Glorious Alpha Two Testers!

Alpha Two Phase II testing is currently taking place 5+ days each week. More information about testing schedule can be found here

If you have Alpha Two, you can download the game launcher here, and we encourage you to join us on our Official Discord Server for the most up to date testing news.

I guess it's not really the botters and so-called "chinese gold farmers" we need to be worried about

NerrorNerror Member, Alpha One, Alpha Two, Early Alpha Two
I just saw this video, and while I was certainly aware of the existence of these hacks, like duping, changing item ID's and integer overflow exploits, I never really grasped the magnitude of it all. It makes total sense, especially with the integer overflow stuff, but I never consciously put two and two together to really understand the scale of it. They are basically creating ingame wealth in a minute, that it would take a bot or dedicated gold farmer years to achieve.

I really, really fucking hope Ashes isn't super vulnerable to this. It eases my mind a little that they've stated they intend to ban the gold buyers as well. That's probably the only thing that really helps. Only going after the sellers means nothing if they can "magic" up 11 quintillion gold in a minute from an integer overflow exploit.

https://www.youtube.com/watch?v=WhKfnVcVHSk

Comments

  • ariatrasariatras Member, Founder, Alpha Two, Early Alpha Two
    edited July 2022
    It's hard to get all of these kinds of bugs and exploits before launch, there are old games in which exploits are still being discovered. I just hope they aren't afraid to do a full currency reset when such bugs are discovered.
    l8im8pj8upjq.gif


  • NoaaniNoaani Member, Intrepid Pack, Alpha Two
    I remember a few years ago we all had a discussion about bots, gold selling and such. From memory, it was all in relation to multiboxing, and was the discussion that led to Intrepid polling us all on our opinion on it.

    In that discussion, I pointed out that botters and farmers are not the people ruining game economies. Sure, developers need to go after them if they are being blatantly obvious - but going after them is for appearance more than any practical results.

    I've known people in some games that have used exploits in the game to make enough money to buy houses without even being suspected, let alone being caught.

    It isn't all that hard to have any major gold increases on an account trigger a flag for Intrepid to investigate. The reason many companies (like Blizzard) don't bother with this is because people that are exploiting like this are still paying Blizzard multiple subscriptions. They look at it as bad business to spend money to just find out that they then need to ban a dozen or more accounts, meaning Blizzard then make less money.
  • SweatycupSweatycup Member, Alpha One, Alpha Two, Early Alpha Two
    edited July 2022
    Heard about botters in some mmo's using some sort of AI to play for them that was shielded by using a secondary computer hooked up to the one running the game. Sure, it would take some time for it to learn but probably not as much as you think. I'm not talking conventional botting like buy/download a program pre-formatted. It literally plays/learns itself. And because its using the primary computer like a port it is almost impossible to detect. Also seen someone setup a robot hand to play. No matter what you do there will always be loopholes. In tech development, you'll never get all the hackers/exploiters. I'm not a big fan of plug and play anti-cheat. I just hope they run it through the ringer so no one gets accidentally banned for something not even remotely wrong.
  • NorkoreNorkore Member, Alpha Two
    As long as games run on our personal computers there will be cheaters, it's an uphill battle.
    That's the only reason why I like the idea of "cloud gaming". If the software runs on machines provided by someone else (and it's made sure the end user only has access to the streamed game) you cannot access logs/processes, inject code/modify the files, etc.

    Intrepid seems to take the cheater problem seriously and I'm hopeful it's going to stay this way (I also hope they will not get rid of active GMs to save money).
  • CawwCaww Member, Alpha Two
    AoC needs a well-paying Bug Bounty scheme
  • BaSkA_9x2BaSkA_9x2 Member, Alpha Two
    edited July 2022
    Even bank systems have vulnerabilities. So it doesn't matter how hard Intrepid tries, there will most likely be vulnerabilities and exploits to be found. It is possible to move some things to the server side instead of client side making some types of exploits harder to be found/exist, but there's a price for doing that, so it's not something easy to do.

    I believe the most important think is to understand how effective the banhammer must be. Bug abusers might rather "sell" bugs to Intrepid for real money/subscription/embers/etc instead of maybe abusing them for their own benefit. If Ashes implements a sturdy logging system and a well built log analysis/monitoring software, it's possible to detect some type of abuses/exploits and easier to identify all accounts involved with people who abuse them. In other words, not only the cheaters get banned, but also every one who was provably involved.

