VRchat bans mods, embraces EAC
hello.vrchat.com
hello.vrchat.com
The problems they mention are all solvable without banning mods:
> Malicious modified clients allow users to attack and harass others, causing a huge amount of moderation issues.
These kinds of issues should be solved on the backend. Rate limiting, pattern matching, etc.
> Every month, thousands of users have their accounts stolen, often due to running a modified client that is silently logging their keystrokes
Keep a list of "blessed" open source clients that have a reputation, and allow people to report them. Chrome and Firefox extensions have solved this
> Additionally, all modified clients – even ones that aren’t malicious – are a burden for creators. We regularly speak to many that have spent hours (or days) debugging user issues, only to realize that the culprit is a modified client.
Provide better debugging info for your creators! They should know which client (or at least that a modified client) is being used.
> This pain extends to VRChat support too – any time we update, we get a massive amount of bug reports that end up just being broken modifications
Ditto. These tickets should be easy to auto-close if you force folks to include info about their client.
I understand all this requires time and effort, and simply restricting the client-side of things is a low-cost solution. But if there's already a vibrant community of mods out there, I think you have a responsibility (and a vested interest) in trying to preserve that.
never seen that work in practice.
> They should know which client (or at least that a modified client) is being used.
That's the modified client's job, not the original client's job. if the modified client is intentionally trying to be hidden, then its not going to show itself. Which is the cause of the whole everything
> Extensions
https://docs.vrchat.com/docs/what-is-udon already exists
> But if there's already a vibrant community of mods out there
is there a vibrant community of mods? besides, they have actively told people to bugger off if they use a custom client for a while now, by the sounds of it (e.g. the two mods I could find, both said that you will likely get banned for using them)
Except in every competitive online game that predates EAC. Rule #1 in networked games is "don't trust the client".
> They are complaining how much time they wasted on mods
You mean their complaint that they wasted time on bug reports coming from modded clients? And instead of using the obvious, dead simple solution of appending a client ID to the bug report to filter out modded clients, they prefer to use this as an excuse to add DRM?
Guild Wars had a similar issue of getting bug reports from clients due to hardware errors. Did they ban all PCs not built by an authorized OEM? No - they simply added a hardware health check to their game, and ignored bug reports by clients that failed it.
Exactly. You write the game logic, you know what the client is and isn't allowed to do. Just ban/kick if the client tries to do something it isn't supposed to do.
The only thing stuff like EAC should be needed for is stopping people from delegating making their game logic legal inputs via an aimbot or some external script instead of their actual fingers, which doesn't seem relevant for VRChat.
Of course couple this with a deep understanding of what your client actually can do. Oh, and keep track of updates you'll have a lot of banned users.
Specs locked behind paywalls/licensewalls. Closed source API:s, lock in via cryptography... It all comes together to create just what large software platforms want, but what people like Engelbart were trying to avoid.
A technically ignorant/illeterate user populace.
Even Ring-0 anti-cheat software hasn’t kept Valorent cheat and abuse free.
The server is the only software not in “malicious” hands; it’s the only place anti-abuse checks are viable.
Is there any online game that has permitted modded clients playing with unmodded clients and had it go well?
But what kind of cheats? Aimbotting and seeing through walls don't apply to VR chat. And no matter how modded your client was, you couldn't spam endless grenades in Counter Strike - the server knows how many grenades you have, and where you can throw them.
Due to starcraft 2's design, defogging hacks were plentiful.
Anyone who has played TF2 for a significant amount of time has run into hackers landing impossible shots, e.g. through walls
before EAC, there has been VAC (along with two separate community-ran anti-cheat services for source games), Battleye, Warden, etc. It seems universal amongst those involved, that client-side anti cheat helps way more than you expect.
Their policy is basically "Don't Ask, Don't Tell". So as long as you aren't yelling at people about DPS meters or streaming with obvious mods, they'll leave you alone.
I’m not arguing that there’s no rate limiting going on in the server, but some things such as not being able to call several api commands with only one hardware event are enforced client side because by definition the server has no idea about whether a hardware event happened.
> never seen that work in practice.
Isn't this solved by basically every game with a persistent economy? If e.g. Eve online or Runescape just trusted the client they would have fallen apart years ago (not mentioning WoW until the next para because its economy is less important/more isolated to each individual player than a lot of other mmos).
