Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×
Security Entertainment Games

Eve Online Client Source Code Leaked 368

An anonymous reader writes to tell us that the game client source code for the popular MMO, Eve Online, has been leaked via torrent. In addition to the source code the user also posted a lengthy chat transcript with someone from CCP customer support. While the end goal may have been to call attention to the continuing security issues within Eve (and ultimately themselves), there are probably better ways of getting through to support. Unfortunately, CCP seems to be responding with the usual knee-jerk reaction of banning everyone breathing a whisper of this incident. I wonder if any large MMO company will ever be brave enough to calmly address an issue rather than wielding the ban-hammer.
This discussion has been archived. No new comments can be posted.

Eve Online Client Source Code Leaked

Comments Filter:
  • Well... (Score:4, Funny)

    by schmidt349 ( 690948 ) on Monday April 14, 2008 @06:06PM (#23070392)
    I would worry that unscrupulous players will dig through the source code to find exploits, but it's reassuring to find something that will bring them back to the real world...
  • by ferat ( 971 ) on Monday April 14, 2008 @06:07PM (#23070406) Homepage
    If you are an active EVE player, don't use the torrent links to download the source. CCP is monitoring the torrents and banning any accounts with matching IP addresses to any of the people using the torrent.

    They obviously can't watch them all, but don't download the torrent from an IP that you use to play the game.
    • Re: (Score:3, Insightful)

      If you are an active EVE player, don't use the torrent links to download the source. CCP is monitoring the torrents and banning any accounts with matching IP addresses to any of the people using the torrent.

      Well that will be great for any of their users who get a dynamic IP that was previously used to download the code.

      I smell corporate suicide.
    • Re: (Score:3, Interesting)

      by Eraslin ( 517849 )
      Makes you wonder what the implications are w.r.t. copyright and trade-secret if CCP is distributing the code themselves. Sure, by seeding they'll be able to snag IP addresses and ban users. But, for down the road, I wonder if they've just given up any ability to claim copyright infringement or some such on anyone (defense: ''CCP themselves were seeding it ,your honour. So, I got it from the copyright owner with their permission.'').
      • Re: (Score:3, Informative)

        by bky1701 ( 979071 )
        Well, they could, in theory, leach but not download (much, at least) and never upload. They would still be able to get peer IPs, but wouldn't have to contribute data (nor even have it).

        This is different than when the RIAA does it, as they actually upload it to unknowing downloaders to get lawsuit fuel.

        If CCP only wants to ban downloaders, they don't need any legal evidence to do so, at least as long as indiscriminate bans are covered in their TOS. Therefore, they don't need to go the RIAA road.
        • Re: (Score:3, Interesting)

          by Sancho ( 17056 ) *
          Different investigation agencies probably do things differently. I can tell you that the RIAA has just hopped on, grabbed the peer list, and then hopped off (I work for an ISP and we actually have to deal with this crap.)
    • Re: (Score:3, Interesting)

      by Anonymous Coward
      http://seashells.partyvan.fm/~januszeal/pre51200sc.rar

      ^ Direct link

      irc.partyvan.fm
  • by Anonymous Coward on Monday April 14, 2008 @06:07PM (#23070416)
    • Re: (Score:3, Interesting)

      by Kayamon ( 926543 )
      Am I the only person who thinks it somewhat wrong to post on Slashdot a link to stolen, unreleased source code?

      Geez, why not just upload a GTA4 ISO while you're at it.
  • Something that the summary missed but was reiterated twice in the actual article is that CCP is accused of seeding most of the torrents and then monitoring all IP addresses acquiring the source and then banning accounts associated with those IPs. So if you're going to get the code just to look at it, I suggest using your mom's house or an internet cafe!

    I wonder if any large MMO company will ever be brave enough to calmly address an issue rather than wielding the ban-hammer.
    This particular user used this code to point out a few things regarding security:

    From all security i saw - were ROLE permissions for logins with priviliges higher than usual player, and some minor things in relation to prevent some remote service calls (some with potentially bad payload)
    I'm not entirely sure if he's implying there's some exploitable permissions bug or if there are some user roles that are jacked up (you know, like a coder at CCP giving himself the keys to the game and claiming it was for debug when it was for his own account's gain). But whatever it is, CCP should fix that.

