45 ms·
We outsmarted CSGO cheaters with IdentityLogger
- Broge 2y agoFeels disgusting with the hidden fingerprinting but very technically impressive!
- Giorgi 2y agoThinking about it, steam should force this on every game developer that has cheating problem (I am assuming mainly shooters), maybe implemented better fingerprinting way, giving developers options to hide cookies somewhere in folders of their choosing.
- Ekaros 2y agoRisk there is that what ever id is generated tends to leak. So lot of cheaters will either tamper with it or circumvent it. So the game will continue and not actually be effective for very long.
- Giorgi 2y agoSure but that can be completely randomized, no? like keep changing folder where cookie gets hidden, or the ID generated.
- Ekaros 2y agoProblem is that you do not want random. You want it to be generated. It should be same say after you reinstall OS and the drivers and the game. Idea really is that you can identify single device time after time. So even if there is slight change in anything like software that can be easily changed that is not good enough. Not that fingerprints should lead straight to bans, but maybe at least heightened awareness.
- jandrese 2y agoThe problem is that once a technique like this becomes standardized the cheat software will know how to automatically disable it. Even in the article it points out that had the cheaters put in the work they could have edited a single text file to break the system, but they did not. If this solution had been implemented for all CS:GO players then it would have been defeated fairly quickly, but since it was just one set of servers those were easy enough for the cheaters to avoid. That said, eyeballing the chart in the article you can see an enormous ban wave that happens when the system is turned on, but afterwards the total level of cheating quickly returns to roughly where it started. If there were long term impacts it was only in the reduction of staff hours needed to review game footage to determine if a player is cheating.
- therein 2y agoI am surprised VGUI browser shares cookies across Steam accounts. When I log out of my Steam account, switch to another one, launch the same game, I would have expected an entirely different datastore to be used for the VGUI browser.
- awestroke 2y agoThe VGUI browser also allowed servers to steal the steam session cookies. So not a very hardened implementation at all.
- jandrese 2y agoThe VGUI browser was a security nightmare, which is why Valve eventually deleted it from Steam.
- mobeigi 2y agoIt was a security nightmare. Basically a half baked browser with a subset of the security considerations you'd expect from a browser. Valve worked on it for a little while patching bugs as they popped up (notoriously slowly I might add). Then in August 2017, an exploit in which server operators could execute JavaScript on players that joined their servers started to spread and was maliciously abused by bad actors. For example, some server operators using their player bases residential IP addresses to sign up to gambling websites so they got kickbacks. Others simply tried to hijack Steam accounts or sell rare Steam virtual items on the Steam marketplace to themselves. After Valve patched the above exploit, some smaller bugs popped up in the following weeks and 2 months later in October, Valve completely binned the VGUI browser in CSGO. They had enough! This broke a lot of plugins like IdentityLogger and music players that would play music in the background as you played the game. But at least the attack vector was removed.
- ZeroCool2u 2y agoServer side only anti-cheat is one of the problem domains that I'd really love to work on at some point in my career. This is the type of adversarial arms race that just seems really fun to think long and hard about.
- Night_Thastus 2y agoOnly problem is, a lot of companies do NOT want to pay for it. It's 'treadmill work'. No matter how many people and how much money you throw at the problem, it still ends up just coming back. It's a losing battle because there are many, many more players than there are developers.
- anamexis 2y agoAre there more sophisticated cheat developers though?
- Night_Thastus 2y agoCheat development these days is incredibly sophisticated. There are swathes of tutorials, old and recent examples to research, advanced inspection tools, etc. It's so much easier to make cheats today than it was, say, 10 years ago. It's also easier because more and more games are sharing common infrastructure like game engines, as compared to the past. What works in one Unreal game may save you a lot of time developing a cheat for another Unreal game. These days, many online games encounter serious cheats within the first couple of days of release - if not the day OF release.
- oneplane 2y agoSome of the sophistication is not really in the technical breaking of the game or protocol anymore, figuring out if something is plausible might yield detections that you cannot "cheat" because it no longer matters if your cursor clicked on a head at the right time or not, it matters if your posture/reputation/experience makes your behaviour plausible. Cheating and anti-cheat used to rely a lot on the pure technical parts (like "is something sneaking some reads from the memory the game engine uses to clip models?"), which is ultimately not something you will win as a game developer (DMA/Hardware attacks or even just frame grabbing the eDP or LVDS signal and intercepting the USB HID traffic has been on the market for quite a while). But implausible actions and results for a player can only be attributed to luck so many times. Do 30 360noscope flick headshots in a row on a brand new account and you can be pretty sure something is wrong. If we can get plausibility vs. luck sorted out to a degree where the method of cheating no longer matters, that's when the tide turns. Works for pure bots as well. But it's difficult to do, and probably not something every developer is able/willing to develop or invest in.
