Rockstar condemns Max Payne 3 cheaters to play only against each other
arstechnica.com
arstechnica.com
Unregulated cheats and hacks led a friend and I to inadvertently invent a proto-minecraft over a decade ago.
Around 1998, I was playing Dark Forces 2: Jedi Knight when I started to experience cheats and hacks. Someone taught me how to do it, which was incredibly easy (each weapon file was a text file with variables you could change: projectile=bullet, damage=5, speed=3). Simply replacing the file client side would change the behavior.
When playing around with the projectile=[id] with some ids I found while map making, a friend and I discovered we could modify all of our weapons to shoot out various world objects such as bridges, platforms, doors, etc. We started playing the game almost exclusively this way for quite awhile, going off to separate corners of a map, building things, then comparing our structures.
So, I have to say, great idea on the quarantine, Rockstar!
You could actually make more complicated hacks by making deeper modifications to the weapon/force power scripts. The game had a simple checksum on the client-side script files where it did a rudimentary count on the number of statements (method argument: one statement, pair of parentheses: one statement), and if you had a count identical to the server file, the rest of the contents of your script didn't matter. So you could basically do a lot of stuff as long as you were careful to keep the script file statement count intact: Change the properties of the levels or surfaces, give yourself all sorts of superpowers, freeze or insta-kill opponents, teleport yourself or others, etc etc etc. The scripting language was somewhat C-like and carried over pretty easily to more traditional programming.
I was one of them. COG scripting was my intro to game modding. I'd been writing small games until that point, but COG made the game a platform to develop for and that was different to anything I'd seen before.
Yeah, I was in middle school at the time.
I think between hacking that game, HTML on angelfire, and the TI-83 calculator, my trajectory for life was set.
I think the cheater's pool is a great idea though. It should be amusing at the least.
You start the game, and have 2 minutes to create defenses. After that, it's a normal game of CTF.
I forget what it's called though.
http://tvtropes.org/pmwiki/pmwiki.php/Series/TheATeam?from=M...
See: http://www.worch.com/portfolio/wot/ for a description of the planned vs implemented Citadel mode.
After they had got themselves banned from just about every server out there they launched their own "anything goes" server which could be actually be a fun experience to play on.
Another interesting thing I remember from the CS days was that me and my friends used to play the game a lot which meant that we were much more skilled than the average player. The result of this was that admins would often accuse us of cheating (we weren't) simply because our kill/death ratio was so much better than anybody elses (I used to have screenshots of myself with 40/2 kill/death ratio on public servers using pistols only).
Of course this made us pissed at the time since we kept getting banned from servers, but now I think about it where they so unjustified in doing this? Having a massive advantage over the average player whether it comes from skills or cheats still has the same affect of reducing the enjoyment of the game for average players & newbies. It's almost like having an olympic athletic squad turn up to the local school sports day and dominate every trophy.
Since I don't have as much time or interest in games as I used to when I was a teenager I tend to avoid online play in many games because the experience is generally just getting curb stomped over and over again by more experienced/obsessive players and sometimes in team based RTS games I get kicked from a team because "I don't team with noobs".
Another thing I don't understand about this is how invincibility cheats would work, I can understand things like aimbots / wallhacks because they are using information that has been pushed to the client but surely the game server should never allow something like the number of health points to be authoritative on the client end?
For Counter Strike: Source for example the server sends the location, and way that a user is pointing to the client. With some calculations you can then draw a line from the other players to where their bullets would go if they fired. Using that knowledge you can find where your hitboxes are and simply make sure that you are never in the path of their line of sight!
That is how wallhacks work as well, the client knows where the other players are so that sound can be properly calculated (so if they are further away and they fire their gun you hear less of a shooting sound and you hear a louder sound when they are closer).
Healthpoints are generally stored server side (at least for the games I've been RE'ing for fun lately), but even then you can cheat, if you have portable med kits you can take at any time, as soon as you drop below a certain percentage you take one, now hack the client to have unlimited health kits and you are set. Keeping everything and all variables on the server is impossible, mainly due to lag the game would become unplayable, and due to having so many variables to calculate there is always something you have to trust the client with (position being the biggest one, you can't take all user input, send it to the server, and then send back where the character should now be).