    Frankly, downloading this would be a stupid thing to get banned over. This is CCP's bread and butter, I don't blame them for taking this action. In their eyes, they are trying to eliminate exploiting players in hopes of making the game better for non-exploiting players. This 'policing' action is usually desired by the community. Yeah, it's unfortunate that they're not taking advantage of the security and stability of an open source coding community ... but you have to admit it would be easy for someone to fork and go off and make their own client with. Maybe there's deep dark secrets they don't want out and since it's only a game and I don't really care for it I'm not too concerned.

    Let's see if Linden Labs can make this OSS client thing work to their advantage. I sure hope so because it will give everyone else a reason to make the switch.
    • by Cro Magnon ( 467622 ) on Monday April 14, 2008 @06:12PM (#23070476) Homepage Journal

      So if you're going to get the code just to look at it, I suggest using your mom's house


      Unless you live in your mom's basement. :-P
    • Re: (Score:3, Interesting)

      by hcmtnbiker ( 925661 )
      Something that the summary missed but was reiterated twice in the actual article is that CCP is accused of seeding most of the torrents and then monitoring all IP addresses acquiring the source and then banning accounts associated with those IPs.

      If they're actually seeding it themselves then I expect to hear about a lawsuit. Since that would be purely legal to download from them. If CCP is effectively giving away their src what's wrong with accepting their offer?
    • by MarkByers ( 770551 ) on Monday April 14, 2008 @06:26PM (#23070640) Homepage Journal

      So if you're going to get the code just to look at it, I suggest using your mom's house or an internet cafe!
      Or if you know an avid Eve Online player that you don't really like, you could hack into their wireless connection and download it that way. Not that I would condone it...
    • by Anonymous Coward on Monday April 14, 2008 @06:50PM (#23070938)
      What they dont want is someone adding functionality to the client they avoided for a long time:

      Fire all weapons on a single click. Automagically select the right ECM jammer for the target ship. And that's what came to my mind in an instant.

      I bet there are many more possibilities which can unbalance tweaked clients and standard clients. It is like a free opportunity for wall hacks if other clients are allowed. It wouldnt be a problem for PvE games, but PvP needs the same client for all.
      • by pthisis ( 27352 ) on Monday April 14, 2008 @07:24PM (#23071302) Homepage Journal
        It wouldnt be a problem for PvE games, but PvP needs the same client for all.

        Or needs to do validation on the server-side of all game-balance-affecting stuff--which is really the only way to ensure fairness, since clients can always be hacked.
        • Re: (Score:3, Interesting)

          by vux984 ( 928602 )
          Or needs to do validation on the server-side of all game-balance-affecting stuff--which is really the only way to ensure fairness, since clients can always be hacked.

          Server-side validation only captures 'illegal commands', it doesn't really capture -automated commands-.

          As long as the bots don't do anything Server side validation isn't going to catch squat. It can't easily tell if its a real player at the helm. And it certainly can't tell the difference between player:

          click-a, click-b, c, d, e, f, g, h, i, j
    • Re: (Score:3, Funny)

      by Provocateur ( 133110 )

      I suggest using your mom's house or an internet cafe


      You must be new here. For most of us, it's one and the same. Though the coffee's not $3 a cup.
    • Re: (Score:3, Interesting)

      by Lonewolf666 ( 259450 )
      From my experience with EVE I have the impression that their QA is a bit understaffed. There are some visible bugs in the game that have been unfixed for a while, so I presume there are exploitable security bugs to match.

      Going the open source route may or may not help them, depending on how much of the data available clientside has to remain hidden from the user:
      The deep dark secrets they don't want out could be something like players getting info on all objects in a solar system, and the client filtering o
  • by JernejL ( 1092807 ) on Monday April 14, 2008 @06:08PM (#23070430) Homepage
    I don't think anything major as this has happened before, and from a online game developer's perspective i will look closely to how this affects cheating and the development of the game further, as something like this is a great nightmare for any game developer, and i really want to see how this one ends.
    • by eldavojohn ( 898314 ) * <eldavojohn@noSpAM.gmail.com> on Monday April 14, 2008 @06:17PM (#23070536) Journal

      I don't think anything major as this has happened before ...
      Really? It was only the client code, they don't know how the server works (although they could reverse engineer the messaging potentially and mock a server after a lot of work and assumptions).