Afaik in World of Warcraft (and by extension probably a lot of other similar games) a bunch of important stuff is totally serverside - your current HP/Mana/Inventory, skill cooldowns, buffs etc. None of that is controlled by the client, and the best you could do by hacking it would be to get it to temporarily show information that was different from what everyone else sees, and couldn't affect any other players.
Movement in WoW (afaik) is a bit more of a hybrid thing - it's a mixture of the client immediately responding to player input, and the server only resetting player position/kicking people off the server if it determines that the player could not have performed that movement with their maximum speed.
With a lot of games this isn't actually that hard either - you just encode rules about what players can do (max movement speed, rate limit amount of chat messages per second, abilities that that player has access to etc) and kick people from the server if their client claims they're doing anything impossible.
In competitive shooters it's a bit different - you don't want to let clients send you technically legitimate "I shoot in this direction" commands that come from an aimbot instead of a mouse, so a multifaceted approach is important here. But VRChat isn't a competitive shooter.
With turn based games it's really trivial, just have clients send you their decisions for each turn, run all the game logic server side and have the client be a dumb UX that plays the animations it's told to.
===================================================
Having an authoritative client and just trying to detect cheating on the server is very difficult/impossible - but that's because it's totally the wrong way to solve the problem in the first place.
You want to have the backend doing all the important logic, and have the client be as dumb as possible (or write a deterministic game engine and have the server replay the same inputs at the same time from the same state and boot people when the outcome doesn't match what they told you happened, but this requires engineering up front - it's not an easy thing to retrofit into an existing game).
===================================================
Edit: Realised WoW is a good example for mods too - the client is moddable, but there's a clearly defined API for what mods are allowed to see/do. It works pretty well.
Doing this the right way is not impossible, it's just probably more engineering effort than the devs of VRChat are willing to put in.
Those guys push major updates on friday evenings, introducing new bugs and causing clients to break right when the weekend parties are scheduled to happen. I doubt it's a matter of "willing" and more about competence.
These is easy when a couple seconds latency is acceptable. In an action game, as opposed to an MMO, it isn't. 100ms is likely to lead to a very subpar experience.
Thus you end up doing stuff client side, even if you sync up with the server a couple times a second.
You can paper over latency by immediately showing animations and stuff clientside, and rolling back if the server decides it didn't happen - most games do do this. But there's not a multiple second gap between e.g. you activating a spell in WoW and the outcome being registered by all players involved - that would be actually unplayable as you say. There's also sub second cast times combined with spells that interrupt/stun those other spells.
Nowadays there's not much difference between a lot of MMOs and what I assume you're referring to by action games - see New World[1], Black Desert, Tera, Elder Scrolls Online for a bunch of examples of games that have fast paced combat with small cooldowns and reticle aiming while also being full fat MMOs.
Besides, this thread is about VRChat, which is definitely not an action game.
Valve is pretty good at this, and they don't even use kernel level anti-tampering as a facet. Trust factor, VACnet (machine learning) and overwatch (community demo review) add up to a system that's pretty decent at not matching you with cheaters if you aren't one.
Linden Labs did just that -- and almost every other better-practices VR thing -- and it worked just fine.
Linden Labs and their teething problems should be the bible for anyone starting a 'VR-experiences' style platform, but for some reason their past struggles have been widely ignored by the newer players in the field.
[0] Or ActiveWorlds, or the metric buttload of VRML chat services before that...
It's also a great example of a hype cycle - it was going to be the future, it was going to be everything, corporates had offices in there, universities had campuses, there were virtual music events and art galleries, there were real-dollar millionaires made from virtual real-estate.
When the hype died down and the smoke cleared, there were still people wanting to use it, but not that many, and not in the way we were all told to expect, and the corporates realised they didn't need a bank branch or an SL office full of virtual meeting rooms in there after all. Neat sandbox with interesting ongoing uses, not the new centre of all our online lives.
But having seen virtual worlds come and go multiple times, I'm going to assume that it's another hype cycle until there's compelling evidence to the contrary.
You might as well not be a person if you live in a virtual world...necessities like money and basic human needs mean people outgrow their fantasy world, and their fantasy games. Moves like this cause fragmentation, such that there is no one virtual world.
As your userbase gradually dwindles to nothing...they grow up and have lives. Or don't, and are usually characterized by low paying jobs, poor health.
Ofc not every low paid worker is there by choice, and some are born disabled, but on average these games are a cause of their plight.
