30 ms·
Valve bans 40k Dota 2 accounts using honeypot patch
- 4gotunameagain 4y ago> This patch created a honeypot: a section of data inside the game client that would never be read during normal gameplay, but that could be read by these exploits. Each of the accounts banned today read from this "secret" area in the client, giving us extremely high confidence that every ban was well-deserved. Any speculation as to how this worked on a lower level ?
- blibble 4y agohardware breakpoint maybe?
- tobyhinloopen 4y agoI imagined the secret area contained fake details about the game, like adding an invisible fake street to a map. If the client refers to the fake street or any location within it, you can be certain the details about that fake street were obtained using cheats. This trick is used to catch cheaters on minecraft, by spawning in fake diamond blocks that would only be visible to specific cheats (xray). If a user suddenly were to dig to these blocks, you can be reasonably certain there's something fishy going on. Other way to think about it, is adding an invisible field to a contact form that is only hidden through CSS
- toxik 4y ago> Other way to think about it, is adding an invisible field to a contact form that is only hidden through CSS Watch out for autocomplete though.
- tough 4y agoAnd as a consumer, watch out for auto-completed css hidden credit card details
- albert_e 4y agooh wow. do current browsers not prevent this by only filling in credit card numbers when that particular field in focus?
- alickz 4y agoI believe current browsers ask for authentication before filling in credit card details. Whenever I focus on a CC field and autocomplete Chrome throws up a biometric auth before it will fill out the textfields
- jfengel 4y agoA nice callback to the "trap streets" used in actual paper maps to catch people violating copyright: https://en.wikipedia.org/wiki/Trap_street https://en.wikipedia.org/wiki/Trap_street
- cptcobalt 4y agoOr just call it what it is, a honeypot: https://en.wikipedia.org/wiki/Honeypot_(computing) https://en.wikipedia.org/wiki/Honeypot_(computing)
- ohgodplsno 4y agoTake the player info struct: struct player_info { std::string name; vector4 position; vector3 orientation; int level; ... } and dump in something like `report_when_accessed<std::list<player_info>> oops_here_are_all_the_other_players_and_their_position_i_am_only_for_debug_please_remove_me`. Your client will never, ever access this list: it's your honeypot. The moment you get any access on list[i], it gets noted down and reported (like sudo does, straight to the naughty list). Cheat makers will see this and, if it doesn't smell of a too obvious honeypot, cannot pass such a golden opportunity: literally free maphack, just locate where the player struct is in memory and read it all!
- throwaway40602 4y agohow do you expect to be able to tell when someone has read one of your pages outside of working set watches/guard pages?
- pedrovhb 4y agoIt doesn't necessarily have to be useful information. They mentioned they understood how the cheat application worked, so it's possible it was doing something like indiscriminately accessing certain memory regions; this would make it possible to detect without any changes to the cheating program.
- jstanley 4y agoBut why bother using `report_when_accessed<>` when you can simply use `automatically_ban_cheaters<>`?
- larschdk 4y agoYou could possibly query the OS for whether physical pages have been allocated or not. Physical pages would only be allocated on the first page fault, when the pages are read.
- jsnell 4y agoI'd do it by read-protecting the page, and install a fault handler that records the access and then unprotects the page (to avoid detection when the cheat causes the game to crash).
- throwaway40602 4y agothere was a convar in the game for 6+ years that let you see particles in the fog of war; 99% of cheats forced this convar on. source lets you request CVars from the client and the value, so they simply did that. to be clear, this was not a honeypot, but they claimed it to be
- kuroguro 4y agoDo the particles alone w/o any cheats give an advantage?
- throwaway40602 4y agoyes, you can tell where enemies are in fog of war
- kuroguro 4y agoHmm, well I wouldn't permaban people for using a known... built in setting, even if it gives an unfair advantage. _edit_ To whoever downvoted me later - I would consider it a bug if it was user settable without cheats. Similarly you could see trough smokes in CS for a long time by changing some video settings. You don't (usually) ban people for bugs.
- throwaway40602 4y agoit was restricted, you couldn't force it without cheats
- kuroguro 4y agoAh, yeah sounds plausible then. I somehow don't buy the guard page/hw breakpoint explanations. This also lines up with "[information] that wasn't visible during normal gameplay".
- jamesfinlayson 4y agoYeah if you ran with the software renderer in Counter-Strike I think the smoke grenade's smoke didn't work properly.
- TheAdamist 4y agoWindows lets you configure guard pages where you get notified on access, normally used to detect stack growth and such. Although that should be an easy and normal thing to avoid for av/cheats. https://learn.microsoft.com/en-us/windows/win32/memory/creating-guard-pages https://learn.microsoft.com/en-us/windows/win32/memory/creat...
