Valve DNS privacy flap exposes the murky world of cheat prevention
arstechnica.com
arstechnica.com
> Cheat versus trust is an ongoing cat-and- mouse game. New cheats are created all the time, detected, banned, and tweaked. This specific VAC test for this specific round of cheats was effective for 13 days, which is fairly typical. It is now no longer active as the cheat providers have worked around it by manipulating the DNS cache of their customers' client machines.
Damn.
Some of the more recent anti-hack work involves recognizing pattern of commands sent from the client to detect when inhumane actions occur such as impossibly fast reactions or aim adjustments. The way I see it, hopefully this style of anti-cheat, although reactive, will prevent any hack from being useful as the advantage of using it is immediately taken away. Things like trigger hacks and wall hacks are still not yet detectable through these means but its a step in the right direction.
Spooky
According to Gabe, this module was not aimed at scraping anyone's web usage or browsing history (not even for game cheat sites), but just to detect whether a machine was likely to be automatically dialing a hack's DRM server, and then sending hashed copies of those, and only those, entries to Valve to flag as a potential cheat. I can imagine that a lot of the gaming community would consider that reasonable behaviour, if it was effective at cutting down on cheats.
Whether Valve is telling the truth, I don't know. I suspect so (Gabe seems smart enough not to try lying to the internet, though, so any deception is likely to be that of omission). Whether this is right or wrong is a matter between you and your shaman/vicar/rabbi/mullah/conscience/etc.
Huh, I didn't realize that nowadays cheat mods charged money and protected themselves with DRM. When I used to dabble in such online games, the cheats/trainers/etc. typically came from the same groups that cracked games' DRM, rather than themselves having DRM.
Are there cracking groups that strip DRM from DRM-using cheats?
Sounds like first the cheat process needed to be detected on your system, then the DNS cache would be checked.
On the surface it sounded like a privacy issue but with these extra details I am having trouble seeing an issue.
If they would tell everything they do it would be way easier to circumvent them. Sure everything will be reverse-engineered eventually but it's a continuous process. They add new ways to detect the cheats and the bad guys try to circumvent them faster than Valve is able to add new features.
"It wasn't until 1987 that Peterffy was able to take people out of the loop entirely. With the world's first electronic stock exchange, the NASDAQ terminal, traders could type in orders directly into a computer.
Peterffy didn't want to type in the orders. He and his engineers hacked into the NASDAQ terminal and wired it up to their own computer, which traded automatically based on algorithms.
A senior NASDAQ official saw Peterffy's setup and said Peterffy was breaking the rules: All orders had to be entered through the keyboard. He gave Petterfy's group one week to fix the problem.
Peterffy and his engineers came up with a solution. They built a robot with rubber fingers that typed entries into the keyboard. It satisfied the NASDAQ rules. And on active trading days, the robot typed so fast it sounded like a machine gun."
That said, it's fun to try to think of ways in which a robot reaching over your shoulder could somehow give you an unfair advantage... perfectly-timed bunny jumps, perhaps.
I do admit it was a lot of fun and incredibly difficult coding to do, the cheat provider programmer was very clever. No clue if it still works today since I left a while ago. It was like military defense vs offense; each side keeps upping the ante and you have to respond.
Oh and it was for Windows and custom code but not this.
Cheating in MMOGs isn't much of a battle. Do everything on the server: problem solved. Consider UO did this correctly in 1997 and yet games like WoW came out much later and still did it wrong (let the client choose its x,y,z position and tell the server, rather than asking the server "is it legal for me to move to x,y,z?").
It is faster paced games where you can't do everything server side that are the problem, first person shooters being the prime example.
And yet ultima online proved that excuse was bogus before WoW ever existed.
First person shooters can be (and I believe usually are) done server side. Official movement, firing, health, and overall physics is handled 100% on the server. To smooth things out though, the client interpolates its view of the world.
For example lets say you fire your gun at a person right in front of you. The server would have final say of whether you actually hit the target. Rather than waiting for a round trip to the server, your client may choose to immediately show some blood/shrapnel effects to give you the illusion that you hit them. If you actually did, the server will handle the health deduction. If not, you probably wouldn't even notice.
Movement and such can be done server-side, mainly.
But visibility pretty much has to be done client-side. Which means that people can hack the client to see through walls. You can do culling server-side to an extent, but not entirely - because otherwise someone with a high latency coming around a corner will have no chance against someone with low latency on the other side.
Also, servers pretty much have to (well, not really. But otherwise games become unplayable to those with higher latencies, as where you see other players is not where you need to fire to hit them) allow you to hit someone that was, according to your client game tick, in target when you fired. Which means that the client has to tell the server what game "tick" the client fired on. Which allows for cheating if the client deliberately tells the server that it fired/started to move on an earlier tick than it actually did.
You've already explained a big chunk of the issue right there. There are many poorly written games. PoE is one of them. That doesn't mean you can't write a similar game well.
These questions are not always straightforward. Why can't you do this in a shooter? Because any mouse position on the screen is valid. How do you know if the user physically moved the mouse or it was some other software that moved the mouse cursor?
