[HN Gopher] Rainbow Six Siege hacked as players get billions of ...
       ___________________________________________________________________
        
       Rainbow Six Siege hacked as players get billions of credits and
       random bans
        
       Author : erhuve
       Score  : 272 points
       Date   : 2025-12-27 19:45 UTC (1 days ago)
        
 (HTM) web link (www.shanethegamer.com)
 (TXT) w3m dump (www.shanethegamer.com)
        
       | dvh wrote:
       | It's not random bans, the nicknames are words from longer text.
       | It's lyrics from Shaggy - It wasn't me.
        
         | ZeWaka wrote:
         | Global game messages being used to meme - reminds me of Team
         | Fortress 2 rings.
        
         | Levitz wrote:
         | Saw a video earlier today with the lyrics of Billie Jean by
         | Michael Jackson too.
        
         | purkka wrote:
         | Per the tweet linked in the article there were _also_ random
         | bans in addition to the ban feed shitposting.
         | 
         | https://x.com/KingGeorge/status/2004902566434668686
        
           | Modified3019 wrote:
           | Copy of tweet:
           | 
           | >@KingGeorge
           | 
           | >Seems like R6 is completely fucked. It's unreal how bad.
           | 
           | >Hackers have done the following.
           | 
           | >1. Banned + unbanned thousands of people.
           | 
           | >2. Taken over the ban feed can put anything.
           | 
           | >3. Gave everyone 2 billion credits + renown.
           | 
           | >4. Gave everyone every skin including dev skins.
           | 
           | >5:09 AM * Dec 27, 2025
        
         | vogtb wrote:
         | The line "How could I forget that I had given her an extra
         | key?" comes to mind. Maybe someone left an API key laying
         | around somewhere? Although I could be giving the hackers too
         | much credit...
        
           | super256 wrote:
           | Maybe the mongo db exploit from two days ago?
           | 
           | https://github.com/joe-desimone/mongobleed
           | 
           | https://beta.shodan.io/host/212.104.194.153
        
             | mrklol wrote:
             | Somebody else said some Postgres dumps are available, not
             | sure if they are even using mongo. But maybe mongo was the
             | start of the chain.
        
             | croes wrote:
             | Seems so
             | 
             | https://x.com/vxunderground/status/2005008887234048091
        
               | nhinck3 wrote:
               | lol leakier than a sieve.
        
               | Modified3019 wrote:
               | Copy of post:
               | 
               | >@vxunderground
               | 
               | >Clarification post, previous post about Ubisoft lead to
               | some confusion. That's my fault. I'll be more verbose. I
               | was trying to compress the information into 1 singular
               | post without it exceeding the word limit.
               | 
               | >Here's the word on the internet streets:
               | 
               | >- THE FIRST GROUP of individuals exploited a Rainbow 6
               | Siege service allowing them ban players, modify
               | inventory, etc. These individuals did not touch user data
               | (unsure if they even could). They gifted roughly
               | $339,960,000,000,000 worth of in-game currency to
               | players. Ubisoft will perform a roll back to undo the
               | damages. They're probably annoyed. I cannot go into full
               | details at this time how it was achieved.
               | 
               | >- A SECOND GROUP of individuals, unrelated to the FIRST
               | GROUP of individuals, exploited a MongoDB instance from
               | Ubisoft, using MongoBleed, which allowed them (in some
               | capacity) to pivot to an internal Git repository. They
               | exfiltrated a large portion of Ubisoft's internal source
               | code. They assert it is data from the 90's - present,
               | including software development kits, multiplayer
               | services, etc. I have medium to high confidence this
               | true. I've confirmed this with multiple parties.
               | 
               | >- A THIRD GROUP of individuals claim to have compromised
               | Ubisoft and exfiltrated user data by exploiting MongoDB
               | via MongoBleed. This group is trying to extort Ubisoft.
               | They have a name for their extortion group and are active
               | on Telegram. However, I have been unable to determine the
               | validity of their claims.
               | 
               | >- A FOURTH GROUP of individuals assert the SECOND group
               | of individuals are LYING and state the SECOND GROUP has
               | had access to the Ubisoft internal source code for
               | awhile. However, they state the SECOND GROUP is trying to
               | hide behind the FIRST GROUP to masquerade as them and
               | give them a reason to leak the source code in totality.
               | The FIRST GROUP and FOURTH GROUP is frustrated by this
               | 
               | >Will the SECOND GROUP leak the source code? Is the
               | SECOND GROUP telling the truth? Did the SECOND GROUP lie
               | and have access to Ubisoft code this whole time? Was it
               | MongoBleed? Will the FIRST GROUP get pinned for this? Who
               | is this mysterious THIRD GROUP? Is this group related to
               | any of the other groups?
               | 
               | >Find out next time on Dragon Ball Z
               | 
               | >12:12 PM * Dec 27, 2025
        
               | squigz wrote:
               | If they do, would this be the first time source code from
               | a major game publisher has been leaked?
        
               | esseph wrote:
               | Not remotely.
               | 
               | Why would you think that?
               | 
               | Witcher 3 / Cyberpunk 2077 / Gwent / GTA 5&6 / FIFA 21 /
               | Watch Dogs: Legion / etc.
        
               | dplgk wrote:
               | Sweet, can we open source Rainbox 6 Raven Shield?
        