What will be the real "VR metaverse" for most consumers is the one that maps to reality. The AR metaverse. Being able to visit people in real life in real locations, virtually: augmented reality. Where the virtual reality part of that is a small extra side bit for the dedicated people.
While there used to always be soft pressure to structure your life in the real world, with work and school online, folks who otherwise would be pressured to interact offline might now find interaction online to be just as fulfilling. Or at least equally fulfilling for things like work while saving quality, offline time for friends.
I know there are headsets now, maybe it will go differently. Maybe not.
As for the metaverse, people need to realize that it's not for everyone . Maybe in 10-20 years or so
Isn’t this is what most teenagers use Fortnite and Minecraft as.
I'd say, Roblox is more sticky, as there's a built in friend list and chat/messages without being in game.
Fortnite and Minecraft do have chat features in them, but those are features tacked-on as a last resort. In the case of Minecraft you don't even have voice chat. In the olden days of the Xbox 360's heyday[0], all we had were one-on-one voice channels or in-game chat, the latter of which would be an absolutely toxic nightmare of getting shouted and screamed at.
Furthermore, Fortnite and Minecraft are games whose camera and movement controls are optimized for the specific game mechanics they feature. If you want to create a generic 3D world, then you have to also create a generic set of controls to move and look around that world; and those controls are always going to be awkward and difficult to use.
Maybe you built a regular house, in which case Sims-style point-and-click-to-move and a fixed camera angle would be your best control option. Or maybe you built a racetrack with cars, which means you want WASD-steering with a car-locked third-person camera. Your FPS level wants first-person or over-the-shoulder third-person.
Second Life tried to do all of the above, so they gave you a default behind-the-head camera that vaguely works in open spaces, but you have to use Maya-style camera orbit controls to look at specific things. You can scroll to zoom to first person, but you can't use any of the builder controls in that view because of mouselook. And all of this was complicated enough that Linden Labs felt it was necessary to add "easy" movement and camera controls driven by UI buttons, but not to add click-to-move for third-person mode.
The thing is, when I look back at Second Life I can't really think of a way that it could have been done better. I can think of features that it's missing, but that wouldn't fix the clunkiness of the controls. Anything I could think of to fix camera movement would bias in the direction of a particular 'genre'; and making people switch between "FPS mode", "car mode", and "hanging out mode" would be a total pain.
This isn't even getting into the other problems these projects have, like the fact that 3D worlds are really expensive to build, or that the copyright maximalists will have a field day suing you over all the pirated content that your users will inevitably port in.
[0] As in, "blades dash" era 360
Every time I see news about the "Metaverse", I remember the articles Shamus Young (RIP) wrote about ActiveWorlds and the DotCom bubble crash:
https://www.shamusyoung.com/twentysidedtale/?p=35399
The metaverse doesn't seem quite that bad (Facebook's people seem to have an understanding of the medium they want to operate in), but the basic "we're going to make the user experience worse by replicating the limitations of the real world for the sake of realism" mentality is still there.
My biggest concern is that I've yet to find a VR headset that I can use for more than about ten minutes before feeling nauseated from motion sickness. I'm told this is somewhat/mostly solved and I've used higher end gear but it's been the same result for me every time.
Sometimes I see these issues being brought but and I always wonder if they are associated with experiencing applications that make your virtual body move artificially without actually moving in real life, instead of staying intact like in Beat Saber or jumping by teleportation like Half Life: Alyx allows?
It seems a popular mistake for VR newcomers is to get in—or be put in—a rollercoaster or drive a car where these kind of problems are very visibile.
There are many mods, authors, and tens of thousands of hours of work put in by game devs.
It's disrespectful to be commenting about a subject you don't have experience with. It's only muddying the waters.
it often doesn't work out even if you do ban modified clients. there's an impressive array of hacked clients for many games out there.
hehe there's a spiderman knuckles that spams webbing and it fills the entire room and you can't see anything it's funny.
I pretty much agree with all your points, but what I see here is that VRChat developers or product people are choosing the solution that requires the least effort. They may have other features or fixes in their roadmap and decided to squash all the fixes into a single one: banning them.
If I were them, given the popularity of modified clients I'd try to turn that into a feature that sets them appart from other competitors, but I still think it's a rational choice to ban them given how much developer time costs.
It should not require much extra developer time at all to let both users and creators choose whether to join an EAC or non-EAC instance.
