[HN Gopher] Speedrunners are vulnerability researchers, they jus...
       ___________________________________________________________________
        
       Speedrunners are vulnerability researchers, they just don't know it
       yet
        
       Author : chc4
       Score  : 158 points
       Date   : 2025-03-02 17:40 UTC (5 hours ago)
        
 (HTM) web link (zetier.com)
 (TXT) w3m dump (zetier.com)
        
       | klysm wrote:
       | This is an interesting premise. I especially like framing speed
       | runners as researchers
        
         | echelon wrote:
         | It's a super interesting premise, and I like it too.
         | 
         | We should distinguish those in the community that actually
         | discover new glitches from those who simply practice what
         | others have uncovered, though. Those aren't always the same
         | person.
        
           | chc4 wrote:
           | Yeah, there's definitely shades. I think for most games the
           | people who find glitches and drive forward this kind of
           | research usually aren't actually that good of runners
           | themselves. But for TAS runs, where there isn't as much of
           | human skill component and technical execution is more
           | important, they're usually closer aligned. And in any case
           | the speedrunners and glitch discovery people are all in the
           | same discords together talking about the game.
        
       | tonetegeatinst wrote:
       | I remember watching a video about this a while ago....it was a
       | fresh perspective into a side of security research I didn't
       | consider.
        
       | Almondsetat wrote:
       | _some_ speedrunners that compete in categories where glitches are
       | _allowed_ and who _find_ the bugs themselves can be labeled
       | _hackers_.
        
         | ismailmaj wrote:
         | It's fairly rare to see people consistently find glitches
         | across games, only distorsion2 comes to mind.
        
         | casey2 wrote:
         | Nope. I completely disagree.
         | 
         | Unless you are using tools and rigorous methods you are just
         | playing around. Just because most games are all broken in
         | easily predictable ways doesn't mean every new game creates a
         | hacker.
         | 
         | It's more correct to say "speedrunners show that almost all
         | game developers are bad at software engineering".
         | 
         | sometimes good at creating fun games, but quick to say "you are
         | holding it wrong" when you breath on the thing and it blows up.
        
           | scott_w wrote:
           | I think it's a harsh interpretation to say they're bad
           | because a determined hacker can break their game. Games
           | aren't security critical software, so they're not going to
           | get the level of investment needed to prevent this kind of
           | thing that, in practice, hurts nobody.
           | 
           | That's to say nothing of exploits that can only be used by
           | TAS software. That's like saying my car is a piece of shit
           | because it'll not survive being driven into a volcano.
        
           | Almondsetat wrote:
           | Hacking _is_ playing around, that 's what hackers will tell
           | you. You are conflating hacking with penetration testing or
           | "formal" disciplines like that
        
           | davidcbc wrote:
           | Even ignoring this weird definition of a "hacker", you've
           | shown how little you know about how many exploits in games
           | are found. They often involve stepping through the assembly
           | of the game to understand how a glitch works and how to use
           | it in a useful way. Not just "screw around in a game until
           | you suddenly discover a useful trick"
        
       | tptacek wrote:
       | This is absolutely and obviously true. Vulnerability researchers
       | watch tool-assisted speedrun videos with jealousy. Side-note:
       | when we did Microcorruption, game devs outperformed everybody but
       | elite vuln researchers.
        
         | chc4 wrote:
         | Microcorruption is basically just a Zachtronics game, if you
         | squint, which I always thought was a fun framing. Reading the
         | blog posts about Starfighter/Stockfighter definitely made me
         | think of video game style exploits, too, if not the same type
         | of glitches. Video game players love to find ways to sell items
         | to NPCs and then buy them back at a lower price for infinite
         | money...
        
         | nonrandomstring wrote:
         | No doubt about this. Game-devs, modders, map-maker/hackers get
         | hands on such a breadth of skills (graphics, sound, scripts,
         | network) inside a contested environment that means a lot to
         | them they naturally feel at home in cybersec.
        