      On a side note, I think this has happened before on a much more serious scale [slashdot.org].
      • by Oriumpor ( 446718 ) on Monday April 14, 2008 @06:35PM (#23070756) Homepage Journal
        The problem isn't so much that the code isn't fixable, or that the client side code will show something obviously exploitable (as this is most likely the case.) But really, it's about the fact that every developer writing code for this has been doing it under the assumption that nobody is going to look at it except their peers, now the world is staring at their dangling unmentionables. Imagine your rushed proprietary coding project was now instantly made open source against your wishes...

        • Re: (Score:3, Insightful)

          Imagine your rushed proprietary coding project was now instantly made open source against your wishes...

          I don't think availability on a warez site is exactly the same thing as "open source",
          Sincerely,
          RMS
      • by Umuri ( 897961 ) on Monday April 14, 2008 @09:12PM (#23072232)
        Let me give you a little history lesson.
        Back in the dark ages, ya know, the 90s, there was a little game called Ultima Online.

        Heard of it? I hope so, it was one of the original MMORPGs.

        Every client ever released for that game had all of it's packets decrypted, and the encryption scheme broken for keys, usually within 24-48 hours. Everytime they updated.

        Add to that that people edited the client to do whatever they wanted, sometimes with other programs hooking in and altering packets, others by directly altering the assembly of the client.
        Many people tried to exploit bugs in the game that way, but most failed, and everytime someone did find one, it was usually fixed relatively quickly. Malformed packets went from "all the rage" and the way to bug up a game to relatively worthless within a span of a month, barring a few new uses that popped up every so often from bad new code introduced.

        Having the source code only simplifies this a little for the people who really care, and it doesn't really enable them to do anything they couldn't already.

        Oh, also, while i'm at it. Did you know ultima online had a special client for staff characters? And that the binary for that client was leaked as well?

        OH NOES! But wait! Ultima online used good security measures and correct privelege systems, so the client was worthless for anything a normal player couldn't do. :)

        Summary: This isn't new, and it's happened before on other games. Except in the past most games were already so well understood by their communities that the source would add almost nothing except a little ease and some time saved duplicating a better version of the client when they stop upgrading.

        Add to that, if this causes ANY security issue with EVE, then the people who coded the game should get in trouble, not the players. Good coding practices prevent all trouble the code could possibly do. You ARE checking for privelege levels and sanitizing your inputs, right?
    • Re: (Score:3, Interesting)

      There was the theft and publication of the Half-Life 2 source code a few years ago. That included the creation of an illicit version of the game, in Russia.
    • by the_humeister ( 922869 ) on Monday April 14, 2008 @07:46PM (#23071530)
      The Second Life client is open source. If that can be done, why is the source code leak for this game such a bad thing?
    • Re: (Score:3, Insightful)

      by BitZtream ( 692029 )
      Great nightmare? Hardly. Its embarrassing, but if they've written their code well and it isn't full of security issues, its not really a big deal.

      The server code is really what matters from a security stand point. Changing the server can effectively kill any hacked client on the planet, but it can require upgrading legitimate clients as well.

      Really, the content is what makes the game. Engines are important and obviously a required part, but the content is what people play. While it is to the companies a
  • From TFA... (Score:5, Insightful)

    by Lisandro ( 799651 ) on Monday April 14, 2008 @06:12PM (#23070480)
    In the lengthy and scatological exchange, the poster of the source code attempts to get some answers about CCPs much maligned security practices, particularly concerning the rife issue of bots and scripting in their flagship game. The conversation was a little less than professional.

    Well, atleast on the tidbit shown on the article, the CCP representative sounds perfectly rational and professional. Am i missing something here?

    And by the way, how does this guy ended up with the sourcecode on the first place?!
    • Re:From TFA... (Score:5, Interesting)

      by vux984 ( 928602 ) on Monday April 14, 2008 @07:42PM (#23071498)
      Well, atleast on the tidbit shown on the article, the CCP representative sounds perfectly rational and professional. Am i missing something here?

      Well, the CCP rep did sound vaguely annoyed to me; I could see him rolling his eyes. But then I imagine they roll their eyes at most of the conversations they have. :)

      And by the way, how does this guy ended up with the sourcecode on the first place?!

      That's still unclear. Some say its just decompiled python that anyone could do themselves easily enough. But he almost alludes to having a source within ccp... so I'm not sure.

