13 ms·
EA got hacked and games source code leaked including new game Battlefield 2042
- agilob 5y agohttps://news.ycombinator.com/item?id=27462952 https://news.ycombinator.com/item?id=27462952
- whereistimbo 5y agoShould I shed tears for them for getting hacked, or laugh to them because they are not taking security seriously?
- emilsedgh 5y agoI'm inclined to laugh at them but honestly what does it even mean at this point to take security seriously? It appears that the only companies capable of being secure are Google and Apple. Aside them everyone is getting hacked every other day.
- papito 5y agoImagine a world where there is no, say, AWS. So many basic security things that we take for granted are automatically set up for you in the cloud, as most shops out there could not care for it to save their own lives. Companies that torch through millions of dollars of VC money need a nice ransomeware kick in the ass to set up a MongoDB password, and will proactively ignore S3 warnings to not make something public, so what do you expect?
- bserge 5y agoI can imagine it, I see many independent security consultants and companies making money instead of Amazon.
- NmAmDa 5y agoI think this my first time I see a leaked source code for a closed source product before its lunch. Viva battlefield 2042. Cheats will be available in a time record.
- din-9 5y agoHalf Life 2 was a big one https://www.eurogamer.net/articles/2011-02-21-the-boy-who-stole-half-life-2-article https://www.eurogamer.net/articles/2011-02-21-the-boy-who-st...
- Hamuko 5y agoThe Half-Life 2 leak happened way before launch (13 months) and there were a lot of changes when it actually released. 2042 is much closer (4 months) if the release date keeps.
- joshspankit 5y agoThe HL2 leak was super cool and practically a behind the scenes copy. Untextured walls, unfinished levels, all sorts of fascinating test areas. Great reference.
- Aeronwen 5y agoShed tears because they're not taking security seriously.
- guavaNinja 5y agoNo, laugh to them for getting hacked. It's EA afterall.
- joshspankit 5y agoIn the old days, EA used to mean genuinely good games with great level design. It’s not even close to the same company now, but I understand some people being sad because they still think about EA as old EA.
- qwerty456127 5y agoI feel neither sorrow nor laugh. Just joy about the fact the source code is going to be available.
- NmAmDa 5y agoMaybe it is not going to be available publicly after all.
- squarefoot 5y agoNot sure if it is a good thing, besides plain studying, though. Imagine some developer in perfect good faith who finds some interesting graphics code online with no references to EA and a fake Open Source license attached to it, and that code happens to be part of EA's code, then imagine this developer incorporating them into an Open Source game, maybe just 150 lines of code out of several tens of thousands. EA's lawyers would hardly ignore him, and the poor guy would see his own career and possibly his entire life ruined. Not to mention the possibility of becoming a case against Open Source.
- rplnt 5y ago> because they are not taking security seriously? I don't think is necessarily the case. You can take security seriously, but there are limits, and you have to balance the effort with the willingness of someone breaching your safeguards. I would use a bicycle as an example. You can buy whatever lock you want, it can be broken by someone. The better the lock, the less people can get through it or are less inclined to do so anyway. You can pay a security guard to look after your bike, but at some point, if your bicycle is really valuable, one guard can be bribed (or killed), and so on, and so on. In summary, just because they were "hacked" does not mean they are not taking security seriously.
- silviot 5y ago> In summary, just because they were "hacked" does not mean they are not taking security seriously. To some extent though it does mean they were not taking security seriously _enough_. In your example, they misjudged whether they needed a guard or not. [EDIT] Actually, I realized it's not about taking it seriously, but executing it efficiently.
- sabas123 5y agoEven so, they could have defended perfectly against a threat model, which might have been completely reasonable. But it might have been pure bad luck. Although I don't know any of the details.
- darumderum 5y ago> I don't think is necessarily the case Back then, when they enforced a maximum 16 character password, I saw enough security. Are they storing them in plaintext or what? Btw, I think they increased the limit to 32 now
- kenniskrag 5y agosome hashing algorithm don't allow longer passwords. https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html#:~:text=bcrypt%20has%20a%20maximum%20length,be%20enforced%20when%20using%20bcrypt https://cheatsheetseries.owasp.org/cheatsheets/Password_Stor....
- incrudible 5y agoRealistically, what are you going to do to protect against this case? Your developers/artists are going to use Windows machines, they're going to need access to the source code and access to the internet. Add in a 0-day and that's all the the ingredients to allow for exfiltration of data. Ultimately, there is no protection against this. Of course you can make your employees' lives worse by siloing them off, enforcing all sorts of security policies and so on. It's just not worth it in this case. So the source code of some video games got leaked... big deal. What are hackers going to do with it, make their own version of Battlefield and FIFA? Write snarky comments on how crappy the code is? Maybe they'll develop cheats, but that can also be done without the source code.
