The creator of a paid mod for Gmod is leaking the IP addresses of anyone who pirates it.

In general sure, but in the specific case of GMod there is a bigger issue, you can force any client to access any web content you want, that's how this tracking was done.

GMod's lua API has silent access to HTTP get/post functions. He would just check from inside the addon itself and then send the user to a website to log who is using it. I don't know what his criteria for 'pirated or not' is, but the tracking part is, unfortunately, very easy.

Ingame, there is no URL whitelisting or blacklisting, no option to disable or prevent it globally, and nothing that notifies you when or before an http request happens. All sorts of nasty stuff can be accomplished using someone else's client/IP... far worse than this, and they will never know until the damage has been done.

Not to be too alarmist about it, but there is no such thing as a safe GMod server unless you're the owner, and no such thing as a safe addon unless you manually check the code yourself. Facepunch seem content to leave it that way, too.

/r/Piracy Thread Parent Link - i.redd.it