<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:admin="http://webns.net/mvcb/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
<channel>
    <title>PlayNoEvil Game Security News &amp; Analysis </title>
    <link>http://playnoevil.com/serendipity/</link>
    <description>On Anti-Cheating, Piracy, Gold Farming, RMT, and Other Security, Industry, Virtual Worlds, Skill Games, Asian Online Games, Gambling, and IT Security News</description>
    <dc:language>en</dc:language>
    <admin:errorReportsTo rdf:resource="mailto:" />
    <generator>Serendipity 1.1.3 - http://www.s9y.org/</generator>
    <pubDate>Fri, 13 Nov 2009 17:52:58 GMT</pubDate>

    <image>
        <url>http://playnoevil.com/serendipity/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: PlayNoEvil Game Security News &amp; Analysis  - On Anti-Cheating, Piracy, Gold Farming, RMT, and Other Security, Industry, Virtual Worlds, Skill Games, Asian Online Games, Gambling, and IT Security News</title>
        <link>http://playnoevil.com/serendipity/</link>
        <width>100</width>
        <height>21</height>
    </image>

<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/PlaynoevilGameSecurityGameCheatingGoldFarmingAndRmtNewsAnalysis" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
    <title>Piracy Shmiracy - UK Developers Undeterred by Game Piracy</title>
    <link>http://playnoevil.com/serendipity/index.php?/archives/2751-Piracy-Shmiracy-UK-Developers-Undeterred-by-Game-Piracy.html</link>
            <category>DRM, Game Piracy &amp; Used Games</category>
            <category>Game Demographics &amp; Metrics</category>
    
    <comments>http://playnoevil.com/serendipity/index.php?/archives/2751-Piracy-Shmiracy-UK-Developers-Undeterred-by-Game-Piracy.html#comments</comments>
    <wfw:comment>http://playnoevil.com/serendipity/wfwcomment.php?cid=2751</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://playnoevil.com/serendipity/rss.php?version=2.0&amp;type=comments&amp;cid=2751</wfw:commentRss>
    

    <author>ceo@secureplay.com (SecurePlay)</author>
    <content:encoded>
    Only 10 percent of game developers think piracy is a serious threat to their business and 60 percent think it is a small threat.&lt;br /&gt;
&lt;br /&gt;
.. make no bones about it, developers do think piracy is real with 60 percent seeing it as an "issue" and 90 percent seeing the problem growing.&lt;br /&gt;
&lt;br /&gt;
The discrepancy comes down to lost sales.&lt;br /&gt;
&lt;br /&gt;
In a world of perfect anti-piracy, how many more sales would a given game gain?&lt;br /&gt;
&lt;br /&gt;
Since so much of the success of any game is due to the game itself (a good thing) and the market (a tricky thing), how much does piracy cost?&lt;br /&gt;
&lt;br /&gt;
