5 ms·
> never seen that work in practice. Except in every competitive online game that predates EAC. Rule #1 in networked games is "don't trust the client".
by AinderS 4y ago
> never seen that work in practice.
Except in every competitive online game that predates EAC. Rule #1 in networked games is "don't trust the client".
- j16sdiz 4y agoThat’s an endless arm race. They are complaining how much time they wasted on mods
- AinderS 4y agoHow is "don't trust the client" an arms race? But now we're moving past the simple empirical fact that for countless games it worked, and still works. > They are complaining how much time they wasted on mods You mean their complaint that they wasted time on bug reports coming from modded clients? And instead of using the obvious, dead simple solution of appending a client ID to the bug report to filter out modded clients, they prefer to use this as an excuse to add DRM? Guild Wars had a similar issue of getting bug reports from clients due to hardware errors. Did they ban all PCs not built by an authorized OEM? No - they simply added a hardware health check to their game, and ignored bug reports by clients that failed it.
- p1necone 4y ago> How is "don't trust the client" an arms race? Exactly. You write the game logic, you know what the client is and isn't allowed to do. Just ban/kick if the client tries to do something it isn't supposed to do. The only thing stuff like EAC should be needed for is stopping people from delegating making their game logic legal inputs via an aimbot or some external script instead of their actual fingers, which doesn't seem relevant for VRChat.
- pixl97 4y ago>Just ban/kick if the client tries to do something it isn't supposed to do. Of course couple this with a deep understanding of what your client actually can do. Oh, and keep track of updates you'll have a lot of banned users.
- alpaca128 4y agoAnother reason for EAC would be a kind of cheat people built for a recent Battlefield game: a modded graphics driver that changed colors to make other players more visible. There's just no way to detect this server side.
- yellowapple 4y agoThat doesn't seem very relevant for VRChat, either.
- etchalon 4y agoThe "dead simple solution of appending a client ID" would completely fail if the modified client sent the Client ID of a supported client.
- nightpool 4y agoCorrect. The problem is users not mentioning they have modified clients when reporting e.g. avatar rendering issues to individual modders. The users aren't being deceptive, they're just non-technical
- salawat 4y agoWelcome to the fruits of a computing industry that hasn't focused on making computing more accessible cognitive load wise in decades. Specs locked behind paywalls/licensewalls. Closed source API:s, lock in via cryptography... It all comes together to create just what large software platforms want, but what people like Engelbart were trying to avoid. A technically ignorant/illeterate user populace.
- falcolas 4y agoEven if it is an arms race, adding anti-cheat software will not make the client trustable. The arms race, as you say, will continue. Even Ring-0 anti-cheat software hasn’t kept Valorent cheat and abuse free. The server is the only software not in “malicious” hands; it’s the only place anti-abuse checks are viable.
- Hikikomori 4y agoPretty much all AC focused on protecting the client and game memory was already ring 0 before Valorant even came out.
- potatolicious 4y agoCheating was rampant in those games? Even nowadays the most liberal modding policy for multiplayer games is "modded copies cannot play with unmodded copies" to try and cordon of modded users from being able to scam/grief/etc the general player base. Is there any online game that has permitted modded clients playing with unmodded clients and had it go well?
- AinderS 4y ago> Cheating was rampant in those games? But what kind of cheats? Aimbotting and seeing through walls don't apply to VR chat. And no matter how modded your client was, you couldn't spam endless grenades in Counter Strike - the server knows how many grenades you have, and where you can throw them.
- asojfdowgh 4y agoAimbotting/wallhacks are relevant, as there are games within VRChat where those are relevant. Due to starcraft 2's design, defogging hacks were plentiful. Anyone who has played TF2 for a significant amount of time has run into hackers landing impossible shots, e.g. through walls before EAC, there has been VAC (along with two separate community-ran anti-cheat services for source games), Battleye, Warden, etc. It seems universal amongst those involved, that client-side anti cheat helps way more than you expect.
- falcolas 4y agoMinecraft. World of Warcraft. FFXIV. Just to name 3 off the top of my head.
- asojfdowgh 4y agoAnd there is a hell lot of complaints about cheaters on hypixel, no?
- anonymoushn 4y agoDoes squeenix explicitly allow FFXIV mods now?
- hinkley 4y agoI’d also invite anyone interested in this space to look at both the rule for World of Warcraft addons and their evolution over time. Many actions are doubly rate limited. Not only can you not spam a single action, you can typically only call one rate limited API action per event handler. So you can make a button that can do one of three actions depending on state, but if a second fires it generates an error.
- hgazx 4y agoUntil you get a Lua unlocker. Because those limits are enforced by the client, not the server. I’m not arguing that there’s no rate limiting going on in the server, but some things such as not being able to call several api commands with only one hardware event are enforced client side because by definition the server has no idea about whether a hardware event happened.
- hinkley 4y agoYes and no. The rate limiting can still be done server side. Reacting to events is simplest on the client, but if you were being a hard ass about it you could do something with correlationIDs. I think it depends on how much state history you want to retain on the server to map actions to outcomes.