    However, this is a slippery slope, as I don't think it's fair if I get banned because a cheater in my guild exploited his way to legendary gear. But what if the cheating guildmate gives me duped items and I unknowingly accept them? Am I guilty? How does Intrepid know if I knew it was a duped item? Unfortunately, it's not something trivial.

    With all that said, if Intrepid's banhammer is effective and has no fear, people will think twice before bug abusing. I'm talking about permanent bans to all parties involved, and if a guild leader is provably involved with the abusers, the guild simply gets deleted.
    🎶Galo é Galo o resto é bosta🎶
  • PatrullPatrull Member, Alpha Two
    Duping can ruin a resource or the entire economy. The way the company are talking about resources with changing of seasons and the caravan system. They cannot have these issues. They did say that if something does happen they will take action based on individual actions. Example. They won't ban or punish someone who has 1 dup item. If you got 20 then something is probably going to happen.
  • NerrorNerror Member, Alpha One, Alpha Two, Early Alpha Two
    BaSkA13 wrote: »
    However, this is a slippery slope, as I don't think it's fair if I get banned because a cheater in my guild exploited his way to legendary gear. But what if the cheating guildmate gives me duped items and I unknowingly accept them? Am I guilty? How does Intrepid know if I knew it was a duped item? Unfortunately, it's not something trivial.

    With all that said, if Intrepid's banhammer is effective and has no fear, people will think twice before bug abusing. I'm talking about permanent bans to all parties involved, and if a guild leader is provably involved with the abusers, the guild simply gets deleted.

    Hopefully Intrepid errs on the side of caution if someone gives you a duped item. Deletion of said item, and if they can check, any money you gained if you sold it would be fair to delete. Unless of course they can see from ingame chat logs that you knew in advance.. then BAM.

    As for deleting the guild if the guild leader is involved, I think that might be a little harsh considering guilds have levels and can take years to max out for all we know. I would rather they add a feature to let an officer assume the mantle, or lacking that, a member.
  • BalanzBalanz Member, Alpha Two
    Transactional Integrity eliminates Duplication Bugs.

    A transaction is a series of changes in records that either succeed entirely, or fail completely. Transactional integrity requires that there are no partial transactions.

    For example, if I deposit a check from you, the transaction is complete when my balance increases by the appropriate amount, and your balance decreases by that amount. It either goes through all the way, or it fails completely.

    To prevent duplication bugs, every transfer of resources from one game location to another must be in the form of a transaction.

    Not just between two players' inventories, or between a player and the bank or NPC merchant, but looting a corpse, moving stuff between bags, dropping items on the ground, giving equipment to a pet, putting crafting components into a workstation, or removing intermediate or finished products from a workstation. Everything.

    Either the transaction completes, or if it does not, it fails, and is rolled back to its prior state.

    This is worth spending code and CPU cycles on.
  • NerrorNerror Member, Alpha One, Alpha Two, Early Alpha Two
    edited July 2022
    Balanz wrote: »
    Transactional Integrity eliminates Duplication Bugs.

    ....

    Either the transaction completes, or if it does not, it fails, and is rolled back to its prior state.

    This is worth spending code and CPU cycles on.

    Absolutely. Basically, never trust the client, as the old saying goes, including what data is sent to the client from the server in the first place. Easier said than done obviously, and Ashes will have vulnerabilities as well of course.
  • BaSkA_9x2BaSkA_9x2 Member, Alpha Two
    edited July 2022
    Nerror wrote: »
    Hopefully Intrepid errs on the side of caution if someone gives you a duped item. Deletion of said item, and if they can check, any money you gained if you sold it would be fair to delete. Unless of course they can see from ingame chat logs that you knew in advance.. then BAM.

    As for deleting the guild if the guild leader is involved, I think that might be a little harsh considering guilds have levels and can take years to max out for all we know. I would rather they add a feature to let an officer assume the mantle, or lacking that, a member.

    If someone is stupid enough to talk about bug abusing, duped items, etc in game chat they deserve to be banned for being completely morons. That sort of chat will take place in Discord.

    In any case, I agree with you that no injustices should happen, but I don't want cheaters to be mildly punished, I want them to regret cheating in this game for the rest of their lives.
    🎶Galo é Galo o resto é bosta🎶
Sign In or Register to comment.