How secure is the default SaveGame feature?

I was looking at the SaveGame feature of UE4 recently, and thought it was really cool and useful, but how safe is it?

What kind of file does it save, and how easy is it for people to tinker with that file in order to cheat?

Are there any special considerations to make my save files “hack-proof”?

It doesnt encrypt a thing, and, in fact, it even writes the actual name of the properties in ascii if used with blueprint variables. Mine is a very simple one with 2 variables, and its something like header, then UE4, then some data, then DWScoreSave_c (name of my class) then BestScore(name of my property) some data, then FloatProperty, then some more data. Its extremelly easy to modify and cause havoc.
I guess you could try modifying the serialization functions so its encrypted, or, easier, add a hash. For example, in my case i have 2 scores, so i could write a 3rd variable that is a hash from those 2, then, when i load, i check that is valid, and if it isnt, i know its been tampered with, but its still a lost cause, if people want, they will probably crack it anyway.

Yeah, I wouldn’t worry about spending a ton of time implementing some wild encryption component. For some people part of the fun is “cheating” / bypassing rules. Now that usually goes out of the window when we involve other players. At that point you’d have a server at your will.

1 Like

We used the SaveGame system for a while, but in the end we just dropped it and went with a custom system. The default saving API has wildly unpredictable behavior when your code evolves, basically don’t hope to load an existing save after changing a field from “int” to “float” - or from “unsigned int” to “int”. Or removing a field. We switched to a JSON save system mostly to be able to load old game saves.

Encrypting your save games is wasted effort for single player games.

Those who want to cheat will cheat, remember your game must decrypt whatever format you put your saved game in, and if your game can do it a player can do it with some grim determination and a debugger. Spend your time on good gameplay instead, and maybe bundle some modding tools, do the opposite and encourage people to mess with the game.

Multiplayer is a whole different kettle of fish, best handled by making the server side completely authoritative to prevent cheating.

Have fun!

3 Likes

yeah you read it right, vanilla .sav is basically plain serialization with property names in ascii, anyone with notepad can edit scores. hash helps detect tampering (store a hash var and check on load) but wont stop editing. for real protection you need to encrypt bytes before writing the file - FAES path in c++ or a wrapper. advanced save system from fab Save System / Cloud Save / Encryption / Slot management | Fab has AES encryption with password-based key gen built in, so you just call SaveGameEncrypted/LoadGameDecrypted and the .sav on disk isnt plain text anymore

The .sav file format is, I believe, exactly the same as the .uasset file format, or at least very similar to it. It’s not exactly easy to edit externally; you’d need a hex editor. However, if you do have a hex editor, it’s probably not that difficult to mess with.

Sure. Don’t. It’s not worth your time, because every consideration you can take can be bypassed by a determined player. I can say that with certainty because any consideration that couldn’t be bypassed by a determined player would be unreadable by the game itself too, rendering it useless.

I don’t claim to fully understand the system, but I’m pretty sure there’s room in the default save system to handle this sort of backwards compatibility. You’d have to take extra measures though, and you might need to customize the save header (which would mean that, instead of using the functions in GameplayStatics, you’d copy them into your own code, edit them, and use those instead… either that, or use a source build and directly edit GameplayStatics).

That’s very much an exaggeration. The property names may be in plain text (though I don’t recall if it’s specifically ASCII – Unreal also uses UTF-16 in places) but the numerical values certainly aren’t. As I said a moment ago, you’d need a proper hex editor to do it right. Maybe you can technically pull it off with just Notepad, sometimes, but I wouldn’t trust Notepad not to silently corrupt the file.