EA got hacked and games source code leaked including new game Battlefield 2042
bbc.com
bbc.com
They would be doing something seriously wrong if that wasn't always the case haha
So yes, never forget...!
Maybe it's an outdated type of humor, but I didn't see a reason to stop myself. While this is HN, we can use some old Slashdot style now and then IMHO.
- Accessible to the general public (it's a BBC article)
- One sentence long (you will lose readers if this becomes a cs101 lecture)
- Articulates why a source code leak matters
Something in the lines of "Source code is the human readable version of the end product before it's packaged for computers, and it's much easier to read and understand. Also, the source code may allow reverse engineering of the product in question" would be more precise and similarly understandable IMHO.
- I would say even that reverse engineering, as mentioned, is not something the layman understands.
Other than that the article was fine IMO
I mean yes. It isn't that long ago that software was sold in boxes. So the packaging analogy is probably within reach of most people.
But maybe "released" or similar would be more widely understood.
> The “source code” for a work means the preferred form of the work for making modifications to it.
But the BBC article definition, while less precise, is more relevant to the subject.
For example, it may be quite hard to reverse-engineer a loaf of bread, but reading assembly is actually quite easy to understand what the program actually does.
If you're trying to explain to a non-technical person what source code is, the bread example from OP is actually a great analogy. It's simple, to the point, and almost everyone will know how bread is made. Is it oversimplified? Sure. But that's the entire point of trying to give a real brief overview to someone with no technical experience.
Not bad. What would you say about saying - " a source code is a set of instructions for a computer to execute". That way, we can still keep the conversation (some what) technical.
You can open the binary file in a text editor and it will be much harder to actually read it. Next best solution is to use a HEX editor but having the source code will make it much easier to understand.
(This is what I used for my child.)
> A blueprint is a reproduction of a technical drawing or engineering drawing [...] allowed rapid and accurate production of an unlimited number of copies.
and even if no-one reads the definition, the term is in common use. Spies stealing blueprints of weapons in movies / real-life being an immediate example.
I think the key element of source code is that this is what is written and read by programmers -- it is akin to the secret recipe for Coke.
Hope that's ok.
All I can say is thank you to danG for implementing expand/collapse on comment threads so you can quickly move on to comments discussing the topic itself.
Did you really need to read what source code was again from the BBC? If you know already, great - but if you don't, why do you need to know what a compiler is?
It's similar to their general coverage of the covid vaccine - does everyone that reads an article about the vaccine really need to know the scientific debate, context, cohort data, vaccine action detail? Or just that the vaccine works & is safe?
I know that joking is not appreciated on HN, but the mental image here is absolutely fantastic. I'm giving my rooster a gigantic beak and three legs.
An apt description of the franchise since FIFA 2013.
It almost seems possible...
Edit: [0] is also a much better source than BBC in this case.
[0] https://www.vice.com/en/article/wx5xpx/hackers-steal-data-el...
I'd love to contribute to something like this.
Of course not best for financials
So the worst case scenario could be worse than just a few cheaters. Either way EA will endure it without problems because it's barely different than the average bad game launch.
Worst part is that the denial doesn't appear to be bandwidth-intensive, just a persistent trickle of bad requests. The hacker may even have forgotten they left the script running, somewhere.
You start a game, 60 user accounts are in it. You inspect their IPs, give them a token, whatever. If they send too many requests you can drop some, and if it’s inhumanly possible given the games code, you ban them. That’s it?
I could see how a public-facing website could get DDOSed but not a game where people are registered. I must be missing something. Maybe input parsing has to happen faster than IP check?
That causes a lot of speculation, including suspicions it's run by an ex-employee who worked on those systems internally.
I remember Quake 3 had a number of exploits that could allow a server owner to essentially run arbitrary code on clients machines.
As a newer game, probably Battlefield 2042 servers are entirely run by EA, so any exploitation will have to go through the server first.
Also I think sometimes there are vulnerabilities where you can technically run some tiny bit of your code on a vulnerable machine, but it would lead to a crash. Hence, people use "arbitrary code execution" to distinguish this particular threat from the less severe ones.
It could be running part of the game code. Deleting saved games, for instance.
Getting control of the client application is different from pushing arbitrary code (any code the attacker want) on the machine and executing it.