      Its too bad he's apparently not an english speaker because that invites mockery. And obviously he's not being terrible mature which further damages his image, but at the end of the day what he is asking for is legitimate in my opinion:

      All he wants is CCP to acknowledge there are specific issues and to demonstrate that there have been real fixes added. Because he is firmly convinced that people have been botting for years using known exploits and that CCP hasn't made even the slightest effort to curb them.

      So he's basically saying if you've fixed it... prove it. "Show me an exploit that used to work that doesn't now. Show me something, ANYTHING, that you've actually fixed in the last year or so related to stopping botters."

      "And Improve your processes, so that if we report exploits you acknowledge them, and fix them, instead of just handwaving that security improvements have been added, because I'm not seeing any."

      "And if you don't, I'm releasing the source, so we can ALL see for ourselves what you've actually improved over the last year, because I'm tired of watching people bot for YEARS without having to so much as adapt to new anti-bot tactics."

      If this guy is just blowing smoke, then CCP really should have no issue publishing some of the hundreds of botting related exploit scenarios that they claim to have fixed over the last several patches...and showing that they no longer worked.

      That much they owe their customers. Frankly, I don't really blame CCP for not publicly acknowledging security issues and bringing additional attention to each exploit before its fixed... BUT... I -do- think that the playerbase deserves some honesty -after- the fact.

      If they release an exploit fix, publish it, what used to work, and what no longer works. CCP lacks credibility, and this would go a long ways towards helping restore it.

      After all we get a better level of security updates disclosure from microsoft. I think all this guy really wants is the same from CCP. And if CCP *hasn't* actually done anything in the last few years to address all the while claiming they have, well... I can see why a segment of the playerbase is boiling mad about it, and wants to blow this into the public eye where they can't sweep it under the rug anymore.
  • The major issue behind the source-code leak is the security surrounding the code. Now that it's out, there is the potential for "unscrupulous players" to find exploits. Anyone familiar with Python will be able to find at least something.

    Also, since it is the client code that was released, an intrepid cheater can find ways not just to exploit functions in-game, but find ways to pull various bits of data from straight out of memory. This is a bit like third-party programs that utilize CCP's API code system,
  • Not a leak (Score:5, Informative)

    by Fweeky ( 41046 ) on Monday April 14, 2008 @06:16PM (#23070514) Homepage
    It's not a leak, the .pyc's have just been decompiled and distributed. Here [crazy-compilers.com] - go do it yourself.
  • by FooBarWidget ( 556006 ) on Monday April 14, 2008 @06:17PM (#23070546)
    "I wonder if any large MMO company will ever be brave enough to calmly address an issue rather than wielding the ban-hammer."

    I doubt it. But this is not without a good reason.

    Many, many MMORPG players are 13 year old kids. Immature kids. These people are not adults. They do not behave like adults. If the company "calmly addresses the issues", then they'll be flooded by complainers, cheaters and opportunists within no time.

    I've been involved in MMORPG for several years. The immaturity in MMORPG communities in general is just sad. There doesn't seem to be any good way to handle issues other than ruling with iron fist.
    • by brkello ( 642429 ) on Monday April 14, 2008 @06:58PM (#23071034)
      I don't understand how the maturity level of the user base has anything to do with how a company reacts. Eve has always been heavy in to banning and suppressing information. Eve also claims to boast a more "mature" player base (which I find a bit laughable). In a game with such mature players, CCP bans more than any other company. I played Eve for awhile and didn't like it very much. The corruption from within the game company made me go from thinking they made a boring game with jerks as a player base to just flat out disliking the game. Don't get me wrong, Eve has its strong points...but fun isn't a part of that.

      Eve banning people and deleting forum posts isn't ruling with an iron fist. It is a desperation move to hold on to customers who may not know what is going on. If they ruled with an iron fist they would actually come down on the people who cheated with the devs. That's the problem, the game should be as cut throat as possible in game...but CCP not only plays the game, but leaks inside knowledge of the game to organizations that are already overpowered. Maybe they are totally clean now (I doubt it) but the game will forever be tainted by the past.

      The reason they ban is because they have too much to hide and would rather do that than address the issue and fix their game.
      • "I don't understand how the maturity level of the user base has anything to do with how a company reacts."

