Rums

182 posts

Rums banner
Rums

Rums

@rumscsgo

Doing browser extension stuff at https://t.co/KR1X5uQibt.

Katılım Kasım 2012
111 Takip Edilen333 Takipçiler
Rums
Rums@rumscsgo·
@Strbacfr We add our sell settings next to the search, so it takes away from the width of this element (CSFloat uses CSS max-width here). BetterFloat is heavily optimized for performance & functionality, so these smaller styling conflicts are the price we pay
English
1
0
0
34
Strbac
Strbac@Strbacfr·
@rumscsgo why the text lookin like this when betterfloat is on
Strbac tweet media
English
1
0
0
25
Rums
Rums@rumscsgo·
@HKPhooey__ @skinscom We don’t seriously assume that a site owned by an online casino plans to adhere to any laws?
English
1
0
3
80
Hong Kong Phooey
Hong Kong Phooey@HKPhooey__·
@skinscom You’ll owe VAT when selling to any European users your spread is nowhere near high enough to cover this. You’re creating a time bomb without knowing it.
GIF
English
1
0
1
325
Skins.com
Skins.com@skinscom·
We've been getting a lot of questions about how Skins plans to monetize as a platform. We want to take the time to break it down in the thread below, as well as dispel any other concerns that members of the community may have in an open Q&A.
English
9
4
55
18.6K
Rums
Rums@rumscsgo·
@Eton_64 Not quite, the account gets a 30d trade ban, the items itself would be tradable again in 7 days. If these items now were permanently untradeable, that would completely remove any way of abusing the system. And it would basically lower the existing supply, another huge plus.
English
1
0
0
76
Eton
Eton@Eton_64·
@rumscsgo These items are untradeable for 30d (:
English
1
0
0
79
Rums
Rums@rumscsgo·
Observing the recent shift in sentiment regarding trade reversals got me thinking. The general concept of reversals is really good, but it's just too abusable in its current state. What if Valve made reversed items untradeable / unmarketable for the initiating party?
English
3
0
0
465
keppler
keppler@keppler10002446·
@rumscsgo yo rums... another request. could add max blue, pink and green gems for dopplers? the guides are pretty well established.
English
1
0
0
36
Orange
Orange@oranges0401·
@rumscsgo @Erroden_ then make it an opt in feature that requests access to the specific websites as needed? Why do you blanket need access to everything
English
2
0
1
258
Roro
Roro@RoroCS_·
well, good bye betterfloat
Roro tweet media
English
6
2
96
17.5K
Rums
Rums@rumscsgo·
@SpectralOwl I totally understand the purpose of minimum required permission. I didn't really think this decision through enough, given how requesting the "all" permission has become the default for extensions. You guys reminded me and you were absolutely right to do so.
English
0
0
11
593
SpectralOwl
SpectralOwl@SpectralOwl·
@rumscsgo Totally understand why you made the decision to change the permissions to begin with, but this is the "proper" way. Lots of people are fairly nervous when it comes to security, especially in the skins community where the security of their browser can be worth thousands of $
English
1
0
10
668
Rums
Rums@rumscsgo·
Thank you, the community, for you involvement in BetterFloat. I read lots of justified concerns about our new permissions today. I heard you and changed the "all" permission back to individual sites to provide additional transparency (v.3.2.2). Thank you for your support 🖤
English
12
3
59
7.4K
Rums
Rums@rumscsgo·
@_pedantic_dev We did include a few more markets in the list, which we are going to support in the near future (including Youpin). So yeah, this is the approach we should have taken from the beginning.
English
1
0
4
142
John
John@_pedantic_dev·
@rumscsgo No, I mean include youpin on your permission list even if you don't support them yet, so when you do it's already on the list.
English
1
0
0
133
Rums
Rums@rumscsgo·
@_pedantic_dev That's what we tried to do with the "all" permission. There's really no in-between solution. Nevertheless, we will now just continue as before and update permissions every ~6 months now to add new markets.
English
1
0
0
415
John
John@_pedantic_dev·
@rumscsgo Might be possible to have the list include all marketplaces, that way you can expand markets and only need to add the up and coming ones.
English
1
0
3
454
Rums
Rums@rumscsgo·
@netstatcs2 @Erroden_ I very much acknowledge that extensions are always a security concern. And I am very much a fan of verify over trust, which is why we are open-source. In this scene (see SIH) I am surprised this is such a big deal given our transparency (betterfloat.com/permissions).