How do you know the user genuinely decided to aim at a random enemy, instead of relying on an on-screen display of player information that is not normally available?
You can't do everything on the server side. If you could, it wouldn't be an interactive game.
Being able to directly set your position in an MMO is not the only way to cheat. Some MMOs have rules against plugins and helper tools. Those are also cheats. You can hack the client and display more in the minimap, or show you exactly how much HP some monster has, run a bot to control your character, etc.
Doing everything on the server only prevents god-mode types of cheats. You can also cheat with extra information, computer assistance, etc.
Yeah, I know the guy who wrote it.
>which let you fast walk
No, it let you work around having a high latency dialup connection. All it did was watch for outgoing movement request packets and respond to them with OKs. The server was still checking though. So if you tried to move somewhere you couldn't, your client would see the OK from UOE, then later see the "nope" from the server and you would rebound back to where you were, and you would often get your client's idea of your position desynced from the servers, which was the one that actually mattered.
>You could dye items glitched out colors, because the server didn't check that you chose a valid color from the dialog
Yes, there were many bugs. Large and complex software has bugs. That bug was fixed. Which demonstrates exactly my point, that you can in fact do everything server side.
>You could reveal hidden people, because the server just tagged them with a "hidden" flag, instead of not sending their location at all.
Which packet sets the "hidden" flag again? http://necrotoolz.sourceforge.net/kairpacketguide/
If I remember right there were actually two stages of the run hack in UO; in the first it was an advantage when the server itself was laggy and not just the client, later it was only an advantage for working around laggy connections and had severe rubberbanding and desyncing.
And no, this can never be worked around solely on the server without resorting to something like OnLive. Another thing I didn't mention about UOE was it could make it always be daytime--how are you going to work around that on the server?
As for which packet: http://necrotoolz.sourceforge.net/kairpacketguide/packet78.h...
which links to: http://necrotoolz.sourceforge.net/kairpacketguide/CS/mobiles...
Which has the status "hidden"
> None
http://www.reddit.com/r/GlobalOffensive/comments/1y0kc1/vac_...
The line between what is "tool assisted", "bot" etc. is entirely artificial, just like "no drugs" is artificial and awkward to deal with in sports. If you're spending $1000 on a fancy computer mouse with special buttons, I don't see why that's much different than if I code myself a smarter mouse driver that autosnaps to enemy faces.
The intellectual exercise of botting is fantastic anyway, and I'd rather see my gamer friends doing that than playing the games vanilla ;)
Online games require a gentleman's agreement about what is OK behaviour. Individual communities should be hosting their own game server instance and allowing people in that follow their friendly rules.
The idea that I'm "not allowed" to "bot" a game is offensive to me in the way that "no reverse engineering" clauses in license agreements are offensive. I do love playing games, and don't normally bot anything (except netcraft this one time.. o_O), I concede there's a conflict here, but I err on the side of my personal liberty rather than convenience of playing games. I wish others would do the same...
Basically, players who have been detected as cheaters only end up with other players who cheat. The problem is once you're on the island, you're probably not getting out.
I personally favor this solution over the outright banning of players.
http://play.esea.net/index.php?s=esports&d=comments&id=12692
> cheat software has its own DRM systems so that the developers can ensure that people pay for their cheats. If the VAC module detects certain cheats, it then checks to see if the system has performed lookups for the relevant cheat DRM servers.
The program could also hijacked the users bank session in order to check if any payment has been made. This would have the same result on a technical basis as digging through users DNS history to see if the client has contacted a cheating tools DRM server.
Is there any technical line that anti-cheat systems can't cross? I do like the gaming experience anti-cheat systems create, but at the same time, I would like that the OS prevented any program from accessing the DNS cache without my expressed and informed consent.
Not technically feasible. Even if the OS didn't allow direct access to the DNS cache, a program could very easily infer if a result was cached based on the query response speed.
Plus anti-cheat typically runs as an administrator or root.
> Is there any technical line that anti-cheat systems can't cross?
Illegality for one. Stealing someone's banking session and monitoring their payments is almost certainly illegal, pulling up the DNS cache and seeing if they requested the IP for a choice domain is not.
If the intention is the same (preventing cheating), I don't know if a judge would rule different based on the technology used. Both techniques steals computer resources (CPU, memory and disk usages), and both steals private information in order to achieve their goal. Would you be sure that knowingly use a computer service (the dns cache) without authorization is legal? Or for that matter, is computer trespass illegal in general if done for the explicit purpose of anti-cheating? The law as described require "intent to commit or attempt to commit or further the commission of any felony".
No.
a cat and mouse game, but interesting nonetheless
It costs $40 a month, and people seem to be happy to pay that.
Valve isn't even the worst offender, some other anti-cheat will not allow you to run ANY virtualization software while the anti-cheat is active.
Oh, wait, it's Peter Bright, nothing to see here. Move along.
Comment:"So you are saying that the tests people had done by bloating DNS and watching traffic that noticed a correlation are wrong, and only hashes that meet a list sent to the client are checked and sent back to Valve? Why would the data sent back to Valve increase on systems without cheats when nothing other than loading many DNS entries is different? Where is the check done?..."