Author Topic: Official Settings for servers-Can tremulous go CAL?  (Read 10360 times)

Stof

  • Posts: 1343
  • Turrets: +1/-1
Official Settings for servers-Can tremulous go CAL?
« Reply #30 on: March 11, 2007, 01:06:55 am »
Quote from: "Smokey"
Perhaps a patch can be made to force all players to take a screenshot, so therefore if the screenshot is requested, it can be provided.

And perhaps the hacker producing a wallhack will create a patch which disables it for a few frames when such a screenshot command arrives.
urphy's rules of combat
8 ) Teamwork is essential; it gives the enemy someone else to shoot at.
18 ) Make it too tough for the enemy to get in and you can't get out.

Clay[Born]

  • Posts: 13
  • Turrets: +1/-1
Official Settings for servers-Can tremulous go CAL?
« Reply #31 on: March 11, 2007, 07:24:57 am »
The point is not to make an invincible system...
the point is to make the crackers work as hard as possible
in order to crack the system and to rotate the system
every-so-often so they crackers have to keep up.

Unfortunately, cracking is.. oh so much easier in an open source game.

The issues with Tremulous and cracking the client are the following:
1) The only system of protection is "pure check"
2) Trem is open source and thus easy modify and potential crackers
have alot less work to do.

I advocate that, if possible, some system be set up
which is hard to crack, gets updated regularly, and
it as easy as possible to notice as an admin if someone
joins the server with it cracked.

Despite all the the pervasive pessimism here...
something > nothing.

Remember, it's not about stopping them
it's about slowing them down and then regularly forcing
them to change direction so that it takes the maximum possible
work to keep a hack running.

- Clay[Born]

Undeference

  • Tremulous Developers
  • *
  • Posts: 1254
  • Turrets: +122/-45
Official Settings for servers-Can tremulous go CAL?
« Reply #32 on: March 11, 2007, 07:36:21 am »
That's like changing the number on your house so people who know your address won't be able to find it. The best way to prevent someone from finding your house is to never give out your address.
Need help? Ask intelligently. Please share solutions you find.

Thats what we need, helpful players, not more powerful admins.

Stof

  • Posts: 1343
  • Turrets: +1/-1
Official Settings for servers-Can tremulous go CAL?
« Reply #33 on: March 11, 2007, 11:31:31 am »
Quote from: "Clay[Born
"]The point is not to make an invincible system...
the point is to make the crackers work as hard as possible
in order to crack the system and to rotate the system
every-so-often so they crackers have to keep up.

Unfortunately, cracking is.. oh so much easier in an open source game.

The issues with Tremulous and cracking the client are the following:
1) The only system of protection is "pure check"
2) Trem is open source and thus easy modify and potential crackers
have alot less work to do.

I advocate that, if possible, some system be set up
which is hard to crack, gets updated regularly, and
it as easy as possible to notice as an admin if someone
joins the server with it cracked.

Despite all the the pervasive pessimism here...
something > nothing.

Remember, it's not about stopping them
it's about slowing them down and then regularly forcing
them to change direction so that it takes the maximum possible
work to keep a hack running.

- Clay[Born]

The point is to make the crackers work as hard as possible, not the devs. Making that screenshot thing would probably be much more work for devs than coding a workaround for crackers.
urphy's rules of combat
8 ) Teamwork is essential; it gives the enemy someone else to shoot at.
18 ) Make it too tough for the enemy to get in and you can't get out.

Clay[Born]

  • Posts: 13
  • Turrets: +1/-1
Official Settings for servers-Can tremulous go CAL?
« Reply #34 on: March 12, 2007, 05:09:20 am »
Quote from: "Undeference"
That's like changing the number on your house so people who know your address won't be able to find it. The best way to prevent someone from finding your house is to never give out your address.


your right, of course.  the trouble is that the game MUST send those addresses to even play the game.  i suppose one could try to entirely re-write the net code for partial information transmission but seriously has anyone ever accomplished that?  it's a true dev's nightmare... not to mention the game state hacks that tends to open up /swt

Quote from: "Stof"

The point is to make the crackers work as hard as possible, not the devs. Making that screenshot thing would probably be much more work for devs than coding a workaround for crackers.


your quite correct.  it is.. and always will be... a battle of work.
if we wanted to takes this seriously we would need a second team
of trustworthy ppl to created a centralized anti-cheat patch
system of some kind.

A screenshot mod is a good second best attempt in the likely event
that we cant' assemble that sort of group, but let's not cut ourselves
off at the pass without at least checking... there are bound
to be some C programmers out there who love this game
and aren't devs atm.

Not being an expert on the code, I have a question: for someone capable enough to break pure check,
how hard would it be to toggle a wallhack on and off as it receives requests for screenshot transmission?

(question: where did my sig go on this post,
the forum refuses to add it to the thread even though
it's in preview mode.)

[later edit]
one thought:
if a server mods in qvms that contain special
codes for screenshots capture etc... do they have to release
the code? they do right? it's GPL after all..
perhaps the server could rotate different vgms with
different security patches to keep people off guard?
i would appreciate input from someone who knows
the term codes and understands more fully than myself
the nature of vgms and server administration.
[/later edit]

- Clay[Born]

player1

  • Posts: 3062
  • Turrets: +527/-401
    • My Avatar! (if they were enabled) [by mietz]
Official Settings for servers-Can tremulous go CAL?
« Reply #35 on: March 12, 2007, 07:32:48 am »
Clay, your sig only shows up in your first post on a particular page (thread?). Enough bandwidth is used up on this server by sigs. Be happy they aren't repeated endlessly. There are some BIG ones. The sig, does show up, however, in the pre-submitted post, because the BB doesn't yet know that it's a secondary post on the same page (in the same thread?), because other people are also using the internet, and they may type faster than you. And be long winded, or quotespammers, or have outrageously huge sigs. Or such is my belief.

Clay[Born]

  • Posts: 13
  • Turrets: +1/-1
Official Settings for servers-Can tremulous go CAL?
« Reply #36 on: March 12, 2007, 06:04:34 pm »
ah so sigs here are configured to only show up
on the first post per page (by you)... fair enough.
that's all you had to say lol.

but back to the topic at hand... (hopefully)