Their “simplest possible solution” has not solved the problem.
Legit users who had modded their clients to have some perfectly fine features (such as performance enhancements) are SOL - they aren't gonna risk it just for features they've lost, they either gonna live with whatever's left or just abandon it entirely.
And those with malicious intent are gonna just work around the anticheat (because why not - what they're doing is most likely was some bannable offense already) and continue. Yes, there's some barrier but just the other day we had a thread where DMA hacks were mentioned (and PCIe cards for that are pretty cheap) - does EAC has anything against those tools?
We don’t put locks on our doors because they’re unbreakable but because they are the right compromise between cost and benefit
there are far too many hacks, too little moderation, and too little community pushback on bad actors. this will _always_ happen if the communities themselves don’t figure out a way to chase the trash out.
it doesn’t matter if it’s a social network, it doesn’t matter if it’s a game, it doesn’t matter if it’s a forum. if it relies on money, then either the community will make trash unwelcome or the company will, and of course the company will do what’s the most convenient for them.
we talk a lot about we want companies to keep things open for communities to run, then when companies try a hands off approach the communities sit by and do nothing while malicious actors take over lol.
then, strangely, the communities who did nothing to address actual real problems act all shocked.
This is a crazy hard problem that is plaguing the majority of our mainstream social platforms. Looking at Twitter/Facebook/Reddit etc. moderation+harassment is mostly solved by brute force community management, and is extremely costly, with a human component that is hard to ignore (Facebook moderators are plain miserable and prone to stay mentally hurt even after leaving the job)
This is where Nintendo decided to bail out of the problem altogether by blocking personal interaction by default on their online platforms. If they don't have the resources to do it properly, limiting the attack surface feels like a sensible strategy.
...that rely on advertising.
It's comparatively easy to moderate communities if you're willing to permanently ban bad actors. Trouble is, that shrinks your audience, which reduces advertising revenue. Reporting accounts on Twitter, Facebook, Instagram, et al, is a multi-step process of making excuses for why your reported post won't actually negatively impact the malicious account.
Youtube demonetizing creators with too aggressive stances is an example of that, but we also had Reddit banning whole subreddits when their sheer existence had a nefarious effect on the platform's ability to negotiate ads.
When the choice comes down to more active users but lower prices offered, vs less users and better ad prices, platform tend to go for the latter I think (4/5/8 chan being exceptions)
Isn't VRchat... Spoken? It's kinda hard to rate limit and pattern match speech. Text is one thing but it's going to take some compute power to do what you're asking.
For competitive games, I can see the argument and demand for anti-cheat.
Here, though? Any actual problem it would solve is better addressed either server side or on the counterparty clients. It seems backwards to require full control of all client software rather than filtering out spam on the receiving and/or intermediary ends.
> Ditto. These tickets should be easy to auto-close if you force folks to include info about their client.
As a (former) modder, though not for VRChat, I can definitely empathize with this. Code quality with mods is a freaking wild west where modularization isn't really a thing and everyone monkey-patches everything. Supporting your mod/content amidst other mods is in the gray area where the etiquette expects content creators to support their stuff even though there's no "warranty" on the label, so you get significant variance in how demanding players are or how accommodating content creators are.
That said, I don't think anti-cheat is the answer here. Officially supporting mods and driving modified clients down a predictable path where you'll know when and how a client is modded seems like a better approach. Modders benefit from having real infrastructure to work with, and as the game dev you can ask players to turn off mods for troubleshooting.
> Finally, we’re aware that many legitimate users install modifications to add features they wish VRChat had natively. We're very aware of the popularity of these modifications, and we’re aware that EAC means those modifications are gone, too. As such, we've been working towards native implementations of features like a main menu that's usable even when you're lying down, a portable mirror that you can use to calibrate your full-body tracking (or provide a face-cam), and more – all planned for upcoming releases.
Imagine not having even this yet and then pretending you weren't the one who dropped the ball
I hope this is the beginning of the end of VRChat and I never thought I'd be holding out hope that Zuckerborg's version will fix the mess that it was.
What community is that, exactly?
Because at least here in 2D land most seem to be accepting censorship and “moderation”
...in what reality do IKv2, OSC, and Avatar Dynamics not count as literally exactly that?