       | Scaevolus wrote:
       | https://x.com/vxunderground/status/2005008887234048091
       | 
       | Here's the word on the internet streets:
       | 
       | - THE FIRST GROUP of individuals exploited a Rainbow 6 Siege
       | service allowing them ban players, modify inventory, etc. These
       | individuals did not touch user data (unsure if they even could).
       | They gifted roughly $339,960,000,000,000 worth of in-game
       | currency to players. Ubisoft will perform a roll back to undo the
       | damages. They're probably annoyed. I cannot go into full details
       | at this time how it was achieved.
       | 
       | - A SECOND GROUP of individuals, unrelated to the FIRST GROUP of
       | individuals, exploited a MongoDB instance from Ubisoft, using
       | MongoBleed, which allowed them (in some capacity) to pivot to an
       | internal Git repository. They exfiltrated a large portion of
       | Ubisoft's internal source code. They assert it is data from the
       | 90's - present, including software development kits, multiplayer
       | services, etc. I have medium to high confidence this true. I've
       | confirmed this with multiple parties.
       | 
       | - A THIRD GROUP of individuals claim to have compromised Ubisoft
       | and exfiltrated user data by exploiting MongoDB via MongoBleed.
       | This group is trying to extort Ubisoft. They have a name for
       | their extortion group and are active on Telegram. However, I have
       | been unable to determine the validity of their claims.
       | 
       | - A FOURTH GROUP of individuals assert the SECOND group of
       | individuals are LYING and state the SECOND GROUP has had access
       | to the Ubisoft internal source code for awhile. However, they
       | state the SECOND GROUP is trying to hide behind the FIRST GROUP
       | to masquerade as them and give them a reason to leak the source
       | code in totality. The FIRST GROUP and FOURTH GROUP is frustrated
       | by this
       | 
       | Will the SECOND GROUP leak the source code? Is the SECOND GROUP
       | telling the truth? Did the SECOND GROUP lie and have access to
       | Ubisoft code this whole time? Was it MongoBleed? Will the FIRST
       | GROUP get pinned for this? Who is this mysterious THIRD GROUP? Is
       | this group related to any of the other groups?
        
         | Group_B wrote:
         | Can't help but laugh a bit. Not a great day for Ubisoft.
         | Hopefully this didn't ruin the holidays for too many employees.
         | That would absolutely suck to get a call in for this.
        
         | adzm wrote:
         | > Will the SECOND GROUP leak the source code? Is the SECOND
         | GROUP telling the truth? Did the SECOND GROUP lie and have
         | access to Ubisoft code this whole time? Was it MongoBleed? Will
         | the FIRST GROUP get pinned for this? Who is this mysterious
         | THIRD GROUP? Is this group related to any of the other groups?
         | 
         | Find out in the next episode of... Tales from Cyberspace!
        
         | pjc50 wrote:
         | This has the air of a parody spy caper where the various people
         | who have broken in keep tripping over each other.
         | 
         | The source leak is really interesting, though. We don't often
         | get to see game source, and it often has surprises in.
        
           | RHSeeger wrote:
           | > Will the SECOND GROUP leak the source code? Is the SECOND
           | GROUP telling the truth? Did the SECOND GROUP lie and have
           | access to Ubisoft code this whole time? Was it MongoBleed?
           | Will the FIRST GROUP get pinned for this? Who is this
           | mysterious THIRD GROUP? Is this group related to any of the
           | other groups?
           | 
           | This read to me like the end of a soap opera. Tune in
           | tomorrow to find out!
        
         | azalemeth wrote:
         | Nothing highlights how pointless e-sports items are more than a
         | real dollar value for a player base of all of them. The entire
         | global GDP is as an order of magnitude roughly $100 trillion.
         | So this $340 trillion figure is 3.4 times planetary total
         | economic output - meaning the theoretical value of Rainbow Six
         | cosmetics exceeds what the entire human civilisation produces
         | in a year. Multiple times over. You'd be valuing pixelated gun
         | attachments higher than annual agricultural output across all
         | nations, all manufacturing, all services, everything.
         | 
         | I bet it appears unchallenged at some point in a court (or
         | insurance) document though.
        
           | andersa wrote:
           | You could achieve a similar sum by adding balances out of
           | thin air to random bank accounts, which is comparable to what
           | happened here.
        
           | RHSeeger wrote:
           | While I understand what you're saying, it's pretty clear what
           | is meant is "$X worth at the price they currently sell for".
           | When there's a story about an object in space made of gold
           | worth 100s of trillians of dollars, nobody believes it would
           | really sell for that much if we captured it and mined all the
           | gold; because the value of gold would plummet based purely on
           | it's existence.
           | 
           | But I agree with you that it would be put into a court
           | document as "it cost us this much" for the full amount, vs
           | the amount they were likely to ever be able to sell (and
           | can't, now that everyone got it for free, so the value is $0)
        
             | chii wrote:
             | and yet, most people use this same measure for market
             | capitalization of companies.
        
               | smallnamespace wrote:
               | The market cap is unambiguous, a more correct estimate of
               | "how much to buy all the shares?" is situational and
               | would just distract from getting the point across.
        
               | Aurornis wrote:
               | Not really. If a company were to manufacture a
               | substantially large number of shares out of nothing (no
               | additional investment money or other value entering the
               | company) then the market cap would not go up. It would
               | stay the same and per-share value would go down.
               | 
               | The market is mostly reasonable about who can and will
               | sell their shares. If a big mover does sell a lot of
               | their shares at once, the price will fall. Most big
               | holders will slowly sell off shares for this reason.
               | 
               | In the other direction, it's also understood that the
               | cost to acquire all shares of a company is more than the
               | market cap of a company. This is why you see acquisition
               | prices being significantly higher than the last funding
               | round valuation, or public shares popping on announcement
               | of an acquisition attempt.
        
           | nkrisc wrote:
           | The valuation is based on them hypothetically selling the
           | same quantities that the hackers gave away at their retail
           | prices, which of course no one believes they would ever
           | actually sell that much.
        
         | bombcar wrote:
         | At least it's webscale.
        
