Hard to have sympathy for Ubisoft the company as they are regularly used as an example of the most anti-consumer practices out there. But the whole situation is a mess, and if anything, it is probably the consumers that will end up suffering the most for this.
The line "How could I forget that I had given her an extra key?" comes to mind. Maybe someone left an API key laying around somewhere? Although I could be giving the hackers too much credit...
It's a shame this game has to pander to eSports fanatics rendering it into a completely hollowed out soulless experience. From the early days of Operation Chimera to selling half of your stake and IPs to Tencent, Ubisoft has seen it all.
+1. Can’t believe how they held amazing IPs and then milked them to death while lowering the quality game over game. Whether it’s far cry or assassin’s creed, all the later iterations are worse than the series start.
Oh wow, they cancelled it?
I played it for a bit on release. Kinda fun, didn't stick with it, but surprised it's already cancelled so short after release.
- THE FIRST GROUP of individuals exploited a Rainbow 6 Siege service allowing them ban players, modify inventory, etc. These individuals did not touch user data (unsure if they even could). They gifted roughly $339,960,000,000,000 worth of in-game currency to players. Ubisoft will perform a roll back to undo the damages. They're probably annoyed. I cannot go into full details at this time how it was achieved.
- A SECOND GROUP of individuals, unrelated to the FIRST GROUP of individuals, exploited a MongoDB instance from Ubisoft, using MongoBleed, which allowed them (in some capacity) to pivot to an internal Git repository. They exfiltrated a large portion of Ubisoft's internal source code. They assert it is data from the 90's - present, including software development kits, multiplayer services, etc. I have medium to high confidence this true. I've confirmed this with multiple parties.
- A THIRD GROUP of individuals claim to have compromised Ubisoft and exfiltrated user data by exploiting MongoDB via MongoBleed. This group is trying to extort Ubisoft. They have a name for their extortion group and are active on Telegram. However, I have been unable to determine the validity of their claims.
- A FOURTH GROUP of individuals assert the SECOND group of individuals are LYING and state the SECOND GROUP has had access to the Ubisoft internal source code for awhile. However, they state the SECOND GROUP is trying to hide behind the FIRST GROUP to masquerade as them and give them a reason to leak the source code in totality. The FIRST GROUP and FOURTH GROUP is frustrated by this
Will the SECOND GROUP leak the source code? Is the SECOND GROUP telling the truth? Did the SECOND GROUP lie and have access to Ubisoft code this whole time? Was it MongoBleed? Will the FIRST GROUP get pinned for this? Who is this mysterious THIRD GROUP? Is this group related to any of the other groups?
I used to work for Ubisoft, though not on Siege- I have met and had detailed conversations with their lead architect though; truthfully I remember little of those conversations.
Regarding the second group and access to source code; this is unlikely for a combination of four reasons.
1) The internal Ubisoft network is split between “player stuff” (ONBE) and developer stuff.
2) The ONBE network is deny by default, no movement is possible unless its explicitly requested ahead of time, by developers, in a formal request that must be limited in scope.
3) ONBE to “developer network” connections are almost never granted. We had one exception to this on the Division, and it was only because we could prove that getting code execution on the host that made connections would require a long chain of exploits. Of course that machine did not have complete access to all of the git repos.
4) Not a lot of stuff really uses git internally. Operations staff and web developers prefer git strongly; so they use Git. But nearly every project uses Perforce. Good look getting a flow granted from ONBE to a perforce server. That will never happen.
Siege, like The Division, worked against Ubisoft internal IT policies to make the product even possible. (IT was punishingly rigid) but some contracts were unviolatable.
The last I heard, Siege had headed to AWS and had free dominion in their tenant, but it would need Ubiservices (also in AWS) and those would route through ONBE.
I’m not sure if much changed, since a member of the board is former Microsoft and has mandated a switch to Azure from the top… But I am certain that these policies would likely be the last to go.