- beeboobaa3 2y ago> If a player joins with a different Steam ID but with an IP address that is already banned, the system now re-bans them This works great until you realize you're punishing innocent players because of CGNAT and IP addresses getting rotated. Cheaters usually know how to get their router to request a new IP address. That IP address then gets assigned to someone else later.
- therein 2y agoYeah, you would think they would rely on their secret cookie in that situation instead, to minimize false positives like that.
- cwmma 2y agoThey addressed this in the section entitled "Problematic cases of IP address fingerprinting"
- onli 2y agoNo, not specifically. That section is still written under the misconception that IPs are bound to households, or static networks like university networks. Instead they can swap at the very least country wide (or rather, however the provider manages the IP addresses it controls). Their mental model is just not how the internet works. By using IP as the ban id they created a system that constantly and regularly banned completely innocent steam IDs, thinking they are somehow linked when a new steam id uses a banned IP, which is nonsense. They just did not notice because the banned gamers did not complain.
- Ekaros 2y agoBeing from country with lot of IPs for operators. I did some packet sniffing on DHCP broadcast traffic seen by my router(ISP should filter that...) and I saw at least 3 non-continuous public IP blocks... And that was just day or less of monitoring this traffic... So if the same connection(plug in wall) can end up with IPs from different blocks, well, trying to do anything sensible with this is too complicated.
- 2y ago
- voytec 2y agoKudos to the author for using RFC5737[0] TEST-NET-2 address for: > An example of an IPv4 IP address is 198.51.100.1. [0] https://www.rfc-editor.org/rfc/rfc5737 https://www.rfc-editor.org/rfc/rfc5737
- mobeigi 2y agoI'm a big fan of using identifiers reserved for examples. I use TEST-NET-2 IP's and example.com all the time in my documentation!
- dangsux 2y ago[dead]
- o11c 2y agoWhere it gets interesting is when documentation uses a typoed reserved address (e.g. 189.51.100.1 or 198.15.100.1). There are actually several RFCs that do this.
- dangsux 2y ago[dead]
- beeboobaa3 2y agoI hope they asked permissions for storing those cookies. Otherwise they're violating various EU laws.
- latexr 2y agoNot every cookie requires consent. https://commission.europa.eu/resources-partners/europa-web-guide/design-content-and-development/privacy-security-and-legal-notices/cookies-and-similar-technologies_en https://commission.europa.eu/resources-partners/europa-web-g... In this case, this one might fit: > User centric security cookies, used to detect authentication abuses and linked to the functionality explicitly requested by the user, for a limited persistent duration
- beeboobaa3 2y agoIt's clearly a tracking cookie. > for a limited persistent duration FTA: > However, the VGUI browser had no issues saving cookies with expiry dates exceeding 10+ years! So no, it doesn't even qualify.
- blahyawnblah 2y ago10 years is a limited duration
- beeboobaa3 2y agoSo is a million years. Not how it works.
- unsnap_biceps 2y agoGDPR didn't take effect until May 2018, this only worked until October 2017.
- ketkev 2y agoGDPR is about the processing of personal data. Cookies (and such) are subject to 2002's ePrivacy directive
- aftbit 2y ago>Now, in order for a player to appear to us as a "fresh player" they would need to change their Steam ID, IP address and Steam installation folder. As you can imagine, no one is going to do the latter. Really? I would expect that a dedicated cheater would reinstall Windows (or reload from a snapshot) every time they are caught.
- Ekaros 2y agoSeems like they were private servers. So they really need only hurdle enough to have cheaters go somewhere else. Not totally kill their ability to play. And well most people will move on. Only those who take it most personally start to spend lot of time.
- latexr 2y ago> The best part was that no one knew how we were able to do this and our admin team kept the implementation a top secret. We should have filed a patent! I know you’re joking, but if you had filed a patent you would have had to reveal the trick, thus rendering it immediately useless. Doesn’t detract at all from your post. Fun read.
- LinuxAmbulance 2y agoExcellent write up and solution. Cheating in video games makes for a wretched experience for those who don't cheat. It's crazy how rampant cheating in multiplayer games, especially competitive ones has gotten. Ten years ago, I thought it was at an extreme, but it's only gone up since then. Part of the problem is that for some software developers, writing cheats brings in a massive amount of money. So instead of some teenager messing around making unsophisticated cheats, you have some devs that are far better at writing cheats than game developers are at preventing them. It doesn't help that game devs have to secure everything, everywhere, but cheat devs only have to find a single flaw.
