<!--#include virtual="/server/header.html" -->
<!-- Parent-Version: 1.79 1.86 -->
<!-- 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
                  Please do not edit <ul class="blurbs">!
    Instead, edit /proprietary/workshop/mal.rec, then regenerate pages.
           See explanations in /proprietary/workshop/README.md.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
-->
<title>Malware in Games
- GNU Project - Free Software Foundation</title>
 <!--#include virtual="/proprietary/po/malware-games.translist" -->
<!--#include virtual="/server/banner.html" -->
<h2>Malware in Games</h2>

<p><a href="/proprietary/proprietary.html">Other examples of proprietary
malware</a></p>

<div class="highlight-para"> class="comment">
<p>
<em>Malware</em> means software designed to function in ways that
mistreat or harm the user.  (This does not include accidental errors.)
</p>

<p>
Malware and nonfree software are two different issues.  The difference
between <a href="/philosophy/free-sw.html">free software</a> and
nonfree software is in <a
href="/philosophy/free-software-even-more-important.html">
whether the users have control of the program or vice versa</a>.  It's
not directly a question of what the program <em>does</em> when it
runs.  However, in practice nonfree software is often malware, because
the developer's awareness that the users would be powerless users would be powerless to fix any
malicious functionalities tempts the developer to impose some.
</p>

<p>Some examples of malware in games are listed below.</p>

<div class="important">
<p>If you know of an example that ought to be in this page but isn't
here, please write
to <a href="mailto:webmasters@gnu.org"><webmasters@gnu.org></a>
to inform us. Please include the URL of a trustworthy reference or two
to serve as specific substantiation.</p>
</div>
</div>
<div class="column-limit" id="malware-games"></div>

<ul class="blurbs">
  <li id="M209900000">
    <p id="addictiveness">Many games are designed to
    keep gamers compulsively playing—and renewing
    their subscription. To achieve this result, developers use <a
    href="http://www.cracked.com/article_18461_5-creepy-ways-video-games-are-trying-to-get-you-addicted.html">
    techniques that derive from behavioral and brain research</a>:</p>

    <dl class="compact"><dt>The Skinner Box</dt>
      <dd>An environment in which the user is trained
      to “push the lever“, i.e. do a certain action over and
      over again in order to get a reward.</dd>

      <dt>Virtual food pellets</dt>
      <dd>Items that have nothing to do with the game itself, but are
      valuable to gamers because of the work required to obtain them
      (e.g., EverQuest); some people will end up collecting them for the
      sake of collecting.</dd>

      <dt>Random rewards</dt>
      <dd>They turn the game into the equivalent of a slot machine (e.g.,
      World of Warcraft, ZT Online).</dd>

      <dt>Elaborate cycles</dt>
      <dd>Gamers' behavior can be “shaped” by making cycles
      (progress from one level to the next) slower and slower, designing
      complex tasks that are difficult to get out of (e.g. World of
      Warcraft), or conversely dividing them up in small chunks to avoid
      frustration (e.g., New Super Mario Bros.Wii).</dd>

      <dt>Decay of game assets</dt>
      <dd>This makes it necessary for a gamer to keep playing, without
      vacations, simply to avoid losing what they have earned so far
      (e.g., Farmville, Ultima Online, Animal Crossing).</dd>
    </dl>

    <p>Games such as World of Warcraft, which are considered very addictive,
    use several of these techniques.</p>

    <p>However, the addictiveness of a game is only one of the determinants
    of addiction. Equally important are the psychological make-up and life
    circumstances of the gamer. Gaming addiction, like other addictions,
    is a form of mental escape from an unrewarding life. The sad truth
    is that, in the long run, it leads to an even worse life.</p>

    <p><em>Note:</em>  We are not gamers. If you think we
    have misunderstood some point, or have suggestions for making
    this text clearer or more correct, please send them to <<a
    href="mailto:webmasters@gnu.org">webmasters@gnu.org</a>>.</p>
  </li>

  <li id="M209800000">
    <p>The developers of gratis mobile games apply <a
    href="/proprietary/proprietary-addictions.html#addictiveness">
    behavioral manipulation techniques</a> to <a
    href="https://www.psychguides.com/interact/the-psychology-of-freemium/">
    turn their products into slot machines</a>. This is clearly described
    in an infographic.</p>