The faster internet connections become the more feasible it is to have a client that just renders the result and have all of the computations done on a remote server somewhere. Kinda like RDP for games. But until the game companies then also put the servers close enough by the user and build the game experience to equalise between different ping times (something CS:S attempts to do but fails at quite well, thus allowing people with AWP's to kill people that are not even near where they were scoping due to timing delays) it is going to be a huge mess and gamers will hate it.
Why not just take the user input from the client, and send it both to the model of the world on the server, and also to a non-authoritative model of the world on the client? The client is then immediately responsive, as the client model of the world is what is rendered, but if the model of the world on the client diverges from the model of the world on the server, the server overrules it.
This would ensure the client did not violate position rules, while still keeping it responsive, at the cost of an occasional noticable update when models get too far out of synch.
As far as I know many games have done this, since Quakeworld. I might be wrong, my knowledge is a little rusty?
Other issues remain that this doesn't solve (e.g. aimbot).
EDIT - Here's a wiki article this: http://en.wikipedia.org/wiki/Client-side_prediction which links to this article describing client side prediction in Half Life (so you can presume there is something at least as sophisticated in Source): http://web.cs.wpi.edu/~claypool/courses/4513-B03/papers/game...
The problem with this is that the game needs to be fully deterministic and you'd be surprised how many games use random numbers to help determine outcomes like damage etc.
This can also cause problems when you have complex physics models, many physics engines are not deterministic and small changes between the ways that different CPUs deal with floating point numbers can cause the game to generate a completely different hash.
Your comment about the differences in how CPUs deal with floats is very interesting.
I found the following interesting comment, from a GPG employee, talking about how they take care to ensure their float math is deterministic:
"I work at Gas Powered Games and i can tell you first hand that floating point math is deterministic. You just need the same instruction set and compiler and of course the user's processor adhears to the IEEE754 standard, which includes all of our PC and 360 customers. The engine that runs DemiGod, Supreme Commander 1 and 2 rely upon the IEEE754 standard. Not to mention probably all other RTS peer to peer games in the market. As soon as you have a peer to peer network game where each client broadcasts what command they are doing on what 'tick' number and rely on the client computer to figure out the simulation/physical details your going to rely on the determinism of the floating point processor."
For anyone else reading, I'd also suggest reading some of the followup posts such as this one: http://www.box2d.org/forum/viewtopic.php?f=3&t=1800&...
This is news? Isn't this the entire point of the IEEE754 standard, to save us from the days when programs that were well-conditioned on a VAX would become numerically unstable on a Cray?
'Cray instability' sounds like a Star Trek episode but it is apparently something that could happen.
The physics engine is a bit more difficult hurdle I suppose.
I'm not convinced of this, and the general trend of every online game that cares about cheating since at least QuakeWorld (1996) is moving in the direction of not trusting the client for important things.
> Keeping everything and all variables on the server is impossible
True, but you can get quite far by only giving the client the information they're supposed to have. Wallhacks were originally possible in Quake because pre-QW, the client received the position of every player on the map.
The strongest way to prevent wallhacks is to only tell the client about other players they should be able to see. The id and valve engines do this, for the most part. Again, quakeworld in 1996 severely curtailed wallhacking by only showing the users players that were visible, or "almost visible", i.e. near corners.
Your example of infinite health packs is something that could be trivially tracked on the server side and is, even for games as big as WoW. WoW tracks the current inventory of every single player in game. You can tell because sometimes when there are server glitches, you're unable to pick up loot from dead monsters.
You can hear somebody moving on the other side of the wall to you and for the sound to be realistic it needs to be played at the correct volume level determined by distance etc.
This isn't a big issue in some games , because you can just make peoples movements silent (of course there is still weapon sounds). However other games (like CS) have a stealth element where you need to make a tradeoff between moving quickly and noisily or slowly and silently so the sound is a big part of that.
I'd go so far as to not even notify the client about sounds that are too quiet and far away for the player to be able to hear in the first place. Calculating echoes on the server and having the client treat them as separate "original" sound sources should also help somewhat.
Pushing this info to the client early also allows the program to make sure all the required assets are loaded into memory before it has to be rendered.
You could stream sound from the server, but latency might be an issue.
