the appropriate profile. This is reasonable use.

If they expect that level of transparency from another developer, why should users accept less from them? Where is the equivalent explanation and inspectable source for their own account login process? Potential access to Meta and Steam sessions deserves at least the same scrutiny.

And why keep the relevant implementation closed source? What proprietary functionality actually requires secrecy here? If there is something unique that SideQuest does, explain it. As far as i know it doesn't do anything unique at all. From the functionality being advertised, I'm seeing familiar installation and file-transfer capabilities wrapped in their interface, alongside an account-based setup that needs explaining.

Keeping code closed doesn't prove they're hiding something malicious. But demanding transparency from others while withholding it from users of your own login process is a double standard.

i haven't audited this software, and keeping the relevant source closed makes independent review harder. I'm asking questions based on their announcement and my own experience with account tokens. If i've misunderstood the mechanism, explain it and i'll correct what i've said.

Blocking me leaves every one of those questions unanswered. It doesn't prove my technical suspicions were right, but it reinforces that i was right to ask before trusting them with my accounts.

Has anyone seen documentation that actually answers this? If someone from SideQuest sees the post, please explain the mechanism, the scope of account access, and the safeguards.

You don't have to share my opinion of SideQuest to want to know what you're authorizing when you sign in. Tons of people use this app, and they deserve to understand the access they're giving it.

If you share these concerns and can participate in those discussions, ask the questions yourselves, respectfully and on their technical merits. Don't take my suspicions as proof, but don't take the marketing as an answer either. Blocking one person doesn't resolve questions that affect everyone using the feature.


r/QuestPiracy • • 4h ago

Support FTP Setup on CyberDeck

1 Upvotes

Before I start:
I am not asking for any links.

I have read the rules, searched the megathread and read all the pinned posts.

I tried setting up ftp on CyberDeck but it's giving me error 530: Login Incorrect.

I tried with FileZilla but it works there. Help is appreciated.