    <p>The revenue generated by these games is directly related to the
    number of strongly addicted gamers (called “whales”) and
    to the amount of money they are willing to spend. Thus developers
    carefully study the behavior of millions of users to increase the
    addictiveness of their games.</p>

    <p>Unfortunately, the article uses “free” to mean
    “zero price.”  We recommend saying “gratis”
    instead.</p>
  </li>

  <li id="M201907090">
    <p>Resourceful children figured out how to <a
    href="https://www.bbc.co.uk/news/technology-48908766"> empty their
    parents' bank account</a> buying packs of special players for an
    Electronic Arts soccer game.</p>

    <p>The random element of these packs (also called “loot
    boxes”) makes the game <a
    href="/proprietary/proprietary-addictions#addictiveness">
    strongly addictive</a>, but the fact that players
    are pressured to spend more in order to get ahead of their
    competitors further qualifies it as <em>predatory</em>.
    Note that Belgium <a
    href="https://www.rockpapershotgun.com/2019/01/29/fifa-ultimate-team-packs-blocked-in-belgium/">
    made these loot boxes illegal</a> in 2018.</p>

    <p>The only good reason to have a copy of such a proprietary
    game is to study it for free software development.</p>
  </li>

  <li id="M201809210">
    <p>Cash of Clans is a good example of a gratis mobile game that its
    developers <a href="https://gamerant.com/clash-of-clans-addiction/">
    made very addictive</a> for a large proportion of its users—and
    turned into a cash machine for themselves—by using <a
    href="/proprietary/proprietary-addictions.html#addictiveness">
    psychological manipulation techniques</a>.</p>

    <p>The article uses “free” to mean “zero
    price,” which is a usage we should avoid. We recommend saying
    “gratis” instead.</p>
  </li>

  <li id="M201807310">
    <p>A nonfree video game, available through the nonfree Steam client, <a
    href="https://www.extremetech.com/gaming/274552-great-now-games-are-hijacking-systems-with-">
    included a “miner”</a>, i.e. an executable that hijacks
    the CPU in users' computers to mine a cryptocurrency.</p>
  </li>

  <li id="M201806250">
    <p>The game Metal Gear Rising for
    MacOS was tethered to a server.  The company <a
    href="http://www.gamerevolution.com/news/400087-metal-gear-rising-mac-unplayable-drm">
    shut down the server, and all copies stopped working</a>.</p>
  </li>

  <li id="M201806240">
    <p>Red Shell is a spyware that
    is found in many proprietary games. It <a
    href="https://nebulous.cloud/threads/red-shell-illegal-spyware-for-steam-games.31924/">
    tracks data on users' computers and sends it to third parties</a>.</p>
  </li>

  <li id="M201804144">
    <p>ArenaNet surreptitiously installed a spyware
    program along with an update to the massive
    multiplayer game Guild Wars 2.  The spyware allowed ArenaNet <a
    href="https://techraptor.net/content/arenanet-used-spyware-anti-cheat-for-guild-wars-2-banwave">
    to snoop on all open processes running on its user's computer</a>.</p>
  </li>

  <li id="M201712060">
    <p>Learn how <a
    href="https://web.archive.org/web/20170319013045/https://www.huffingtonpost.com/joseph-farrell/the-fascinating-psycholog_b_6076502.html">
    gratis-to-play-and-not-win-much games manipulate their useds
    psychologically</a>.</p>

    <p>These manipulative behaviors are malicious functionalities, and they
    are possible because the game is proprietary. If it were free, people
    could publish a non-manipulative version and play that instead.</p>
  </li>

  <li id="M201711070">
    <p>The driver for a certain gaming keyboard <a
    href="https://thehackernews.com/2017/11/mantistek-keyboard-keylogger.html">sends
    information to China</a>.</p>
  </li>

  <li id="M201612290">
    <p>In the game Fruit Pop, the player buys boosts with coins to get
    a high score. The player gets coins at the end of each game, and can
    buy more coins with real money.</p>

    <p>Getting a higher score once leads the player to fix any
malicious functionalities tempts desire higher
    score again later. But the higher score resulting from the developer boost <a
    href="https://qz.com/873348/50000-coins-for-1-99-how-mobile-game-in-app-purchases-are-warping-kids-understanding-of-basic-economic-ideas/">does
    not give the player more coins, and does not help the player get
    a higher score in subsequent games</a>. To get that, the player
    will need a boost frequently, and usually has to impose some.
</p>
</div>

