[HN Gopher] Speedrunners are vulnerability researchers, they jus...
___________________________________________________________________
Speedrunners are vulnerability researchers, they just don't know it
yet
Author : chc4
Score : 158 points
Date : 2025-03-02 17:40 UTC (5 hours ago)
(HTM) web link (zetier.com)
(TXT) w3m dump (zetier.com)
| klysm wrote:
| This is an interesting premise. I especially like framing speed
| runners as researchers
| echelon wrote:
| It's a super interesting premise, and I like it too.
|
| We should distinguish those in the community that actually
| discover new glitches from those who simply practice what
| others have uncovered, though. Those aren't always the same
| person.
| chc4 wrote:
| Yeah, there's definitely shades. I think for most games the
| people who find glitches and drive forward this kind of
| research usually aren't actually that good of runners
| themselves. But for TAS runs, where there isn't as much of
| human skill component and technical execution is more
| important, they're usually closer aligned. And in any case
| the speedrunners and glitch discovery people are all in the
| same discords together talking about the game.
| tonetegeatinst wrote:
| I remember watching a video about this a while ago....it was a
| fresh perspective into a side of security research I didn't
| consider.
| Almondsetat wrote:
| _some_ speedrunners that compete in categories where glitches are
| _allowed_ and who _find_ the bugs themselves can be labeled
| _hackers_.
| ismailmaj wrote:
| It's fairly rare to see people consistently find glitches
| across games, only distorsion2 comes to mind.
| casey2 wrote:
| Nope. I completely disagree.
|
| Unless you are using tools and rigorous methods you are just
| playing around. Just because most games are all broken in
| easily predictable ways doesn't mean every new game creates a
| hacker.
|
| It's more correct to say "speedrunners show that almost all
| game developers are bad at software engineering".
|
| sometimes good at creating fun games, but quick to say "you are
| holding it wrong" when you breath on the thing and it blows up.
| scott_w wrote:
| I think it's a harsh interpretation to say they're bad
| because a determined hacker can break their game. Games
| aren't security critical software, so they're not going to
| get the level of investment needed to prevent this kind of
| thing that, in practice, hurts nobody.
|
| That's to say nothing of exploits that can only be used by
| TAS software. That's like saying my car is a piece of shit
| because it'll not survive being driven into a volcano.
| Almondsetat wrote:
| Hacking _is_ playing around, that 's what hackers will tell
| you. You are conflating hacking with penetration testing or
| "formal" disciplines like that
| davidcbc wrote:
| Even ignoring this weird definition of a "hacker", you've
| shown how little you know about how many exploits in games
| are found. They often involve stepping through the assembly
| of the game to understand how a glitch works and how to use
| it in a useful way. Not just "screw around in a game until
| you suddenly discover a useful trick"
| tptacek wrote:
| This is absolutely and obviously true. Vulnerability researchers
| watch tool-assisted speedrun videos with jealousy. Side-note:
| when we did Microcorruption, game devs outperformed everybody but
| elite vuln researchers.
| chc4 wrote:
| Microcorruption is basically just a Zachtronics game, if you
| squint, which I always thought was a fun framing. Reading the
| blog posts about Starfighter/Stockfighter definitely made me
| think of video game style exploits, too, if not the same type
| of glitches. Video game players love to find ways to sell items
| to NPCs and then buy them back at a lower price for infinite
| money...
| nonrandomstring wrote:
| No doubt about this. Game-devs, modders, map-maker/hackers get
| hands on such a breadth of skills (graphics, sound, scripts,
| network) inside a contested environment that means a lot to
| them they naturally feel at home in cybersec.
| Graziano_M wrote:
| I got more satisfaction out of solving the last level of micro
| corruption than I probably have from beating any game.
| tptacek wrote:
| That rules. That last level was Nick Carlini and Hans
| Nielsen, both of whom have done awesome things since then; we
| just interviewed Nicholas on cryptanalytic attacks against
| LLMs:
|
| https://securitycryptographywhatever.com/2025/01/28/cryptana.
| ..
| joshdavham wrote:
| Interesting article!
|
| Though it's too bad that cyber security is not as intrinsically
| fun and interesting to a lot of speed runners as video games. A
| large part of what allows speedrunners to spend hours searching
| for glitches and exploits in these games is that they're having
| an absolute blast while doing it! Also exploiting glitches in
| decades old games is generally pretty accessible and doesn't have
| a high barrier to entry like cyber security.
| egypturnash wrote:
| Opens with an AI-generated image, I'm gonna assume the text is
| from the same source and close the tab.
| Dwedit wrote:
| Also no author listed on the article. Just "a Senior Cyber
| Engineer".
| prophesi wrote:
| I think if they're active in the speedrunning community, then
| they're already well aware of this! And for a fun additional
| example to add to this article, you can often find TAS'ers
| talking about arbitrary code execution. The legendary GDQ run of
| TASBot's alternate ending to OoT[0] utiziling an ACE exploit they
| found in that game absolutely blew me away.