- ed_mercer 4y agoI wonder if this can be circumvented by running Dota in a VM.
- poizan42 4y agoNot helping as long as the page fault is triggered and handled by the process. You could just not do a regular read of the page though. No need for a VM for that, just call VirtualQueryEx and check MEMORY_BASIC_INFORMATION.AllocationProtect for the PAGE_GUARD flag.
- userbinator 4y agoIt could be bypassed by running the cheat outside the VM. Of course, there's plenty of detection techniques for VMs too.
- HHad3 4y ago(Wrote anti-cheat software in the past.) There are multiple ways to detect this. Hardware breakpoints were already mentioned, but they only work per thread, so if one is sniffing on your memory from another process or the kernel then these won't help. The most stealthy and evil way I found was to allocate a page but never actually use it. Windows lazily allocates physical memory for fresh memory pages when they are first used. The detection is to periodically poll the page map from your process and check your canary pages via NtQueryVirtualMemory. If your unused page suddenly is backed by some physical memory then something happened to read from it! Bonus-points for putting such canary pages into places previously used for real game data. This method is not foolproof: Anti-virus programs can read memory of all programs (but don't, Overwatch e.g. does not like this and crashes randomly due to this exact protection method). A bug in the program could also read from the page accidentally (e.g. out-of-bounds array read). But it's a /very/ good indicator that something is wrong when other cheat detection mechanisms also trigger. Once you know how this works it's pretty easy to defeat unfortunately: Read the page map first, then avoid reading pages that have no backing physical memory, because those contain no useful data at best and are canary pages at worst.
- pixl97 4y agoHmm, this sounds like you should always run your cheat tools with the executable name/faked exe information of anti-virus application.
- HHad3 4y agoOldest trick in the book, good luck faking the PE signature to match the vendor's certificate ;-) (Jokes aside, the kernel does not provide any information about which application reads a canary page. It's best to just use this as necessary condition and take it with a good pinch of salt.)
- rogers18445 4y agoI used to work on an anti-cheat briefly, and migrated away form relying on Windows API to do this as the parent comment suggested, instead we used cache timing "attacks". Antivirus was a concern but easily solved by the fact that cheats access memory many times a second, antivirus does it rarely if ever.
- wrren 4y agoVAC probably sets up a hardware breakpoint conditioned to trigger when the start of that memory region is read. When triggered, a function registered via AddVectoredExceptionHandler will be called. It probably just sets some flag somewhere indicating that the memory region was accessed before resuming flow. You can guard entire pages of memory using a similar approach (https://dzone.com/articles/memory-access-breakpoint-large https://dzone.com/articles/memory-access-breakpoint-large).
- elzbardico 4y agoI don't think it needs something deeply clever involving hardware breakpoints, sniffing for virtual pages backed by real memory or something like that. And probably that's why it is described as a honeypot. It can just be something exposing a data structure that gives the player some unfair advantage and them watching the players that could only have achieved some very unlikely advantage in the game by exploiting this information. In a FPS for example, if a player consistently anticipates their adversaries sneaking behind a wall, well beyond what would be dictated by probability laws, there's a very high chance that he is cheating in a way that allows him to "see" their adversaries behind walls.
- pandog 4y agoImplementing what you describe sounds to me way more "clever" and less robust than the canary page approach described above. Specifically - I wouldn't fancy writing the "consistently anticipates their adversaries sneaking behind a wall" heuristic you describe but the earlier post describes the API that already exposes the "has read canary page" functionality.
- bmitc 4y agoHow does that work with latency? For example, if someone has extremely fast internet and a low ping, they are going to "see" around walls more often than opponents.
- tester756 4y ago15 years ago in Tibia there was concept of let's call it - changing network payloads. I know it only from stories, so forgive me mistakes. So basically action X at patch Y sends instruction Q1 and then action X at patch Y+1 sends instruction Q2 but cheating/botting software when ran straight after the update still sends old instruction Q1, which is now impossible to be generated by legit player and this way you can instantly mark player as botter. but I think it cannot be it since modern cheaters wouldnt be this stupid, right?
- dark-star 4y agoYou can mark a page as inaccessible (not present), and then, in the page fault handler, note somewhere that it was accessed and then allocate it/make it readable. you might not trigger the cheater-flag on a single access (because of, as mentioned, antivirus etc.) but if your page gets accessed over and over again, you can be quite certain that someone is reading it who probably shouldn't...
- Dwedit 4y agoYour injected code can just as easily read the protection status of a memory page.
- cabirum 4y agoSo they detect reads from an external process? What if, instead of an exploit app, an antivirus read the memory?
- marcinzm 4y agoPresumably the access pattern (ie: how often, which regions, etc.) of a hack is very different than an antivirus.
- Jamie9912 4y agoThe article just says anything that read that section
- marcinzm 4y agoIf I was them I wouldn't give out all the details on this.