         | dijit wrote:
         | I used to work for Ubisoft, though not on Siege- I have met and
         | had detailed conversations with their lead architect though;
         | truthfully I remember little of those conversations.
         | 
         | Regarding the second group and access to source code; this is
         | unlikely for a combination of four reasons.
         | 
         | 1) The internal Ubisoft network is split between "player stuff"
         | (ONBE) and developer stuff.
         | 
         | 2) The ONBE network is deny by default, no movement is possible
         | unless its explicitly requested ahead of time, by developers,
         | in a formal request that must be limited in scope.
         | 
         | 3) ONBE to "developer network" connections are _almost never_
         | granted. We had _one_ exception to this on the Division, and it
         | was only because we could prove that getting code execution on
         | the host that made connections would require a long chain of
         | exploits. Of course that machine did not have complete access
         | to all of the git repos.
         | 
         | 4) Not a lot of stuff really uses git internally. Operations
         | staff and web developers prefer git strongly; so they use Git.
         | But nearly every project uses Perforce. Good look getting a
         | flow granted from ONBE to a perforce server. That will never
         | happen.
         | 
         | Siege, like The Division, worked against Ubisoft internal IT
         | policies to make the product even possible. (IT was punishingly
         | rigid) but some contracts were unviolatable.
         | 
         | The last I heard, Siege had headed to AWS and had free dominion
         | in their tenant, but it would need Ubiservices (also in AWS)
         | and those would route through ONBE.
         | 
         | I'm not sure if much changed, since a member of the board is
         | former Microsoft and has mandated a switch to Azure from the
         | top... But I am certain that these policies would likely be the
         | last to go.
        
           | jacquesm wrote:
           | I wonder how many times former Microsoft people demanding
           | switches to MS infrastructure are still actually working for
           | Microsoft.
        
             | dijit wrote:
             | I mean, I worked for Nokia in 2011..
             | 
             | .. you don't have to tell me.
        
               | jacquesm wrote:
               | Yes, that was a particularly dirty episode. I wrote about
               | it when it happened.
               | 
               | https://jacquesmattheij.com/microsoft-just-bought-nokia-
               | for-...
               | 
               | I think I got one prediction wrong but the rest stuck.
        
         | sznio wrote:
         | Four attackers present in a system at the same time?
         | 
         | How?
        
           | sureglymop wrote:
           | Misconfigured database that was publicly accessible,
           | vulnerability/exploit dropped around the same time.
        
         | fainpul wrote:
         | > Players across PC and console are being urged by the
         | community to stay offline, as reports continue to surface of
         | accounts receiving billions of in game credits, rare and
         | developer only skins, and experiencing random bans.
         | 
         | Regardless if this is true or not, and how it works exactly, I
         | find it an interesting scenario.
         | 
         | For players: should I go online to maybe get gifted tons of
         | ingame valuables while risking a ban? It turns playing into a
         | gamble.
         | 
         | If I take on the hackers' view, I would find it exciting to
         | dish out rewards and punishment at random on a large scale.
        
         | The_President wrote:
         | The attackers better hope they fully hid their tracks - this is
         | a bold hack, and such an level of overt cybercriminality with
         | financial damages will result in a decade in prison if caught.
        
       | navigate8310 wrote:
       | It's a shame this game has to pander to eSports fanatics
       | rendering it into a completely hollowed out soulless experience.
       | From the early days of Operation Chimera to selling half of your
       | stake and IPs to Tencent, Ubisoft has seen it all.
        
         | reactordev wrote:
         | Ubisoft kept making garbage and sacrificed their IP's for the
         | sake of keeping the company alive...
         | 
         | It was doomed.
        
           | Insanity wrote:
           | +1. Can't believe how they held amazing IPs and then milked
           | them to death while lowering the quality game over game.
           | Whether it's far cry or assassin's creed, all the later
           | iterations are worse than the series start.
        
             | chatmasta wrote:
             | I'm still bitter at them for canceling XDefiant... it
             | wasn't a COD killer but it filled a comfortable niche and
             | had potential.
        
               | Insanity wrote:
               | Oh wow, they cancelled it? I played it for a bit on
               | release. Kinda fun, didn't stick with it, but surprised
               | it's already cancelled so short after release.
        
               | reactordev wrote:
               | >"too far away from reaching the results required to
               | enable further significant investment"
               | 
               | That's the statement they said when they shut it down.
               | Ubisoft only had one goal all of 2010s, to turn item shop
               | marketplace micro transactions into their primary
               | business. They failed. They failed because they forgot
               | why they existed. So let's all make them remember.
        
         | newsclues wrote:
         | This game was amazing at launch, recently tried it again and
         | it's become trash
        
         | bob1029 wrote:
         | > It's a shame this game has to pander to eSports fanatics
         | rendering it into a completely hollowed out soulless
         | experience.
         | 
         | There have been many victims of the eSports neuroticism. League
         | of Legends is probably the most extreme example I can come up
         | with. You will eventually get _banned from the game_ if you
         | choose the  "wrong" play style. You don't even have to cheat or
         | play poorly. Overwatch suffered a very similar fate - They
         | removed a player slot to force it to fit the "5 man" meta. In
         | the case of OW, the changes proved so unpopular they had to
         | literally delete the original title from everyone's PC to force
         | use of the only remaining option.
        
           | morshu9001 wrote:
           | Not much good happens where people are treating video games
           | like a hobby or even job. Last time I played that type of
           | game was csgo in college, never again.
        
       | lysace wrote:
       | A 9 year old random FPS game.
       | 
       | WTF happened to non-shooter games? I am so bored of these FPS
       | variations.
        
         | dmbche wrote:
         | Maybe check out game awards finalists
        
           | lysace wrote:
           | I checked them out. I guess I just miss a time when Falcon
           | 3.0 and https://en.wikipedia.org/wiki/Stunt_Island sold
           | really well.
        
