> Riot went as far as pushing a UEFI firmware update to Valorant players to close a hardware attack — the first time an anti-cheat has reached below the operating system to change your firmware
I don't believe Vanguard did this at all? It told users they need to update their firmware to play, it didn't touch the firmware itself.
> Cheats started in user space, so anti-cheat moved into the kernel to see them. Cheats followed into the kernel, and then below it into hypervisors
I think cheats moved into kernel space before anti-cheats did.
> I want to preface this with the fact that I’m not a gamer.
So you're prefacing it as someone who has never really dealt with the games you like to play getting totally infested with and nearly unplayable with so many cheaters in practically every lobby.
Its easy to think its something that's not needed if one never spends any time in the space.
Do they stop all cheats? No. Do they make the bar extensively higher to cheat? Absolutely. Even they point this out: "A DMA cheat is a separate FPGA card that sits in a PCIe slot and reads the game’s memory directly over the bus, while a second computer processes what it sees and feeds back aim and wallhacks..." Any random person can go run some executable they found on a forum, what percentage of the playerbase has these FPGA cards and a second computer to properly run these cheats? And even then, more modern systems can even detect these kinds of things.
Are there lots of problems with these anti-cheat platforms? Sure. Are they now often developed with ties to countries many wouldn't want have that deep of access to their computers? Sure. Is kernel-level anti-cheat overall as a concept overreach? Probably not for what a lot of players actively want. Players want systems to ensure everyone is playing on a somewhat equal playing field. Other than the games being rendered in the cloud I don't know any other real way to begin to enforce it.
> I would rather share a match with the occasional cheater
What if it wasn't "the occasional cheater" and instead was "nearly every match of every game you like to play"?
Since you're not a gamer sorry but your opinion does not means much, you don't seem to realize how cheating is a problem in online games, it's not just an inconvenience, it kills games.
The tl;dr from the post is that kernel anti-cheat presents both an attack vector for malware and a backdoor for firms. The former is already known to be exploited.
I don't know why comments here are so negative. PC gamers should be wary of installing this stuff, and PC users in general wary of attempts to lock down their computer. If game companies want a fully locked down PC, they already have one; it's called a console.
No but it has largely reduced it to where you can play competitively and not run into cheaters. Go play f2p csgo and enjoy a hacker in nearly every single game blatantly spinning in spawn head shotting everyone.
The overreach of kernel anticheats that this article complains about can be done just as easily from user mode anticheats. It's not whether an anticheat is kernel mode or not for whether it is overreaching or not.
>The hardware requirements lock out Linux and the Steam Deck
Because their security is out of date. Meanwhile macOS has modern security good enough to not even require Vanguard to need kernel mode to be effective.
Uninstalled riot years ago, not playing games that dont run on linux with proton, problem solved and you should do the same.
Avoiding to play games that take over my system on a low-level is a no go, I can live without LoL or BF6 and I live even better :)
ignoring this problems means you don't care about your identity, data, privacy and you prefer to keep ignoring this and play the games that hype abd you like, but inside you know that long term your are profiled and such profiling will be used against you!
I don't think kernel goes far enough. We are pushing down the wrong path. We don't need kernel level anti cheats.
I think there should be real world legal consequences for exploiting information systems like this. "Gaming" shouldn't magically exempt a business sector from reasonable protection against fraud and abuse. Just because it's easy to do or involves bits in a computer (that isn't physically on the game developer's premises) should not magically exempt bad actors from prosecution. Yes, it's your computer, those are technically your bits, but this is about how these things are used and the context within which they are.
We have the CFAA in the US, but you'd need a fairly loose interpretation to cover most forms of cheating today. I don't really see the distinction between client and server when the actions taken on the client side cause a dramatic loss in quality of service for other clients connected to that same server or p2p relay.
I play a lot. Competitive shooters mostly. Most of them are unplayable for one or two reasons. Cross play (controllers with aim assist) and cheaters. As a PC player I would like to see no aim assist and actual consequences for cheating. I’ll gladly verify my real world identity, if it meant cheaters where banned once and forever. I’ve heard this is how it works in Korea (claim not verified) and could see it work here too as most of Europe has access to very UX friendly state sponsored digital ID.
If there were actual stakes to cheating, it would be less prevalent. Now you can create another account and keep playing. Often for free!
On a side note. How come replay analysis doesn’t catch more cheaters?
> So I would rather share a match with the occasional cheater than run un-auditable ring-0 software on the same machine I use for anything private.
You’re not a gamer so you don’t have a word here. I was a competitive gamer and I would happily accept even the game where you need a government id to be allowed to play in ranked/matchmaking. I do dual boot for gaming/home stuff though.
> I was forced to convert the disk with mbr2gpt and spent about an hour manually rebuilding the boot drive to work under UEFI.
I'm surprised Windows 11 even booted on MBR, I was under the impression that after 7 all Windows installs had to be GPT/EFI, regardless of whether secure boot was on or not.
In my opinion, the debate about kernel anti-cheat on Windows is disingenuous fear-mongering. I'm confused why Hacker News of all places misrepresents the technical details.
