5 ms·
I thought that piracy in multiplayer games was a solved problem these days. Even the first Half-Life (1998!) had an online authenticity check.
by madisp 14y ago
I thought that piracy in multiplayer games was a solved problem these days. Even the first Half-Life (1998!) had an online authenticity check.
- nicholassmith 14y agoAnd there was ways and means around that, the problem being it's a partially solved problem. Every step that's taken to solve it is broken pretty shortly after, short of sending a man with a gun to watch every single person playing and establish ownership it's not going to be a completely solved problem.
- jiggy2011 14y agoNo, if the authenticity check is client side you can hack the asm to neuter it. If it runs server side you can redirect those packets (often as simple as changing HOSTS file) to a server that you control which can be set to always say "yes, you are legit!" This is why a lot of games are now removing LAN play, because if you can run the pirated game on a LAN you can use a VPN to turn it into an internet game etc.
- rmc 14y agoNo, if the authenticity check is client side you can hack the asm to neuter it. This is security 101 people. Don't trust what the client says.
- jiggy2011 14y agoThe issue with games however is that often all the actual content and game that you want to get access to actually lives on the client. For example Call of Duty singleplayer campaign. If you have most of your interesting stuff on the server (e.g WoW) then of course it makes sense to do checks server side. This is why DRM is fundamentally broken for singleplayer games (or music , or movies) in that you have to trust the client.
- rmc 14y agoYes for single player games. For mulitplayer games that require a server, you only allow them to connect and do the multiplayer bit if they have paid. Simples.
- jiggy2011 14y agoNot quite so simples. Your choice is either to do as these guys did and run all the servers themselves in which case you need to factor the lifetime cost of running the servers into the purchase price or charge subscriptions. If you ever take the game servers offline the game then becomes unplayable and will preclude modded servers (which were fun in games like CS) and LAN play. There's till a risk that if your game is popular enough someone will reimplement the server. So the other way to do it is to allow third party servers or build the game to work on a type P2P system (I think a lot of xbox games still work this way). At that point you are basically back to the original problem.
- antihero 14y agoThat said I don't remember HL1/CS ever being cracked.
- jiggy2011 14y agoNo? I played CS quite extensively. I only bought a legit copy (of HL, CS 1 was a free download) about a year into playing because I felt guilty.
- amorphid 14y agoI was wondering the same thing. If there's a central server, I presume you need an account to access it. The it seems you'd just check for having purchased the app and limit the number of simultaneous per user 1 (or a small upper limit). Am I missing something?
- jiggy2011 14y agoThat depends. If the game is fundamentally built in such a way that the gameplay requires everyone to be on one set of servers (e.g WoW) then you can prevent piracy by strictly controlling access to those servers. For example if you wanted to pirate WoW you would have to reverse engineer the game to the extent where you could implement your own WoW server from scratch which would be a huge amount of work and you would have a situation where pirates would only be able to play with other pirates. If on the other hand the server is used only to verify authenticity then you simply have to re-implement the authenticity part (easy because you only need to genereate a 'yes' response). You also have to make the client redirect some of the traffic to the fake server (easy to do). Many games with centralised authenticity servers still run on a fairly P2P system for running the multiplayer itself (i.e the game is actually hosted by one the players). This means that you already have the server software built into the client so that part doesn't need reimplementation.