Tuesday, December 8, 2009

X marks the Games


Sony Playstation Celebrates Its 15th Anniversary, Happy 20th birthday, Game Boy, Happy 10th anniversary, Sega Dreamcast! and November Marks the Launch Anniversary of Many a Gaming Platform.  Gaming has come a long way since the Atari 2600 and the Fairchild Channel F when we would screw those little U connectors to the UHF/VHF thingy.  Then we got ColecoVision’s arcade quality games like Donkey Kong and the early Nintendo’s and Sega’s to today’s Sony PlayStation, Microsoft Xbox (there’s your 24th letter) and Nintendo Wii.  These days, not only can you hook you console up to your TV monitor, you can connect to the internet and play games online, even without a console.  While gaming threats & breaches don’t always make the splashy headlines like stolen credit cards and hacked financial applications, there is still plenty of things to worry about while you’re having fun.  Whether you’re a player or provider, the risks are out there and many (both technical & social) are no different than the exploits, malware and thieves we typically hear about from general online communities. 

Over the last couple years, a number online gaming sites experienced DDoS attacks that forced outages and tossed some sites offline and even Pirate Bay got hit with a DDoS attack when their users were not happy about the sale to Global Gaming Factory.  Even back in 2004, there were articles that covered the Security Issues of Online Gaming and a few of those mentioned still hold today.

For users, the risks loom since they spend a lot of time and money on these games and there are always crooks out there looking to exploit that.  There is also significant amount of social interaction with other players and many of the social media threats, like being tricked into exposing personal or financial information, are just a prevalent.  And it’s not just hidden criminals.  Full on media companies offering rewards, points or other game enhancements trick users into signing up for bogus offers and monthly subscriptions all while capturing their email address, credit card and other personal info.  This is quick money for game developers (and social sites, advertisers and others) even if it is done in an unscrupulous way.

Malware infection whether it be worms, viruses or bots are also a risk.  Most of us have learned that we should not click on an embedded email link for fear of computer infection.  But do you use the same technique when searching for a new/hidden game file or conversing with another player over IM?  They might have been part of your online ‘team’ for some time and you’ve exchanged tips.  Then they promote some cool new ‘add-on’ and send you an IM saying, ‘download this hidden gem – earn points faster!!’  Would you use the same caution as a phishing email or click away?  If the game required administrative rights for installation, would you grant it?  Would you allow all JavaScript and ActiveX to run, knowing the inherent browser risks?  Also, since you’re playing online, you have to be connected to a server somewhere.  Is that server vulnerable?  Has it been compromised?  If it has, then you too can be vulnerable – it’s really no different than other server exploits.  This applies to game operators also.  How are you protecting your infrastructure from malicious behavior?

This document (pdf) from US-CERT has a nice overview of avoiding online gaming risks, was an inspiration for this blog post and offers several protective measures….which look a lot like the general security good practices we hear on a daily basis:
• Use antivirus and antispyware programs.
• Be cautious about opening files attached to email messages or instant messages.
• Verify the authenticity and security of downloaded files and new software.
• Configure your web browsers securely.
• Use a firewall.
• Identify and back up your personal or financial data.
• Create and use strong passwords.
• Patch and update your application software.
Not to dampen any of your fun this year as many of us rip open new gaming consoles, connect them to the internet and start firing away, just use the same caution, suspicion and protection when you enter that fun zone.  Don’t let your guard down just because you’re having a great time – that holiday glee can morph into your winter of discontent with a single click.
ps

Related resources:

No comments:

Post a Comment