Pcileech WebRadar – browser based radar cheat for CS:GO
github.com
github.com
The problem historically has been that game clients have access to a lot of game state that enables cheats. With a "thin client" like Google Stadia, there should be a lot less opportunity for hacks. The incoming game data is an audio/video stream, which makes many hacks hard/impossible.
It would be great to play FPS games without any cheaters, they can easily spoil an otherwise amazing game. Maybe future online tournaments will be cloud gaming only.
Not sure if something like that exists (I don’t game really)
Alternatively, servers where certain categories of cheats are allowed, so if you just prefer playing with a minimap you can be with like-minded people.
This is assuming the mind of a cheater is “I prefer playing in this mode”, rather than “I want to win a lot of fake internet pints”. Idk which is more accurate.
Of course, that doesn't address all of it: one could still have the very best cheats that never get detected on a highly trusted account. It's silly, but then if they did get detected one day, they'd lose all their precious skins (which have non-zero to significant monetary value), as they become untradeable forever.
But yeah, I think ESEA has some of what you're talking about built in already. Why spend a bunch of money on accounts that keep getting banned?
Valve also do this on their matchmaking servers semi-secretly using Trust Factor. Unfortunately this can make the experience for new players much much worse.
You don't need to be across the world for it to matter, just across the continent.
I almost want to write one of these that looks at Twitch streams to figure out how common the "no-reg" that streamers complain about actually happens. (Or, if I were the game company, I would write one of these to figure out if there's a bug in the netcode, or people just aren't really as good as they think they are. I have a theory, but data is better than a theory.)
To eliminate cheating, I think games have to move away from the mechanical aim aspect and focus more on ability management, which is harder to write a cheat for. I don't think it's a coincidence that most of the new heroes in Overwatch have projectile-based weapons instead of hitscan weapons -- even if you're cheating with a projectile, you're not guaranteed to hit the shot. The enemy can just move out of the way. (Of course, a "move out of the way" bot could be written, which would be a lot more insidious and harder to detect. Overwatch streamers accuse everyone that hits a hitscan shot of cheating, but nobody has ever accused someone of moving out of the way of cheating. There is enough spam in the game that eventually you'll kill the enemy; writing a cheat that kills enemies more quickly will get you better results than a cheat that lets you live longer.)
There is also a lot of low-hanging fruit where the client is trusted when it doesn't need to be. Hearthstone had a combo where people could generate infinite copies of a card ("SN1P-SN4P Warlock"), but the animations on the client limited the number that could actually be played in a turn. This is how the combo was balanced; not by a hard limit on resources, but by timers on the client. So people hacked their client to skip animations. This would be fixed with a thin client, but it's also possible to fix with 100% certainty on the traditional fat client. Just calculate how long the animations take on the server side, and reject client updates after the server thinks the turn is over. Add a few seconds of slop for people playing on 2G networks.
This isn't true for a number of reasons:
1. Good players are exceptionally good. In pro gaming you'll hear the term "pixel shot" because someone fired at essentially one pixel. The shooter is holding an angle where they know that a change of one pixel is someone running by. That sort of thing; and
2. If you watch any streams you'll see aimbots from cheaters (eg when the streamer gets killed and spectates who killed them) and it's pretty funny to see just how blatant aimbots are, like shooting through bushes that don't block bullets but have no visible indication of an enemy.
But I agree with other comments: I think cloud gaming is 100% never going to be relevant for competitive esports (of this kind) because of latency. That's not a technology problem. It's a physics problem.
> I think games have to move away from the mechanical aim aspect and focus more on ability management,
It's interesting that you bring that up. That's actually a criticism a lot of people have of games like Overwatch (that you mention) in that it's not about gun play but ability management. That's actually seen as a negative by many. Riot Games apparently has made a deliberate design decision to focus more on gun play than ability management in Valorant, as just one example.
> This is how the combo was balanced; not by a hard limit on resources, but by timers on the client.
This is surprisingly common actually. Timers on many games are really just approximated with frame rates. Good players will do better at a game if they can get 200fps over those that get 100fps.
An example of this is the much-beleaguered Fallout 76. Bethesda games use this pervasively and, at least for awhile, Fallout 76 had a cap put in place of 63fps to avoid some of the benefits high frame rates gave players (eg faster movement), such that I took to calling it Fallout 63.
There is already too much rent-seeking in gaming.
I like competitive games, or at least I did when I was younger, but nowadays I yearn for some good-ol' tribes server community where you have 32 players playing CTF and there are actual administrators who are engaged with the community. If someone becomes a problem you just ban them from your server. Similarly if someone brings a friend to your LAN party and that friend is a cheater, you uninvite your friend and/or punch the cheater.
"Cloud gaming" sounds like a hellscape.
It reminded me of the Heavy Personnel Carrier. Loading the HPC with 5 heavies armed with Grenade Launchers and Heavy Mortars was fun.
it'll just turn the cheats from memory manipulation to computer vision -- less powerfully 'psychic', but still fast enough to cheat.
But a streaming-exclusive game would be impossible to pirate. That's why publishers are so enthusiastic about it.
For example, this data had to come from network packets, so if the server is oversharing data, why wouldn't you just intercept the packets? What exactly is the cheat?
The file doesn't explain much.
So if I'm reading this right, the partial fork has changes specifically to read CS:Go data directly out of device memory to another device, which in turn processes that data and renders a web-based map of all player locations.
https://developer.valvesoftware.com/wiki/Counter-Strike:_Glo...
To achieve real-time feeling game apply (most) your inputs immediately without having to wait relatively long time confirmation from server. So if you decide to push button and peek around corner you expect to see enemy immediately but server will know about your peek "much" later.
You can for sure limit some information by locations but you always must leak more than it's actually seen by client. Also it isn't easy to solve: can any part of volume be seen from another volume inside arbitrary 3D environment. Enemy size and movement through network frame => players all possible eye positions.
I think current best solutions rely on very rough (manual?) map piecing. So is it worth to invest for such thing that makes some cheats bit less powerful but cannot really prevent them.
Shouldn't the hardware ID be randomised to start off with? Not that I plan on using this either way, though.
Ugh, now I want to write my own game cheats for the sake of curiosity!
How so? Is it really common for non-cheaters to have exotic PCIe devices connected?
You could certainly build the cheating functionality into a common PCIe device, but I’m not sure I’d call that easy. There may not be enough money to be made from cheating on ESEA to justify such efforts.
My stance on this is it's inevitable and game design shall be changed to make this cheat irrelevant, by revealing everybody the all players location, thereby the player who use this cheat has no advantage over the other. I think it doesn't change the game that much for most of the game.
In case of the game which requires secret, it can be achieved by trusted authority server or by using mental poker algorithm.
My guess is, you can't use this system to modify the target memory without detection. Since it's impossible to change the multiple memory location atomically, it would be pretty easy to detect from the target computer.
Also the guess, but to detect this memory peak attack, you take control of all the memory bandwidth, no code but you can use all of the memory access, then consume all memory bandwidth with cache disabled so you can detect the slight bandwidth change that is either this attack, or it's DMA from the motherboard(Possibly malicious access from evil binary blob firmware such as Intel ME or AMD PSP)
Utility is limited, since you can just .. hear the sound in the correct direction anyway.