An in-between is return-oriented programming, where an attacker gains complete control over the execution flow of a given program. Even if they aren't able to push different code on the machine, they can chain parts of existing code to perform arbitrary computations on the machine: https://en.wikipedia.org/wiki/Return-oriented_programming
A vulnerability that lets someone run arbitrary code means they can run whatever code they want; that's what makes it such a problem.
This is the same security risk that anything with plugin/extension/mod functionality experiences.
Generally, the best way to secure that vulnerability is to verify downloads from a moderated source, i.e. run a mod forum/plugin repository that disenfranchises bad actors and verify checksums at download.
A good example is Emacs and melpa.
https://www.eurogamer.net/articles/2021-05-11-unbannable-ape...
Same for Frostbite.
I'm just curious about the tech behind AAA games and it would be fascinating to explore the innards.
Where does it say battlefield 2042 was leaked?
All I see is Fifa and Frostbite (a game engine)
It appears that the only companies capable of being secure are Google and Apple. Aside them everyone is getting hacked every other day.
Companies that torch through millions of dollars of VC money need a nice ransomeware kick in the ass to set up a MongoDB password, and will proactively ignore S3 warnings to not make something public, so what do you expect?
I don't think is necessarily the case. You can take security seriously, but there are limits, and you have to balance the effort with the willingness of someone breaching your safeguards.
I would use a bicycle as an example. You can buy whatever lock you want, it can be broken by someone. The better the lock, the less people can get through it or are less inclined to do so anyway. You can pay a security guard to look after your bike, but at some point, if your bicycle is really valuable, one guard can be bribed (or killed), and so on, and so on.
In summary, just because they were "hacked" does not mean they are not taking security seriously.
To some extent though it does mean they were not taking security seriously _enough_. In your example, they misjudged whether they needed a guard or not.
[EDIT] Actually, I realized it's not about taking it seriously, but executing it efficiently.
Back then, when they enforced a maximum 16 character password, I saw enough security. Are they storing them in plaintext or what? Btw, I think they increased the limit to 32 now
2. Only in the UTF-32 encoding, which no one uses, are all characters represented by 4 bytes.
Most sites today use UTF-8 where most characters on a standard keyboard are 1 byte, and almost all characters from any language take 3 bytes.
3. Even 19 characters is a lot better than 12.
If that kind of hashing algorithm is a must, why not use first X bytes of the password input?
https://en.wikipedia.org/wiki/LM_hash
Save-ya-a-click: basically what jfrunyon describes, along with a whole lot of other insecurity goodness (and to be fair, LANMan was a long time ago).
My point is that throwing a "password too long" error, especially for 32 characters or less, feels like a wrong approach to me; no matter the circumstances or the amount of backward compatibility that has to be kept.
I assume “problematic” here means “difficult but possible”. If problems arise then I guess it’s a matter of priorities; but I think that not inconveniencing the user with password length limits should be high priority.
Of course you can make your employees' lives worse by siloing them off, enforcing all sorts of security policies and so on. It's just not worth it in this case. So the source code of some video games got leaked... big deal. What are hackers going to do with it, make their own version of Battlefield and FIFA? Write snarky comments on how crappy the code is? Maybe they'll develop cheats, but that can also be done without the source code.
Whitelisting also won't protect you from exploits in the software itself. If some non-technical user gets compromised and starts sending out malicious PDFs, you better make sure every single installation of Acrobat is up-to-date. If you get hit by a 0-day in Outlook - good luck.
Now perhaps in this case people were just sloppy, but again, if you want to rule out exfiltration of data - as opposed to just making it less likely - you need a completely different approach and it'll cost you.
Maybe instead, individual business units (or even smaller) should be independently responsible for security.
[1] https://www.bloomberg.com/news/articles/2020-07-21/ubisoft-s...
The head of global HR was covering for Serge. She was axed immediately (as was Serge).
It’s important to know though. Serge was _insanely_ core to the functionality of Ubisoft; he was the sole approver of every AAA game. Axing him was like removing the beating heart of the company to shareholders.
Obviously our morality says that this was the right thing to do, but I’ve seen other CEOs who would cover for such an “invaluable asset”.
And Serge was axed before this was public, so it’s not like the hand was forced- there was a “creative directors board of editoriale” which sprung up shortly before because of this.
Looks to me like it's all the same since Battlefield 3 and they only change the look.
But possibly I'm too ignorant and expect too much of major game releases.