<p>Here pay real money
    for that. Since boosts are examples of malware in games.</p>

<ul>
<li><p>nVidia's exciting and entertaining, the player is
    subtly pushed to purchase more coins with real money to get boosts,
    and it can develop into a costly habit.</p>
  </li>

  <li id="M201611070">
    <p>nVidia's proprietary GeForce Experience <a
    href="http://www.gamersnexus.net/industry/2672-geforce-experience-data-transfer-analysis">makes
    users identify themselves and then sends personal data about them to
    nVidia servers</a>.</p>
  </li>

<li><p>Modern

  <li id="M201609240">
    <p>A Capcom's Street Fighter V update <a
    href="https://www.theregister.co.uk/2016/09/23/capcom_street_fighter_v/">
    installed a driver that could be used as a back door by
    any application installed on a Windows computer</a>, but was <a
    href="https://www.rockpapershotgun.com/2016/09/24/street-fighter-v-removes-new-anti-crack">
    immediately rolled back</a> in response to public outcry.</p>
  </li>

  <li id="M201605200">
    <p>Oculus Rift games now have <a
    href="https://motherboard.vice.com/en_us/article/vv77ea/new-oculus-drm-cross-platform">
    DRM meant to prevent running them on other systems</a>.</p>
  </li>

  <li id="M201512290">
    <p>Many <a
    href="http://www.thestar.com/news/canada/2015/12/29/how-much-data-are-video-games-collecting-about-you.html/">
    video game consoles snoop on their users and report to the
    internet</a>—even what their users weigh.</p>

    <p>A game console is a computer, and you can't trust a computer with
    a nonfree operating system.</p>
  </li>

  <li id="M201509160">
    <p>Modern gratis game cr…apps <a
    href="http://toucharcade.com/2015/09/16/we-own-you-confessions-of-a-free-to-play-producer/">
    collect a wide range of data about their users and their users'
    friends and associates</a>.</p>

    <p>Even nastier, they do it through ad networks that merge the data
    collected by various cr…apps and sites made by different
    companies.</p>

    <p>They use this data to manipulate people to buy things, and hunt for
    “whales” who can be led to spend a lot of money. They also
    use a back door to manipulate the game play for specific players.</p>

    <p>While the article describes gratis games, games that cost money
    can use the same tactics.</p>
  </li>

<li>
<p>Oculus Rift games now have

  <li id="M201507290">
    <p>Game Of War: Fire Age is an iPhone game with <a href="http://motherboard.vice.com/read/new-oculus-drm-cross-platform">
DRM meant to prevent running them
    href="http://www.cracked.com/personal-experiences-1762-5-reasons-i-lost-249000-iphone-game.html">
    addictive features</a> which are based on other systems</a>.</p>
</li>

<li>
<p>Some proprietary <a
href="http://www.theguardian.com/technology/2014/jan/19/apple-talking-cats-in-app-purchases">
games lure children
    href="/proprietary/proprietary-addictions.html#addictiveness">behavioral
    manipulation techniques</a>, compounded with group emulation. After a
    fairly easy start, the game slows down and becomes more difficult,
    so gamers are led to spend more and more money in order to keep up
    with their parents' money</a>.
</p> group. And if they stop playing for a while, the equipment
    they invested in gets destroyed by the “enemy” unless
    they buy an expensive “shield” to protect it. This game
    is also deceptive, as it uses confusing menus and complex stats to
    obfuscate true monetary costs.</p>
  </li>

  <li id="M201410130">
    <p><a
    href="https://www.eff.org/deeplinks/2014/10/nintendo-updates-take-wii-u-hostage-until-you-agree-new-legal-terms">Nintendo
    remotely sabotaged all Wiis, making them refuse to work unless the
    user agrees to a new EULA</a>.</p>

    <p>We can be quite sure this EULA is unjust because injustice is the
    only motive for imposing an EULA.</p>
  </li>

<li><p>Angry

  <li id="M201401280">
    <p>Angry Birds <a
    href="http://www.nytimes.com/2014/01/28/world/spy-agencies-scour-phone-apps-for-personal-data.html">
    spies for companies, and the NSA takes advantage
    to spy through it too</a>.  Here's information on <a
    href="http://confabulator.blogspot.com/2012/11/analysis-of-what-information-angry.html">
    more spyware apps</a>.</p>