         | Graziano_M wrote:
         | I got more satisfaction out of solving the last level of micro
         | corruption than I probably have from beating any game.
        
           | tptacek wrote:
           | That rules. That last level was Nick Carlini and Hans
           | Nielsen, both of whom have done awesome things since then; we
           | just interviewed Nicholas on cryptanalytic attacks against
           | LLMs:
           | 
           | https://securitycryptographywhatever.com/2025/01/28/cryptana.
           | ..
        
       | joshdavham wrote:
       | Interesting article!
       | 
       | Though it's too bad that cyber security is not as intrinsically
       | fun and interesting to a lot of speed runners as video games. A
       | large part of what allows speedrunners to spend hours searching
       | for glitches and exploits in these games is that they're having
       | an absolute blast while doing it! Also exploiting glitches in
       | decades old games is generally pretty accessible and doesn't have
       | a high barrier to entry like cyber security.
        
       | egypturnash wrote:
       | Opens with an AI-generated image, I'm gonna assume the text is
       | from the same source and close the tab.
        
         | Dwedit wrote:
         | Also no author listed on the article. Just "a Senior Cyber
         | Engineer".
        
       | prophesi wrote:
       | I think if they're active in the speedrunning community, then
       | they're already well aware of this! And for a fun additional
       | example to add to this article, you can often find TAS'ers
       | talking about arbitrary code execution. The legendary GDQ run of
       | TASBot's alternate ending to OoT[0] utiziling an ACE exploit they
       | found in that game absolutely blew me away.
       | 
       | [0] https://youtu.be/PNbkv_DJ0f0?t=3112
        
         | chamomeal wrote:
         | I forgot the details, but I think I saw a YouTube upload of a
         | streamer who wrote flappy bird into super Mario by like...
         | jumping at apples at specific times. Or some weird thing like
         | that lol. I'll try to find it later on my computer
        
           | janetmissed wrote:
           | https://youtu.be/hB6eY73sLV0?si=pF-etE5W-xZhoVBf
           | 
           | here is the link for anyone curious
        
             | Cockbrand wrote:
             | Just when I thought I'd seen it all...
             | 
             | Thank you for sharing this!
        
           | Dwedit wrote:
           | That would be SethBling who performed that.
        
         | thatswrong0 wrote:
         | I love Ocarina of Time speedruns. The sheer level of love that
         | went into that specific run was sooooo beautiful, and like the
         | fact they made it internet live.. via an N64...?
         | 
         | I want to shout out ZFG if ppl arent aware cause he has IMO
         | done the most technically impressive real time speedrun of any
         | game - specifically the 100% SRM run he did is inscrutably
         | insane. But it wasn't just about him - it was an effort by so
         | many people. The number of glitches and exploits that have been
         | found by the community, as well as the NP hard routing and
         | tools created for finding angle perfect setups by various
         | people..
         | 
         | It's straight up community driven exploit art. And it's like
         | yeah, the fastest way to beat the game is to practically
         | manually manipulate memory to redirect specific function calls
         | to give you stuff you need and float around and purposely void
         | out facing exactly a 1/65536 perfect angle setup a hundred
         | separate times to randomly jump around to various rooms in the
         | game?? Wowwwww
         | 
         | And the community around it is so wholesome. The sheer amount
         | of collective curiosity, ingenuity, and effort to dismantle and
         | exploit a 20+ year old game for no other purpose than going
         | fast.. idk. Love it.
         | 
         | Here's a commentated tool assisted human-like run (but not
         | live): https://www.youtube.com/watch?v=R8EE9FXeJnE
         | 
         | And the actual run: https://www.youtube.com/watch?v=Sdxdwnpi-wU
        
       | pdpi wrote:
       | At its most extreme, this crossover gets you things like
       | arbitrary code execution on Super Mario World.
       | 
       | EDIT: There was supposed to be a link here.
       | https://www.youtube.com/watch?v=jnZ2NNYySuE
        
       | GrantMoyer wrote:
       | I also think a lot of speedrunnimg tecniques demontrate the
       | "anything can happen" nature of undefined behavior in an
       | viscerally, not-purely-theoretical way. What happens when you
       | don't take undefined behavior seriously? Well, then Mario can
       | backward longjump into a parallel universe and teleport enemies
       | on a whim.
        