I do seem to circle around this issue regularly:&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://playnoevil.com/serendipity/exit.php?url_id=9155&amp;amp;entry_id=2751" title="http://playnoevil.com/serendipity/index.php?/archives/2725-Price-and-Piracy-PixelJunk-and-World-of-Goo.html"  onmouseover="window.status='http://playnoevil.com/serendipity/index.php?/archives/2725-Price-and-Piracy-PixelJunk-and-World-of-Goo.html';return true;" onmouseout="window.status='';return true;" &gt;Price and Piracy: PixelJunk and World of Goo&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://playnoevil.com/serendipity/exit.php?url_id=9156&amp;amp;entry_id=2751" title="http://playnoevil.com/serendipity/index.php?/archives/2696-Does-Game-Piracy-Matter.html"  onmouseover="window.status='http://playnoevil.com/serendipity/index.php?/archives/2696-Does-Game-Piracy-Matter.html';return true;" onmouseout="window.status='';return true;" &gt;Does Game Piracy Matter?&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
For conventional "boxed"-type games (games that are sold, not operated as a service), I think the actions of the industry show that the problem is not a big threat to revenue. The obvious lack of attention to piracy in the game development process and underinvestment in anti-piracy techniques demonstrates the "state of the industry" much more clearly than rhetorical posturing by executives and trade groups.&lt;br /&gt;
&lt;br /&gt;
Console piracy is even less of an issue as it seems to merit bi-monthly press releases and aperiodic busts (funded by tax payers, not the companies, it should be noted). &lt;br /&gt;
&lt;br /&gt;
There are just not that many extra sales that can be gained by battling piracy.&lt;br /&gt;
&lt;br /&gt;
Downloadable content (DLC) is another matter. Everyone seems to see DLC as the next game industry gold mine. We don't get a lot of data on DLC and, more interestingly, on piracy of DLC. Given the choice between spending some money on anti-piracy vs. a DLC package, the DLC package wins (and that probably is correct).&lt;br /&gt;
&lt;br /&gt;
If one really steps back, the game industry has to reconsider price. Games are no longer a niche product for early adapters, they are a mass market phenomenon and are competing with other forms of entertainment and other games. While Activision trumpeted Modern Warfare 2 sales in 2 days rivaled those of Titanic, the James Cameron movie sold 128 million tickets compared with a mere 16 million units &lt;strong&gt;projected &lt;/strong&gt;for Modern Warfare 2 on all platforms).&lt;br /&gt;
&lt;br /&gt;
How many copies of Modern Warfare 2 would be sold if the game was $10 (like a movie) instead of $60?&lt;br /&gt;
&lt;br /&gt;
If $5 is the "sweet spot" for indie games (see World of Goo recent sales), is $10 the "perfect price" for a AAA game? or should they be priced the same as a hardback novel - $20 to $30?&lt;br /&gt;
&lt;br /&gt;
Considering there are 1 billion PCs worldwide and 384 million in the US, sales in the modest millions for even the most popular "sold" games is pretty unimpressive.&lt;br /&gt;
&lt;br /&gt;
P. Elliiot (2009), "&lt;a href="http://playnoevil.com/serendipity/exit.php?url_id=9157&amp;amp;entry_id=2751" title="http://www.gamesindustry.biz/articles/developers-piracy-a-problem-but-not-threat-to-survival"  onmouseover="window.status='http://www.gamesindustry.biz/articles/developers-piracy-a-problem-but-not-threat-to-survival';return true;" onmouseout="window.status='';return true;" &gt;Developers: piracy a problem, but not threat to survival&lt;/a&gt;", http://www.gamesindustry.biz/articles/developers-piracy-a-problem-but-not-threat-to-survival 
    </content:encoded>