             | ThrowawayTestr wrote:
             | We've come a long way in the past 30 years
        
               | lysace wrote:
               | Yeah, 1000 variations later, the latest Doom/Quake
               | iteration looks great.
        
               | manytimesaway wrote:
               | Summing up the entire FPS genre as Doom-like is unfair
               | and discredits you more than anything else. Heck, even
               | Doom and Quake are wildly different.
               | 
               | FPS haven't been under the spotlights for a while, these
               | days it's mostly MOBAs.
        
               | dmbche wrote:
               | I do like Dusk (and most New Blood releases) if that's
               | what you mean
        
               | bigyabai wrote:
               | Ultrakill is better than every DOOM campaign combined.
        
             | happosai wrote:
             | Miss falcon 3.0? Go with Falcon BMS. For any genre of games
             | there is a modern remake and community these days.
        
               | iamacyborg wrote:
               | I literally discovered a completely free and open source
               | Total Annihilation/Supreme Commander remake last month
               | which is great for nostalgia's sake.
               | 
               | https://www.beyondallreason.info/
        
             | xioxox wrote:
             | Stunt Island was pretty good. However, there are more
             | unusual games out there with reasonable budgets, like Death
             | Stranding, The Talos Principle, The Outer Wilds, Portal and
             | X4:Foundations. Even games involving shooting like Control
             | or Alan Wake 2 are driven by unusual story telling.
        
           | Akronymus wrote:
           | IMO the vidya gaem awards [0] are far superior to the game
           | awards.
           | 
           | [0] https://www.youtube.com/watch?v=mXMcq_LJ8ro
        
             | waffleiron wrote:
             | Maybe you can give a bit of context why you feel that way?
             | Dropping a 2+ hour, <2000 views, 4chan video without
             | context isn't really the type of comment HN is looking for
             | as far as I can tell
        
               | navigate8310 wrote:
               | https://vidyagaemawards.com/previous-years
        
         | tyre wrote:
         | Play Hades 2!
        
         | comrh wrote:
         | We're currently in a golden age of Indie games catering to
         | hyper specific niches. Ignore all AAA games and you'll find
         | absolute gems.
        
         | bavell wrote:
         | Some very fun indie games I've been playing this past year
         | (lots of early access):
         | 
         | - Hexarchy / Rogue hex (Civ-like)
         | 
         | - The Last Caretaker
         | 
         | - Captain of Industry (factorio-like, was posted here on HN by
         | dev awhile back)
         | 
         | - 9 kings
         | 
         | - Super Fantasy Kingdom
         | 
         | - Manor Lords
         | 
         | - Astronomics
         | 
         | - Heart of the Machine
        
           | lysace wrote:
           | Those games have 100x to 500x smaller budgets than the AAA-
           | games. Yes, they often have cute ideas, but, like a
           | blockbuster movie, 99 times out of 100 you need a solid
           | budget to make a solid movie/game.
        
             | egypturnash wrote:
             | Wikipedia has a list of the most expensive video games to
             | develop, with a lower limit of $50mil. https://en.wikipedia
             | .org/wiki/List_of_most_expensive_video_g...
             | 
             | The top of the list is Genshin Impact, although it'll
             | probably be displaced by GTA6 soon - that one's estimated
             | to come in at $1.5-2 million. There's multiple FPS games on
             | there but there's some pretty expensive open-world games
             | too.
        
               | Hendrikto wrote:
               | > $1.5-2 million
               | 
               | You mean billion?
        
               | egypturnash wrote:
               | yeah, sorry :)
        
               | FarmerPotato wrote:
               | I love that E.T. from 1982 stays on the list because of
               | inflation. Adds some perspective.
        
             | handoflixue wrote:
             | > 99 times out of 100 you need a solid budget to make a
             | solid movie/game.
             | 
             | Sure, but 1 in 100 still gets you dozens of games a year
             | now. There's plenty of genres where the top titles are
             | nowhere near an AAA budget: Hades 2, Silksong, and Claire
             | Obscura all being popular examples from this year, and
             | Factorio being another well known example around here. Even
             | simpler games like Balatro and Vampire Survivor are plenty
             | of fun for some people.
             | 
             | The biggest studios have rarely been the ones producing the
             | best work - budget gets you fancy cinematics and a
             | beautifully rendered 3D world, but it doesn't make level
             | design go any faster. It could plausibly buy better
             | writing, but that requires all the executives to back off
             | and trust the creatives.
             | 
             | And for what it's worth, the big studios are all happy
             | raking in money on mindless remakes - it keeps working for
             | them.
        
               | reyqn wrote:
               | I would argue clair obscur is actually a shooter game
               | seeing the variety of op builds
        
             | Broken_Hippo wrote:
             | If you want AAA games, you are going to have a safe game.
             | You get the same with movies - Bigger budgets cause safer
             | behavior with less risk taking. You wind up with a pretty
             | game, a somewhat safe story (that they think will sell) and
             | gameplay they think is just good enough to keep you going.
             | 
             | It isn't that the other games are bad, though. It isn't
             | like we are talking "handheld camcorder student-written
             | movie" vs "polished hollywood blockbuster" but more....
             | Beautiful painting by a mostly unknown artist vs beautiful
             | large, publically displayed and privatly funded artist. Big
             | budgets get you more assistance and more/better tools and
             | more space and more human help and more connections.
             | 
             | It is probably important to remember that a large portion
             | of a blockbuster's budget is advertising. Advertising is
             | often 50-100% of the production budget and I'm guessing AAA
             | games have similar advertising budgets. I'm not sure how a
             | large advertising budget gives you better products, though
             | it might get you more folks if your game is online.
             | 
             | Of course, I'm guessing if you limit your search to FPS
             | games, your experience might be a different.
        
