Implementing secure leaderboards for my game
vittorioromeo.info
vittorioromeo.info
> Sadly, the C++11 <random> library is not portable, but the excellent PCG Random library is, so I used the latter.
Yes it is. std::random_device will not give you a deterministic sequence (obviously!), but the standard PRNGs absolutely will. Check, for instance, std::mt19937, which specifies exactly what the 10,000th value has to be [1].
That's not to say that you shouldn't go with PCG. PCG is a fantastic PRNG. But claiming that the <random> PRNGs are not portable is just FUD.
[1]: https://en.cppreference.com/w/cpp/numeric/random/mersenne_tw...
If people want to use PCG, that’s perfectly fine, it’s a great library. My point is, there’s nothing wrong with the PRNGs in <random>, they work great. Mersenne Twister is not state of the art anymore, but I guarantee you that unless you’re doing something truly insane, neither the throughput nor the statistical properties of MT is gonna be your bottleneck.
[0] https://www.protondb.com/app/1358090/ Okay it's one person, a year ago, but for $4.49 I'll take the risk.
Edit: Running it on Mint 20, works perfectly so far.
In my case, I whipped up a quick-and-dirty replay viewer for my game that runs in the browser (no sound or textures or anything): https://fbg-db.netlify.app/
For the record: no one ever even attempted to cheat at my game :)
Avoid.
B) I loaded the page without an adblocker and didn't see anything phish-y or inappropriate.
Hedgewars uses fixed point math. I believe Spring uses streflop now. I don't know too much about the 0AD situation.
https://m8y.org/hw/fp.html A chart of floating point variations. In time idling in the Spring and 0AD channels I picked up similar desync matrices from them.
3 seems easy to defeat too. Just add a duplicate set of fields, which default to the same values as the original ones, and have the first set control the RNG and the second set control the display. Then you can change the second set all you want.
3 is not fully solvable I think, it's the same class of hacks as x-raying. You can only make it really difficult. At the end of the day, you can't control what's being rendered client-side, short of cloud gaming. I have seen ML approaches to detecting behaviour server-side for things that shouldn't be humanly possible (like seeing through a wall) but it's an arms race.