Live data from Hacker News

Winning at Candy Crush

stavros.io

11–20 of 148 posts

Re: Winning at Candy Crush

#12
post #8

it is crazy that a game that makes multi million dollars every day has no server side validation at all and just trust the client. crazy

Why spend unnecessary resources? People trying to cheat will find ways that are very hard to prevent.

Which brings us to another question - besides hackers, who is interested in cheating these kinds of games? Probably people who want to impress their group of friends who also play the game. I smell a market opportunity here.

Re: Winning at Candy Crush

#14
post #12
post #8

it is crazy that a game that makes multi million dollars every day has no server side validation at all and just trust the client. crazy

Why spend unnecessary resources? People trying to cheat will find ways that are very hard to prevent. Which brings us to another question - besides hackers, who is interested in cheating these kinds of games? Probably people who want to impress their group of friends who also play the game. I smell a market opportunity here.

Isn't that how Candy Crush makes money now? You spend money to buy your way to new levels, through the use of special items and bonuses. Or are you targeting the subset of people who want to pay to cheat, but want it to be secret.

Re: Winning at Candy Crush

#15
post #12
post #8

it is crazy that a game that makes multi million dollars every day has no server side validation at all and just trust the client. crazy

Why spend unnecessary resources? People trying to cheat will find ways that are very hard to prevent. Which brings us to another question - besides hackers, who is interested in cheating these kinds of games? Probably people who want to impress their group of friends who also play the game. I smell a market opportunity here.

Surely there's a big market for cheats? You could sell Candy Crush powerups for half price to all those people who are buying them now...

Re: Winning at Candy Crush

#17
post #13

Earlier quoted context omitted.

I take it that the secret key is visible in the requests within Charles?

Yes in a way, but actually no, it is hashed with some other values.

It's both hashed and the first few chars (four, IIRC) of the hash are transmitted, so it's really unlikely that one will be able to brute-force it.

Re: Winning at Candy Crush

#18
Step 1: ATT adds the 'infinite lives' interception/response to the proxy servers for the Starbucks hotspots/WiFi.

Step 2: Starbucks Marketing advertises 'Unlimited Candy Crush lives at Starbucks!'

Step 3: Profit! Well, assuming all of the squatters actually buy stuff.

Re: Winning at Candy Crush

#19
Awesome breakdown. I wrote a blog post in late September - based on some industry rumors - that speculated on whether Candy Crush was "cheating" by varying the random seed to generate monetization or retention events:

http://blog.thinkgaming.com/is-candy-crush-cheating-will-it-...

Based on the "seed" going back and forth at the start/end of games, I'd have to assume that they are doing something with it. Anyway to see if that's happening?

Re: Winning at Candy Crush

#20
post #16

What's the best solution for this, managing game state server-side? Did they do it this way to offload storage and processing for scalability reasons?

For one, sanity checks (this level can't really be solved in two seconds, that score is too large, etc). For two, probably more signing of requests, but that's pretty easy to bypass too. You really shouldn't be able to get ten thousand of something when the most the game gives you is two or three per day, though.

I guess they did it this way because they don't care about people cheating, since pretty much only one person (me) will bother to do it, and it will have no benefit other than their friends being puzzled.

Post reply on HN