- DJBunnies 2y agoI think a better question here is: why is game code so exploitable? A: laziness and cost. It just doesn’t matter the same way that baking code matters, I guess. So they toss on some cheap anti cheat instead of architecting it safely (expensively.)
- doctorpangloss 2y ago> I think a better question here is: why is game code so exploitable? The nature of FPS games means only environment integrity can stop cheating. It's not exploitable per se. Just the game skill can be done by a computer perfectly. Conversely who knows how long it will take for AIs to play Hearthstone with never-before-seen-cards well.
- wbl 2y agoProbably three years
- jsheard 2y agoArchitecture can help up to a point but it can't stop everything - the usefulness of ESP can be reduced by not sending the client information it doesn't need to know, but that gets computationally expensive on the server, and culling information too aggressively can interfere with lag compensation. Perfect recoil compensation can be prevented by not replicating the servers RNG state on the client so it can't predict where the next bullet will go, which CS:GO started doing at some point. Aimbots though? Those are just automating an input the user could theoretically make legitimately, so you're pretty much stuck with statistical heuristics or client-side detection.
- ycombinatrix 2y ago>We Outsmarted CSGO Cheaters by Exploiting the Client Fixed
- mobeigi 2y agoThe game's the game.
- deleted 2y ago[deleted]
- snarfy 2y agoFor UT2004, you can ban by player GUID (a hash of the CD key) or IP. With the game abandoned by Epic, a number of key generators have cropped up, which makes GUID bans useless. IP bans only go so far with VPNs costing $2 these days. The main solutions we have today are IP ban + VPN blocking using a database of known VPN subnets and adding them all to the firewall, and a similar fingerprinting technique which scans their folder structure of certain system folders.
- deleted 2y ago[deleted]
- ghxst 2y agoThis still leaves you wide open to cheaters using mobile data tethering and proxies. Have you considered more advanced network analysis? It's one of the areas I have an interest in (professionally and personally) so if you want any suggestions let me know.
- kelnos 2y ago> This still leaves you wide open to cheaters using mobile data tethering and proxies Is latency going to be good enough on mobile data (especially if they're also using proxies) for a FPS, though? Sure, they're using cheating software, but I wouldn't be surprised if the software gets the information it needs to cheat too late often enough for it to be useful.
- Sayrus 2y agoAssuming obvious cheat, even 100ms or 200ms latency is unbeatable by a human. Especially since the cheat doesn't need time to aim. Even for non-obvious use-cases, it's hard to beat the advantage provided by knowing the position of players. On my own hotspot, I have less than 30ms of latency.
- ghxst 2y agoYes the latency is not nearly as bad as you might think, it's comparable to a VPN in my experience, though the quality will depend on your location and the available connections. Sophisticated cheats in games like CSGO (and other competitive shooters) are usually very subtle, such as displaying enemies on the mini-map when they shouldn't be visible which provides a major advantage without requiring superhuman input, and the added latency is often negligible—especially when the info can be relayed to teammates and now you essentially have the entire team cheating with only 1 player suffering from a bit of increased latency. And I wouldn't say this is an edge case either as in my experience the majority of cheaters I encountered are individuals that play on an alt account and offer a service to guarantee wins in ranked games.
- leetbulb 2y agoThis isn't about stopping cheaters (cheat detection). This is about stopping repeat cheaters trying to ban evade. Detecting cheats, especially nowadays with hardware cheats (DMA, etc), is an entirely different ballgame. IMHO, one of the most effective way to stop ban evaders is to actually charge money for the game.
- kemitche 2y agoAt the time of the events in the blog, CS:GO was NOT free, and yet there were still cheaters that apparently had access to 80+ accounts.
- connicpu 2y agoWhy pay for the game when you can go to an onion site that will sell you hundreds of compromised accounts that own the game for a fraction of the price?
- ManlyBread 2y agoAt that time CS:GO would cost around $3 during various Steam sales and it was possible to buy a huge amount of gift copies that could be stored in your Steam inventory. So one "legit" account would buy lots of copies and then "gift" them to new accounts that would go on a cheating spree.
- leetbulb 2y agoThat's fair. There will always be cheaters like this. However, anecdotally, after CS or any other game I've played that went free-to-play, cheaters became a much much larger problem: from seeing one every now and again, to at least one in nearly every match.