Nothing highlights how pointless e-sports items are more than a real dollar value for a player base of all of them. The entire global GDP is as an order of magnitude roughly $100 trillion. So this $340 trillion figure is 3.4 times planetary total economic output - meaning the theoretical value of Rainbow Six cosmetics exceeds what the entire human civilisation produces in a year. Multiple times over. You'd be valuing pixelated gun attachments higher than annual agricultural output across all nations, all manufacturing, all services, everything.
I bet it appears unchallenged at some point in a court (or insurance) document though.
The valuation is based on them hypothetically selling the same quantities that the hackers gave away at their retail prices, which of course no one believes they would ever actually sell that much.
While I understand what you're saying, it's pretty clear what is meant is "$X worth at the price they currently sell for". When there's a story about an object in space made of gold worth 100s of trillians of dollars, nobody believes it would really sell for that much if we captured it and mined all the gold; because the value of gold would plummet based purely on it's existence.
But I agree with you that it would be put into a court document as "it cost us this much" for the full amount, vs the amount they were likely to ever be able to sell (and can't, now that everyone got it for free, so the value is $0)
The market cap is unambiguous, a more correct estimate of "how much to buy all the shares?" is situational and would just distract from getting the point across.
> Players across PC and console are being urged by the community to stay offline, as reports continue to surface of accounts receiving billions of in game credits, rare and developer only skins, and experiencing random bans.
Regardless if this is true or not, and how it works exactly, I find it an interesting scenario.
For players: should I go online to maybe get gifted tons of ingame valuables while risking a ban? It turns playing into a gamble.
If I take on the hackers' view, I would find it exciting to dish out rewards and punishment at random on a large scale.
> Will the SECOND GROUP leak the source code? Is the SECOND GROUP telling the truth? Did the SECOND GROUP lie and have access to Ubisoft code this whole time? Was it MongoBleed? Will the FIRST GROUP get pinned for this? Who is this mysterious THIRD GROUP? Is this group related to any of the other groups?
This read to me like the end of a soap opera. Tune in tomorrow to find out!
Can’t help but laugh a bit. Not a great day for Ubisoft. Hopefully this didn’t ruin the holidays for too many employees. That would absolutely suck to get a call in for this.
> Will the SECOND GROUP leak the source code? Is the SECOND GROUP telling the truth? Did the SECOND GROUP lie and have access to Ubisoft code this whole time? Was it MongoBleed? Will the FIRST GROUP get pinned for this? Who is this mysterious THIRD GROUP? Is this group related to any of the other groups?
Find out in the next episode of... Tales from Cyberspace!
Streamer[1,2], formerly pro gamer[3]. “Creator” here is a clipping of “content creator”, an overtly ad-industry term that makes me a little sad(der) each time I hear it but is unfortunately universal nowadays, especially for people making videos (as we don’t really have another umbrella word for that).
This is like complaining all modern movies are superhero movies. It’s hard to think that unless you’re hardly looking at all, or have fairly narrow taste and aren’t counting most of the medium.
Those games have 100x to 500x smaller budgets than the AAA-games. Yes, they often have cute ideas, but, like a blockbuster movie, 99 times out of 100 you need a solid budget to make a solid movie/game.
If 1% of indie games are solid, and all AAA game are solid, and there are 100 times more indie games than AAA games, then there would still be the same amount of solid indies as there are solid AAA games. As it is, I think for every good AAA game, there are somewhere between 50 and 500 great indie games.
Finding them is slightly harder, but absolutely worth it.
In any case, complaining about how many games there are out there that are not your thing is a waste of time. Much better to define what you like and look for recommendations from people who like similar games. Who care how many FPSs are released if you don't like FPSs? If you like RPGs, find RPG gamers and ask them what's good. Substitute for any genre; there is no genre out there that's not getting more releases than you could possibly play.
If you want AAA games, you are going to have a safe game. You get the same with movies - Bigger budgets cause safer behavior with less risk taking. You wind up with a pretty game, a somewhat safe story (that they think will sell) and gameplay they think is just good enough to keep you going.