- nradov 5y agoApplication whitelisting can prevent most vulnerabilities from being exploited.
- incrudible 5y agoApplication whitelisting can prevent the execution of unapproved executables, that's about it. Oh, you need to run Python scripts? You're using npm? There go your whitelisting efforts... Whitelisting also won't protect you from exploits in the software itself. If some non-technical user gets compromised and starts sending out malicious PDFs, you better make sure every single installation of Acrobat is up-to-date. If you get hit by a 0-day in Outlook - good luck. Now perhaps in this case people were just sloppy, but again, if you want to rule out exfiltration of data - as opposed to just making it less likely - you need a completely different approach and it'll cost you.
- deleted 5y ago[deleted]
- Bancakes 5y agoCapcom, CD Projekt Red, and now EA?
- markedathome 5y agoUbisoft and Crytek were also hacked last October
- inDigiNeous 5y agoYou forgot Nintendo.
- kingofclams 5y agoThis is news to me, what happened to Nintendo?
- sumtechguy 5y agoFrom what I remember a company that had a copy of Nintendo's source code for many N64/wii items got hacked and people took a copy of the code. That company was making some sort of portable hand held N64 thing. Apparently Nintendo had copied more into that copy of the repo than they intended and so a bunch of stuff leaked. It was mostly early 2000s stuff.
- swebs 5y agoLots of source code for old games and console firmware was leaked about a year ago. https://en.wikipedia.org/wiki/2020_Nintendo_data_leak https://en.wikipedia.org/wiki/2020_Nintendo_data_leak
- TameAntelope 5y agoIs it possible that corporations generally are getting so large that comprehensively securing their entire network is more or less untenable? Maybe instead, individual business units (or even smaller) should be independently responsible for security.
- swarnie_ 5y agoIt couldn't happen to a more deserving company.. Well, maybe Ubisoft.
- NetOpWibby 5y agoThat actually happened in Watch Dogs 2. It was a funny tongue-in-cheek mission.
- dijit 5y agoI worked for Ubisoft, curious why you think we’re worse than EA.
- AlexandrB 5y agoAs far as I know, EA did not permit and then cover for a bunch of sex pests in upper management[1]. It's sad that the work of a bunch of talented people is tarnished by these kind of management misdeeds. [1] https://www.bloomberg.com/news/articles/2020-07-21/ubisoft-sexual-misconduct-scandal-harassment-sexism-and-abuse https://www.bloomberg.com/news/articles/2020-07-21/ubisoft-s...
- dijit 5y agoI worked for Ubi during that time and honestly, I think if Yves had known any of this Serge would have been let go long ago. The head of global HR was covering for Serge. She was axed immediately (as was Serge). It’s important to know though. Serge was _insanely_ core to the functionality of Ubisoft; he was the sole approver of every AAA game. Axing him was like removing the beating heart of the company to shareholders. Obviously our morality says that this was the right thing to do, but I’ve seen other CEOs who would cover for such an “invaluable asset”. And Serge was axed before this was public, so it’s not like the hand was forced- there was a “creative directors board of editoriale” which sprung up shortly before because of this.
- swarnie_ 5y agoThey publish the same sandbox reskinned 3 times a year, i could effectively do your job with a find and replace tool coupled with Ctrl C + Ctrl V.
- MIBMA 5y agoI'm really interested to know more about the actual effect this will have on EA. Because other than the problems with potential cheats and bots, there are not much anyone can do. No one will use closed source engine for developing a game without permission. Maybe the only other problem for EA is if there are many exploits that can lead to a serious security implications.
- alpaca128 5y agoI've heard Titanfall 1 and 2 multiplayer are basically unplayable for many people, as a hacker with knowledge about the game's internals managed to get such comprehensive access to the multiplayer servers that they can literally ban certain players (like streamers) independently of IP address or game account. And so far developers haven't been doing anything even though it's been going on for many months. So the worst case scenario could be worse than just a few cheaters. Either way EA will endure it without problems because it's barely different than the average bad game launch.
- MIBMA 5y agoI don't know about this game, but I wonder how this hacker can identify those certain players without targeting their IP or account. The only thing I can think of is if the game collects data about players statistics with Mac addresses included. This way he can ban them if he got internal control which is something developers should be able to handle and I wonder why they didn't quickly. They can rewrite the control module of the servers for example instead of just doing nothing and lose everything.