- bob1029 2y agoCharging money and banning at the payment provider level can be quite effective. It isn't a perfect answer but it cuts out gigantic chunks of the problem space. I'll take a ~99% cheat-free experience over not having any improvement at all.
- lwansbrough 2y agoI suppose different people are entitled to different opinions about fingerprinting, but I reckon it only takes working on a single project where this is a real issue for you to change your mind. We do behavioural analysis on top of various fingerprinting for bot detection - some people are trying really hard to ruin the internet! I suspect a sufficiently advanced server side behaviour analysis could do a pretty good job discovering cheaters.
- ghxst 2y agoNot at the expense of false positives, though. Sophisticated cheat developers and bot creators are skilled at exploiting that narrow margin of error where companies can't push detection further without compromising the experience for legitimate users and destroying their game or service.
- Retr0id 2y ago> Wonderful, we have found a way to silently persist a cookie for each player as they join the server. This violates GDPR, no? Edit: It sounds like this took place before GDPR was being enforced.
- kemitche 2y agoGDPR isn't a blanket ban on cookies. You don't require a cookie notice for strictly necessary cookies, which you have a "grounds of legitimate interest" for: https://commission.europa.eu/law/law-topic/data-protection/reform/rules-business-and-organisations/legal-grounds-processing-data/grounds-processing/what-does-grounds-legitimate-interest-mean_en https://commission.europa.eu/law/law-topic/data-protection/r... Fraud prevention is listed as an example of a "legitimate interest." So no, by my layman's interpretation, they would not have been bound by GDPR to notify the user of cookies or other fingerprinting used solely for anti-cheat. They'd run into trouble if they use that same ID for marketing/advertising without consent, though.
- Retr0id 2y agoThey're perhaps not required to gather explicit opt-in consent, but my understanding is that they'd be required to disclose what information they collect/store.
- phire 2y agoThe same rules apply to the steam ID and IP address. As far as I'm aware, you can get away with disclosing the fact that you are tracking "unique identifiers for the purpose of anti-cheating" in the terms and conditions, without explicitly explaining the technical details that it's a cookie. Also, this is a server covering the Australia/New Zealand region, so it doesn't have to worry about GDPR compliance.
- xxs 2y ago>the fact that you are tracking "unique identifiers for the purpose of anti-cheating" A person can requests to delete their data at any time, and also can request to provide all the personal data collected.
- Joel_Mckay 2y agoIn general, hardware/GPU/MAC signature hash checks are the only consistent way to bind player account histories, and even then cheats will change their identity with new hardware on fake postal addresses. Best to add a few weeks delay with "reviewing" ban status to prevent them returning hardware to retailers. Each day randomly permute which hardware signature trips the auto-re-ban after a random number of minutes. Cheaters ruin the fun for everyone including themselves. Admins need to provide a personal cost deterrent for problem users, and randomly hang the game for people using code mods. Let the ban hammer fall =3
- johnisgood 2y agoUnless I misunderstood, I do not see how this would actually work in practice considering the client can be modified and I can send whatever I want to the server, i.e. spoofing.
- Joel_Mckay 2y agoEven the Webgl signature check is resilient, and is the new tracking cookie on many sites like YT etc. It is a robust unique property of a specific system, and GPU. Not just the serial number... Indeed, duplicate salted-hash signatures on multiple active users mean shills, and immediate bans issued for both accounts tainted by the black list. The trick is to randomize a mix of easy and difficult signature checks daily. i.e. the exploit writers will have to spend time cleaning up bugs, redistributing the patches, and dealing with angry people that have a GPU that is on the blacklist for a game. The more hardware details collected, the more difficult it is to prevent tripping the admin alert. This is already done by some studios... "Play Stupid Games, Win Stupid Prizes" as they say... =3
- wnevets 2y agoI wonder what kind of theories these cheaters invented to explain how they were getting caught.
- ultimafan 2y agoCheating in online games is a scourge and I really don't understand why people do it. It's one person selfishly getting a "win" at the expense of ~60 other people in that match having their time, pleasure, potentially money absolutely wasted. I think even more infuriating than blatant hacking is this epidemic of "micro cheating" for lack of a better way to put it that I've seen prevalent in some games that just boost some stats or reactions by amounts large enough to help the cheater but low enough where new or inexperienced players have absolutely no way of telling if someone is cheating or genuinely good especially in games with high skill ceilings. At least when it's blatant you can leave without time wasted but when they're doing it subtly you end up getting tilted and spending the whole match with a bad taste in your mouth second guessing if someone is actually playing fair or not. Chivalry 2 is a really bad offender for this, once you notice it you can't unnotice it anymore, almost every match will have at least one guy with his swing/move speed adjusted by ~10% and in a game where swing manipulation is a legitimate mechanic it can be borderline impossible to catch someone out on it unless you're really paying attention.