It isn't that the other games are bad, though. It isn't like we are talking "handheld camcorder student-written movie" vs "polished hollywood blockbuster" but more.... Beautiful painting by a mostly unknown artist vs beautiful large, publically displayed and privatly funded artist. Big budgets get you more assistance and more/better tools and more space and more human help and more connections.
It is probably important to remember that a large portion of a blockbuster's budget is advertising. Advertising is often 50-100% of the production budget and I'm guessing AAA games have similar advertising budgets. I'm not sure how a large advertising budget gives you better products, though it might get you more folks if your game is online.
Of course, I'm guessing if you limit your search to FPS games, your experience might be a different.
The top of the list is Genshin Impact, although it'll probably be displaced by GTA6 soon - that one's estimated to come in at $1.5-2 million. There's multiple FPS games on there but there's some pretty expensive open-world games too.
> 99 times out of 100 you need a solid budget to make a solid movie/game.
Sure, but 1 in 100 still gets you dozens of games a year now. There's plenty of genres where the top titles are nowhere near an AAA budget: Hades 2, Silksong, and Claire Obscura all being popular examples from this year, and Factorio being another well known example around here. Even simpler games like Balatro and Vampire Survivor are plenty of fun for some people.
The biggest studios have rarely been the ones producing the best work - budget gets you fancy cinematics and a beautifully rendered 3D world, but it doesn't make level design go any faster. It could plausibly buy better writing, but that requires all the executives to back off and trust the creatives.
And for what it's worth, the big studios are all happy raking in money on mindless remakes - it keeps working for them.
I think he is saying where is the creativity in the AA+ space. Which still might be a lack of depth / breadth of search, or platform exclusive content. Not everyone can own all the consoles.
Maybe you can give a bit of context why you feel that way? Dropping a 2+ hour, <2000 views, 4chan video without context isn’t really the type of comment HN is looking for as far as I can tell
Nice to see anti-cheats working and protecting Linux players from hacks, by preventing them from actually playing the game.
Hard to have sympathy for Ubisoft the company as they are regularly used as an example of the most anti-consumer practices out there. But the whole situation is a mess, and if anything, it is probably the consumers that will end up suffering the most for this.
It's not random bans, the nicknames are words from longer text. It's lyrics from Shaggy - It wasn't me.
The line "How could I forget that I had given her an extra key?" comes to mind. Maybe someone left an API key laying around somewhere? Although I could be giving the hackers too much credit...
Maybe the mongo db exploit from two days ago?
https://github.com/joe-desimone/mongobleed
https://beta.shodan.io/host/212.104.194.153
Somebody else said some Postgres dumps are available, not sure if they are even using mongo. But maybe mongo was the start of the chain.
Per the tweet linked in the article there were also random bans in addition to the ban feed shitposting.
https://x.com/KingGeorge/status/2004902566434668686
Global game messages being used to meme - reminds me of Team Fortress 2 rings.
Saw a video earlier today with the lyrics of Billie Jean by Michael Jackson too.
It's a shame this game has to pander to eSports fanatics rendering it into a completely hollowed out soulless experience. From the early days of Operation Chimera to selling half of your stake and IPs to Tencent, Ubisoft has seen it all.
This game was amazing at launch, recently tried it again and it’s become trash
Ubisoft kept making garbage and sacrificed their IP’s for the sake of keeping the company alive…
It was doomed.
+1. Can’t believe how they held amazing IPs and then milked them to death while lowering the quality game over game. Whether it’s far cry or assassin’s creed, all the later iterations are worse than the series start.
I’m still bitter at them for canceling XDefiant… it wasn’t a COD killer but it filled a comfortable niche and had potential.