- cathdrlbizzare 4y agoSecurity through obscurity isn’t security.
- Wowfunhappy 4y agoThis isn't security in the same sense, and consider they also do ban waves for a reason.
- MAGZine 4y agoSo in your view, anticheat companies would be better to publish their methods of detecting cheats? cheat detection and cheat development is an arms race. always was, always has been. By publishing, you just give an advantage to the cheaters.
- michaelcampbell 4y agoNor is complete transparency.
- fatfox 4y agoAny top players banned? ;)
- Festro 4y agoA Chinese team called Knights were suspected of cheating with an exploit that might have been detectable through this honeypot method. However, so far, the whole team continues to play in the current major tournament that began yesterday in Lima. The honeypot doesn't seem to have had anywhere near a 100% hit rate on users of a well-known exploit system. Lots of exploiters self-reporting that they have had some of their accounts, but not all, banned. Valve have likely been fairly careful in reviewing the results from this method. It's a banwave after all, not an automated detection system that issues bans in realtime. Also worth noting that exploiters have reported game bans, account bans, and VAC bans, from this wave. So, the severity of the punishment seems to have been measured against some metric too. It's not a simply boolean of 'UserExploit=True', there's shades of grey involved.
- thrdbndndn 4y agoRumors (from Chinese community) also said that the honeypot was only implemented after Knights "incident". They could (would be stupid to not, if they did use) simply stop using hacks after they were in spotlight.
- FartyMcFarter 4y ago> This software was able to access information used internally by the Dota client that wasn't visible during normal gameplay, giving the cheater an unfair advantage. I'm curious what this information was - does the Dota 2 client have access to all the game state including players hidden from view?
- Festro 4y agoSo, there's a character in the game that has a passive ability that lets it recover HP faster if they are not being observed by the enemy. That ability necessitates a function that checks for enemy vision, from heroes or from static observer wards that you can buy. From an exploit perspective that is a huge boon to use for a variety of purposes. Lately it may have been used to allow exploiters to detect those purchaseable wards so that they can be countered and removed in gameplay.
- FartyMcFarter 4y agoInteresting. I would have thought such an ability would be implemented by increasing the HP on the server and then sending the new HP value to the client. But perhaps this is impractical for some reason.
- Festro 4y agoI think it's a matter of network performance, and the visual bugs that you can create without due care in such a fast-paced online game. Valve have commented on this hero's mechanics, and issued fixes relating to client/server-side interactions within the past year in fact. But apparently, the exploiuts still exist. Their comments have been around how redoing such mechanics can cause undue lag between clients that need to be 'caught up with' as quickly as possible. Too long and a client could see something they shouldn't and get a competitive advantage. Valve don't want to have a server updating 10 clients on 10 different network connections if they can avoid it. The compromise is to do more client-side, but that leaves the system vulnerable to such exploits. Considering that the game includes fog of war, and invisibility mechanics, visual bugs from these systems do crop up a fair bit.
- throwwaway8529 4y agoHow can they be so sure that that memory wasn’t accessed due to corruption of a pointer
- izacus 4y agoThey're willing to take that risk I guess.
- brookst 4y agoCould also be cosmic rays. Or ghosts. But I imagine they tested the patch, like any other patch, and did not find evidence of any other access to that memory. You can never be 100% sure, but if that’s the standard, then how could any banned player be 100% sure cheat software wasn’t secretly installed on their system using nation state invisible rootkit capabilities?
- mschuster91 4y agoCosmic rays can be excluded by sampling. Say, someone triggering a guard page once or twice gets ignored, but consistent read activity whenever the user is playing is likely to be either an antivirus (which can be correlated and culprits identified) or a cheat.
- Festro 4y agoIt seems like they haven't been overzealous and cross-referenced hits with other data. People are getting varying degrees of bans, and exploiters with several accounts are reporting that not every account has been banned. i.e. Valve are only banning when they are certain. I imagine they are looking at the honeypot, and in-game actions that would be a result of the player having information they shouldn't. Unlikely that they checked each of the 40,000 bans individually, but I imagine they devised a simple quantitative check that they could automate like "honeypot = true, check how far from STDDev player's dewarding accuracy was", then they spotchecked the highest confidence rates until they were happy to rollout the banwave.
- agilob 4y agoOMG I hope this means they will ban TF2 bots too. This game has been so fucking bad for like 2 years now.
- tpxl 4y agoThe last content patch (that wasn't Halloween) was in 2017. They're planning a new content patch for this summer/autumn, and I'm cautiously optimistic they'll increase moderation prior to the patch to increase player engagement.
- bilekas 4y agoThat is an insanely large number of accounts, I understand there's always going to be cheaters but I had no idea the scale of it was so bad!