Also a lot of older games would mainly use a hitscan model for bullet collision detection. The projectile itself was not modelled, instead there was a ray intersection test done at the time the bullet was fired so there was no "movement" for the bullet so to speak. Do most modern games now use a physics engine to simulate every bullet instead?
> Do most modern games now use a physics engine to
> simulate every bullet instead?
It might depend on the game, but as the parent suggested, the cheat could just avoid 'line-of-sight' with the barrels of the opponents guns, though those movements might become more obviously mechanical to other players.Then, one could even have a limited set of extremely beefy full-game simulation machines that run in lockstep against a certain sampling of active game sessions (like 10%), banning a large enough subset of cheaters in real-time to ensure player confidence in the game's anti-cheating system.
I think some recent AAA titles work this way, although I'm not 100% positive as I have no insight into the server end of their systems (and what I observe as automated asynchronous cheating detection could be a vast number of human observers as well).
> Keeping everything and all variables on the server is impossible [...]
> Kinda like RDP for games.
Are you familiar with OnLive?CS was also one of the first popular games where weapon recoil was modelled and new players would tend to spray full auto at a target (because that's what you did in quake).
He was of course one of those often banned, since he was able to shoot at full auto without suffering recoil. I remember playing with him; his handle was kylyk, so I went with kylyks_meatshield.
I have a few friends who were often accused of cheating in Counter Strike Source and Call of Duty even though they definitely weren't.
As soon as that guy left, I would be able to play and would appear to get much better. This would lead to me being called a cheater, on the grounds of "you weren't that good just five minutes ago".
These servers quickly became havens for players connecting using modified software (free clients and so on) and those who had steam accounts which had been "vac'd".
Ironically, included in this list were a lot of servers who hosted third-party anti-cheat software, as it conflicted with VAC - creating unjustified bans.
That reminds me of how in Mass Effect 2, secret files on the character Legion (a sapient machine, for those who don't know) reveal that he has been banned from several online games for cheating; however in each case he appealed and successfully overturned the ban.
This is about cheaters that cheat their saves by giving themselves items that they haven't yet unlocked (or bought). It's punishing those that don't care for earning items or buying them.
Source: http://www.reddit.com/r/Games/comments/uyk1v/rockstar_target...
My experience has been in two online games, one an Aces game where you flew against WWII planes and cheaters would make their planes make impossible turns or suddenly have 3000' of altitude etc. Made it unplayable. And in World of Warcraft where a sort of soft-core cheating or 'twinking' was making player vs player for non-twinks seriously non-fun, they added a 'twinks' mode where twinks had to play only other twinks. (this was done with a combination of things but it worked.)
I enjoy playing games on 'god' mode some times, and its hilariously fun with friends, and have many fond memories of running a Unreal Tournament (UT) server with some really crazy environments. So I expect there is a market there. Very happy to see Rockstar being creative here.
Such a league would appear unplayable or non-fun to those players who abide by the traditional rule-set. So it's important to segregate players by skill-range. I wouldn't have much fun trying to play football against cyborgs, but I'd love to watch them compete against each other.
Pro sports leagues are run by technophobes who don't even want to run lasers down the field to augment the referees' abilities, so we won't see cyborg sports any time soon. But online games are hardly run by technophobes, so we ought to see more and more of this insightful approach.
All games should accept that players choose their own level of rule conformance. Place players in competitions based on their skill level, and and the games will be playable and fun for everyone.
A lot of pro athletes use drugs anyway these days but making it legal would present some ethical issues.
Speaking with at least some amount of insight, I can say that cheat-detection in modern networked multiplayer action games is far from easy.
But really, it doesn't matter. You can winnow out the obvious game-breaking things like wallhacking and instant-headshotting, but to the average player it doesn't make a difference whether the person who keeps killing them is a phenomenal player or just a skilled cheater; it's not fun either way.
A solution to one is a solution to both: Your game needs to be designed such that it maintains balance and remains fun when some players are performing much better than others, for whatever reason.
True, but getting the flagrant ones is usually enough so that in any given game the average player does not have to deal with cheating.
The thing is, that once code is running on my machine technically the game is over and it becomes a huge cat and mouse game. I can choose what to execute and how to execute it. Sure it takes time to figure out all of the different ways that you are trying to detect it, but I have control over my machine and thus can make it do what I want.
This is in a relatively walled garden - the client software and hardware is controlled; the servers are controlled.