- daghamm 2y agoCheating is also big business. Players can pay big bucks to rent (!) a cheat. IIRC there is an episode on darkness diaries podcast about this.
- ultimafan 2y agoYeah I get that, I understand why cheat developers do what they do. It seems like there's a huge market and I find it hard to blame them trying to make a living- morality wise they're probably more worried about rent, bills, family than whether or not someone's game time is ruined. But it's only this way because so many people are willing enough to cheat that dropping money on it is fine for them. It's their psychology I don't really get. Even if they're doing it because they want the satisfaction of a "win", doesn't that victory feel hollow because it's something they paid money for? It's like the difference between a community valuing you enough to give you an award vs going down to the trophy shop and paying someone a make you your own trophy that doesn't really mean anything.
- 2y ago
- avree 2y agoThis link is 404ing for me. Anyone else?
- notwhereyouare 2y agoseems like the whole site is 404'ing
- mobeigi 2y agoIf the website is down or slow and you want to read the article, here is a full page screenshot of the post: https://i.imgur.com/SPp6IHX.jpeg https://i.imgur.com/SPp6IHX.jpeg Sorry :'( I didn't expect the post to get this much traffic.
- codefined 2y ago> I only shared the solution and technique with one other server operator I fully trusted based in the UK I think that was us! We ended up combining it with other fingerprinting indicators, but the whole 'use VGUI' was a surprisingly effective way at handling this. I believe they removed the web browser in ~2018, which was disappointing. Being able to have custom skill trees / fun integrations with servers was really powerful!
- kjkjadksj 2y agoCouldn’t you stop cheaters by just looking at how their telemetry metrics are different from the baseline? If you get to a point where the cheater has to cheat to only be as good as a median player in the lobby in order to evade detection, you’ve effectively neutered it.
- grayhatter 2y agoHow would something like that work?
- kjkjadksj 2y agoYou’d compare all the telemetry you can from a sample of non cheater users and compare that to the cheater. Chances are the cheat is better than a non cheat user because thats the entire point of cheating. It will probably manifest in stuff like accuracy for aimbots, how fast they train onto a target they see, if they put their reticle on another user through a wall and how often that happens, how they move or jump, etc. theres bound to be some significant difference in some of these or other metric compared to non cheaters. And if there is no significant difference, maybe the cheaters don’t have the edge they thought they did after all and you don’t need to worry about it.
- Omni5cience 2y agohttps://archive.ph/xcad7 https://archive.ph/xcad7
- Charon77 2y agoI got 404
- xyst 2y agoSo adtech tracking techniques also work for fingerprinting ban evaders. Go figure.
- pingec 2y agoThe idea of client-side "cookies" existed even before CS:GO. I remember in CS:S the server was able to change game variables set on the client. I wrote a script for a CS:S server that would fingerprint a cheater by setting an obscure game variable to a unique value and so being able to identify the player through that even if they had a different steam id and ip. It seemed to work well for a long time for getting rid of the most common cheaters but of course the most commited and capable ones with RE skills will always be ahead of the game.
- baruchthescribe 2y ago> M̶a̶y̶b̶e̶ ̶h̶a̶v̶e̶ ̶s̶o̶m̶e̶ ̶m̶o̶r̶e̶ ̶c̶u̶n̶t̶ ̶k̶i̶d̶s̶.̶ He took that back. A very clever nod to In Bruges. Well played sir.
- spyder 2y agoAt the part were he writes about the human analysis of game data, I thought the article would end up with training an AI or just statistical analysis on that data to identify players. That would have been a little more interesting (but harder to do) than exploiting the game.
- Mashimo 2y agoThat is actually how current CS cheat detection works. I think valve had a talk about it. I think it's called valve overwatch.
- suborange 2y agoa bit late to the party, but recently watched this video: https://www.youtube.com/watch?v=x-EbjGSRyKA https://www.youtube.com/watch?v=x-EbjGSRyKA Interested to hear thoughts on this level of both cheating and detecting cheats
- MarcoZavala 2y ago[dead]
- precommunicator 2y ago> but the traffic itself was encrypted over HTTPS. This meant that even if one were to use a packet sniffing tool like Wireshark, you would not be able to find the raw token. It's trivial to decrypt HTTPS with tools like Fiddler or Burp Suite, assuming this build in browser used system proxy and system certificates list.