    <p><a
    href="http://www.propublica.org/article/spy-agencies-probe-angry-birds-and-other-apps-for-personal-data">
    More about NSA app spying</a>.</p>
  </li>

  <li id="M201401190">
    <p>Some proprietary <a
    href="http://www.theguardian.com/technology/2014/jan/19/apple-talking-cats-in-app-purchases">
    games lure children to spend their parents' money</a>.</p>
  </li>

  <li id="M201105070">
    <p><a href="https://www.defectivebydesign.org/sony">The Playstation
    3 is a tyrant</a>.</p>
  </li>

  <li id="M201003300">
    <p>Sony <a
    href="https://www.eff.org/deeplinks/2010/03/sony-steals-feature-from-your-playstation-3">sabotaged
    the Playstation 3</a> with a firmware downgrade that removed the
    feature that allowed users to run GNU/Linux on it.</p>

    <p>Sony subsequently sent police after Geohot, after he cracked the
    code that blocked users from changing the firmware, and we responded by
    calling for a <a href="http://boycottsony.org">boycott of Sony</a>.</p>

    <p>In a court settlement Sony is <a
    href="http://arstechnica.com/tech-policy/2016/06/if-you-used-to-run-linux-on-your-ps3-you-could-get-55-from-sony/">
    now paying for the sabotage</a>.</p>
  </li>

  <li id="M200510200">
    <p>Blizzard Warden is a hidden
    “cheating-prevention” program that <a
    href="https://www.eff.org/deeplinks/2005/10/new-gaming-feature-spyware">
    spies on every process running on a gamer's computer and sniffs a
    good deal of personal data</a>, including lots of activities which
    have nothing to do with cheating.</p>
  </li>
</ul>


</div><!-- for id="content", starts in the include above -->
<!--#include virtual="/server/footer.html" -->
<div id="footer">
<div class="unprintable">

<p>Please send general FSF & GNU inquiries to
<a href="mailto:gnu@gnu.org"><gnu@gnu.org></a>.
There are also <a href="/contact/">other ways to contact</a>
the FSF.  Broken links and other corrections or suggestions can be sent
to <a href="mailto:webmasters@gnu.org"><webmasters@gnu.org></a>.</p>

<p><!-- TRANSLATORS: Ignore the original text in this paragraph,
        replace it with the translation of these two:

        We work hard and do our best to provide accurate, good quality
        translations.  However, we are not exempt from imperfection.
        Please send your comments and general suggestions in this regard
        to <a href="mailto:web-translators@gnu.org">
        <web-translators@gnu.org></a>.</p>

        <p>For information on coordinating and submitting translations of
        our web pages, see <a
        href="/server/standards/README.translations.html">Translations
        README</a>. -->
Please see the <a
href="/server/standards/README.translations.html">Translations
README</a> for information on coordinating and submitting translations
of this article.</p>
</div>

<!-- Regarding copyright, in general, standalone pages (as opposed to
     files generated as part of manuals) on the GNU web server should
     be under CC BY-ND 4.0.  Please do NOT change or remove this
     without talking with the webmasters or licensing team first.
     Please make sure the copyright date is consistent with the
     document.  For web pages, it is ok to list just the latest year the
     document was modified, or published.

     If you wish to list earlier years, that is ok too.
     Either "2001, 2002, 2003" or "2001-2003" are ok for specifying
     years, as long as each year in the range is in fact a copyrightable
     year, i.e., a year in which the document was published (including
     being publicly visible on the web or in a revision control system).

     There is more detail about copyright years in the GNU Maintainers
     Information document, www.gnu.org/prep/maintain. -->

<p>Copyright © 2016 2016, 2017, 2018, 2019 Free Software Foundation, Inc.</p>

<p>This page is licensed under a <a rel="license"
href="http://creativecommons.org/licenses/by-nd/4.0/">Creative
href="http://creativecommons.org/licenses/by/4.0/">Creative
Commons Attribution-NoDerivatives Attribution 4.0 International License</a>.</p>

<!--#include virtual="/server/bottom-notes.html" -->

<p class="unprintable">Updated:
<!-- timestamp start -->
$Date: 2019/07/17 10:01:40 $
<!-- timestamp end -->
</p>
</div>
</div>
</div><!-- for class="inner", starts in the banner include -->
</body>
</html>