Oh wow, they cancelled it? I played it for a bit on release. Kinda fun, didn't stick with it, but surprised it's already cancelled so short after release.
https://x.com/vxunderground/status/2005008887234048091
Here's the word on the internet streets:
- THE FIRST GROUP of individuals exploited a Rainbow 6 Siege service allowing them ban players, modify inventory, etc. These individuals did not touch user data (unsure if they even could). They gifted roughly $339,960,000,000,000 worth of in-game currency to players. Ubisoft will perform a roll back to undo the damages. They're probably annoyed. I cannot go into full details at this time how it was achieved.
- A SECOND GROUP of individuals, unrelated to the FIRST GROUP of individuals, exploited a MongoDB instance from Ubisoft, using MongoBleed, which allowed them (in some capacity) to pivot to an internal Git repository. They exfiltrated a large portion of Ubisoft's internal source code. They assert it is data from the 90's - present, including software development kits, multiplayer services, etc. I have medium to high confidence this true. I've confirmed this with multiple parties.
- A THIRD GROUP of individuals claim to have compromised Ubisoft and exfiltrated user data by exploiting MongoDB via MongoBleed. This group is trying to extort Ubisoft. They have a name for their extortion group and are active on Telegram. However, I have been unable to determine the validity of their claims.
- A FOURTH GROUP of individuals assert the SECOND group of individuals are LYING and state the SECOND GROUP has had access to the Ubisoft internal source code for awhile. However, they state the SECOND GROUP is trying to hide behind the FIRST GROUP to masquerade as them and give them a reason to leak the source code in totality. The FIRST GROUP and FOURTH GROUP is frustrated by this
Will the SECOND GROUP leak the source code? Is the SECOND GROUP telling the truth? Did the SECOND GROUP lie and have access to Ubisoft code this whole time? Was it MongoBleed? Will the FIRST GROUP get pinned for this? Who is this mysterious THIRD GROUP? Is this group related to any of the other groups?
I used to work for Ubisoft, though not on Siege- I have met and had detailed conversations with their lead architect though; truthfully I remember little of those conversations.
Regarding the second group and access to source code; this is unlikely for a combination of four reasons.
1) The internal Ubisoft network is split between “player stuff” (ONBE) and developer stuff.
2) The ONBE network is deny by default, no movement is possible unless its explicitly requested ahead of time, by developers, in a formal request that must be limited in scope.
3) ONBE to “developer network” connections are almost never granted. We had one exception to this on the Division, and it was only because we could prove that getting code execution on the host that made connections would require a long chain of exploits. Of course that machine did not have complete access to all of the git repos.
4) Not a lot of stuff really uses git internally. Operations staff and web developers prefer git strongly; so they use Git. But nearly every project uses Perforce. Good look getting a flow granted from ONBE to a perforce server. That will never happen.
Siege, like The Division, worked against Ubisoft internal IT policies to make the product even possible. (IT was punishingly rigid) but some contracts were unviolatable.
The last I heard, Siege had headed to AWS and had free dominion in their tenant, but it would need Ubiservices (also in AWS) and those would route through ONBE.
I’m not sure if much changed, since a member of the board is former Microsoft and has mandated a switch to Azure from the top… But I am certain that these policies would likely be the last to go.
Nothing highlights how pointless e-sports items are more than a real dollar value for a player base of all of them. The entire global GDP is as an order of magnitude roughly $100 trillion. So this $340 trillion figure is 3.4 times planetary total economic output - meaning the theoretical value of Rainbow Six cosmetics exceeds what the entire human civilisation produces in a year. Multiple times over. You'd be valuing pixelated gun attachments higher than annual agricultural output across all nations, all manufacturing, all services, everything.
I bet it appears unchallenged at some point in a court (or insurance) document though.
The valuation is based on them hypothetically selling the same quantities that the hackers gave away at their retail prices, which of course no one believes they would ever actually sell that much.
While I understand what you're saying, it's pretty clear what is meant is "$X worth at the price they currently sell for". When there's a story about an object in space made of gold worth 100s of trillians of dollars, nobody believes it would really sell for that much if we captured it and mined all the gold; because the value of gold would plummet based purely on it's existence.
