Pirated copies of a pair of 2004鈥檚 most hotly anticipated computer games were leaked online this week, highlighting the need for better technical and physical security at the companies that make the games.
Rockstar Games鈥 Grand Theft Auto: San Andreas, a sequel to one of the top-selling video games of all time was scheduled for commercial release on 26 October but surfaced on websites on Wednesday. Microsoft鈥檚 Halo 2, also a best-seller sequel, was leaked on 15 October, weeks before its 9 November release date.
Game software finds its way online before a release date either via a dishonest employee or by a remote hack attack which captures code stored online on a vulnerable system.
Advertisement
Neither Microsoft nor Rockstar have pinned down precisely the source of their leaks but security experts are convinced that in both cases company insiders leaked the software, either for a bribe, or to gain 鈥渦nderground notoriety鈥.
鈥淭he code was stolen and posted before the game was released 鈥 this kind of leak is more likely to be from a disgruntled company employee than due to a hacker,鈥 says Greg Costikyan, a games industry consultant based in New York City.
Background checks
To protect themselves, companies must do background checks on staff, audit who has access to which components of the game during the development process and ensure that no single person has access to all components before its release, says Angela Orebaugh, a security expert at intrusion detection software vendor Sytex in Washington DC.
It sounds basic, she says, 鈥渂ut I am assuming they are not doing that or else the games would not have been leaked鈥.
Another strategy is to use software to make games unplayable when they are stolen, says Ron Vandergeest of the security software vendor Cloakware in Ottawa, Canada.
His company started selling software based on 鈥淲hite-box encryption鈥 to game companies earlier in 2004. Traditional encryption can be broken easily, he says, because the string of bits that act as the key is embedded in one place on the disk and is simple to pinpoint.
Hackers strip the game of its protection and post an 鈥渦nwrapped鈥 version online. But Whitebox encryption makes extracting the key much more difficult because it diffuses the bits that make up the key throughout the code of the game itself.
Fading away
Another trick, from Macrovision in Santa Clara, California, is 鈥淔ade鈥. It not only stops pirates, it converts them from a liability into vehicles for advertising (New 杏吧原创, 10 October 2003).
When a game is copied on to a CD, its master program recognises that certain 鈥渟cratches鈥 on the original are no longer present and runs a disabled version of the code that allows just enough playing time to entice the user, before the graphics literally start 鈥渇ading鈥 away.
Meanwhile Gavriel States of Transgaming, a company in Toronto that writes games for the Linux operating system, has suggested 鈥渨atermarking鈥 games with unique string of bits that changes according to which employee is working on it.
This should act as a deterrent because games companies can then identify suspects when code is leaked. However, this approach has sometimes caused other applications on Linux-based systems not to work properly, forcing Transgaming to withdraw the system.
States advocates forcing a user to register online with the game company鈥檚 server the first time the game is played, allowing the company to monitor the spread of that copy. But he admits that network-based approaches raise privacy concerns because the company would knows exactly when a particular game is played.