Live data from Hacker News

Rainbow Six Siege hacked as players get billions of credits and random bans

shanethegamer.com

151–159 of 159 posts

Re: Rainbow Six Siege hacked as players get billions of credits and random bans

#151

Earlier quoted context omitted.

> He sees an opportunity to let others do the work and investment to build platforms, then selectively swoop in to compete once the risk and investment pay off. Sure. Just as long as you agree Google and Apple let others do the work and investment to develop new games, apps and media, then swoop in and demand a cut if the risk and investment pay off.

They don't automatically take a cut, they only take a cut when you want to sell to their captive audience, on their hardware, using their distribution system. Wait until you hear about how the entire entertainment industry has always worked!

Their hardware, huh?

You're right, customers don't really own an iphone, even if they've paid $1000 for it.

Re: Rainbow Six Siege hacked as players get billions of credits and random bans

#152

My heart goes out to the devs forced to return to work to solve these issues. Numerous groups claiming numerous exploits - mostly MongoBleed. One has to wonder: why didn't anyone anticipate this happening? Surely the moment this exploit was discovered the team would've locked it down immediately?

If this is a result of that vulnerability, Ubisoft only have themselves to blame. Our support contacts ensured that we knew about the vulnerability as early as possible and gave us a clear guide to remediation for our self-hosted clusters. Our Atlas clusters were automatically patched before this was announced publicly. You'd have to be running your database open to the internet (already a mistake), ignore the advice to simply turn off zlib, and ignore the fixed versions that have been available for over a week.

If you're going to be in the business of running your own critical infrastructure, you better have spent a lot of effort planning for these situations, because they are inevitable. Otherwise, it's easier to just pay a vendor to do it for you.

Re: Rainbow Six Siege hacked as players get billions of credits and random bans

#153
post #140
post #120

Earlier quoted context omitted.

1. They're not, not sure where you've seen that, not in western games at least.

> "The researchers investigated the techniques used in online game cheating, as well as those deployed by ‘anti-cheat’ technologies. Most modern anti-cheat engines run in the Windows kernel, alongside applications such as anti-virus, at the highest levels of privilege. Software can only run in the Windows kernel if it has been approved and signed by Microsoft. This makes it more powerful than software run normally by…

None of that talk about exploiting anti cheats, nowhere. Not a single concrete example.

The goal of cheats is to make money not to hack PCs.

Re: Rainbow Six Siege hacked as players get billions of credits and random bans

#154
post #153
post #140

Earlier quoted context omitted.

> "The researchers investigated the techniques used in online game cheating, as well as those deployed by ‘anti-cheat’ technologies. Most modern anti-cheat engines run in the Windows kernel, alongside applications such as anti-virus, at the highest levels of privilege. Software can only run in the Windows kernel if it has been approved and signed by Microsoft. This makes it more powerful than software run normally by…

None of that talk about exploiting anti cheats, nowhere. Not a single concrete example. The goal of cheats is to make money not to hack PCs.

https://www.threatshub.org/blog/ransomware-actor-abuses-gens...

> Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus

Re: Rainbow Six Siege hacked as players get billions of credits and random bans

#155

Earlier quoted context omitted.

They don't automatically take a cut, they only take a cut when you want to sell to their captive audience, on their hardware, using their distribution system. Wait until you hear about how the entire entertainment industry has always worked!

Their hardware, huh? You're right, customers don't really own an iphone, even if they've paid $1000 for it.

Surely in context, and reading the most charitable interpretation, you understood that the hardware I was referring to isn’t the end user’s device.

Re: Rainbow Six Siege hacked as players get billions of credits and random bans

#157
post #113
post #72

Earlier quoted context omitted.

"kernel anti-cheat" is actually a re-branding of "anti-(non steamdeck)-linux" software, probably to please msft (since sole beneficiary). We all know they are inefficient and weaponized by hackers. You know on linux there is a feature for a process to snoop into another process, that for the same user (non root), can be use for anti-tampering: with a proper "security" team, as all live-service games should have, you…

> We all know they are inefficient and weaponized by hackers. Name an exploit in EAC/BattlEye/Vanguard/FaceIT/whatever other big name anticheat middleware (though Vanguard and FaceIT don’t sell their services I think) that has actually been used for anything. Genshin Impact’s driver got used as a vulnerable driver that one time, yeah. EAC had an exploit to inject your own code into processes, but that quickly got pat…

Well, I read HN. I did stop counting.

Unless you beleive in the conspiracy of AI generated news on HN.

You are the same type of guys who is going to try to sell 'computer security' as a deliverable, thing which does not exist.

Please, stop that.

Re: Rainbow Six Siege hacked as players get billions of credits and random bans

#158
post #111

Earlier quoted context omitted.

Yeah, we do those things. 1) they’re not foolproof 2) there is a delay in aggregating the data this has annoying effects when the game has a trial period/goes on sale/has lots of cheap CD keys floating around. 3) if you weren’t delayed then the cheaters get better at adjusting to how you catch them. We actually do a lot of statistical analysis, but it works in tandem with endpoint anti-cheat, and would hardly work at…

I know when I spent a lot of time dealing with fraud in a different market, the most effective tool was to catch and shadowban the accounts rather than banning them. If we banned them, they just created a new account and kept doing the same things. When we detected them and the isolated them from all other good standing accounts, only allowing them to interact with other shadowbanned users, it virtually solved the pr…

And to manage this purgatory and detect the accounts which will end up there, a live-service game needs an active, permanent and competent team of honnest people, period. If a game studio is not ready to do just that for its live-service game, it has to stop developping that game and move to another type of game.

Give this team server side data, user level 'traps' and 'pitfalls' with frequent updates (they do that for dota2 and probably cs2, they don't need a kernel module), and you should end up with a rather sane gaming experience.

Re: Rainbow Six Siege hacked as players get billions of credits and random bans

#159
post #153
post #140

Earlier quoted context omitted.

> "The researchers investigated the techniques used in online game cheating, as well as those deployed by ‘anti-cheat’ technologies. Most modern anti-cheat engines run in the Windows kernel, alongside applications such as anti-virus, at the highest levels of privilege. Software can only run in the Windows kernel if it has been approved and signed by Microsoft. This makes it more powerful than software run normally by…

None of that talk about exploiting anti cheats, nowhere. Not a single concrete example. The goal of cheats is to make money not to hack PCs.

In the current state of things, YOU have to provide the proof a kernel anti-cheat is not weaponized by hackers (yet...). It is now common knowledge, kernel level anti-cheats are leveraged by hackers.

And we all know this is fully hypocrit. "Computer security" does not exist, but for sure, adding a "gaming" _kernel module_ won't improve anything there... (irony).

Post reply on HN