IKv2: IKTweaks
OSC: VRCSTT and other mods that leveraged tweaking avatar parameters
Avatar Dynamics: Cross- avatar interactions
'In order to prevent that, we’ve implemented Easy Anti Cheat (EAC) into VRChat.'
All this stuff sounds like it should be enforced on the server side, not client side.
'EAC is the industry-leading anti-cheat service. It’s lightweight, effective, and privacy-focused. In short, for any game or platform looking to prevent malicious users from breaking the rules, it’s a powerful solution.'
EAC is the industry-leading DRM ass. It sometimes persists game installations and you need to go to greater lengths to purge the system of its trace. I don't know what 'privacy-focused' even means here.
Honestly this whole post smells of PR.
Unless they manage to make VRChat mainstream (which will likely erase a lot of its appeal to plenty of current users and will mean directly competing with Meta), this may be the beginning on its slow end.
How?
This is always a stupid call.
Open source the clients and do the hard work of server side controls to remove abusive behavior.
Imagine forcing everyone to use one proprietary web browser with DRM because webdevs could not be bothered to implement rate limiting and input validation.
The issue is that because there is no perfect solution even if you have a pretty good all server side solution you’ll still improve by adding client side anti-cheat.
Anti-cheat systems are the compromise that allow games to be played on PCs instead of only locked down dedicated hardware.
You can have official servers that are safe from "harassment", and let people have their own "non-secure" servers they do whatever they want in. It's not that complicated.
For some instances that are public, and needs rules and clients to obey those rules, it would make sense to ban modded clients. But for some private instances, it doesn't make sense to ban anyone, as it's private and presumably accessible to only trusted parties. The instance creator ought to be allowed control.
In a similar vein, the new minecraft reporting features (https://www.minecraft.net/en-us/article/addressing-player-ch.... ) affects private servers as well, and it's not an opt-in by the server admin.
What does this mean? Do users not connect directly to private servers? Does every minecraft client have to authenticate with a central server before joining a private one?
Or is it just an on-by-default "use official banlist" option?
yes - login is required by the user iirc. You need a microsoft account to play minecraft (and i believe they recently migrated all old mojang accounts to microsoft now?)
So much for that.
The clients always authenticated before launching the game and required a valid session to join even private servers. I’ve assumed the change just disables the option to join any games similar to if they weren’t properly authenticated.
So central authentication has been a part of the game since the beginning of multiplayer more or less, but Microsoft has taken it quite a bit further with the recent changes. Quite a shame to potentially be banned from a private server I host myself, whitelisted only for IRL friends. How strict the criteria to actually get banned is irrelevant in my opinion, I bought the game over ten years ago, and now suddenly risk losing access to multiplayer, which was the only reason I bought the game. But we'll have to see how it actually gets implemented, I really hope it's opt-in, or at the very least possible to opt out for privately hosted servers, but I have no issue with it being implemented on Realms.
Yes. The way it works is that when a client attempts to join a (private) server, it sends the user id to the private server, and then sends Mojang a message informing them they it's trying to connect to a server at this address.
The private server then asks Mojang if the supplied user id is valid, and attempting to sign in to the server at this address. Mojang then replies to the server confirming the authentication of the client, and then the server lets them in.
There's also an exchange of cryptographic keys mixed in there, but that's the basics.
Minecraft servers in the default "online mode" authenticate users against Mojang's "session server". The clients get a token when they log in to their launcher and the servers then validate that token when the user logs in. This verifies both that the user is who they're claiming to be and has a legitimate copy of Minecraft.
Server admins can turn off online mode, but this means that anyone can claim to be anyone else unless some independent authentication scheme is implemented. As a result it's usually only done for actual offline servers and those that want to allow pirate copies to play.
I'm not super familiar with the current controversy but the understanding I have is that chat reports could potentially result in being unable to log in to online mode servers which seems likely to have overreaching effects.
For example Discord has a splendid unofficial client(Ripcord), but because they don't care about their users they choose to ban people who use it and force them to use the original lag-o-matic mammoth of a client(Like, seriously, an IM that takes up a gig of ram on its own).
Which is intentionally garbage to use. I'm with the GP, pop it into an unprivileged LXD container and stop dealing with their corp snooping nonsense.
This brings me to a different pet peeve of mine. Discord is really opaque in a way that it handles activity status, it doesn't show you what status it thinks you are (i.e it can show you as Online but Away or Mobile to others). Which is very annoying when working with others.