    <pubDate>Fri, 13 Nov 2009 09:11:45 -0800</pubDate>
    <guid isPermaLink="false">http://playnoevil.com/serendipity/index.php?/archives/2751-guid.html</guid>
    
</item>
<item>
    <title>Modern Warfare 2 cheats for sale - 1 day after launch</title>
    <link>http://playnoevil.com/serendipity/index.php?/archives/2750-Modern-Warfare-2-cheats-for-sale-1-day-after-launch.html</link>
            <category>Bots, Memory Editors, Macros, Triggers, and Duping</category>
    
    <comments>http://playnoevil.com/serendipity/index.php?/archives/2750-Modern-Warfare-2-cheats-for-sale-1-day-after-launch.html#comments</comments>
    <wfw:comment>http://playnoevil.com/serendipity/wfwcomment.php?cid=2750</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://playnoevil.com/serendipity/rss.php?version=2.0&amp;type=comments&amp;cid=2750</wfw:commentRss>
    

    <author>ceo@secureplay.com (SecurePlay)</author>
    <content:encoded>
    Several sources are reporting that Activision / Infinity Ward's Modern Warfare 2 has been compromised with cheats available for the PC version. The game's new centralized infrastructure, which has been roundly criticized for just this reason, may not allow players to kick suspected cheats out or effectively detect cheaters. The cheats seem to be standard FPS cheating fare - aimbots, radar, and such. The cheat creators are offering the cheats for sale for $20 (Free or for-sale, cheat programs should be considered very suspect as they are prime targets for malware distribution).&lt;br /&gt;
&lt;br /&gt;
What is interesting is that it almost certainly would be possible for Infinity Ward to have maintained the types of control that they seem to wish over the game's online experience without getting rid of dedicated servers. (An interesting architectural challenge).&lt;br /&gt;
&lt;br /&gt;
&lt;object id="flashObj" width="486" height="412" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=9,0,47,0"&gt;&lt;param name="movie" value="http://c.brightcove.com/services/viewer/federated_f9/22881388001?isVid=1&amp;publisherID=22717159001" /&gt;&lt;param name="bgcolor" value="#FFFFFF" /&gt;&lt;param name="flashVars" value="videoId=49764000001&amp;linkBaseURL=http%3A%2F%2Fgamevideos.1up.com%2Fvideo%2Fid%2F27045&amp;playerID=22881388001&amp;domain=embed&amp;" /&gt;&lt;param name="base" value="http://admin.brightcove.com" /&gt;&lt;param name="seamlesstabbing" value="false" /&gt;&lt;param name="allowFullScreen" value="true" /&gt;&lt;param name="swLiveConnect" value="true" /&gt;&lt;param name="allowScriptAccess" value="always" /&gt;&lt;embed src="http://c.brightcove.com/services/viewer/federated_f9/22881388001?isVid=1&amp;publisherID=22717159001" bgcolor="#FFFFFF" flashVars="videoId=49764000001&amp;linkBaseURL=http%3A%2F%2Fgamevideos.1up.com%2Fvideo%2Fid%2F27045&amp;playerID=22881388001&amp;domain=embed&amp;" base="http://admin.brightcove.com" name="flashObj" width="486" height="412" seamlesstabbing="false" type="application/x-shockwave-flash" allowFullScreen="true" swLiveConnect="true" allowScriptAccess="always" pluginspage="http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;
NOTE: The video has already been pulled from YouTube by Activision based on copyright claims&lt;br /&gt;
&lt;br /&gt;
The next question is how long will it take for game save and configuration hacks to show up on consoles.&lt;br /&gt;
&lt;br /&gt;
The real impact of these design choices will not appear for months - will the game have legs as an online, multi-player service?&lt;br /&gt;
&lt;br /&gt;
J. Tolentino (2009), "&lt;a href="http://playnoevil.com/serendipity/exit.php?url_id=9147&amp;amp;entry_id=2750" title="http://www.destructoid.com/big-surprise-modern-warfare-2-already-hacked-154854.phtml"  onmouseover="window.status='http://www.destructoid.com/big-surprise-modern-warfare-2-already-hacked-154854.phtml';return true;" onmouseout="window.status='';return true;" &gt;Big surprise: Modern Warfare 2 already hacked&lt;/a&gt;", http://www.destructoid.com/big-surprise-modern-warfare-2-already-hacked-154854.phtml&lt;br /&gt;
&lt;br /&gt;
E. Cavalli (2009), "&lt;a href="http://playnoevil.com/serendipity/exit.php?url_id=9148&amp;amp;entry_id=2750" title="http://www.escapistmagazine.com/news/view/96056-Modern-Warfare-2-Seemingly-Hacked-One-Day-Post-Launch"  onmouseover="window.status='http://www.escapistmagazine.com/news/view/96056-Modern-Warfare-2-Seemingly-Hacked-One-Day-Post-Launch';return true;" onmouseout="window.status='';return true;" &gt;Modern Warfare 2 Seemingly Hacked One Day Post Launch&lt;/a&gt;", http://www.escapistmagazine.com/news/view/96056-Modern-Warfare-2-Seemingly-Hacked-One-Day-Post-Launch 
    </content:encoded>

    <pubDate>Thu, 12 Nov 2009 07:52:51 -0800</pubDate>
    <guid isPermaLink="false">http://playnoevil.com/serendipity/index.php?/archives/2750-guid.html</guid>
    
</item>
<item>
    <title>NOTED: Borderlands vulnerable to Gamesave Hack</title>
    <link>http://playnoevil.com/serendipity/index.php?/archives/2749-NOTED-Borderlands-vulnerable-to-Gamesave-Hack.html</link>
            <category>Game Cheating, Griefing, and Scams</category>
    
    <comments>http://playnoevil.com/serendipity/index.php?/archives/2749-NOTED-Borderlands-vulnerable-to-Gamesave-Hack.html#comments</comments>
    <wfw:comment>http://playnoevil.com/serendipity/wfwcomment.php?cid=2749</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://playnoevil.com/serendipity/rss.php?version=2.0&amp;type=comments&amp;cid=2749</wfw:commentRss>
    