- dleslie 5y agoThey aren't. No one can play TF1 because the hacker is applying a denial of service attack on the servers. Worst part is that the denial doesn't appear to be bandwidth-intensive, just a persistent trickle of bad requests. The hacker may even have forgotten they left the script running, somewhere.
- 5y ago
- ryanjshaw 5y agoWow: "Source code is a version of computer software which is usually much easier to read and understand than the end version in a finished product, and could be used to reverse engineer parts of the product."
- aurbano 5y ago> usually much easier to read and understand They would be doing something seriously wrong if that wasn't always the case haha
- ejolto 5y agoMaybe EA writes their games in brainfuck.
- odiroot 5y agoRemember the golden days of Perl?
- Retr0spectrum 5y agoCodebases with high levels of abstraction and metaprogramming are often easier to understand in IDA/Ghidra, if your goal is to understand how a specific part of the program works.
- meowface 5y ago
- 0xThiebaut 5y agoI must be missing something but I don’t see any mention that the Battlefield 2042 source code got leaked, nor in this article nor from any other credible sources. There is a difference between the game engine and the game itself.
- slezyr 5y agoThe title is incorrect in many ways. The source code is stolen, not leaked. Source codes of Frostbite + FIFA were stoles, not other titles.
- bserge 5y agoFIFA? That could be 10 year old source code, who can tell the difference?
- amarant 5y agoYou look for references to new players. Can't find any? It's an older FIFA then.
- nkozyra 5y agoWould you expect those assets to be included in source code, though? Roosters are generally fully customizable and EA games vary little year to year, I wouldn't expect players to ever show up in source.
- gmueckl 5y agoThat depends on how data driven player appearance, animations and behaviors are. I would start with the AI code and see if there are any player specific exceptions (that is, hacks) in there to match a certain play style.
- fullstop 5y ago> Roosters I know that joking is not appreciated on HN, but the mental image here is absolutely fantastic. I'm giving my rooster a gigantic beak and three legs.
- animal531 5y agoAt least now we can get Fifa 22-25 as soon as next month.
- mtrovo 5y agoA really good time to get access to the loot box code and verify what exactly are the drop rates for items.
- EricMausler 5y agoIf you find out, please update
- BatteryMountain 5y agoIt probably comes from config/database, not hard-coded, so might not get it after all.
- deleted 5y ago[deleted]
- e_proxus 5y agoWith the code it should be easier to fake a client, download and decode that configuration. Hopefully some further experiments can be done with access to the real source.
- bspammer 5y agoThe configuration will be server-side only. It would be madness to generate the lootbox result client-side.
- ryathal 5y agoI think it's Korea or China that requires the rates to be published, so they might be available somewhere already.
- layoric 5y agoI wonder if some of the persistent cheaters like Tufi from Apex Legends have gotten hold of the source code, making it easier to find exploits. https://www.eurogamer.net/articles/2021-05-11-unbannable-apex-legends-cheater-faces-potential-legal-action https://www.eurogamer.net/articles/2021-05-11-unbannable-ape...
- tyingq 5y agoThankfully, no ransom. That fire doesn't need more fuel.
- Tenoke 5y agoHow is stealing something better than stealing something + optionally offering to return it for money?
- jfrunyon 5y agoBecause ransoms are more profitable and therefore more likely and therefore more profitable...
- tyingq 5y agoPersonally, for me, because the decision makers around me are spending an inordinate amount of time worrying and talking about ransoms. It's the overworn topic-du-jour, and I'm happy for something else to shift the news cycle.
- thomastjeffery 5y agoBecause we are talking about copying, not stealing. Critically, the thing was not taken away, and the victim is still in possession of it.
- martin_a 5y agoAre these games any different than in name and textures? Looks to me like it's all the same since Battlefield 3 and they only change the look. But possibly I'm too ignorant and expect too much of major game releases.
- ZuLuuuuuu 5y agoIs it known what kind of source code hosting solution EA is using that got hacked, and how it got hacked?
- kizer 5y agoAlthough I don't condone hacks like this of course, I think it would be amazing for someone to interpret the engineering and mechanics behind a title like FIFA for the rest of us; I'd look through the code myself though I'd imagine it would take a long time to make sense of it. Same for Frostbite. I'm just curious about the tech behind AAA games and it would be fascinating to explore the innards.
- brink 5y agoHopefully this means we'll finally get dedicated servers from the community for these games. I'd love to contribute to something like this.
- RGamma 5y agoModdable dedicated servers are the best. There's still active communities on e.g almost 20 years old CS:S and probably older games. Of course not best for financials
- arduinomancer 5y agoThere is literally no mention of 2042 in the article. Where does it say battlefield 2042 was leaked? All I see is Fifa and Frostbite (a game engine)