- MengerSponge 4y agoDo you know how many active (have played >1 match in the last month) accounts exist? 40k is a lot, but there's got to be redundancy. I'd also love to see a breakdown by region. Just knowing what servers were more impacted would be super interesting.
- bilekas 4y agoAbsolutely no doubt a lot, can't check steam metrics right now but I just didn't expect so many people to be cheating. Especially with a pvp game. I don't see the point personally how you could feel good after. You didn't win.. your cheats won. Strange pov.
- c22 4y agoI think to adopt this pov you have to feel good about other people losing.
- bob1029 4y agoThis is why some of us are not giving up on the streaming gaming idea. It doesn't solve 100%, but it definitely fixes this entire universe of "oops the client has to know a little bit too much about the game state" problems.
- Jamie9912 4y agoDon't popular antiviruses scan entire process memory?
- adzm 4y agoPopular antiviruses often have exclusions for particular processes in order not to trip anti-cheat / tamper-detection code, as well. Especially for well-known anti-cheat mechanisms.
- throwaway40602 4y agothere was a convar in the game for 6+ years that let you see particles in the fog of war; 99% of cheats forced this convar on. source lets you request CVars from the client and the value, so they simply did that. it has nothing to do with reading memory, but rather writing memory to allow you to see particles
- kurisufag 4y agoif dota is anything like CS:GO, then most CVar-editing cheats are done by hooking the underlying functions instead of just forcing them. I distinctly remember the word on the street a few years ago being that manually writing to CVars was Dangerous Stuff To Be Messing With.
- mkl95 4y agoCould there be any false positives? Data mining for legit use is a big thing in games like World of Warcraft
- GuB-42 4y agoHow is data mining by reading from the client software memory "legit"? You are supposed to discover things by playing the game, not by doing things that are explicitly forbidden by the terms of service. Even when it is tolerated, it is always "at your own risks".
- nozzlegear 4y agoI play much more World of Warcraft than I should but I'm not sure what kind of data mining you're referring to. I don't think Blizzard allows anything that can read the memory of the game while you're playing it. Are you maybe referring to the raid logs that people use? Those are just addons that write the raid combat log to an external file, and then someone in the raid runs a program that reads the log file and uploads it to www.warcraftlogs.com
- wildrhythms 4y agoThe average Dota 2 player count over the last 30 days was around 396,000[1] so am I correct in understanding that at least 10% of all Dota 2 players were cheating in some way? https://steamcharts.com/app/570 https://steamcharts.com/app/570
- agilob 4y agoI don't play Dota2, but it would surprise me in TF2 and L4D2. I've been in games where 5 of 8 players were bots.
- reportgunner 4y agoSince Dota is a free to play game I would point out that it is likely that cheaters almost always have more than one account to evade bans so I don't think 1 account = 1 irl user is always true. Even for non F2P games it is usual for cheaters to use phished or hacked accounts that they buy for a few cents. There are also accounts that are tradebanned because they were used as bots for 3rd party trading websites and they are basically worthless after getting tradebanned.
- ridgered4 4y agoThis always seems obvious to me with F2P games. They create more and more complicated measures to detect cheats, but when it cost nothing (except an SMS service now I guess) to spin up a new account you aren't getting anywhere. The old business model of just charging a lot of money up front for the game seems like it wouldn't have this problem to the same extent. You just ban their key and they're out $20-60. But that business model is less popular now I guess.
- ferminaut 4y agoI've had the idea that a deposit in free to play games would be sufficient. Put some amount of money in, say $20. When you are done with the game, you get the $20 back. If you cheat, you lose the $20.
- 4y ago
- NKosmatos 4y agoNice move and it’s better that they’re open about it so that any wannabe cheaters might consider it. On the other hand, what is stopping cheaters from creating new accounts and trying to read data from the client with a new exploit or other means?
- ROTMetro 4y agoCan Valve do anything about all the Z flags in their community? I mean, yeah, I know they can. But why don't they? F Valve.
- squarefoot 4y agoBecause a letter is just a letter, and although we all know the nefarious meaning of that Z, it's still a generic letter. Same reason why nobody would have grounds for reporting you here for writing that (well deserved) "F Valve".
- ambientqtns 4y agoValve has been historically quite comfortable with Nazis and white ethnonationalists on steam. There are limits, but Valve generally doesn't care about making sure steam/Valve games are friendly places to players. If it's not illegal, Valve isn't going to do anything about it.
- deleted 4y ago[deleted]
- s09dfhks 4y agoI'm curious about what data the "cheats" were reading and how it gave them an advantage
- CursedUrn 4y agoSome of them read unit positions/type/health to auto-aim at the best target.
- gregw134 4y agoI heard you could tell when your opponents had vision on you. Useful for detecting ward spots or incoming ganks.