For times when I work off my iPad, I use a vnc and xdotool to press a button every few seconds on my PC (not in Discord though, don't want to get banned). That is the only way I found to make sure it shows me as Online and not breaks their T&C.
Like I get that this is HN and the hacker ethos is “anything I can do as a human I should be able to automate” but that makes the already intractable spam problem that much harder.
Preventing spam is more a task for server-side detection and filtering. Gmail's been doing it very well for decades, and i can't see why similar methods won't work for messaging. And adding a rate-limit server-side is another defence. The least useful option of banning modded clients for chats is a bad trade-off for most users whilst providing very little actual protection.
Gmail actually does rely on various forms of "anti cheat" to control spam, including obfuscated code that detects attempts to automate the browser. That doesn't help for inbound mail but it helps a lot to stop people sending spam from Gmail.
Not by an order of magnitude, esp, for chat applications that are limited by http application protocols.
> ..that detects attempts to automate the browser.
Nobody sends spam from the gmail web browser client, but suppose google successfully bans (somehow?) all other email clients, the enterprising spam sending people would still easily automate the browser, esp. with things like autohotkeys (which doesn't require modifying the browser itself, nor run code in the browser).
The point is, banning a client side mod for any service is irrational if the justification is to prevent spammers.
"the enterprising spam sending people would still easily automate the browser, esp. with things like autohotkeys"
It's not at all easy for them, and people who try approaches as simple as that don't make any money. Or didn't when I worked on it at least.
"The point is, banning a client side mod for any service is irrational if the justification is to prevent spammers."
That belief is widespread, but I built a part of my career on proving it wrong. We got unexpectedly excellent results from cracking down on alternative clients that were pretending to be browsers.
Users still get banned for that, even when they are well within reasonable use, and then they are unbanned with words “This serves you right, now use our spyware* of a client”.
* Discord used to scan your entire HDD “for games” when starting up.
Perhaps not the most crucial reason in non-competitive gaming like VR Chat, but generally many companies want to have full control of their interface. It often totally makes business sense, but comes at a cost to the users.
I worry about the day reddit closes their APIs the same way Twitter did.
Tens of thousands of hours have been spent here, and it actively increased user count and value of VRchat. Yet Tupper (ceo), not only gives nothing in return, but actively takes the work and shuts down the original.
They even banned other game devs that made good mods that were commonly known. But they didn't ban any malicious authors because they were unknown. (Duh)
They have made agreements with mod authors to not interfere with premium features, and they obliged even.
What even is there to "anti cheat" in a social game where you can do anything? This isn't an fps game, no goal, no "game". That logic is implimented per world by world creators.
Just completely disrespectful and slimy. Anything this team touches is tainted as far as I'm concerned. You don't make your product and paycheck off others work and then slap them with it. Especially not to your fellow industry.
Tbh if I were Valve id be enticed to delist this game for that behavior. It against what the VR ecosystem is for.
Valve doesn't care about VR. Last week Steam VR Fest is a proof.
Games that literally have basic functionality broken and are on the way to be completely shut off (due to servers being unavailable soon) were still discounted and promoted on page 1. While new indie games doing innovative stuff were left to rot on page 60. Nothing changed in the algorithm compared to previous year, promoting the same set of games once again.
On top of that, SteamVR unity plugin that arguably at some point powered most of VR games haven't been updated in years with any new functionality.
Modded clients aside, it's fairly easy in VRChat to have an avatar with too many performance hitting effects that can outright crash other players on lesser hardware in PC worlds. I've heard anecdotes of the Quest version, while receiving recent improvements, is also prone to crashing on mixed PC/Quest worlds. To be fair, the default view settings are aggressive enough to cull the more offensive avatars (for both performance and moral objections ) back to a safe default and it can be adjusted to taste. Avatars are also graded by their performance impact and you can see a full spec sheet of their polygon counts and various performance metrics right within the game.
They do a decent enough job providing good defaults and the content is gated in a way you can individually whitelist people and specific avatars/worlds as you experience them. There is a global "Trust Tier" system that allows you to move up the ranks by racking up play time and friend count, new players are tagged as visitors for a long enough time that it's not too hard to weed out bad actors. I don't believe I've encountered any modded clients personally but I will be interested to see what kind of effect this has in the in-game world.
Wow, I only played for a few hours and it seems like every lobby had someone trying and succeeding to crash people.