             | Fargren wrote:
             | If 1% of indie games are solid, and all AAA game are solid,
             | and there are 100 times more indie games than AAA games,
             | then there would still be the same amount of solid indies
             | as there are solid AAA games. As it is, I think for every
             | good AAA game, there are somewhere between 50 and 500 great
             | indie games.
             | 
             | Finding them is slightly harder, but absolutely worth it.
             | 
             | In any case, complaining about how many games there are out
             | there that are not your thing is a waste of time. Much
             | better to define what you like and look for recommendations
             | from people who like similar games. Who care how many FPSs
             | are released if you don't like FPSs? If you like RPGs, find
             | RPG gamers and ask them what's good. Substitute for any
             | genre; there is no genre out there that's not getting more
             | releases than you could possibly play.
        
             | bavell wrote:
             | I've played the above games at least 100x more than I've
             | played any AAA titles this year :)
        
             | malka1986 wrote:
             | Hopefully, AAA games era is coming to an end.
        
         | phantasmish wrote:
         | This is like complaining all modern movies are superhero
         | movies. It's hard to think that unless you're hardly looking at
         | all, or have fairly narrow taste and aren't counting most of
         | the medium.
        
         | cortesoft wrote:
         | I play non FPS video games almost every night. There are so
         | many great games available.
        
           | amanaplanacanal wrote:
           | Yes. I tend to lean to MMOs, ARPGs, and survival/building
           | games.
        
       | 476392647282 wrote:
       | > Prominent Siege creator KingGeorge
       | 
       | So, the lead developer?
        
         | mananaysiempre wrote:
         | Streamer[1,2], formerly pro gamer[3]. "Creator" here is a
         | clipping of "content creator", an overtly ad-industry term that
         | makes me a little sad(der) each time I hear it but is
         | unfortunately universal nowadays, especially for people making
         | videos (as we don't really have another umbrella word for
         | that).
         | 
         | [1] https://www.youtube.com/channel/UCsHlla-bq0C_2OtEy8s2_Sg
         | 
         | [2] https://www.twitch.tv/kinggeorge
         | 
         | [3] https://liquipedia.net/rainbowsix/KingGeorge
        
         | leetbulb wrote:
         | "Prominent" being sub 1000 views on YouTube?
        
           | nixgeek wrote:
           | A million subscribers on Twitch?
        
             | leetbulb wrote:
             | Fair. Didn't check Twitch.
        
       | jay_kyburz wrote:
       | I wonder if they could push out an update. That would be super
       | scary.
        
         | jacquesm wrote:
         | That depends, they might just fix some bugs and call it a day.
         | There would have to be a trial of the pyx for sure to figure
         | out what got changed and by who.
        
           | afdbcreid wrote:
           | I think GP is saying that if the _attackers_ can push an
           | update it will be scary.
        
             | jacquesm wrote:
             | Yes, I got that.
        
       | petterroea wrote:
       | Hard to have sympathy for Ubisoft the company as they are
       | regularly used as an example of the most anti-consumer practices
       | out there. But the whole situation is a mess, and if anything, it
       | is probably the consumers that will end up suffering the most for
       | this.
        
       | pjmlp wrote:
       | This is why security actually matters in game development.
        
       | miohtama wrote:
       | It is Mongo
       | 
       | https://x.com/vxunderground/status/2005008887234048091?s=20
        
       | butz wrote:
       | Nice to see anti-cheats working and protecting Linux players from
       | hacks, by preventing them from actually playing the game.
        
         | sylware wrote:
         | "kernel anti-cheat" is actually a re-branding of "anti-(non
         | steamdeck)-linux" software, probably to please msft (since sole
         | beneficiary). We all know they are inefficient and weaponized
         | by hackers.
         | 
         | You know on linux there is a feature for a process to snoop
         | into another process, that for the same user (non root), can be
         | use for anti-tampering: with a proper "security" team, as all
         | live-service games should have, you can give hell to hackers
         | without a kernel module...
        
           | firtoz wrote:
           | How trivial is it to pretend to be a steam deck?
        
             | jdubs1984 wrote:
             | In what context? To show up at work and convince everyone
             | you're a steam deck?
             | 
             | Thats probably pretty difficult.
        
               | westmeal wrote:
               | Easy enough with the right costume and plenty of
               | confidence.
        
           | Thaxll wrote:
           | Kernel anti cheat in the client are the strongest form of
           | protection by far, your comment makes no sense, anything
           | userspace is easily spoofed. You can create a driver ( module
           | ) that intercept calls and that is completely invisible to
           | userspace processes.
           | 
           | The default security measures on Linux are pretty bad
           | compared to windows, it's not even close. People like to bash
           | windows but they have a way better security model.
        
             | sylware wrote:
             | 1 - kernel module from anti-cheats are weaponized by
             | hackers.
             | 
             | 2 - if I recall properly, that linux feature is a direct
             | mapping of the target user process allowing extreme
             | dynamicity in time, performant, and much more powerfull
             | mechanisms than basic 'calls'. Namely hell for hackers if a
             | live service game has a proper "security" team, all that
             | without a kernel module.
        
               | dijit wrote:
               | What are you even talking about?
               | 
               | The parent is right.
               | 
               | I'm quite literally the first person to bash Windows for
               | being a shitty operating system, but the requirement for
               | signed modules puts a massive barrier to entry for
               | cheaters, where Linux can load just about anything.
               | 
               | If every system call can lie to you, there's a few things
               | you can do, but it's not many.
               | 
               | I know this because I've actually done a lot of due
               | diligence on anti-cheat.
               | 
               | One mechanism I attempted to employ was to replay
               | initalisation vectors and determinism of inputs; this
               | means I could replay your session out of band and witness
               | the same outcomes. If there was variation then there's a
               | fault. Except as soon as you introduce floating point
               | numbers there's no more determinism... Oh well.
               | 
               | The other was to watch for "impossible" things, but then
               | you need to run full complex physics simulations for
               | every client. If your game requires you to effectively
               | buy an i7-11700k for every user then you'd have to sell
               | your game for a lot more money, _and_ limit how long they
               | can play - nobody wants this.
               | 
               | The third option was to score our best players and anyone
               | who performs better than that gets their behaviour
               | tracked. The problem is, coming up with a scoring system
               | that's server side is much harder than you think.
               | 
               | GameDevs don't actually like paying a shit load of money
               | for anti-cheat (that also breaks their debugging systems
               | and causes bugs: a wonderful combination)... so if you've
               | got a better way: join the industry and fix it. You'll be
               | a moderately wealthy person.
        