- macinjosh 4y ago> Useful for detecting ward spots or incoming ganks. This phrase makes me feel old, haha. No idea what it means. As a programmer with no game dev experience what are the most common technical mechanisms used for cheating? Are they modifying outgoing network traffic on the fly or something like that?
- margorczynski 4y agoWard - object placed somewhere to give you vision around it Gank - suprise attack basically, usually when a guy from one lane go to another one to suprise kill an enemy player
- zinclozenge 4y agoI'm no longer in the game, but circa counter-strike 1.1 or 1.3, the typical way was using windows hooking API to load your hack into the running process. You could then simply use the freely available half life modding sdk to use the same structs and things like that. Network related stuff also happened, but I never paid attention to it.
- acchow 4y agoIt's not really an age thing. If you don't know anything about Dota or the MOBA genre, these concepts will be meaningless. Let's translate to the more commonly understood First Person Shooters. In a FPS, you don't know if someone is hiding behind a door. But with cheats on, the cheat program could be reading game data and know that someone is behind a door. It could highlight that person on your screen in a red color, that way you can see them even tho they are hidden. It could also move your mouse cursor automatically for you so you get an easy headshot without even trying to aim. Neither of these involve modifying outgoing network traffic.
- ctvo 4y agoDoes anyone remember when Warcraft 3 was in beta and got leaked? Pirates created an emulated Battle.net that could work with the beta assets and had matchmaking, ladder, etc. working. Hundreds of thousands played. Blizzard released patches in beta that would, for example, spawn infernals to attack your town hall if it detected you were on the emulated server. This reminds me of that. Blizzard lost their battle, by the way, and people pirated WC3 all the way until release.
- duffyjp 4y agoAlong the same lines I loved the Serious Sam solution to piracy. They let you play but spawned an invincible enemy occasionally to ruin the experience. https://www.thesixthaxis.com/2011/12/08/how-to-get-rid-of-the-invincible-scorpion-in-serious-sam-3/ https://www.thesixthaxis.com/2011/12/08/how-to-get-rid-of-th...
- nottorp 4y agoHow buggy was it? I remember in Settlers 2 or something (before Ubisoft ruined it) the iron smelter was producing pigs in pirated versions. However, it wasn't extremely good at detecting them leading to pissed off legit players.
- duffyjp 4y agoNo idea, my first encounter with Serious Sam was a cheap Steam bundle so it never happened to me. They're really fun over the top games and hearing about that "feature" it made so much sense. The developers definitely prioritize fun over taking things seriously (no pun intended).
- nottorp 4y agoOh I've played all the Serious Sams :) It's about the only modern 3d shooter series I can still stomach. Battlefield of Honor of Duty and derivatives take themselves too seriously and are too much for hypercompetitive dudebros.
- izzydata 4y agoI have found over the last 5 years that it is impossible for me to take online multiplayer gaming serious in any capacity anymore. Cheating has become so rampant and so ubiquitous that I have no confidence in any online gaming match to be cheater free. If people are cheating then what am I even playing for? It's only fun for me when I know there is some semblance of integrity between the players, but nobody else seems to care. I don't even particularly care about being good or winning. You wouldn't cheat at tic tac toe despite the inherently low stakes of the game so it doesn't seem any different in any other video game. I also have no trust in any sort of gaming related records of feats of ability. I've been deeply involved with gaming communities in the past where people would show off their world records. I would question such scores only to be flamed and then years later it is discovered they were cheating after all. Really my only point is that I despise cheaters and any game that isn't single player or only between friends may as well not exist for me anymore.
- dumpsterlid 4y ago[dead]
- JohnClark1337 4y agoI feel like I've "aged out" of online multiplayer gaming. I could pick up COD for maybe the hour or two of gaming time I have a day and immediately be dominated by those younger who have a vast amount of more time to hone their techniques. Or I could play something single player (or something that can easily be played single player like an MMO) that relaxes me after a stressful day at work. I choose the latter.
- mrguyorama 4y agoExcept, ten years ago "older folk" COULD enjoy much less competitive online multiplayer experiences. I place the moment Call of Duty started spawning you randomly during team deathmatch as the marker. Instead of spawning in a safe zone with clearish "Fronts" to approach and attack and plan around. Instead, you spawn randomly, often with your back to an enemy, and half the time you spawn you instead have an enemy's back to you. I hypothesize that quick "yeah I got a kill" made the game more attractive to kids, and not allowing you to plan and implement any sort of individual strategy other than "click heads faster than the other guy" made online games more demanding in ability.
- voldacar 4y agoHow does the client know when the cheat reads data from the honeypot?
- deleted 4y ago[deleted]
- warent 4y agoCould just be a simple property that existed on some game object, which was exposed in the interface but nothing in the game ever accessed the property. Then a getter would report the read to their backend. The cheat programs probably automatically read every property of these objects.