NSFW (http://www.youtube.com/user/GeneralMinus?feature=watch)
Of course there were people who didn't know the convention, and would violate this rule of netiquette. So a mischievous hacker who got sick of all the people asking "please remove me" set up a special mailing list called "please-remove-me@mit-mc" just for them, to which he subscribed people who didn't know the convention, so they could all talk to each other about how to remove themselves from mailing lists.
http://www.codinghorror.com/blog/2011/06/suspension-ban-or-h...
(There is one additional form of hellbanning that I feel compelled to mention because it is particularly cruel – when hellbanned users can see only themselves and other hellbanned users. Brrr. I'm pretty sure Dante wrote a chapter about that, somewhere.)
A lot of them are just trolls/spammers , however there are a number that I feel sorry for because they post relevant and sometimes long comments on threads and I imagine that they wonder why they are not getting any votes or replies.
I think it's easy to get off to a bad start on an online community simply because you don't understand it's ethos rather than outright malice.
* The test for a comment being auto-killed (marked [dead]) is "(or (ignored user) (< (karma user) comment-threshold*))"
* comment-threshold* = -20
* Karma is still updated on item authors if their post is dead - as long as the tests on the person doing the voting pass.
* Once you have the ignore flag set, only administrators can remove it - it is independent of karma.
* You get the ignore flag set for posting a link to a banned site, posting a comment containing banned text, or if one of your posts is blasted or nuked by an administrator.The rationale is that trolls and spammers will usually register new accounts upon being notified of a ban, but a hellbanned troll/spammer might continue to use the hellbanned account without realizing that their posts are ignored.
Sounds like a blurb to an awesome dystopian libertarian science fiction novel.
again, not a big gamer here, but i think that sounds like a totally reasonable way for the studio to minimize the negative impact of cheating on the majority of players who don’t, and while keeping those who do cheat (i’m assuming all of whom would have to be super-hardcore gamers/fans) engaged with the game and loyal to the brand (rather than being kicked-off outright).
also, and more importantly, i’m just imagining how cool it would be, and what a rush one would get, in having to compete with other like-minded hackers in a never-ending arms race to dominate in a (game) world of cheaters!
And for many, having to compete with other cheaters would be boring and annoying, since for them the main satisfaction is 1) making ridiculously large scores compared to others and 2) watching others complain and leave.
An indication that this wouldn't be attractive to them is the fact that there are many Punkbuster¹-free servers out there, yet cheaters still spend time looking for cheats that can evade it.
¹ Anti-cheating system.
(for reference: http://en.wikipedia.org/wiki/Valve_Anti-Cheat)
For those not familiar, a bit of gaming history: Tribes is a FPS where the players have jetpacks and can fly around in the air. The jetpacks have limited energy, so players ended up having to spend a lot of time on the ground too. One particularly innovative aspects of Tribes was it's expansive maps. It was like a Battlefield game, but 5 years earlier. By only running and jetting, it could take minutes to get across a map, which is important considering the primary objective of the game was to move the opposing team's flag from side of the map to your team's side.
The hack was: players discovered that jumping at the instant the player lands on downhill surface caused them to accelerate in the downhill direction. Mashing repeatedly on the jump key going down a large hill would cause the player to accelerate all the way down the hill, as if there was no friction with the ground (hence "skiing"). Someone wrote a script that automated this act so all a player had to do was hold down the jump button instead of pressing it repeatedly.
This bug completely re-invented the game into something no one imagined it would be. Many players embraced it, I am sure some did not. It added a layer of complexity and made the game addictively fast paced (with skill you could now get across a map in seconds). The competitive community embraced the new style of play and the developers had no choice but to not patch the bug. This bug arguably became the defining gameplay aspect of Tribes.
The lesson? As mentioned here many times, the users are what make your product special. Sometimes they will invent uses for it you never imagined :)
There was an article on HN a few months ago (can't find it right now) that discussed hooking into the GPU to avoid detection.
Sorta like the idea that there should be two leagues for the Olympics, the Tour de France, et al.: one with steroids, one without.
It would be interesting to see which got more viewers.
However people who go to jail tend to come out more dangerous and knowledgeable than before.
in any case, it sounds like this could actually be a little more fun. I give it a 50/50 chance of working how they anticipate.