|
| [0] https://youtu.be/PNbkv_DJ0f0?t=3112
| chamomeal wrote:
| I forgot the details, but I think I saw a YouTube upload of a
| streamer who wrote flappy bird into super Mario by like...
| jumping at apples at specific times. Or some weird thing like
| that lol. I'll try to find it later on my computer
| janetmissed wrote:
| https://youtu.be/hB6eY73sLV0?si=pF-etE5W-xZhoVBf
|
| here is the link for anyone curious
| Cockbrand wrote:
| Just when I thought I'd seen it all...
|
| Thank you for sharing this!
| Dwedit wrote:
| That would be SethBling who performed that.
| thatswrong0 wrote:
| I love Ocarina of Time speedruns. The sheer level of love that
| went into that specific run was sooooo beautiful, and like the
| fact they made it internet live.. via an N64...?
|
| I want to shout out ZFG if ppl arent aware cause he has IMO
| done the most technically impressive real time speedrun of any
| game - specifically the 100% SRM run he did is inscrutably
| insane. But it wasn't just about him - it was an effort by so
| many people. The number of glitches and exploits that have been
| found by the community, as well as the NP hard routing and
| tools created for finding angle perfect setups by various
| people..
|
| It's straight up community driven exploit art. And it's like
| yeah, the fastest way to beat the game is to practically
| manually manipulate memory to redirect specific function calls
| to give you stuff you need and float around and purposely void
| out facing exactly a 1/65536 perfect angle setup a hundred
| separate times to randomly jump around to various rooms in the
| game?? Wowwwww
|
| And the community around it is so wholesome. The sheer amount
| of collective curiosity, ingenuity, and effort to dismantle and
| exploit a 20+ year old game for no other purpose than going
| fast.. idk. Love it.
|
| Here's a commentated tool assisted human-like run (but not
| live): https://www.youtube.com/watch?v=R8EE9FXeJnE
|
| And the actual run: https://www.youtube.com/watch?v=Sdxdwnpi-wU
| pdpi wrote:
| At its most extreme, this crossover gets you things like
| arbitrary code execution on Super Mario World.
|
| EDIT: There was supposed to be a link here.
| https://www.youtube.com/watch?v=jnZ2NNYySuE
| GrantMoyer wrote:
| I also think a lot of speedrunnimg tecniques demontrate the
| "anything can happen" nature of undefined behavior in an
| viscerally, not-purely-theoretical way. What happens when you
| don't take undefined behavior seriously? Well, then Mario can
| backward longjump into a parallel universe and teleport enemies
| on a whim.
| tennisflyi wrote:
| Maybe QA as well
| turtleyacht wrote:
| Yes, exactly. Detail-oriented, fault-finding domain experts.
| Bridge the idea that functional testing, perf testing, and the
| like are certain aspects of security. (Stealth) training folks
| to cultivate a hacking mindset.
| cushychicken wrote:
| Worked with the folks at Zetier previously. They're bright. Go
| work with them if you want to do some cool VR stuff.
| andrewmcwatters wrote:
| And some vulnerability researchers are just prosecution
| speedrunners!
| davedx wrote:
| I watched the world record speedrun of Subnautica the other day
| and someone was kind enough to have posted a comment with a full
| list of all the bugs he exploited to beat the game in 28 minutes.
|
| It was quite mind boggling. When I played the game I barely
| encountered a single bug or glitch - it seemed pretty polished! -
| but in actual fact there were 100's of outstanding bugs, years
| after the game's release and multiple updates.
| rat87 wrote:
| It's doubtful that there is one piece of software that does
| anything non trivial that has bugs, even short command line
| programs. The best we can hope for is that bugs don't seem to
| cause too many problems.
| oasisaimlessly wrote:
| I assume this is the speedrun you're talking about:
| https://www.speedrun.com/subnautica/runs/ylp925xm
|
| If you look in the top-right corner at 0:19, the build being
| played is "Sep-2018 61056", strange for a Dec 2024 speedrun.
| Presumably that specific old version was used _because_ the
| glitches it relies on have been fixed in current versions.
| chc4 wrote:
| A lot of speedruns will not only use specific versions of
| online patchable games, but old games will have players use
| specifically Japanese or European physical copies for the
| same reason: there are glitches that are only present on the
| Japanese version of Pokemon Red/Blue that were fixed for the
| NA release, for example. Some of the time it gets really
| weird, like people specifically using the Wii Virtual Console
| re-release of a game in order to take advantage of its
| emulator being different from physical hardware - which is
| (usually) allowed, because it's still an "official release".
| n_plus_1_acc wrote:
| Sometimes simply because the japanese Text is shorter,
| taking less time to display. And there are also games that
| run at different speeds on NTSC vs PAL versions.