       | tennisflyi wrote:
       | Maybe QA as well
        
         | turtleyacht wrote:
         | Yes, exactly. Detail-oriented, fault-finding domain experts.
         | Bridge the idea that functional testing, perf testing, and the
         | like are certain aspects of security. (Stealth) training folks
         | to cultivate a hacking mindset.
        
       | cushychicken wrote:
       | Worked with the folks at Zetier previously. They're bright. Go
       | work with them if you want to do some cool VR stuff.
        
       | andrewmcwatters wrote:
       | And some vulnerability researchers are just prosecution
       | speedrunners!
        
       | davedx wrote:
       | I watched the world record speedrun of Subnautica the other day
       | and someone was kind enough to have posted a comment with a full
       | list of all the bugs he exploited to beat the game in 28 minutes.
       | 
       | It was quite mind boggling. When I played the game I barely
       | encountered a single bug or glitch - it seemed pretty polished! -
       | but in actual fact there were 100's of outstanding bugs, years
       | after the game's release and multiple updates.
        
         | rat87 wrote:
         | It's doubtful that there is one piece of software that does
         | anything non trivial that has bugs, even short command line
         | programs. The best we can hope for is that bugs don't seem to
         | cause too many problems.
        
         | oasisaimlessly wrote:
         | I assume this is the speedrun you're talking about:
         | https://www.speedrun.com/subnautica/runs/ylp925xm
         | 
         | If you look in the top-right corner at 0:19, the build being
         | played is "Sep-2018 61056", strange for a Dec 2024 speedrun.
         | Presumably that specific old version was used _because_ the
         | glitches it relies on have been fixed in current versions.
        
           | chc4 wrote:
           | A lot of speedruns will not only use specific versions of
           | online patchable games, but old games will have players use
           | specifically Japanese or European physical copies for the
           | same reason: there are glitches that are only present on the
           | Japanese version of Pokemon Red/Blue that were fixed for the
           | NA release, for example. Some of the time it gets really
           | weird, like people specifically using the Wii Virtual Console
           | re-release of a game in order to take advantage of its
           | emulator being different from physical hardware - which is
           | (usually) allowed, because it's still an "official release".
        
             | n_plus_1_acc wrote:
             | Sometimes simply because the japanese Text is shorter,
             | taking less time to display. And there are also games that
             | run at different speeds on NTSC vs PAL versions.
        
       | minimaxir wrote:
       | The metaphor is a bit stretched for the purposes of content
       | marketing a startup. The major difference between vulnerability
       | researchers and the speedrunning community is that speedrunning
       | is highly _collaborative and open_. There are massive
       | speedrunning Discord communities for each game, and even before
       | Discord existed, tricks and hacks were discovered iteratively
       | just by many people watching other people do them often
       | unintentionally and trying to figure out how they work (a common
       | trend in every Summoning Salt video).
       | 
       | Nintendo doesn't care if people find ACE in decade-old games
       | (usually) and post decompiled versions of games on GitHub so
       | people can find out how they tick, but vulnerability researchers
       | can't do that unless they want to risk causing a legal shitstorm.
        
         | qwery wrote:
         | Yes, the differences are substantial. It's also worth noting
         | that although _some_ speedrunning may be akin to vulnerability
         | research, the vast majority of speedrunners are  "only"
         | practicing and replicating exploits demonstrated by others.
         | They're in different columns.
        