        Because you can't trust the user base to handle appropriately even when you do the right thing. In other words: *not* banning those people makes the situation even worse.
    • by Morpeth ( 577066 ) on Monday April 14, 2008 @06:59PM (#23071040)
      "Many, many MMORPG players are 13 year old kids. Immature kids. These people are not adults. They do not behave like adults..."

      I keep hearing people saying this, where's the proof? People just make up stats on the fly and like to blame kids -- there's PLENTY of adult players who act like complete asshats.

      Here's some actual stats --
      "Also of note is the fact that the average age of the typical gamer is 33."

      "...female gamers over the age of 18 make up 31 percent of all gamers, a larger percentage than that of male gamers under the age of 17 (20 percent), a group traditionally seen as the majority."

      http://blog.wired.com/games/2008/03/38-percent-of-g.html [wired.com]

      I will say I've seen my share of immature players in WoW - BUT that doesn't mean I actually know they're age. Also, WoW is also just ONE mmorpg, albeit the largest.

      I've played mmorpgs for about 9 yrs starting with EQ. Currently, I play EQII as well as WoW -- and the maturity level is vastly different there. Played AO, DAoC, CoH, GW and generally had good experiences with the player base. Anonymity is really the big issue with mmorpgs, it let's some people (mainly adults) act like idiots without any real repercussions.

      Most of my WoW guild is 30 and 40-somethings. One however is a 12 year old boy, and his online behavior is often much more mature/conservative than the adults.

      • "Many, many MMORPG players are 13 year old kids. Immature kids. These people are not adults. They do not behave like adults..."

        I keep hearing people saying this, where's the proof? People just make up stats on the fly and like to blame kids -- there's PLENTY of adult players who act like complete asshats.
        90% of all statistics are just made up on the fly.
    • If the company "calmly addresses the issues", then they'll be flooded by complainers, cheaters and opportunists within no time.

      I understand the cheaters part, but being flooded with complainers is what a CSR is paid to handle. Simply banning all discussion hurts the community in the long run and if I was a shareholder of said company I would be upset that the customer relations department is damaging the image of the company by not putting up with things its paid to handle.
    • by Xelios ( 822510 ) on Monday April 14, 2008 @07:00PM (#23071062)
      Actually EVE is unique in that most of the player base is made up of adults. The average age of an EVE player in 2006 was 27, according to the article on Wikipedia [wikipedia.org]. And I believe it, having played the game for a few years until 2007 the vast majority of people I came across were in their late 20's or early 30's.
    • Except that the majority of Eve players are over the age of 20, many in their 30s.

      I rarely meet anyone in Eve that's younger than 18 (that I know of).
      • Re: (Score:3, Informative)

        by brkello ( 642429 )
        Not that I disagree with your point or agree with the GP's...but age often has nothing to do with maturity. Particularly in Eve.
    • "I wonder if any large MMO company will ever be brave enough to calmly address an issue rather than wielding the ban-hammer."

      I doubt it. But this is not without a good reason.

      Many, many MMORPG players are 13 year old kids. Immature kids. These people are not adults. They do not behave like adults. If the company "calmly addresses the issues", then they'll be flooded by complainers, cheaters and opportunists within no time.

      I've been involved in MMORPG for several years. The immaturity in MMORPG communities i

    • A lot of people act like 13 year olds but are really much older in MMO land, as well. Sad but true.
    • I call BS (Score:3, Insightful)

      by Moraelin ( 679338 )
      I'll call BS there.

      1. Just as a counter-example: Blizzard may not be perfect on the whole, but I don't think there is even 1 documented case of anyone being banned for discussing a bug. You _can_ get banned for using bots, yes, but not discussing bots, for example.

      Their internal policy, as documented repeatedly and even recently on Slashdot, is to rely on criticism and try to fix problems. It's a piss poor company who thinks that the "ban hammer" to silence bug-reports is a perfectly normal way to hold a co
  • by Gossi ( 731861 ) on Monday April 14, 2008 @06:26PM (#23070642)
    Okay, the torrent is here [thepiratebay.org].

    First things first - it's not the full source. In fact, it's not even 2mb big. It's not even a fraction of the source.