    <author>ceo@secureplay.com (SecurePlay)</author>
    <content:encoded>
    Apparently, the recent and quite popular First Person Shooter / RPG "&lt;strong&gt;Borderlands&lt;/strong&gt;" is vulnerable to a &lt;strong&gt;game save attack&lt;/strong&gt;. &lt;br /&gt;
&lt;br /&gt;
Most games do not protect games saves at all or use a "hash function", such as MD5, as a signature which is trivial to spoof.&lt;br /&gt;
&lt;br /&gt;
An actual public key signature or keyed hash function can work quite effectively to largely address this problem against casual hackers (and are equivalent from a security perspective).&lt;br /&gt;
&lt;br /&gt;
There are more advanced techniques that are possible (and are more effective), but it depends on the game's design.&lt;br /&gt;
&lt;br /&gt;
It should be noted that this type of attack can work on both PC games and consoles.&lt;br /&gt;
&lt;br /&gt;
... and I discuss the topic further in &lt;strong&gt;Chapter 14 - App Attacks: State, Data, Asset, and Code Vulnerabilities and Countermeasures&lt;/strong&gt; of my book &lt;a href="http://playnoevil.com/serendipity/exit.php?url_id=9140&amp;amp;entry_id=2749" title="http://www.amazon.com/gp/product/1584506709?ie=UTF8&amp;amp;tag=playnoevil-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=1584506709"  onmouseover="window.status='http://www.amazon.com/gp/product/1584506709?ie=UTF8&amp;amp;tag=playnoevil-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=1584506709';return true;" onmouseout="window.status='';return true;" &gt;Protecting Games&lt;/a&gt;.&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://playnoevil.com/serendipity/exit.php?url_id=9140&amp;amp;entry_id=2749" title="http://www.amazon.com/gp/product/1584506709?ie=UTF8&amp;amp;tag=playnoevil-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=1584506709"  onmouseover="window.status='http://www.amazon.com/gp/product/1584506709?ie=UTF8&amp;amp;tag=playnoevil-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=1584506709';return true;" onmouseout="window.status='';return true;"&gt;&lt;img src="http://playnoevil.com/images/protecting-games-cover-icon.jpg" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Rick (2009), "&lt;a href="http://playnoevil.com/serendipity/exit.php?url_id=9141&amp;amp;entry_id=2749" title="http://blog.gib.me/2009/10/31/borderlands-save-editor-revision-10/"  onmouseover="window.status='http://blog.gib.me/2009/10/31/borderlands-save-editor-revision-10/';return true;" onmouseout="window.status='';return true;" &gt;Borderlands Save Editor (Revision 10)&lt;/a&gt;", http://blog.gib.me/2009/10/31/borderlands-save-editor-revision-10/ - NOTE - DOWNLOAD OF GAME CHEAT TOOLS CAN POSE A REAL RISK TO YOUR COMPUTER - THESE TOOLS CAN OFTEN INCLUDE MALWARE THAT CAN DAMAGE YOUR COMPUTER OR STEAL YOUR DATA&lt;br /&gt;
&lt;br /&gt;
via&lt;br /&gt;
&lt;br /&gt;
Zubon (2009), "&lt;a href="http://playnoevil.com/serendipity/exit.php?url_id=9142&amp;amp;entry_id=2749" title="http://www.killtenrats.com/2009/11/11/cheat/"  onmouseover="window.status='http://www.killtenrats.com/2009/11/11/cheat/';return true;" onmouseout="window.status='';return true;" &gt;Cheat&lt;/a&gt;", http://www.killtenrats.com/2009/11/11/cheat/&lt;br /&gt;
&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Thu, 12 Nov 2009 05:14:00 -0800</pubDate>
    <guid isPermaLink="false">http://playnoevil.com/serendipity/index.php?/archives/2749-guid.html</guid>
    
</item>
<item>
    <title>Bingo Caller jailed for Cheating</title>
    <link>http://playnoevil.com/serendipity/index.php?/archives/2748-Bingo-Caller-jailed-for-Cheating.html</link>
            <category>Gambling and Skillgames</category>
            <category>Game Cheating, Griefing, and Scams</category>
            <category>Game Culture, Policy, Law, and Politics</category>
    
    <comments>http://playnoevil.com/serendipity/index.php?/archives/2748-Bingo-Caller-jailed-for-Cheating.html#comments</comments>
    <wfw:comment>http://playnoevil.com/serendipity/wfwcomment.php?cid=2748</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://playnoevil.com/serendipity/rss.php?version=2.0&amp;type=comments&amp;cid=2748</wfw:commentRss>
    