But I agree with you that it would be put into a court document as "it cost us this much" for the full amount, vs the amount they were likely to ever be able to sell (and can't, now that everyone got it for free, so the value is $0)
and yet, most people use this same measure for market capitalization of companies.
The market cap is unambiguous, a more correct estimate of "how much to buy all the shares?" is situational and would just distract from getting the point across.
You could achieve a similar sum by adding balances out of thin air to random bank accounts, which is comparable to what happened here.
> Players across PC and console are being urged by the community to stay offline, as reports continue to surface of accounts receiving billions of in game credits, rare and developer only skins, and experiencing random bans.
Regardless if this is true or not, and how it works exactly, I find it an interesting scenario.
For players: should I go online to maybe get gifted tons of ingame valuables while risking a ban? It turns playing into a gamble.
If I take on the hackers' view, I would find it exciting to dish out rewards and punishment at random on a large scale.
This has the air of a parody spy caper where the various people who have broken in keep tripping over each other.
The source leak is really interesting, though. We don't often get to see game source, and it often has surprises in.
> Will the SECOND GROUP leak the source code? Is the SECOND GROUP telling the truth? Did the SECOND GROUP lie and have access to Ubisoft code this whole time? Was it MongoBleed? Will the FIRST GROUP get pinned for this? Who is this mysterious THIRD GROUP? Is this group related to any of the other groups?
This read to me like the end of a soap opera. Tune in tomorrow to find out!
Can’t help but laugh a bit. Not a great day for Ubisoft. Hopefully this didn’t ruin the holidays for too many employees. That would absolutely suck to get a call in for this.
> Will the SECOND GROUP leak the source code? Is the SECOND GROUP telling the truth? Did the SECOND GROUP lie and have access to Ubisoft code this whole time? Was it MongoBleed? Will the FIRST GROUP get pinned for this? Who is this mysterious THIRD GROUP? Is this group related to any of the other groups?
Find out in the next episode of... Tales from Cyberspace!
At least it's webscale.
Four attackers present in a system at the same time?
How?
Misconfigured database that was publicly accessible, vulnerability/exploit dropped around the same time.
It is Mongo
https://x.com/vxunderground/status/2005008887234048091?s=20
This is why security actually matters in game development.
> Prominent Siege creator KingGeorge
So, the lead developer?
Streamer[1,2], formerly pro gamer[3]. “Creator” here is a clipping of “content creator”, an overtly ad-industry term that makes me a little sad(der) each time I hear it but is unfortunately universal nowadays, especially for people making videos (as we don’t really have another umbrella word for that).
[1] https://www.youtube.com/channel/UCsHlla-bq0C_2OtEy8s2_Sg
[2] https://www.twitch.tv/kinggeorge
[3] https://liquipedia.net/rainbowsix/KingGeorge
"Prominent" being sub 1000 views on YouTube?
I wonder if they could push out an update. That would be super scary.
A 9 year old random FPS game.
WTF happened to non-shooter games? I am so bored of these FPS variations.
This is like complaining all modern movies are superhero movies. It’s hard to think that unless you’re hardly looking at all, or have fairly narrow taste and aren’t counting most of the medium.
Some very fun indie games I've been playing this past year (lots of early access):
- Hexarchy / Rogue hex (Civ-like)
- The Last Caretaker
- Captain of Industry (factorio-like, was posted here on HN by dev awhile back)
- 9 kings
- Super Fantasy Kingdom
- Manor Lords
- Astronomics
- Heart of the Machine
Those games have 100x to 500x smaller budgets than the AAA-games. Yes, they often have cute ideas, but, like a blockbuster movie, 99 times out of 100 you need a solid budget to make a solid movie/game.
If 1% of indie games are solid, and all AAA game are solid, and there are 100 times more indie games than AAA games, then there would still be the same amount of solid indies as there are solid AAA games. As it is, I think for every good AAA game, there are somewhere between 50 and 500 great indie games.