    Secondly, from the IM conversation they had with support:

    [20:18] I don\'t know HOW you work
    [20:19] i see the RESULT of this work
    [20:19] and UNDERPANTS of it

    They see the UNDERPANTS of it. Hilarious.
  • by EWAdams ( 953502 ) on Monday April 14, 2008 @06:31PM (#23070712) Homepage
    What planet are you on? Gosh, I wonder how Microsoft would respond to someone putting the code for Office online? Banning would be the least of it. Open source is a good thing; software patents are bad; but EVERY company is legitimately entitled to its trade secrets.
  • Wait a minute... (Score:3, Interesting)

    by jeffbax ( 905041 ) on Monday April 14, 2008 @06:58PM (#23071032)
    Does this mean that someone will finally make a proper Mac and Linux build without the Transgaming garbage ;)
  • by rsmith-mac ( 639075 ) on Monday April 14, 2008 @07:41PM (#23071490)

    For those of you asking "what's the big deal about this?" here are what people have found so far digging through the code.

    • 1) Since the client logic is in Python, introducing new logic is a matter of injecting new Python code in to the game. It turns out this is very easy to do right now, there are several ways, including using the telnet server the client runs so that CCP can upload code to the client computer when it connects
    • 2) The big concern is bots, EVE can be botted and this is a problem like any MMO
    • 3) The other big concern is that the EVE client knows far more than it shows, a problem for a PvP game. It is possible to hack the client to the point where it will tell you exactly who and what entered a system you are in, and where they are at at all times.
    • 4) It's also possible to disable the client's "anti-addiction" code required to meet China's MMO laws. Apparently the server isn't actually booting players, it's telling the client to disconnect. The Chinese government is going to love that one
    • 5) Finally, the game has a custom made built-in web browser (the In Game Browser) that's extremely cruddy and isn't used very much. It's also so cruddy that it's holier than the Pope himself; it's possible to craft links to induce it to execute external applications and web browsers. Basically with a little social engineering you can be trick people in to letting you compromise their machine.

    EVE is a fine game, but the code is a joke. This is very likely going to lead to a lot of problems for CCP for some time to come. If they're lucky they'll only get a flood of bots, if they're not then the game may very well turn in to a wild west of hacking players looking for an edge.

    • Well that last point seals it for me.

      Won't be playing EVE online's trial any time soon.
    • Suggestion: allow bots. That aught to level the playing field a bit.

      I loved EVE when i played it years ago, but i really felt that most of the game should have been automated, or at least have the potential for automation. You just gotta make things in the actual environment a bit more unpredictable for offset.

      Eve is already structured around this idea, with corps controlled from the top, etc. I think, done right, it could add a lot more depth to the game.
  • by Hachima ( 718971 ) on Monday April 14, 2008 @07:53PM (#23071586)
    Back in the day the EVE/script folder had the decompiled python in it in plain text. People did stuff like modify it to create merchant bots that would auto buy/sell stuff on the markets and whatever else they wanted to modify. Then CCP changed it to one 'compiled.code' file instead of all the uncompiled python files, which is easier to manage and check for people making changes. So you can still just take that 'compiled.code' file and decompile it to readable code. Which is what got 'leaked' It's nothing special at all really, and is only a portion of the client code. Anyone that was interested in messing with it has already seen the Python, especially people that played when it wasn't even pre-compiled. Next thing you know right clicking a web page to 'view source' will be considered leaking source code too?
  • Could we rephrase it to say

    EVE Online Client Open Sourced

    but not by choice?

  • I read the chat-log, but I'm having a hard time understanding "Abused's" position; what is his motivation for releasing the source code? Why is he so interested in forcing the EVE developer to make a news release confirming that some security exploites have existed "for years"? The code isn't open source, so releasing detailed descriptions of what security holes exist would only allow them to be exploited easier. Is that what he wants?
    • Re:Motivation? (Score:4, Informative)

      by cowscows ( 103644 ) on Monday April 14, 2008 @08:51PM (#23072088) Journal
      No, he just wants some of the obvious technical problems with the game to be addressed. EvE is a pretty amazing game, but it has plenty of rough edges and some glaring flaws. EvE is also an extremely competitive game, beyond pretty much anything I've ever played online. There's many examples of bots and macro-miners, and those sorts of things. In a game that's so cut-throat, and that has relatively few restrictions/rules, when someone does break the rules it tends to make many of the players very upset.