| minimaxir wrote:
| The metaphor is a bit stretched for the purposes of content
| marketing a startup. The major difference between vulnerability
| researchers and the speedrunning community is that speedrunning
| is highly _collaborative and open_. There are massive
| speedrunning Discord communities for each game, and even before
| Discord existed, tricks and hacks were discovered iteratively
| just by many people watching other people do them often
| unintentionally and trying to figure out how they work (a common
| trend in every Summoning Salt video).
|
| Nintendo doesn't care if people find ACE in decade-old games
| (usually) and post decompiled versions of games on GitHub so
| people can find out how they tick, but vulnerability researchers
| can't do that unless they want to risk causing a legal shitstorm.
| qwery wrote:
| Yes, the differences are substantial. It's also worth noting
| that although _some_ speedrunning may be akin to vulnerability
| research, the vast majority of speedrunners are "only"
| practicing and replicating exploits demonstrated by others.
| They're in different columns.
| ajuc wrote:
| They are script kiddies ;)
| rfoo wrote:
| > the vast majority of speedrunners are "only" practicing and
| replicating exploits demonstrated by others
|
| So they are red teamers :p
| tbalsam wrote:
| I'm a speedrunner, and I'm pretty sure this is well known -- and
| accepted as standard in some categories! It's a pretty well
| accepted standard (to the point of the headline being almost a
| mild offense!).
|
| In the gaming world, undefined software behavior is critical to
| this sort of thing, we see this especially in some games like the
| legendary exploits found in the Ocarina of Time speedruns for
| example.
|
| I mean, in Super Mario World, SethBling did code injection to
| manually run a version of Flappy Bird (how ironic given the
| origin of the pipes!) in the game. By hand. No savestates. It
| took forever and the run through is really and truly fascinating:
| https://youtu.be/hB6eY73sLV0?si=nIP07o_fa6O9rauW
|
| I speedrun things other than games as well -- and so the
| generalization is not just that we are security researchers, we
| are people who fundamentally learn the "shape" of a thing very,
| very well, and ways that this shape can be used to get from one
| state on that shape to another.
|
| In conclusion -- yes, it can be something as simple as security
| research! But the joy and the beauty of speedrunning is something
| so much bigger and beautiful than that -- though it certainly is
| one outcome that can be had!
| MrCheeze wrote:
| I've wondered myself why there's so little overlap between these
| two closely related interests of mine. Some of it seems to be the
| "But I don't want to cure cancer. I want to turn people into
| dinosaurs." effect, where some of the people working on
| exploiting games ONLY care about what can be done in their one
| game of interest - it doesn't always generalize to interest in
| using the same techniques against everything else.
|
| Of course there's also the fact that exploiting 20-30 year old
| games is just vastly easier than modern software, due to the
| total lack of mitigations in them. And that's on top of the fact
| that with popular games, you're building on decades of reverse
| engineering work rather than (potentially) starting from scratch.
| And the arguably superior toolset (savestates etc).
|
| But I think a very big factor is the one this blogpost is trying
| to address - most people just don't know anything at all about
| the vuln research industry, which is not exactly searching for
| attention in the ways that speedruns broadcast to hundreds of
| thousands of viewers for charity are.
| minimaxir wrote:
| For HN reference, MrCheeze is well known and has done quite a
| lot of work over the years glitch-hunting in older games. (and
| is cited in the SethBling video posted several times in this
| thread)
| orbital-decay wrote:
| Because actual gaming vulnerability researchers that do know
| who they are are called cheaters and are mostly active in
| cutthroat PvP games, not single player ones. Just ask the
| developers of Rust (the game, not the language), they know
| everything about it. They were one of the very few devs to ask
| the community to do what all communities in such games always
| do anyway - find exploits and glitches, _and_ publish them on
| Youtube. As a result, they ended up with a game that is pretty
| robust to item duplication and general exploits.
| TZubiri wrote:
| Also competitive gamers and pannenkoek, which I can't fit into
| any category. But the man found all of the bugs in super mario 64
| and then some.
| gunian wrote:
| what about the road runner?
| babuloseo wrote:
| LOL another business exec or MBA bro trying to flood the
| cybersecurity market, you guys are seriously reaching here.
| stuaxo wrote:
| For every fun thing there is a boring version someone will pay
| you for that has none of the real reasons or joy in it.
| oinkbutton wrote:
| They really aren't, they are speedrunners.
|
| They may have a set of skills and focus that overlaps with
| vulnerability researchers, but they are doing a different thing.
|
| It's like saying, "hunters are photographers, they just don't
| know it yet" or "taxi drivers are f1 drivers..."
|
| Resist the urge to collapse the world into the world view you
| already have. Resist the urge to treat every skill and hobby like
| a professional one for work. Let people enjoy things.
___________________________________________________________________
(page generated 2025-03-02 23:00 UTC)