- jeroenhd 4y agoI'm no reverse engineering expert but I doubt cheats would actually call getters when they have access to the raw memory underneath. Maybe lazy cheats do use that mechanism, but it's hardly a foolproof system. If this is how detection was done, I imagine Valve has targeted this detection system for a specific cheat tool/framework.
- warent 4y agoYes I'm seeing now how unsophisticated and probably incorrect my approach is, clearly running into the limits of my understanding of compiled programs / cheat engines :)
- voldacar 4y agoA getter? If I write a cheat, I'm just reading bytes from the address of the honeypot in ram
- jamesfinlayson 4y agoPossibly - a lot of Source engine (and so probably Source 2 as well) plugins work by reverse engineering Linux/Mac builds of the games and building class definitions for in-game objects and calling the methods to get health/armor/ammo counts etc.
- warent 4y agoMeanwhile, Riot Games issued a warning to League of Legends and Teamfight Tactics players earlier this year that new cheats could be developed after source code for both games and the legacy anti-cheating software they use was stolen in a data breach. As a past fan of League of Legends and Riot, this is a very typical response from them. Zero effort; meaningless notices. After years of playing, I quit permanently after reviewing my games and finding I was the only one not cheating in about 10 games in a row (that means I encountered about 90 cheaters in a row). This was before the code leak. God help the remaining legitimate community now. It's so obvious that Riot sees people as an obstacle to their money. Seeing this news for Dota 2 warms me up inside. I don't play Dota 2 because I don't want to allocate the time to it, but it seems like they truly care about their community, at least to a much greater degree. Very happy news.
- Llamamoe 4y ago"after reviewing my games and finding I was the only one not cheating in about 10 games in a row" how did you know that all the other 90 people were cheaters?
- warent 4y agoI'm not sure if "cheat" is the exact word to use here. They were all bought accounts or in the process of being boosted. One way to tell is by looking at a player's match history and seeing their account plays one or two champions for a while repeatedly getting MVP with 20/0/x, and then suddenly switches champions and either plays significantly worse or somehow playing even better depending on the ELO. The opposite is also true--consistently playing horrendously, then suddenly switching to different champions and steamrolling beyond their ELO. There are networks of boosters and account sellers. Some people spend full time hours farming hundreds of accounts to level 30 for ranked play, and these accounts are purchased by other boosters who spend full time hours getting to Diamond+, to then resell. This is how you can find fresh level 30 accounts at the highest ranks--it's account farming. When you analyze closely, the majority of the community is composed of these bogus Chinese account farms. Hardly anyone is actually playing the game. This problem goes all the way even to the Challenger level; streamers constantly deal with this problem and Riot doesn't do anything. Even when League was having betting problems at the Grandmaster/Challenger level, of people betting against their own games and then "soft throwing" to make money, it wasn't Riot that did anything about this. It was the betting companies themselves that banned League from being gambled on their platforms.
- jeffbee 4y agoI wonder how they developed this honeypot in such a way that the magic page or region of memory was known to have been accessed by a cheat and not by, for example, an antivirus daemon.
- fwlr 4y agoI doubt they’re doing anything super clever with examining access to memory regions. From the way they use the word ‘honeypot’ and other comments here about cheating software setting team vision flags, I suspect they simply noticed some of their internal functions were commonly being used by cheating software. From there it’s simple: duplicate those functions, add “_legit” suffixes, find/replace all use of those functions in your code with the _legit-suffixed version, and add logging to the original function without breaking its functionality. You can even formally prove that the original function will never be called by legitimate clients with dead code analysis. Cheating software will go on using the original functions because they still work, not realizing that the core game logic functions they were using have suddenly become dead code with logging.
- helf 4y agoI do not understand the appeal of cheating in MP games. What is the point of being invincible in a FPS or unlimited gold in something else etc? It takes all the effort and skill out of it. It's like it's a buncha 12yos who cant stand "to lose".
- skibz 4y agoIn a popular esports title like Dota, people can make an income on the black market by selling accounts that they've ranked up. Accounts that are in the higher brackets of matchmaking can fetch a reasonable sum. So using hacks (provided it has gone undetected by anti-cheat software and other players) can make this process easier. I'm certainly not condoning the behaviour, of course.
- int_19h 4y agoIt's just a form of griefing.
- seatac76 4y agoGreat work. They need to do it for CS GO too.