      The developers are fully aware of many of these issues, yet when the players ask for them to be addressed, the devs sometimes play dumb or more often say it'll be dealt with and then never really say whether it got fixed or not.

      Short version: There's lots of bots in the game. Players complain. CCP keeps saying Don't worry, we're taking care of it. But the bots never go away. Rinse and repeat that sequence for various other issues.
  • Old: Eve Online Client Source Code Leaked
    Revised: Eve Online Client now open source!
  • by britneys 9th husband ( 741556 ) on Monday April 14, 2008 @09:24PM (#23072326) Homepage Journal
    It's no wonder they tried so hard to keep this code hidden.  I'm not even sure what this is supposed to do.

    //Both people are represented by an abstract class
    public abstract class Person
    {
      public bool StrangersToLove { get; set; }
      public bool KnowTheRules { get; set; }
    }

    //Possible thoughts
    public enum Thought
    {
      FullCommitment
    }

    //Class
    public sealed class Me : Person
    {
      public Thought Thinking()
      {
        return Thought.FullCommitment;
      }
    }

    //The target of the song, notice that GetThought can only be called by passing in an instance of Rick
    //which satisfies that she can't get this from any other guy
    public class You : Person
    {
      private Thought whatHeIsThinking;
      public void GetThought(Me guy)
      {
        whatHeIsThinking = guy.Thinking();
      }
    }

    class Program
    {
      //The first verse
      static void Main(string[] args)
      {

        var Rick = new Me() { KnowTheRules = true, StrangersToLove = false };

        var Girl = new You() { KnowTheRules = true, StrangersToLove = false };

       Girl.GetThought(Rick);
      }
    }
  • by Vecna! ( 74330 ) on Monday April 14, 2008 @09:37PM (#23072438)
    CCP is aware that an individual claims to have access to the source code of the EVE client. This access is not a security risk to CCP in any way. CCP does not believe in security by obscurity. The Python scripting language that is used by the client can be easily decompiled to generate human-readable code, and CCP has designed its server-side systems with that understanding. Access to the source code for the EVE client exposes no security vulnerabilities, has no privacy protection issues, and poses no threat to our customers' billing information. The server-side interface used by the client is carefully protected to ensure that no abusive or unwanted information is transmitted to, or from the EVE system. Nothing the EVE client can do can affect the game state, no advantage can be gained by manipulating the EVE client, no advantageous or disadvantageous information can be transmitted to other EVE users by altering the EVE client. The EVE client is signed with a security certificate registered to CCP, and hashes are available on our web site for those who wish to ensure the integrity of EVE client download files they may have received from a source other than direct download from CCP's web site.

    CCP does not confirm or deny, nor make any comment, regarding issues of internal security, and will not be doing so in this case. As a policy, CCP removes message board posts regarding violations of its EULA and Terms of Service, and CCP considers any alteration of the Client software, including decompilation, to be such violations.

    --------

    Ryan S. Dancey
    Chief Marketing Officer
    CCP
    • Re: (Score:3, Insightful)

      by MORB ( 793798 )

      Nothing the EVE client can do can affect the game state, no advantage can be gained by manipulating the EVE client, no advantageous or disadvantageous information can be transmitted to other EVE users by altering the EVE client.

      While I agree with not relying on security through obscurity, there are cheats that can be created trivially with the client code.

      For instance, integrating a fully automated mining bot in the client would be easy by using the auto pilot code as a starting point (it has more than likely already been done for ages too).

      Altough I don't think it's a security problem as much as it is a game design problem: if mining wasn't mind numbingly stupid boring and repetitive, a bot probably wouldn't be able to do it as

  • At the risk of sounding like the guy who can't stop telling people how he doesn't have a TV and doesn't miss it in the least, boy am I glad I stopped playing EVE. The waiting game on the bug fix list got old quick, Godot would get here before they ever fixed drones.

    I successfully avoided getting hooked on MUD's and Evercrack but huge honkin' space games were my biggest weakness, a space MMO was where I finally made the plunge. It's a good thing the game couldn't keep me hooked, I still have a life (or what
  • Full source? (Score:3, Interesting)

    by Anonymous Coward on Monday April 14, 2008 @10:51PM (#23073062)
    So has anyone actually recompiled it into a working client? Is it even possible or are these just, as people have said, decompiled portions of the client?

He has not acquired a fortune; the fortune has acquired him. -- Bion

Working...