    <author>ceo@secureplay.com (SecurePlay)</author>
    <content:encoded>
    A bingo caller at Gala Bingo in the UK was jailed for cheating the bingo hall. &lt;br /&gt;
&lt;br /&gt;
How did he do it?&lt;br /&gt;
&lt;br /&gt;
The bingo hall used an electronic system for the random number draw.... so far so good.&lt;br /&gt;
&lt;br /&gt;
Alas, it has a "manual draw" option which the caller used to conveniently call the numbers which corresponded to has co-conspirators bingo cards.&lt;br /&gt;
&lt;br /&gt;
How did he get caught?&lt;br /&gt;
&lt;br /&gt;
Apparently, complacency and greed. The group seems to have abused the system so much that someone noticed and complained.&lt;br /&gt;
&lt;br /&gt;
... the bingo hall's internal controls did not pick up the problem.&lt;br /&gt;
&lt;br /&gt;
... totaling £9000.&lt;br /&gt;
&lt;br /&gt;
(Financially, bingo is a player vs. player game, so its revenues are not dependent on the game being fair)&lt;br /&gt;
&lt;br /&gt;
A. Richards (2009). "&lt;a href="http://playnoevil.com/serendipity/exit.php?url_id=9130&amp;amp;entry_id=2748" title="http://bingostreet.com/news-20091109/gala-bingo-caller-jailed-for-fraud-online-bingo-news"  onmouseover="window.status='http://bingostreet.com/news-20091109/gala-bingo-caller-jailed-for-fraud-online-bingo-news';return true;" onmouseout="window.status='';return true;" &gt;Gala bingo caller jailed for fraud&lt;/a&gt;", http://bingostreet.com/news-20091109/gala-bingo-caller-jailed-for-fraud-online-bingo-news 
    </content:encoded>

    <pubDate>Wed, 11 Nov 2009 09:04:25 -0800</pubDate>
    <guid isPermaLink="false">http://playnoevil.com/serendipity/index.php?/archives/2748-guid.html</guid>
    
</item>
<item>
    <title>1 Million Hacked Xboxes?</title>
    <link>http://playnoevil.com/serendipity/index.php?/archives/2747-1-Million-Hacked-Xboxes.html</link>
            <category>DRM, Game Piracy &amp; Used Games</category>
    
    <comments>http://playnoevil.com/serendipity/index.php?/archives/2747-1-Million-Hacked-Xboxes.html#comments</comments>
    <wfw:comment>http://playnoevil.com/serendipity/wfwcomment.php?cid=2747</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://playnoevil.com/serendipity/rss.php?version=2.0&amp;type=comments&amp;cid=2747</wfw:commentRss>
    

    <author>ceo@secureplay.com (SecurePlay)</author>
    <content:encoded>
    An article in the Guardian is putting the number of modified Xboxes as high as 1 million out of 20 million on Xbox Live.&lt;br /&gt;
&lt;br /&gt;
I'm not sure if this is detected, banned, or whatever, but it is certainly a healthy number in absolute terms.&lt;br /&gt;
&lt;br /&gt;
I'm also not sure if this was an extrapolation from Microsoft's recent statement about the number of banned consoles (see previous article).&lt;br /&gt;
&lt;br /&gt;
Any corrections, follow ups, or clarifications would be welcome.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
C. Arthur (2009), "&lt;a href="http://playnoevil.com/serendipity/exit.php?url_id=9127&amp;amp;entry_id=2747" title="http://www.guardian.co.uk/technology/2009/nov/11/xbox-modded-consoles-live-cut-microsoft"  onmouseover="window.status='http://www.guardian.co.uk/technology/2009/nov/11/xbox-modded-consoles-live-cut-microsoft';return true;" onmouseout="window.status='';return true;" &gt;Microsoft cutting off up to 1m gamers with modified Xbox 360 consoles&lt;/a&gt;", http://www.guardian.co.uk/technology/2009/nov/11/xbox-modded-consoles-live-cut-microsoft&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Wed, 11 Nov 2009 08:58:43 -0800</pubDate>
    <guid isPermaLink="false">http://playnoevil.com/serendipity/index.php?/archives/2747-guid.html</guid>
    
</item>

</channel>
</rss>