- jiggawatts 4y agoThis suddenly reminded me of how I was “cheating”. Before the game starts each of the ten players gets to pick a distinct hero for themselves out of a pool of about 120 choices. This is over 10^20 distinct combinations! Each hero has some unique capabilities that combo with allies or counter enemy heroes. I tried to train a “hero recommender” based on tens of millions of games. It turned out that this is obscenely difficult because even the best AI training algorithms struggle with such highly noisy labels. A good hero combo might shift win rates by some positive percentage but have a single sample data point, which is a loss because of one stupid kid in the team throwing the game. You also can’t naively simplify the problem into 2-hero or 3-hero combinations because this misses the “total team composition” metrics. I found some research papers that were just a few months old at the time which covered this corner of the AI training space. Their conclusion were: “We don’t know either but it’s an interesting problem!”
- sbdaman 4y agodotabuff.com does this on a broader scale (offers hero counter suggestions etc.) A better example is u.gg or op.gg which do this for LoL.
- mminer237 4y agoDota Plus in an integrated paid service that does this too.
- csours 4y agoYou would also have to match with the skill and preference of the player
- ScoutOrgo 4y agoI wanted to do this but never figured out where I could get access to the data. I think with setting up the inputs correctly to handle 0-5 heroes chosen per team it could work. Once you have a model you just need to rank remaining heroes by the expected win probability if they are included with the team. If you have a way to get data I would be interested.
- tskool3 4y ago[dead]
- quadcore 4y agoIm surprised reading data in the client can give unfair advantages.
- romland 4y agoThere are many reasons why a server must "over-share" in a game: - Bob and Alice have different latencies and are walking toward eachother, lowest latency will have a huge advantage (there are of course mitigations for this in games, but it _does_ involve the client doing some of that work) - There's rendering: Alice opens a door, behind that door was Bob but he will only plop into view later for Alice; which makes for a rather ugly and awkward experience in a game - in the same vein, in a fog of war, people can very quickly change their line of sight -- server will want to share this information with clients before-hand - As for data that is _always_ there: take 'aim-bots' which just harvest data from targets in your view and well, target them in the best order Making a competitive multiplayer game is hard. All that said, cheating is harder in streamed games. Client will send controller data, servers only send video streams; in this scenario you'd still have the aim-bot problem, but a lot of other cheats go away.
- O__________O 4y agoOnly way cheating will ever end if players have to risk losing a meaningful percentage of their real world wealth — and even then you would have accounts that get stolen for the sole purpose of being a throw away account to cheat with.
- bredren 4y agoI played a lot of this game (WD for the win) a while back but gave up on it years ago. Cheating was only a secondary problem to the toxic community. It went all the way up to the casters.
- tgsovlerkhgsel 4y ago> Each of the accounts banned today read from this "secret" area in the client, giving us extremely high confidence that every ban was well-deserved. I wonder how many non-cheating users of some obscure AV solution that scans memory they banned.
- throwthere 4y agoOr a use after free bug from an unlucky player. With millions (billions?) of account-hours over the honeypot period surely at least a few bans are outrageous coincidences
- mouse_ 4y agoOutrageous coincidences are an unfortunate side effect of any method of moderation I can think of.
- saghm 4y agoI imagine they'd probably agree with that assessment; they didn't say they were 100% positive that every single ban was deserved, just that this gave them a very high degree of confidence. I think this method is probably more accurate than most other anti cheat methods for online games out there, and it definitely is less invasive than most of the ones I've heard of. I have trouble thinking that this is a worse way of doing things than not addressing cheating at all or relying on much more invasive methods.
- d110af5ccf 4y agoI was wondering about this as well. What exact mechanism did they use to detect the read? Something like mprotect would only trigger for the game process, not another process that snooped the game's memory remotely. I wonder if the cheat tool was really dumb enough to run in the same process as the game itself? That would be pretty amusing.
- VoodooJuJu 4y agoHopefully some of the banned cheaters are in this thread. I'd like to hear their story.
- Waterluvian 4y agoWhen this came up on a Reddit thread years ago, I recall a few of the common motives: - kids experimenting with boundaries. - trolls just happy to screw around. They don’t get pleasure from winning, they get pleasure from ruining the game. - those with something to gain, like money. - people from a background where doing anything to get ahead isn’t always seen as wrong.
- shadowtree 4y agoIf only Battlefield did the same. Or force hard regional blocks between servers, blanket ban China. Release Cheaterfield for them, different kind of entertainment definition in that market.
- dbg31415 4y agoI remember this... "Why It's Rude to Suck at Warcraft" and I feel like a lot of people want to be good so they cheat... they want to not be seen as bad, or a drag on their team. But yeah... DotA, and League of Legends... some of the most toxic games out there. No community to speak of, just a bunch of sweaty try-hards who probably don't get out around humans enough since they're too busy playing these games. It's rough. https://www.youtube.com/watch?v=BKP1I7IocYU https://www.youtube.com/watch?v=BKP1I7IocYU
- _madmax_ 4y agoPersonally I thought cheating was a thing of the past since Diablo trainer (for Diablo 1..)