- wobfan 2y agoIt's also pretty easy to export the secret keys from Firefox and import it into Wireshark. Like, it's some clicks, and (depending on which TLS it uses) you gotta do it for every connection, but it's not too hard.
- ricardo81 2y agoI think the author has the average script kiddie in mind, rather than the HN crowd.
- fiskfiskfisk 2y agoIts all about how apparent the issue is if you're running Wireshark - it does not stand out, so you have to do a lot more work to discover what is actually happening. The request is also hidden in plain sight along other requests, and those requests are what you'd expect (you'd normally expect a motd request, so this isn't out of the place). Given that the way of circumventing the issue at hand is to delete a single local file, which is far simpler than finding the actual request and setting up fiddler or burp suite, this worked good enough. No need to overengineer.
- santialbo 2y agoBanning new Steam IDs on banned IPs seems too strict to me. Some ISP use CG-NAT or rotate IPs, meaning a single bad actor could harm many innocent players.
- wobfan 2y agoYeah that sounded like a very bad idea. It was already a bad idea years ago when there were enough IPv4 addresses, because still people were using NAT behind routers. So, it could happen that you just ban a whole family or people that are living together in the same flat, although only one of them cheated. But now, with this whole carrier grade NATting, it seems like not only a bad, but a dysfunctional idea.
- Cthulhu_ 2y agoThis is mentioned in the article, hence why they added a third method.
- emaro 2y agoThey added the third identifier to detect ban evasion by changing the Steam ID and the IP address. They implemented some specific exceptions but generally recommended to not play on untrusted networks to avoid getting banned along cheaters in the same network. That's my take from the article.
- tomooot 2y agoThey actually cover these concerns, acknowledge it was a problem with examples of siblings or students behind a shared IP, and then developed a parallel cookie based tracking system, using the "server welcome message" which is served as a web page in the in-game browser. It's also worth noting this is a 3rd party dedicated server provider, who manages and leases community run game servers. Getting a ban here would prevent you from playing on that provider's servers, but not any of the official matchmaking ones or servers from another hosting provider.
- cedws 2y agoYeah. IPs are NOT identifiers. At best they are a session ID. Using IPs to ban players on the basis that they've been used by a cheater before seems extremely unfair and probably even an opportunity for denial-of-service.
- rashidae 2y agoI loved the idea!! How clever. Congrats on your accomplishment, I learned a lot from your approach. Thanks for sharing.
- runxel 2y agoStill doing IP bans in the year 2024? Lmao.
- consp 2y agoWhy not? It's effective and easy to do and while it can be circumvented it will stop some players with very little effort. Also, the article is about 2017/2018.
- runxel 2y agoBecause it is stupid, that's why. If only I had a dollar for every time I was blocked somewhere just because somebody else had used the IP just before me to do bad stuff. Worst offenders out there never clear the list, even. In a world of a shortage of IPv4 that approach is just madness. It's also the opposite of effective. More like bogus effectiveness. Only hurts innocent bystanders.
- mrguyorama 2y agoI have hard business data that shows, no, IP bans are still effective today, across millions and millions of people from all over the world. Using IP bans on bad actors helps immensely to block script kiddies and other low effort techniques, and forces more intelligent actors to pay for residential IP addresses to do their bullshit.
- mlok 2y agoWhat about some sort of shadowbanning ? Or "shadowsegregating" : I mean if you detect and group cheaters so that they play with other cheaters ? Leaving normal players alone ? (I am not a player, I don't know how these multiplayer games work, I'm just wondering)
- thrdbndndn 2y agoNo idea about CSGO but Dota 2 already does this (another Valve game).
- rldjbpin 2y agorespect the ingenuity of the solution and how well it did. although it has to be said that we are better off without having vgui in the first place. this kind of sneaky tracking is so widespread today on the Web that it is nearly impossible to be bothered with evading it. whether it is the "wideport" or what extensions you use, you might as well use tails to surf the internet at that rate. but using a logical fallacy, to exploit for the better good does seem appealing.
- robertlagrant 2y agoWould it be worth charging for CSGO? Or Counter-Strike 2, whatever the latest is? Because being banned by Steam ID might mean something if you have to pay $10 each time for the privilege.
