Welcome Guest ( Log In | Register )

Bump Topic Topic Closed RSS Feed

Outline · [ Standard ] · Linear+

Steam Steam Promotion, Discussion and FAQ Thread V39

views
     
Angel of Deth
post Feb 18 2014, 03:29 PM

Regular
******
Senior Member
1,242 posts

Joined: Sep 2008
From: Cheras


QUOTE
Valve DNS privacy flap exposes the murky world of cheat prevention

Company denies any breach of privacy, as angry gamers cry foul.

by Peter Bright - Feb 18 2014, 11:55am MPST

Like most online game makers, Valve uses a cheat detection system to protect popular multiplayer games like Counter-Strike: Global Offensive, Team Fortress 2, and Dota 2 from hacks that would give a player an unfair advantage. That Valve Anti-Cheat (VAC) system was at the center of a potential privacy bombshell earlier today, with accusations that the system was sending Valve a list of all the domains that a system has visited whenever a protected game was played.

The claim rose to popularity thanks to a Reddit post that included an image originating from a cheating/hacking forum, purportedly showing a partial decompilation of the offending VAC module. However, while the initial evidence suggested that VAC is doing something with users' DNS history, it wasn't clear from the decompiled code provided that it is in fact transmitting the information back to Valve. Valve CEO Gabe Newell has subsequently and categorically denied that the module transmits any private information back to the company.

Windows operates a DNS cache to accelerate the translation from domain names into IP addresses. Windows users can see the domains stored within the cache, both at the command-line (ipconfig /displaydns) and within the GUI. The partial decompilation of VAC shows that the module is using undocumented Windows functions to enumerate all the cached entries. In turn, each entry is converted to lower case and then hashed using MD5.

Contrary to the original claims, though, the module doesn't immediately appear to actually send the information to Valve. Each MD5 hash is compared to a bunch of other values (the image of the decompilation doesn't include the actual values it's being compared to), and if any of these comparisons are successful, the hash is stored; otherwise, it's discarded. What happens to these stored values is also not shown in the code provided.

In spite of the lack of clarity or convincing evidence of the true nature of this VAC check, Reddit immediately blew up with speculation earlier today, with some suggesting that the entire set of hashes is sent to Valve, others suggesting that instead the module is doing a client-side check. Many seemed willing to assume the worst; some posters said that the company had "pulled an [Electronic Arts]," alluding to EA's poor reputation among many gamers.

In light of the controversy, Valve's CEO Gabe Newell stepped in this evening with a Reddit response to put people's minds at ease. The nature of anti-cheating systems makes open public discussion of systems like VAC something of a rarity; in an arms race against the cheaters, obfuscation and secrecy remain important weapons. Nonetheless, Newell is remarkably straightforward in explaining why VAC is so interested in the system DNS cache.

According to Newell, cheat software has its own DRM systems, so that the developers can ensure that people pay for their cheats. If the VAC module detects certain cheats, it then checks to see if the system has performed lookups for the relevant cheat DRM servers. If it has, then (and only then) is the data sent to Valve, so a ban can be issued. The module doesn't disclose the contents of the DNS cache, and Valve has no interest, in general, in which domains gamers' systems have looked up.

With this explanation, it's likely that the fuss will blow over soon enough. Still, today's brouhaha shows the vulnerable position Valve is in. Due to the techniques used by the cheat developers, it's common for anti-cheat software to use some fairly underhanded techniques itself; VAC, for example, uses obfuscated code and undocumented API functions to go about its business. Anyone wanting to cast Valve in a bad light, or even simply raise suspicion about (otherwise desirable) anti-cheat software need only make this same kind of partial, incomplete disclosure, and fearmongering will do the rest.

- arstechnica

I know this has been discussed before, but I thought this is quite a fair article, without taking any obvious side.

And, welcome to the internet. What Valve VAC (allegedly) did, i'm sure not worse than what most of reputable security company already did since decades ago.
Angel of Deth
post Feb 18 2014, 04:48 PM

Regular
******
Senior Member
1,242 posts

Joined: Sep 2008
From: Cheras


QUOTE(pikachu01 @ Feb 18 2014, 03:37 PM)
Yeah, and what happened to the reputable companies that did it decades ago? They're now fallen to obscurity, or have had some flak that people distrust them or disable any modules that has privacy concerns. The point is, it's bad no matter who is doing it. The only difference is how the companies involved handled it post-crisis.
*
Nope, there are still plenty of heavyweights allegedly spying on their user: http://www.informationweek.com/security/vu.../d/d-id/1112911, then you have Facebook allegation as well. At least in this VAC case, Gaben is pretty upfront and responsive to the customer's concern.
Angel of Deth
post Feb 18 2014, 08:49 PM

Regular
******
Senior Member
1,242 posts

Joined: Sep 2008
From: Cheras




This look like a quality indie city-builder. People can die, spreading diseases if not buried properly. Once your settlers are more civilized, you need to build churches, graveyard, fighting crimes etc. Natural disaster, accident also can happen. Pretty realistic take on city builder simulator.

I'll keep an eye on this game.

This post has been edited by Angel of Deth: Feb 18 2014, 08:50 PM
Angel of Deth
post Feb 23 2014, 08:17 PM

Regular
******
Senior Member
1,242 posts

Joined: Sep 2008
From: Cheras


I like rail shooter. It's fun once in a while, especially when you want to kill some time. But this Rambo video game is poorly executed. It look like an upgrade of their previous Heavy Fire games. Look at House of the Dead, always creative. They always bring something new to this 'prehistoric' genre. Light gun isn't necessary to enjoy THotD.

Topic ClosedOptions
 

Change to:
| Lo-Fi Version
0.0172sec    0.32    7 queries    GZIP Disabled
Time is now: 24th December 2025 - 08:51 AM