English
0
0
1
64
netstatCS - csflips.com
netstatCS - csflips.com@netstatcs2·
@rumscsgo @Erroden_ The steamguard part is true. With the latest change you can't even list a $0.03 item on steam market without 2FA. I overreacted a bit in my initial post, you clearly are clean, but me, as a security guy, I always stay away from stuff like this.
English
1
0
0
52
Rums
Rums@rumscsgo·
@netstatcs2 @Erroden_ Changing requests requires a special permission called "webrequest", which we DONT request. Also MV3 heavily limits what extensions are able to do. Without your Steam Guard or 2FA, we still can't do those things if you setup your account correctly.
English
2
0
1
40
netstatCS - csflips.com
netstatCS - csflips.com@netstatcs2·
@rumscsgo @Erroden_ amigo, MITM is totally doable by chrome extensions, generally speaking. That doesn't mean that you are doing it. Respectfully, don't get too offended.
English
1
0
0
37
Rums
Rums@rumscsgo·
@netstatcs2 @Erroden_ Of course, that it s well in your right to limit the permissions you grant. Doesn't change anything about the fact that we CANNOT do the things you talked about like replacing responses or randomly taking your skins. Please do not talk about stuff you got no idea about.
English
2
0
1
42
netstatCS - csflips.com
netstatCS - csflips.com@netstatcs2·
@rumscsgo @Erroden_ It's not braindead, it's reality. True, I wasn't aware that the code is open source, but don't expect the average user to accept that. My opinion is just to stick to the most important websites without asking for perms as you did before.
English
1
0
0
45
Rums
Rums@rumscsgo·
@oranges0401 @Erroden_ You realise that extensions don't just "work" forever? I would have to maintain two separate code bases and update both of them on the regular to stay up-to-date with CSFloat's website changes.
English
1
0
2
121
Orange
Orange@oranges0401·
@rumscsgo @Erroden_ I don't see a significant time cost, money cost, or punishment for paying users to releasing a lite version that just works on float.
English
1
0
0
114
Rums
Rums@rumscsgo·
@oranges0401 @Erroden_ Because it costs time and money. I don't see how punishing our paying users makes sense here. I'd rather spend the little time I can into developing cool stuff for the people that are willing to support the project.
English
1
0
1
95
Orange
Orange@oranges0401·
@rumscsgo @Erroden_ Then why not release a 'lite' version of the extension that isn't future proofed for the users happy with what already is?
English
1
0
0
94
Rums
Rums@rumscsgo·
@MDLcsgo @Erroden_ You aren't wrong. That would mean that every time we add a new market, the extension would get disabled for every single user and you would have to manually accept this single permission for the new market. Please read my article about it: betterfloat.com/permissions
English
1
0
6
804
MDL
MDL@MDLcsgo·
@rumscsgo @Erroden_ ..? It's literally just a manifest change to add each new website without operating on a dangerous wildcard - max. 72h delay from commit -> live. I don't want to call this being lazy, but it's just unnecessary when Extensions support multiple forms of wildcard host entries.
English
1
0
11
811
Rums
Rums@rumscsgo·
@kirincs @DrexCS2 Totally understandable, I won't judge anyone that uninstalls the extension as a consequence. Our permissions hindered us in development for a long time, so this was a necessary change. Extension development isn't as fun as it may seem at this scale.
English
0
0
1
56
kirin
kirin@kirincs·
@rumscsgo @DrexCS2 Yep thx for the clarification, tool is awesome still and I understand the permission thing even though as you say probably understand I’m not loving the idea of it 🙏
kirin@kirincs

@DrexCS2 @wucksao I will say though I rudimentarily went through the git and couldn’t find anything particularly concerning + now also only allowed it to work on float so I am back onboard for now (also didn’t require me to log in like with my friend)

English
1
0
4
110
Rums
Rums@rumscsgo·
@DrexCS2 @kirincs While it would be possible, I personally just don't have the capabilities to do it. In the end, actively developing and maintaining an extension costs money and our Pro users are the ones supporting us financially here.
English
1
0
1
58
Drex✜ ⇆ Trading
Drex✜ ⇆ Trading@DrexCS2·
@rumscsgo @kirincs Would a Pro and a Normal version be possible so that the normal doesn’t need access to all sites since it only has 4 markets anyways? Or would that be way too difficult/too much work?
English
1
0
0
62