               | sylware wrote:
               | What are you talking about?
               | 
               | 1 - kernel anti-cheats ARE weaponized by hackers. This is
               | not a matter of discussion unless you are into the AI
               | generated HN news conspiracy.
               | 
               | 2 - this linux feature should provide (if I recall
               | properly) a very complex and flexible (not limited to
               | "calls"), and performant, set of interactions between a
               | set of anti-cheat processes and the set of game
               | processes. All that as being non-root priviledge (I think
               | you must be have the same effective user id). The actual
               | and real parameter is the level of competence and
               | creativity of the "anti-cheat" team which is a
               | requirement of any "live-service games" with frequent
               | updates.
               | 
               | 3 - for FPS games where aiming skill is critical, anti-
               | cheat are close to useless due to "external" AI based aim
               | assist hardware.
        
               | Thaxll wrote:
               | 1. They're not, not sure where you've seen that, not in
               | western games at least.
        
               | esseph wrote:
               | > "The researchers investigated the techniques used in
               | online game cheating, as well as those deployed by 'anti-
               | cheat' technologies. Most modern anti-cheat engines run
               | in the Windows kernel, alongside applications such as
               | anti-virus, at the highest levels of privilege. Software
               | can only run in the Windows kernel if it has been
               | approved and signed by Microsoft. This makes it more
               | powerful than software run normally by the user. An
               | example of kernel level software is the Crowdstrike
               | system that recently failed, bringing down large parts of
               | the internet."
               | 
               | > "While the anti-cheats are allowed in the kernel by
               | Microsoft, the study also revealed that cheat software
               | commonly uses weaknesses in Windows protections to
               | 'inject' itself into the kernel and gain higher
               | privileges. Many techniques mirror what is commonly seen
               | in the domains of malware and anti-virus, with a
               | difference in motivation."
               | 
               | > "This kernel injection technique has previously been
               | observed in advanced ransomware attacks to disable anti-
               | malware protections before the main attack."
               | 
               | https://www.eurekalert.org/news-releases/1061994
        
               | transcriptase wrote:
               | I've seen so many cases of cheaters online where even the
               | most braindead of checks would neuter most cheats:
               | 
               | Are they moving faster than conceivably possible by a
               | real player? Even the most basic (x2-x1)/t > twice the
               | theoretical will catch people teleporting or speed
               | hacking.
               | 
               | Is their KDR or any other performance metric outside 5
               | standard deviations from the mean?
               | 
               | Here's one: is everyone they encounter reporting them for
               | cheating along with one of the above? Do people leave
               | their matches constantly?
               | 
               | Defining and detecting objectively impossible things is
               | not impossible.
        
               | dijit wrote:
               | Yeah, we do those things.
               | 
               | 1) they're not foolproof
               | 
               | 2) there is a delay in aggregating the data
               | 
               | this has annoying effects when the game has a trial
               | period/goes on sale/has lots of cheap CD keys floating
               | around.
               | 
               | 3) if you weren't delayed then the cheaters get better at
               | adjusting to how you catch them.
               | 
               | We actually do a lot of statistical analysis, but it
               | works in tandem with endpoint anti-cheat, and would
               | hardly work at all alone.
        
               | brightball wrote:
               | I know when I spent a lot of time dealing with fraud in a
               | different market, the most effective tool was to catch
               | and shadowban the accounts rather than banning them.
               | 
               | If we banned them, they just created a new account and
               | kept doing the same things.
               | 
               | When we detected them and the isolated them from all
               | other good standing accounts, only allowing them to
               | interact with other shadowbanned users, it virtually
               | solved the problem. Normal users went about their day and
               | the cheaters/fraudsters wasted a lot of time never
               | getting through to anyone.
               | 
               | In gaming it seems like creating a cheaters purgatory
               | where they are stuck competing against other cheaters
               | forever would probably end up being its own special
               | league after a while. Like when people suggested steroids
               | in pro-baseball should be legal.
        
               | dijit wrote:
               | Yeah, we actually discussed doing something like that.
               | 
               | That's what GTA5 did (though, they marked you with a
               | dunce cap)...
               | 
               | .. even though it's a good idea (and we nearly
               | implemented it actually), there's probably a reason that
               | GTA5 is _still_ plagued with cheaters.
        
               | Thaxll wrote:
               | Scoring ect ... is kind of useless because it's not a
               | proof, basically it means nothing tangible to be able to
               | ban with 100% confidence. That's why ML is not good for
               | detecting cheaters.
               | 
               | It gives a score that is hard to use.
        
               | Aerroon wrote:
               | > _Are they moving faster than conceivably possible by a
               | real player? Even the most basic (x2-x1) /t > twice the
               | theoretical will catch people teleporting or speed
               | hacking._
               | 
               | This is how I imagine Amazon ended up banning a large
               | amount of players for speedhacking. The players were
               | lagging. I'm guessing their anti-lag features ended up
               | moving them faster than the anti-cheat expected.
               | 
               | But I agree that a combination approach would probably
               | work.
        