- trowflahbung 2y agoThey semi-charge, i.e. the new “Premier” league is gate-kept by a $15 charge and an XP gate that requires extensive playtime in their other game modes. However, one can pretty easily buy a wholesale account if and when that happens and skip the time-money sink.
- schmorptron 2y agoYou do have to pay to play the ("prime") competitive mode. Sadly that doesn't seem to be much of a deterrence.
- hypercube33 2y agoI used to believe this, but in Call of Duty you burn $40-60 a ban plus it was or is tied to a phone number at one point and that didn't slow cheating down one bit. It's ultimately why my group quit playing.
- robertlagrant 2y agoBut in that case I suppose you could pass around a disk, at least for physical. For digital-only I imagine it would be more expensive.
- jeemusu 2y agoWhile the game is free, they do charge $14.99 if you want access to the ranked matchmaking called Premier. Sadly, the cost of entry is not enough to dissuade most cheaters it would seem.
- robertlagrant 2y agoWell that's annoying. Perhaps they just aren't being detected?
- jeemusu 2y agoIt feels like cheating as become endemic, every game I've played online in the last 2-3 years seems to be rampant with cheating. I don't remember it being this big of an issue 5-10 years ago, or maybe I was just ignorant to it? It's at the point now where I run into cheaters frequently enough that I find it hard to justify investing time into multiplayer games anymore. I can only assume the recent uptick is due to games adding tradable cosmetic items which has made it financially viable to cheat as most cheaters seem happy to drop a lot of money on cheats as well as $80 to re-buy a game once they eventually get banned.
- tm-guimaraes 2y agoDon’t most games with expensive cosmetics lock them behind paywalls? I assume there is lots of cheating because of every game having matchmaking system for fair with rankings. And there’s a huge amount of people that feel locked into low ranking because of bad teammates (which makes no sense statistically speaking), and if they just bump something they would do well. There’s others who just want to showoff an high ranking. And the guys that just want a cheap win, at the expense of ruining everyone else game. And then there’s the business of this. Cheat tool makers making money of these lind of people. High ranking players selling boosting services or high ranking accounts (smurfing and cheating feels very similar on the loosing side). And even the high ranking players selling player providing boosting can cheat to perform the service in less time. Skill based matchmaking with any form of public ranking (showing a number or tier) will always be full of people trying to game the system instead of trying to get better at the game. Specially in team games.
- rampajar 2y agoI always felt that valve didn't go far enough to prosecute cheaters (back in the day). I wonder if there are metrics out there for how effective methods like Overwatch actually were.
- animal531 2y agoPlayers from big countries often miss out on the sense of community that exist in smaller ones. When there are only 3-4 servers worth of people playing a game every day you quickly come to know them all, which really adds to the banter and sense of enjoyment.
- Glide 2y agoIf you’re old enough you remember favoriting servers in Gamespy. You’d end up on the same servers depending on who is there and mainly how good your connection was.
- doublerabbit 2y agoI didn't use Gamespy but did use "The All Seeing Eye" https://en.m.wikipedia.org/wiki/The_All-Seeing_Eye https://en.m.wikipedia.org/wiki/The_All-Seeing_Eye which was sold to yahoo. Yahoo was a powerhouse back in the day and one that google offered to sell to. The world would be so different if it had.
- ozarker 2y agoI’ve gotten a taste of that experience playing older multiplayer games that have a small player base. I much prefer it to games with millions of players where you’ll never see the people you play a match with again I also love games with community ran servers for the same reason
- deleted 2y ago[deleted]
- lesuorac 2y agoPerhaps not applicable to a hidden web browser in counter strike but for public webpages you can apply the same fingerprint technique and only include the payload on _some_ page loads for non-fingerprinted users. Has a very nice advantage of if they go looking for fingerprinting they may or may not find it by random chance. It is security through obscurity but by making the bar higher for ban evasion you did actually remove a lot of people.
- DanielHB 2y agoI want to share a story in a somewhat related topic: anti web-scraping techniques The most devious version I ever seen of this, I was baffled, astonished and completely helpless: This website I was trying to scrap generated a new font (as in a .woff file) on every request, the font had the position of the letters randomly moved around (for example, the 'J' would be in place of the 'F' character in the .woff and so on) and the text produced by the website would be encoded to match that specific font. So every time you loaded the website you got a completely different font with a completely different text, but for the user the text would look fine because the font mapped it to the original characters. If you tried to copy-and-paste the text from the website you would get some random garbled text. The only way I could think of to scrap that would have been to OCR the .woff font files, but OCR could easily prevent mass-scraping due to sheer processing costs.
