4 ms·
hashing the binary?
by dajohnson89 7y ago
hashing the binary?
- phkahler 7y agoThe server would need to provide the binary, or at least a large precompiled core library. Even then, with all of it open source it seems like one could hack it.
- JoshTriplett 7y ago1) A modified binary can send in the hash of an unmodified binary. The server has no way to know. 2) Linux distributions compile BZFlag themselves, they don't just distribute upstream's binaries.
- thomble 7y agoI always keep a legitimate binary of BZFlag around and make sure my hacked version hashes that one instead of itself.
- Sayrus 7y agoYou can't stop cheating even on a closed source software with an anti-cheat running with kernel privileges. The same idea applies to open-source, especially as any anti-cheat feature is open sourced too. No matter how powerful your anti-cheat protection is, it can be bypassed (There were ROP-based cheats recently on HN if you want to take a look: https://news.ycombinator.com/item?id=21355058 https://news.ycombinator.com/item?id=21355058). At the very least, you won't be able to protect info like the position of entities and players (You need them even before you see the players to avoid problems, meaning anyone can create a wallhack or an aimbot). If one could create a trusted environment, that would be a different story. I do think this is possible with cloud gaming. If you can't interact with the game memory, the game files or the underlying operating system, the best you can do should be macro or AI based on what's displayed on the screen.
- jdietrich 7y agoYou can't necessarily detect the cheat software, but you can detect the behaviour of cheat software. Writing an algorithm that can play a first-person shooter at a superhuman level is pretty trivial, but writing an algorithm that plays like a really skilled human is vastly more difficult. This behavioural approach to anti-cheat is now highly practical thanks to deep learning. https://www.youtube.com/watch?v=ObhK8lUfIlc https://www.youtube.com/watch?v=ObhK8lUfIlc
- dragontamer 7y agoAs long as the network and its weights are open-source, you can create adversarial examples automatically. So the idea is to run the auto-aim bot, but then run the network on your inputs backwards to morph your inputs to look more "human-looking". Raw Autoaim Bot -> Neural Net (since its open source) -> tweak inputs until its considered a human -> send the tweaked autoaimed command.
- samus 7y agoThe weights don't really have to be open-source though. After they are trained, they should be subjected to the same policies as database passwords to counter your attack, or to at least force the cheater to train the counter-network via the game.
- dragontamer 7y ago> After they are trained Are you suggesting that BzFlag sysadmins are going to be custom-training their own neural nets? Based on my experience with LeelaZero, its far more likely for people to share weights with each other. And participate in community-training. Not everyone has the skill to spin up TensorFlow, carefully partition off training data, and monitor neural nets through training. But almost anybody can download the "latest weight file" as a Cronjob and update their bzflag server every day or week.
- itsthecourier 7y agoTo restrict this you may refuse to share the position of all units unless they are visible