               | mschuster91 wrote:
               | > GameDevs don't actually like paying a shit load of
               | money for anti-cheat (that also breaks their debugging
               | systems and causes bugs: a wonderful combination)... so
               | if you've got a better way: join the industry and fix it.
               | You'll be a moderately wealthy person.
               | 
               | I got a better way... just look at the past. Back in ye
               | goode olde UT2004 times, there was no random matchmaking
               | / ranking bullshit that removed the social element, game
               | licenses cost money, people ran their own servers, and if
               | you pissed off server mods enough, no matter if you were
               | a cheater, a suspected cheater, or just an asshole, your
               | serial got banned - sometimes, across a fleet of servers
               | that shared ban lists. Cheating had _costs_ associated.
               | 
               | But of course, that means you can't lure in whales with
               | free to play games and loot them via microtransactions
               | any more...
        
               | dijit wrote:
               | Thats a cynical take.
               | 
               | The truth is that UT2004 sold 234,451 units over its life
               | according to Wikipedia.
               | 
               | The Division sold over 10,000,000 copies in the first
               | weekend.
               | 
               | The requirements change drastically when you have a
               | larger audience.
        
               | mschuster91 wrote:
               | > Thats a cynical take.
               | 
               | Primarily driven by my utter disgust for modern
               | monetization mechanics, corporate greed and gambling.
               | Cheaters, IMHO, are an inevitable side effect of
               | combining gamification with gambling, with no barriers to
               | entry, and with removing social barriers of entry.
               | 
               | > The requirements change drastically when you have a
               | larger audience.
               | 
               | The market has exploded in the 12 years between UT2004
               | and The Division.
        
               | dijit wrote:
               | > The market has exploded in the 12 years between UT2004
               | and The Division.
               | 
               | Yes, and you can't assert that it didn't happen at least
               | in part due to efforts to make games more accessible.
               | 
               | You couldn't release a game like UT2004 today with the
               | same UX and expect competitive sales. Even if you did,
               | the experience would scale very poorly.
        
               | mjr00 wrote:
               | I played Warcraft 3 competitively in the "goode olde"
               | times. Ladder was full to bursting with maphackers. It
               | was still the way most people played, even though it also
               | fully supported custom lobbies/rooms, which were used
               | plenty for DotA, but almost never for random 1v1 matches.
               | It sucked.
               | 
               | You _don 't_ have a better way. You have a nostalgic
               | memory of how games should be played which doesn't match
               | what people in a modern audience expect. It's like saying
               | the solution to cell phones tracking you is to use a
               | landline, because that's how we used to do things.
        
               | ThatPlayer wrote:
               | This ignores that community servers basically invented
               | client anticheats. Almost all the current 3rd party
               | anticheats started for community servers. Even Quake 3
               | Arena was updated with Punkbuster at some point.
               | 
               | You still see this with modern day servers. Modded GTA V,
               | FiveM, had additional anticheat even before the unmodded
               | game added anticheat. Part of the appeal of CS2 servers,
               | Face-IT and ESEA, is the additional anticheats.
        
               | esseph wrote:
               | If companies have the ability to control the binaries
               | that run on your PC, and prevent you from running the
               | ones you want, you're cooked.
        
           | well_ackshually wrote:
           | Man, even "Area 51 has aliens" is a better and more backed up
           | conspiracy theory than this. Kernel AC isn't to please MS,
           | nor is it to shit on Linux/Steam Deck. They don't matter.
           | They're inexistent. They're a blip of very vocal users that
           | keep believing that Proton is going to save them from EA
           | making shit games.
           | 
           | KACs exist because they want to have higher privileges to not
           | be injected into, closed or otherwise touched by any other
           | process. That's also why a bunch of them have started to ask
           | for Secure Boot, so that they can guarantee at least some
           | chain of trust that ensures you've probably not tampered with
           | your machine.
           | 
           | Your Linux example 1/ turns anti cheats into not only
           | something that analyzes what runs on your machine, but
           | actively tries to attack it, which is the textbook definition
           | of malware, but also a gigantic liability should you happen
           | to say, write into word.exe because you fucked up and thought
           | it was a cheat. 2/ turns it into an infinite game of chasing
           | each others with you injecting into cheats, cheats injecting
           | into you, back and forth. In addition, you're running on an
           | actively hostile machine with a hostile user that _wants_ to
           | fuck over your anti cheat.
           | 
           | Please do some proper research on the subject.
        
             | sylware wrote:
             | A user level anti-tampering software (and more with such
             | linux feature) is not a kernel module which is weaponized
             | by hackers.
        
           | not_a9 wrote:
           | > We all know they are inefficient and weaponized by hackers.
           | 
           | Name an exploit in EAC/BattlEye/Vanguard/FaceIT/whatever
           | other big name anticheat middleware (though Vanguard and
           | FaceIT don't sell their services I think) that has actually
           | been used for anything.
           | 
           | Genshin Impact's driver got used as a vulnerable driver that
           | one time, yeah. EAC had an exploit to inject your own code
           | into processes, but that quickly got patched
           | (https://blog.back.engineering/10/08/2021/).
        
             | Aerroon wrote:
             | ESEA's anticheat was used to mine Bitcoin on the players'
             | computers. They are/were a major competitor of FaceIt. They
             | supposedly had to pay a $1 million settlement over it.
             | 
             | So not an exploit, but even worse.
        
         | cedws wrote:
         | Games using Easy AntiCheat can opt in to Linux support. Arc
         | Raiders runs on Linux (but not in VMs) whereas Fortnite does
         | not, because Epic has chosen not to support Linux. Ironic given
         | Tim Sweeney's supposed anti-monopoly stance.
        
           | bhargav wrote:
           | > Ironic given Tim Sweeney's supposed anti-monopoly stance.
           | 
           | This doesn't really make sense. If you are implying he is FOR
           | monopoly, he would want the game on every possible platform
           | right? He loses money by not having more players playing his
           | game.
        