- CHB0403085482 4y agoImagine a multi-player first person shooter game. There are complaints that some players are cheating to win matches. Many of these complaints include a common description in the experience: the alleged cheaters seem to "know" where the other players are, even when not within direct line of sight. In this hypothetical game, there is a feature where, in specific circumstance, one player can in fact see on a map where the enemy players are located. Maybe this feature occurs when enemies are within a specific distance and shooting a weapon. Or maybe it occurs for a limited time when somebody on one team activates a drone and then that team can see the positions of everyone on the enemy team. Regardless, there exists some function called "DisplayPlayersEnemy" that provides this feature. It's only supposed to be running in specific circumstances and otherwise is not active. Unless, of course, some players figured out how to always have Function "DisplayPlayersEnemy" constantly running. This gives those players an obvious advantage. So the developers decide to quietly release an update to the game to test this theory. They create an alternative function called "DisplayEnemyPlayers". It does the same thing as the older "DisplayPlayersEnemy". And all the processes that had previously initiated the old function now initiate the new function instead. So the game continues to function just the same as it did before. The developers keep the old function in the game, even though there's no longer any legitimate way to initiate it. It will still do all the things it did before, so if the function is initiated, it will seem to work as it did before. Except that the developers added a process to that function to identify when and by whom the function was initiated. The developers release the update and then wait. From the players' perspectives nothing has changed. Except that the cheaters are now about to fall into a trap. Some players did in fact modify their game with additional code that caused the old function to initiate when it wasn't supposed to. Since the old function is still in the game, their modifications have continued to work. Many of the cheaters did not notice that the old function had been modified and that a new function had been added. So these cheaters did not know to update their modifications to use the new function. But since there's no legitimate way for the old function to initiate after the update, and since the old function now reports data to the developer, the developer knows who modified their game to cheat.
- DanHulton 4y agoThat also sounds like a classic mistake on the behalf of the developers: never trust the client. The client should never be able to call a "DisplayEnemyPlayers" function, like _ever._ That should be calculated entirely server-side. The client should only ever know what the player could possibly know, and the inputs limited, checked, and sanitized to ensure that they're valid inputs based on the server's known player state, not the client's reported player state. Of course, there's limited situations where the client can still do cheaty things despite your best intentions, like refusing to display smoke particles that should partially obscure another player and make it difficult to hit them (if they fully obscured the other player, the client should not receive updates about that other player), but aside from that and other "partial knowledge" problems, what you describe is a completely solved problem.
- GoofballJones 4y agoTIL that Dota had over 40k people still playing. ZING! But seriously, I haven't played it in years and years...mostly because of the cheating and the toxicity of it's players.
- ElijahLynn 4y agoWhere is the published list of banned accounts/users?
- zizee 4y agoCould you just match-up players to similarly skilled opponents? I'm not a player, but I assume people access Dota using the same account each time they play? Their win/loss record should produce a decent "skill" ranking. Those that are cheating will un/naturally do better, and eventually they'll just be playing each other. It would be sort of like a shadow-banning. They still get to play, but real people don't have to come in contact with them. Who cares if the cheaters play other cheaters? Perhaps it's a drain on the company resources? But if they're paying participants, does it matter?
- jamesfinlayson 4y agoI think they already do this with their matchmaking system. I'm a bit out of the loop on Valve's newer games but at least with the older ones, if you were cheat banned you could still play but were just stuck playing on the servers without cheat protection (so basically cheaters got stuck playing with cheaters).
- sfrigon 4y agoYeah that's what I thought too. I think they could even get those cheaters to pay for the non-cheaters. Say they pay a monthly fee (I'm not sure if it's the case for DotA? I don't play any games right now). You create a monthly challenge where you get a chance to get a month of subscription for free! But you make it very hard for the cheaters to get it, like a ration of 1/20 (either through shadow banning or by redirecting them to an almost impossible challenge). Another alternative I thought, you could monetize cheaters by pushing ads to them whereas the non-cheaters don't get any ads. And you could make it so that if you don't cheat for a while, give up all the items/experience you got while cheating, you're welcome back to the normal process. Just to keep them paying the monthly fee as they have a path to redemption.
- gloosx 4y ago>If you are running any application that reads data from the Dota client as you're playing games, your account can be permanently banned from playing Dota. This is weird wording, Dota client stores data inside my RAM, on my hard drive, am I free to read what I want from my own hardware? They send me network packages and i send them back, so am I free to sniff my own traffic and examine it? How do they even detect this? I mean, if they exposed the data which leads to unfair advantage, it's their fault
- seanw444 4y agoNow this is the type of anti-cheat I like to see.
- diebeforei485 4y agoDefinitely a downside of PC games. This is a lot harder on a console.