It’s opaque, unhelpful and constantly crashes my computer. There’s a whole stack of stuff I can’t play with friends, but EAC politely sends my computer into a boot-loop every time I try to play something that uses it. Apparently it’s my choice of hardware, because even clean windows installs aren’t enough to avoid its ire. And of course it won’t tell you, and epics help amounts to “uuhhh update your bios lol?”.
At least Valorants anti-cheat has the dignity to tell you what it doesn’t like, and how to resolve it.
So good luck to all the people who will effectively lose access to vr chat because of epics awful piece of software.
I don't understand how this could be the case, TFA says it's industry-leading
/s
I think there's a case to be made that VRChat allowing mods in a safe way is possible, if they wanted to do it. But they clearly don't see value in that. I hope they're proven wrong soon.
"Every month, thousands of users have their accounts stolen, often due to running a modified client that is silently logging their keystrokes as well as other information. These users – often without even realizing it! – run the risk of losing their account, or having their computers become part of a larger botnet."
People running a backdoor client and getting their passwords stolen? That doesn't sound... wrong?
Imagine if non-game companies were this open about their servers being exploitable
Some things are legitimately much easier to restrict client side e.g. for FPS: you can send other-user data all (or much) of the time and not have to worry about if they're looking in that direction, or if there's line-of-sight through the hole they just shot in a wall. That kind of thing takes a lot of server-side compute, and unless it's perfect it's still a competitive advantage.
But when it's not competitive? And they're basically just blocking abusive clients? Heck no, they do server side restrictions. And they often pay the price badly when they do not.
If you’re upset that they’re banning modding and adding an invasive anti-cheat, it’s a good time to look for alternative VR platforms or start creating your own. This is one of those cases where "open-source" means something. And while the meta verse isn’t small or new anymore, it’s still experimental buggy stuff, so a small team working on their free time may actually have the potential to compete.
I believe they do collect a ton of data on how the user interacts with instances already.
> it’s still experimental buggy stuff
Kind of. They did have several years to build up a community and find a content creation pipeline that kind of works for a lot of people. And many millions of VC.
You're right, though, ideally the "metaverse" should run on open source software.
There's still cool stuff there and unique and positive interactions to be had, but it's a slog.
What I think happens in places like this is similar to what happens in the crypto world. Money and financial situations can be abused hard, and it has been for a long time, so we have a good amount of rules, laws, international agreements and so on regarding it. Then crypto came, it kinda resembled money, and had none of these restrictions. So every trick is new again: market manipulations, all the different kind of frauds, all unprotected from the existing legal framework that we have for regular money. I think online communications enjoy a similar situation, or at least it did, for quite some time.
The Facebook crowd would be just as bad in VR, probably, but VRChat is its own sort of hive of scum and villainy.
"Second Life Is Plagued by Security Flaws, Ex-Employee Says; A former infosec director at Linden Lab alleges the company mishandled user data and turned a blind eye to simulated sex acts involving children."
https://www.wired.com/story/second-life-plagued-security-fla...
This community is now deeply imbedded in VRChat, another platform full of unsupervised children and security flaws.
In this case, an exploitable platform filled with children and near-zero moderation of sexualized content. As you know, VRChat doesn't even have an NSFW tagging system or option for users to filter such content out (without hiding all custom avatars, i.e. disabling VRChat's core functionality).
emmVRC, a hugely popular legitimate mod (referred to as a "wholesome" mod by the community), used to have this feature, but removed it an implored their users to support VRChat instead if they wanted it. Other more gray-area mods still have it.
They're going to lose that opportunity now. For what? Tighter control so VRchat can engineer their own knock off mods? Greedy. Sad.
At least it still works on Linux.
But Linux probably no longer works on VRChat
If everything goes through their servers, it seems like a huge waste of time. If it's peer-to-peer it makes sense.
I'm trying to google it and there seems to be a lot of semi-informed lore, some people say it's centralized and some people say parts are p2p.
People would want client side checks for variety of reasons. It is more performant (for your server), it is more robust (imagine you are not sending player data that are behind a wall. Now that player might be visible very quickly by moving but your server response might be too late) and some stuff is almost impossible (aim bots etc. Sure your server make some guesses but a client detecting existence of such programs is still a plus)
Suppose we have a competitive game where the goal is to click on a target quickly. Most online shooters have this property.
A cheat can always do this at least as fast as the best players in the world can.