- DaiPlusPlus 2y ago> easily prevent mass-scraping due to sheer processing costs. my 2018 iPad Pro does OCR on images in Safari instantly. People only think OCR is slow because Adobe Acrobat still uses the same single-threaded OCR algo it’s had for decades now; then consider how blazing a GPU-based impl would be…
- DanielHB 2y agoI dunno, I never measured it. If you are scraping billions of small social media posts I would expect it to add up and make it unviable.
- jakjak123 2y agoIt pre processes your photo library while charging
- ChadNauseam 2y agoThe GP mentioned it working for pictures viewed in safari
- SirMaster 2y agoSeems trivially easy to hit their evade scenario though. If I merely change the mac address in the device connected to my cable modem, I get a new IP, every time. Combined with the fact that the game is free, so you can easily make new steam accounts.
- kurtoid 2y agoThe whole point of the article is that they set an identifier in the in-game browser, which will survive MAC address, IP resets, and new steam accounts.
- SirMaster 2y agoThey said if a user changes their IP and SteamID then it would be considered a new user and they wouldn't know. What did I miss?
- compootr 2y agodid you even read half of the article? summary: guy found that the IP and steam ids can be rotated with low cost, so he used the in-game web browser to set a persistent cookie (on that installation of the game), so once cheaters get banned, rotate their IP/steam id, they'll be banned until they clear the app's data.
- SirMaster 2y agoI read the whole article. Which sounds trivially easy...
- compootr 2y ago> trivially easy Yes, I agree! for techies on here, they'll know that as well. The target here is script kiddies —whose tech knowledge is limited to downloading a program from github and following easily laid out instructions — which it's pretty effective protection against.
- stevefan1999 2y ago> I'm not being funny and I mean no disrespect. > But cheaters are cunts. They're cunts now, they've always been cunts. > And the only thing that's going to change is they're going to become bigger cunts. > Maybe have some more cunt kids. That statement is really shows how big of a dick you are, like come on man, it's just a game. Without learning game cheats and writing trojans and botnets since 14, although I'm kind of clean now, I wouldn't have mastered C++, C# and Java together and later get deep into computer science (and cybersecurity to some extent).
- RedCurrent 2y agoI disagree. Cheating in singleplayer games is fine, but you're ruining the experience of others when hacking in multiplayer games.
- stevefan1999 2y ago> but you're ruining the experience of others when hacking in multiplayer games What I meant was, cheating can be a good learning experience to programming for a lot of kids, because they get immediate feedback and rewards. At least that's what I see it as.
- RedCurrent 2y agoI'm with you, but the environment they cheat in matters. Learning to hack with CTFs is great, but against real targets? Of course, I'm overplaying the severity of cheating a bit, but the point still stands.
- lightbulbish 2y agoBy breaking the agreed-upon rules you gain resources and others lose resources (energy, morale, money, w/e). That the activity impacts the cheater in other ways is beside the point if its a dick move or not.
- stevefan1999 2y ago
- kurtoid 2y agoI know there's a steam client setting now to clear the data of the overlay browser (either on exit, or manually? Can't remember) - does that affect the VGUI browser? I don't know about CS, but TF2 has the ability to disable server MOTDs - how does that affect this?
- retentionissue 2y agoCatching/stopping people who want to cheat for profit is something I personally think is never going to happen. For a time, I would buy keys for CS:GO and different Steam accounts and use a subscription based cheat provider to provide me with ESP/chams on screen. I knew that overwatch/admins would be seeing the demos as the accounts were new Starting from unranked meant you would be under scrutiny already so I adjusted my playstyle. I learned not to linger around looking at walls. People's movement patterns and decision making eventually became predictable as I reviewed demos or learned in the middle of a match how players have habits and abused that information. I was able to determine when to throw a round away to avoid suspicion and deliberately ensured I had a string of 2/3 bad games every so often so my K/D wasn't insane. I never used any aim assists, spinbots etc., and I always, always communicated with my team through ingame VOIP (not giving cheat calls) and maintained a legit facade. I went undetected for nearly 2 years and sold hundreds of CS accounts successfully and made a tidy profit doing it. It's another string of the gaming industry that brings in money and it will never go away. I like to think of it as an online drug war, however insensitive that may seem.
- lovethevoid 2y agoAt that point, you're putting more effort into cheating than regular players do at playing the game lol
- devwastaken 2y agobanning by public IP is a rookie mistake. ISP will change their IP automatically over time, they charge extra for static IP. So what youre actually doing is banning anyone who ever receives that IP in the future.