             | Hendrikto wrote:
             | The person you replied to obviously referred to the Windows
             | monopoly.
        
             | Zambyte wrote:
             | That's why it's ironic. Maybe you're missing the context of
             | the iOS App Store case, which is why he is supposedly anti
             | monopoly.
        
           | brookst wrote:
           | Sweeney isn't anti-monopoly, he's pro-Sweeney. He sees an
           | opportunity to let others do the work and investment to build
           | platforms, then selectively swoop in to compete once the risk
           | and investment pay off.
           | 
           | It's not a bad business model if he can get the courts on his
           | side: let others spend billions and take risks, then cherry
           | pick the successful platforms and compete with their
           | distribution using a cost basis that doesn't have those up-
           | front costs and risks.
        
             | michaelt wrote:
             | _> He sees an opportunity to let others do the work and
             | investment to build platforms, then selectively swoop in to
             | compete once the risk and investment pay off._
             | 
             | Sure. Just as long as you agree Google and Apple let others
             | do the work and investment to develop new games, apps and
             | media, then swoop in and demand a cut if the risk and
             | investment pay off.
        
               | EA-3167 wrote:
               | They don't automatically take a cut, they only take a cut
               | when you want to sell to their captive audience, on their
               | hardware, using their distribution system.
               | 
               | Wait until you hear about how the entire entertainment
               | industry has always worked!
        
               | michaelt wrote:
               | _Their_ hardware, huh?
               | 
               | You're right, customers don't really _own_ an iphone,
               | even if they 've paid $1000 for it.
        
             | CamperBob2 wrote:
             | _He sees an opportunity to let others do the work and
             | investment to build platforms^H^H^H^H^H^H^H^H^H apps, then
             | selectively swoop in to compete once the risk and
             | investment pay off._
             | 
             | If that's not a flawless description of a walled-garden app
             | store, I can't imagine what would be.
        
           | not_a9 wrote:
           | > because Epic has chosen not to support Linux
           | 
           | Because Epic doesn't want payhack configs to be advertised in
           | whatever leaderboards Fortnite has, like CS2 had for a while.
        
             | cedws wrote:
             | Fortnite is easy to run in a hypervisor and also cheaters
             | are using hardware DMA to cheat these days anyway. The
             | proposition that Linux enables more cheating relative to
             | Windows is unproven.
        
           | reactordev wrote:
           | Tim Sweeney is anti other-people's-monopoly. He's happy to
           | support his own.
        
         | Thaxll wrote:
         | This hack has nothing to do with client cheats.
        
         | Aurornis wrote:
         | These changes are occurring in a server backend database.
         | They're not client side cheats.
         | 
         | The people receiving the credits aren't even the ones
         | initiating the changes.
         | 
         | Also many anti-cheat packages do have Linux versions. The
         | primary reason you're not getting ports for Linux is because
         | companies don't want to do the port and support all versions of
         | Linux clients they would encounter in the very tiny number of
         | additional installs.
        
           | netbioserror wrote:
           | Proton is a single build target, and it's just the Windows
           | build target.
        
             | reactordev wrote:
             | Exactly, this argument wasn't a good one 10 years ago and
             | it definitely isn't one now.
        
             | tpxl wrote:
             | Valve maintains a 'Steam Runtime', which is similar to a
             | docker container, to ensure it's easy to develop games that
             | run on many distributions.
        
             | mschuster91 wrote:
             | The problem is kernel level cheats, can't defend against
             | those from pure userland.
        
               | seba_dos1 wrote:
               | Soon: The problem is DMA level cheats, can't defend
               | against those from the kernel.
        
               | jetbalsa wrote:
               | Oh those are already here, Its why Battlefield needs
               | Secureboot turned on so it can use the IOMMU to protect
               | the game kinda
        
       | runtimepanic wrote:
       | This is the nightmare scenario for live-service games: once the
       | integrity of progression and bans is compromised, trust
       | evaporates fast. Rolling back "billions of credits" is easy
       | compared to undoing random bans.
        
       | Surac wrote:
       | Ubislop, Ubislop never changes. Never trust a Ubislop
        
       | prmoustache wrote:
       | "That wording has been met with heavy backlash from players, many
       | of whom believe Ubisoft is attempting to downplay the severity of
       | the situation."
       | 
       | Come on it is just a game (*_*)
        
       | luxuryballs wrote:
       | Rainbowhood
        
       | mlacks wrote:
       | It appears to be from the mongo db exploit. Sort of like
       | Heartbleed from a few years ago.
       | 
       | https://github.com/joe-desimone/mongobleed
       | 
       | https://beta.shodan.io/host/212.104.194.153
        
       | MattDaEskimo wrote:
       | My heart goes out to the devs forced to return to work to solve
       | these issues. Numerous groups claiming numerous exploits - mostly
       | MongoBleed.
       | 
       | One has to wonder: why didn't anyone anticipate this happening?
       | Surely the moment this exploit was discovered the team would've
       | locked it down immediately?
        
       | rldjbpin wrote:
       | poured way too many hours into this game long back before it
       | became too painful to play. this almost made me go back and check
       | on the madness but unfortunately the servers are taken offline.
       | 
       | while i don't agree with how devs and the publisher works on
       | community feedback, it is still miles better than what EA does.
       | not that it is a high bar to clear.
        
       | kjkjadksj wrote:
       | I remember when gta5 was getting hacked left and right when it
       | was released. People would just hand you millions in in game
       | currency and you'd get to unlock all the hypercars and military
       | vehicles. Really made the game fun removing the grind and pay to
       | win and allowing everyone to do anything. And it gave people a
       | chance if someone was dominating a lobby with something broken or
       | overpowered to actually fight back fire with fire.
        
       ___________________________________________________________________
       (page generated 2025-12-28 23:01 UTC)