Game guide · source of truth
Tech

Security, anti-cheat and auto-ban

Security from day one — the server-authoritative base, the security event log, detection rules in three confidence tiers, automatic bans only for certain evidence, the action ladder, rollback, the "Contact us" ban review (review only when a player appeals), rule-quality limits and the red-team tests.

Decision (owner, round 6): design security in from the first line of code. When a player does something that is not allowed, the system bans automatically; a human reviews only if the player asks through Contact us. Rules and thresholds live in packages/game-data/data/security.json (proposed).

◆1. The base: cheats that can't work

Most MMO cheats fail before detection is needed, because the server owns every outcome:

  • The client sends inputs, never results: no damage, no loot claims, no positions without inputs (ARCHITECTURE rules).
  • Every cast and move is validated on the server (range, line of sight, cooldown, mana, speed, walkability).
  • Every item, gold and Zoe change is a transaction with a receipt (duplication races fail atomically).
  • Manual play, Smart Chain, Auto-Hunt, Auto-Quest and offline actors use one command path, so a bot gains nothing the official automation doesn't already give.

So detection focuses on attempts (a modified client trying impossible things), abuse (bots outside the official automation, economy fraud, spam) and account security.

◆2. Security event log (day one, M1 onward)

Every rejected or suspicious action writes an append-only security event: account, character, rule id, evidence (packet summary, positions, timings, receipt ids), client version, device id, time. Events are kept 180 days, are never shown publicly, and feed the rule engine. Gameplay code never bans directly; it only reports events.

◆3. Rules in three confidence tiers

TierMeaningExamplesAutomatic action
Certainimpossible from an unmodified clientforged or malformed protocol messages; replayed session or admission tokens; acting for another player's entity; repeated movement far beyond physics after server corrections; client integrity check failed (modified build)permanent ban at once + rollback of everything gained
Strongvery unlikely for a human, measured over timeinput timing too regular for hours outside the official automation; 24/7 manual-mode play without breaks; gold funnelling between unrelated accounts (real-money trading pattern); chat spam with linkstemporary restriction (mute, trade lock or 24 h suspension); a repeat within 30 days → permanent ban
Watchunusual, can be legitimateunusually fast levelling, rare-drop streaks, many accounts per deviceno action; logged and charted for the team

A rule may only enter the Certain tier when legitimate play can never trigger it (proved by the red-team and false-positive tests below).

◆4. Action ladder

warn → kick → mute / trade lock → 24 h suspension → 7-day suspension → permanent ban. Certain rules skip to a permanent ban. Every action stores its ban id, rule, evidence and the receipts to roll back. Permanent bans also flag the device so a fresh account on the same device starts under watch (no automatic ban).

◆5. Rollback

Items, gold, Zoe, XP and ranking entries gained through the violation are removed using the receipts. Players who traded with the cheater keep what they paid for when possible; duplicated items are deleted wherever they ended up.

◆6. "Contact us" ban review (only on appeal)

  • The ban screen (game and website) shows the ban id, date, rule category (e.g. "modified client") and a Contact us button → site Support → Ban review form, prefilled with the ban id.
  • Bans that nobody appeals need no human review.
  • Appeals are reviewed within 7 days by a staff member who sees the evidence; outcomes: upheld, reduced, or reversed. A reversal restores everything from the receipts and adds a goodwill note.
  • This also covers privacy law: players can ask for human review of an automated decision (e.g. GDPR art. 22). The Terms of Service and Privacy Policy must describe automated enforcement — owner to confirm the final wording with legal advice; this guide is not legal advice.

◆7. Rule quality limits (self-correcting)

  • Every rule tracks bans, appeals and reversals. If more than 2 % of a rule's bans are reversed in 30 days, the rule is automatically demoted one tier and the team is alerted.
  • New rules start in Watch for 14 days (shadow mode: they log what they would have done) before they can act.

◆8. Security engineering checklist (day one)

  • TLS everywhere (wss, HTTPS); no plaintext ports.
  • Input validation at every boundary; message sizes and rates capped per connection; connection caps per IP.
  • Secrets only in the server secret store; none in the repo, client builds or logs.
  • Least privilege: zone servers can't touch the account database directly; admin/GM tools need 2-step sign-in and every GM action is logged (GM room actions included).
  • Dependency audit in CI: cargo audit/cargo deny, pnpm audit, Unity package review (toolchain gate).
  • Signed builds and update manifests (Patching).
  • Client hardening (deterrent only, never trusted): IL2CPP builds, string/asset obfuscation where cheap, integrity hash reported at login.
  • DDoS: the website behind a CDN; game servers behind the hosting provider's protection (an owner decision with cost).
  • Account protection: Google/Apple sign-in, new-device notice, "sign out everywhere", trade lock for 24 h after a suspicious sign-in.
  • Report-a-player in game and on the site; reports are an input to rules, never an automatic ban by themselves.

◆9. Tests (gates)

  • Red team (M6): a hacked bot client sends forged packets, replays tokens, speed-hacks and races item transactions — each must produce the expected security event and ban; nothing duplicates.
  • False positives (M6, repeated every milestone): 1,000 legitimate bots plus Auto-Hunt/Auto-Quest/offline actors for 60 min must produce zero bans and zero restrictions.
  • Appeal flow end-to-end on the site: ban → Contact us → review → reversal restores receipts.

Source: zoen/docs/tech/SECURITY_ANTICHEAT.md · 1,003 words · edit the Markdown, not this page.