Finding them is slightly harder, but absolutely worth it.
In any case, complaining about how many games there are out there that are not your thing is a waste of time. Much better to define what you like and look for recommendations from people who like similar games. Who care how many FPSs are released if you don't like FPSs? If you like RPGs, find RPG gamers and ask them what's good. Substitute for any genre; there is no genre out there that's not getting more releases than you could possibly play.
If you want AAA games, you are going to have a safe game. You get the same with movies - Bigger budgets cause safer behavior with less risk taking. You wind up with a pretty game, a somewhat safe story (that they think will sell) and gameplay they think is just good enough to keep you going.
It isn't that the other games are bad, though. It isn't like we are talking "handheld camcorder student-written movie" vs "polished hollywood blockbuster" but more.... Beautiful painting by a mostly unknown artist vs beautiful large, publically displayed and privatly funded artist. Big budgets get you more assistance and more/better tools and more space and more human help and more connections.
It is probably important to remember that a large portion of a blockbuster's budget is advertising. Advertising is often 50-100% of the production budget and I'm guessing AAA games have similar advertising budgets. I'm not sure how a large advertising budget gives you better products, though it might get you more folks if your game is online.
Of course, I'm guessing if you limit your search to FPS games, your experience might be a different.
Wikipedia has a list of the most expensive video games to develop, with a lower limit of $50mil. https://en.wikipedia.org/wiki/List_of_most_expensive_video_g...
The top of the list is Genshin Impact, although it'll probably be displaced by GTA6 soon - that one's estimated to come in at $1.5-2 million. There's multiple FPS games on there but there's some pretty expensive open-world games too.
> 99 times out of 100 you need a solid budget to make a solid movie/game.
Sure, but 1 in 100 still gets you dozens of games a year now. There's plenty of genres where the top titles are nowhere near an AAA budget: Hades 2, Silksong, and Claire Obscura all being popular examples from this year, and Factorio being another well known example around here. Even simpler games like Balatro and Vampire Survivor are plenty of fun for some people.
The biggest studios have rarely been the ones producing the best work - budget gets you fancy cinematics and a beautifully rendered 3D world, but it doesn't make level design go any faster. It could plausibly buy better writing, but that requires all the executives to back off and trust the creatives.
And for what it's worth, the big studios are all happy raking in money on mindless remakes - it keeps working for them.
I would argue clair obscur is actually a shooter game seeing the variety of op builds
What’s your point
I think he is saying where is the creativity in the AA+ space. Which still might be a lack of depth / breadth of search, or platform exclusive content. Not everyone can own all the consoles.
I play non FPS video games almost every night. There are so many great games available.
We're currently in a golden age of Indie games catering to hyper specific niches. Ignore all AAA games and you'll find absolute gems.
Play Hades 2!
Maybe check out game awards finalists
IMO the vidya gaem awards [0] are far superior to the game awards.
[0] https://www.youtube.com/watch?v=mXMcq_LJ8ro
Maybe you can give a bit of context why you feel that way? Dropping a 2+ hour, <2000 views, 4chan video without context isn’t really the type of comment HN is looking for as far as I can tell
I checked them out. I guess I just miss a time when Falcon 3.0 and https://en.wikipedia.org/wiki/Stunt_Island sold really well.
Miss falcon 3.0? Go with Falcon BMS. For any genre of games there is a modern remake and community these days.
I literally discovered a completely free and open source Total Annihilation/Supreme Commander remake last month which is great for nostalgia’s sake.
https://www.beyondallreason.info/
We've come a long way in the past 30 years
Yeah, 1000 variations later, the latest Doom/Quake iteration looks great.
Summing up the entire FPS genre as Doom-like is unfair and discredits you more than anything else. Heck, even Doom and Quake are wildly different.
FPS haven't been under the spotlights for a while, these days it's mostly MOBAs.