Without client-side cheat detection, you will not be able to detect, on the server side, whether or not the commands sent from the client are coming from a cheat, of a world champion player.
Yes, client-side detection isn't perfect. But in security, perfect is unattainable.
At the time the client was Unity + Mono (haven't checked if it still is) so you could just add a DLL with your own code that gets loaded, as well as ahead-of-time patching Assembly-CSharp to introduce your own hooks. Super simple & really mod friendly.
https://neos.com/#neos-credits
The selling point of Neos used to be that it allowed 10-point full-body tracking (as opposed to 6-point) while VRChat did not, but VRChat recently added that functionality.
- real time world creation and collaboration while being in game (no external unity editor) including a node scripting system
- user hosting session (instead of full server hosting) at the cost of the user
- inventory system from which you can save/spawn from any world (this actually have a limit in size, 1Gb for the free account)
- mods are well more accepted (maybe for now because it could change like we see with vrc) and more that i forgot.
Note: I'm a regular Neos user, I'm not trying to sell the game there is stuff who are annoying (like the game is not really optimized compared to vrc).
And for the subject of crypto the community is actually really divided about it while is not really useful for now...
They're going to lose a big portion of their clientele
They want to ban them because they compete with VRC+, their premium service.
There is no NSFW tagging system, no content filtering for uploaded avatars, no effective means to permanently ban abusive users, and extremely lax in-game moderation. There are tons of sexualized, fully nude, and fully-functional avatars all over the place. Spend a couple hours in the main public worlds and you're almost guaranteed to see some. Remember, this game is absolutely full of children and pre-teens, and the kind of adults who choose to hang out around them. The game is free on the Meta Quest store with zero age restrictions.
But I would like a NSFW-tag on content.
And as a side-note: The game is free everywhere, Steam, too.
I have tested a fully SFW avatar with the NSFW flag checked in the past and I was able to use it just fine inside private and public lobbies so what we actually need here is a way for either world creators and/or lobby visibility settings to restrict what avatar flags are allowed within the current session of that lobby, as well as the ability for users to auto hide/show avatars with specific flags checked.
This wont be bullet proof as this relies heavily on user based trust (which VRChat have a long history of being against) and someone can very easily reverse what I did and mark a heavily NSFW avatar as SFWto bypass such filters, but it will be a good start for limiting exposure to these avatars.
If you’re a kid, it can be scary and potentially dangerous. The game is advertised with cartoon characters and a child-friendly aesthetic, far from what you actually find in public worlds. It’s easy for bad actors to hone in on kids based on voice, then corner them and do bad things. I’ve spoken to kids who were approached and “flashed” by much older users with explicit, ejaculating sexual avatars. It’s unpleasant and disorienting. Not to mention adults who zero in on kids, drop a portal to show them a “cool world” and then get them one-on-one in essentially an unsupervised VoIP call. This platform is practically designed to trap and abuse kids.
And yes, kids technically aren’t allowed to play VRChat or even go online using the Quest per Terms of Service. Enforcement is impossible, not that anyone tries, so kids are everywhere.
Please don't let your child talk to strangers - in person, in Roblox or VRChat, in sketchy forums, etc. If you do, set boundaries for them and have the talk about danger.
If you let your kid talk to strangers, strangers will talk to them.
To go even further, it seems the same issues occur on Twitter, Instagram, and TikTok, and those sites don't have to install kernel level anti-cheat to ensure you don't look at illicit content. At the same time, I would argue that this shows that kid-unfriendliness is an internet-wide problem and maybe we should be doing more in general to build an internet that works for kids.
They do flag you for this but not actionable on its own as PatchGuard demonstrates the exact same kind of behavior. RWX memory in Kernel Space that's not associated with a signed module.
As you also surely know, there is also a lot of rwx memory that's not actually utilized yet allocated by many drivers that you can deploy your shellcode into.
I'm sure most cheats use drivers that are pretty similar to each other (e.g. will have the same imports that show up as plaintext I think) so they can look for that. And PG threads/pages have plenty of identifiers.
> As you also surely know, there is also a lot of rwx memory that's not actually utilized yet allocated by many drivers that you can deploy your shellcode into.
Usually most cheats will use this shellcode to still jump back into the larger suspicious RWX memory region. I guess discardable sections might be large enough to hold an entire driver. I haven't really been following the latest developments in this field≥