5 ms·
I'm really interested to know more about the actual effect this will have on EA. Because other than the problems with potential cheats and bots, there are not m
by MIBMA 5y ago
I'm really interested to know more about the actual effect this will have on EA. Because other than the problems with potential cheats and bots, there are not much anyone can do. No one will use closed source engine for developing a game without permission. Maybe the only other problem for EA is if there are many exploits that can lead to a serious security implications.
- alpaca128 5y agoI've heard Titanfall 1 and 2 multiplayer are basically unplayable for many people, as a hacker with knowledge about the game's internals managed to get such comprehensive access to the multiplayer servers that they can literally ban certain players (like streamers) independently of IP address or game account. And so far developers haven't been doing anything even though it's been going on for many months. So the worst case scenario could be worse than just a few cheaters. Either way EA will endure it without problems because it's barely different than the average bad game launch.
- MIBMA 5y agoI don't know about this game, but I wonder how this hacker can identify those certain players without targeting their IP or account. The only thing I can think of is if the game collects data about players statistics with Mac addresses included. This way he can ban them if he got internal control which is something developers should be able to handle and I wonder why they didn't quickly. They can rewrite the control module of the servers for example instead of just doing nothing and lose everything.
- dleslie 5y agoThey aren't. No one can play TF1 because the hacker is applying a denial of service attack on the servers. Worst part is that the denial doesn't appear to be bandwidth-intensive, just a persistent trickle of bad requests. The hacker may even have forgotten they left the script running, somewhere.
- singhrac 5y agoRespawn continues to have DDOS issues with Apex today. Where did you hear it’s a trickle of malformed requests? I don’t understand how DDOSing is still a problem in this day and age… You start a game, 60 user accounts are in it. You inspect their IPs, give them a token, whatever. If they send too many requests you can drop some, and if it’s inhumanly possible given the games code, you ban them. That’s it? I could see how a public-facing website could get DDOSed but not a game where people are registered. I must be missing something. Maybe input parsing has to happen faster than IP check?
- alpaca128 5y agoIt's not a standard DDOS relying on brute force. Titanfall is attacked by someone with in-depth knowledge of how the whole distributed backend is organised and they're abusing that to keep the infrastructure from working properly. In TF2 there seems to be a whole list of unofficially "banned" streamers, for example, and if one of them tries to play multiplayer some automated script will immediately disconnect all players in the match. That causes a lot of speculation, including suspicions it's run by an ex-employee who worked on those systems internally.
- deleted 5y ago[deleted]
- aardshark 5y agoThere probably shouldn't be such exploits, but there probably are. I remember Quake 3 had a number of exploits that could allow a server owner to essentially run arbitrary code on clients machines. As a newer game, probably Battlefield 2042 servers are entirely run by EA, so any exploitation will have to go through the server first.
- FearlessNebula 5y agoRun arbitrary code as opposed to what code on clients machines? Wouldn’t running any code on a clients machine be a potential security risk? I’m just curious why people always refer to it as “arbitrary code”
- tryauuum 5y agoAs opposed to, say, running a code (already existing in client software) for rendering transparent surfaces (by sending client a level that features such surfaces) Also I think sometimes there are vulnerabilities where you can technically run some tiny bit of your code on a vulnerable machine, but it would lead to a crash. Hence, people use "arbitrary code execution" to distinguish this particular threat from the less severe ones.
- MayeulC 5y agoAs opposed to code that's already there. It could be running part of the game code. Deleting saved games, for instance. Getting control of the client application is different from pushing arbitrary code (any code the attacker want) on the machine and executing it. An in-between is return-oriented programming, where an attacker gains complete control over the execution flow of a given program. Even if they aren't able to push different code on the machine, they can chain parts of existing code to perform arbitrary computations on the machine: https://en.wikipedia.org/wiki/Return-oriented_programming https://en.wikipedia.org/wiki/Return-oriented_programming
- TchoBeer 5y agoA server always runs some sort of code on a client's machine (such as sending it instructions about the game world for it to render into an image). This isn't a problem because it can only do this in an incredibly constrained way.