           | ajuc wrote:
           | They are script kiddies ;)
        
           | rfoo wrote:
           | > the vast majority of speedrunners are "only" practicing and
           | replicating exploits demonstrated by others
           | 
           | So they are red teamers :p
        
       | tbalsam wrote:
       | I'm a speedrunner, and I'm pretty sure this is well known -- and
       | accepted as standard in some categories! It's a pretty well
       | accepted standard (to the point of the headline being almost a
       | mild offense!).
       | 
       | In the gaming world, undefined software behavior is critical to
       | this sort of thing, we see this especially in some games like the
       | legendary exploits found in the Ocarina of Time speedruns for
       | example.
       | 
       | I mean, in Super Mario World, SethBling did code injection to
       | manually run a version of Flappy Bird (how ironic given the
       | origin of the pipes!) in the game. By hand. No savestates. It
       | took forever and the run through is really and truly fascinating:
       | https://youtu.be/hB6eY73sLV0?si=nIP07o_fa6O9rauW
       | 
       | I speedrun things other than games as well -- and so the
       | generalization is not just that we are security researchers, we
       | are people who fundamentally learn the "shape" of a thing very,
       | very well, and ways that this shape can be used to get from one
       | state on that shape to another.
       | 
       | In conclusion -- yes, it can be something as simple as security
       | research! But the joy and the beauty of speedrunning is something
       | so much bigger and beautiful than that -- though it certainly is
       | one outcome that can be had!
        
       | MrCheeze wrote:
       | I've wondered myself why there's so little overlap between these
       | two closely related interests of mine. Some of it seems to be the
       | "But I don't want to cure cancer. I want to turn people into
       | dinosaurs." effect, where some of the people working on
       | exploiting games ONLY care about what can be done in their one
       | game of interest - it doesn't always generalize to interest in
       | using the same techniques against everything else.
       | 
       | Of course there's also the fact that exploiting 20-30 year old
       | games is just vastly easier than modern software, due to the
       | total lack of mitigations in them. And that's on top of the fact
       | that with popular games, you're building on decades of reverse
       | engineering work rather than (potentially) starting from scratch.
       | And the arguably superior toolset (savestates etc).
       | 
       | But I think a very big factor is the one this blogpost is trying
       | to address - most people just don't know anything at all about
       | the vuln research industry, which is not exactly searching for
       | attention in the ways that speedruns broadcast to hundreds of
       | thousands of viewers for charity are.
        
         | minimaxir wrote:
         | For HN reference, MrCheeze is well known and has done quite a
         | lot of work over the years glitch-hunting in older games. (and
         | is cited in the SethBling video posted several times in this
         | thread)
        
         | orbital-decay wrote:
         | Because actual gaming vulnerability researchers that do know
         | who they are are called cheaters and are mostly active in
         | cutthroat PvP games, not single player ones. Just ask the
         | developers of Rust (the game, not the language), they know
         | everything about it. They were one of the very few devs to ask
         | the community to do what all communities in such games always
         | do anyway - find exploits and glitches, _and_ publish them on
         | Youtube. As a result, they ended up with a game that is pretty
         | robust to item duplication and general exploits.
        
       | TZubiri wrote:
       | Also competitive gamers and pannenkoek, which I can't fit into
       | any category. But the man found all of the bugs in super mario 64
       | and then some.
        
       | gunian wrote:
       | what about the road runner?
        
       | babuloseo wrote:
       | LOL another business exec or MBA bro trying to flood the
       | cybersecurity market, you guys are seriously reaching here.
        
       | stuaxo wrote:
       | For every fun thing there is a boring version someone will pay
       | you for that has none of the real reasons or joy in it.
        
       | oinkbutton wrote:
       | They really aren't, they are speedrunners.
       | 
       | They may have a set of skills and focus that overlaps with
       | vulnerability researchers, but they are doing a different thing.
       | 
       | It's like saying, "hunters are photographers, they just don't
       | know it yet" or "taxi drivers are f1 drivers..."
       | 
       | Resist the urge to collapse the world into the world view you
       | already have. Resist the urge to treat every skill and hobby like
       | a professional one for work. Let people enjoy things.
        
       ___________________________________________________________________
       (page generated 2025-03-02 23:00 UTC)