You can already completely compromise the average user's privacy with an underprivileged process (nearly all of your personal information is accessible with zero privileges!), and you can already persist with administrator privileges (that is routinely given on Windows).
In regard to the "RCE attacker risk", attackers can RCE to escalate just as easily into vulnerable Windows services (there's too many to count). Kernel drivers aren't that special.
In regard to the "CrowdStrike risk", that's not privacy related and is extremely overblown.
What exactly does a kernel driver change regarding privacy? Nothing I can think of.
It's this simple: If games want your personal data, they don't need a kernel driver to get it.
> So I would rather share a match with the occasional cheater than run un-auditable ring-0 software on the same machine I use for anything private.
The article makes an argument that anti-cheat is not worth the trade-off, yet the author admits they are a non-gamer. Then they go on to present one example of anti-cheat that tells us all we need to know about actual gamers' preferences—FACEIT. For those who don't know, FACEIT is a third-party matchmaking service, primarily for CS2. People choose to go through the hoops of using third-party service that installs kernel-level anti-cheat on their computer because it helps to keep cheaters out of their games. This seems like pretty strong evidence that the author's argument is not a good representation of gamers' thoughts on this. I don't know what the actual solution is. I suspect if Valve made their own kernel-level anti-cheat people might trust it more, but it's still the same problem.
I suspect the only technical alternative would be the extreme of "this is not your system at all" mode, and necessarily involve dedicated hardware, where you can boot your computer as a "game console". I also suspect this would mean that mode would necessarily be the "primary" mode [1], PS2 style.
Faceit has cheaters too by all accounts and some of the cheats have advanced to the point that not even kernel access under secure boot helps as they don't even run on the same device.
Behavioral patterns are a much better target.
If your cheats make you play like a legit player, who cares? It's the same as in the gym. People are bothered by people who look like Ahnold, and still can't lift one plate. Not the fattie who takes t to look like a normal person.
I think that's the spirit of VAC.
The only issue is it can't —or won't— detect people helicopter–hopping no–scope sniping around the map or terrible players who shoot you in the face every time in 12ms.
Except cheating in games isn't the equivalent of steroids in the gym, since they let cheaters do things that literally no one can without them. And steroids at least have the argument behind them that you still have to put the work in (it's not "free" gains like cheats are, that guy that looks like Arnold is still putting hours into the gym every week to look like that, you can't just take steroids and look the same if you aren't willing to put in the effort)
A much better analogy would be showing up to a weightlifting competition with a construction crane and thinking competing with it against human lifters is fair.
The only acceptable and correct trade-off for anti-cheat is fully remote gaming + locked-down console, where the Game companies own the software and servers and hardware and just rent you a "play slice" via their locked-down console. I suspect even then, they will want to install tools to monitor you to satisfy their "analytics"
online real-money and crypto poker sites have a big cheating problem too - and face similar issues for detection.
Alarmingly the software for one popular operator has some very invasive features - verging on spyware - including harvesting screenshots of all screens (sent to some unknown biz in india, stored under "who-knows-what" security), hardware fingerprinting, and 'remote access' wired in for future releases.
Is there some reliable tool which can list all the kernel anti cheat that may be installed on my Windows system, and the games I need to uninstall to remove them? Or remove them directly? Thanks!
32 comments
[ 2.9 ms ] story [ 59.1 ms ] threadYeah except that’s not the options here. Even with ring-0 there are lots of cheaters. Without it the game would be completely infested with them.
I don't believe Vanguard did this at all? It told users they need to update their firmware to play, it didn't touch the firmware itself.
> Cheats started in user space, so anti-cheat moved into the kernel to see them. Cheats followed into the kernel, and then below it into hypervisors
I think cheats moved into kernel space before anti-cheats did.
So you're prefacing it as someone who has never really dealt with the games you like to play getting totally infested with and nearly unplayable with so many cheaters in practically every lobby.
Its easy to think its something that's not needed if one never spends any time in the space.
Do they stop all cheats? No. Do they make the bar extensively higher to cheat? Absolutely. Even they point this out: "A DMA cheat is a separate FPGA card that sits in a PCIe slot and reads the game’s memory directly over the bus, while a second computer processes what it sees and feeds back aim and wallhacks..." Any random person can go run some executable they found on a forum, what percentage of the playerbase has these FPGA cards and a second computer to properly run these cheats? And even then, more modern systems can even detect these kinds of things.
Are there lots of problems with these anti-cheat platforms? Sure. Are they now often developed with ties to countries many wouldn't want have that deep of access to their computers? Sure. Is kernel-level anti-cheat overall as a concept overreach? Probably not for what a lot of players actively want. Players want systems to ensure everyone is playing on a somewhat equal playing field. Other than the games being rendered in the cloud I don't know any other real way to begin to enforce it.
> I would rather share a match with the occasional cheater
What if it wasn't "the occasional cheater" and instead was "nearly every match of every game you like to play"?
cs2 is infested with hackers, arc raiders died because of hackers... many games I've played and loved are dead because of hackers.
I don't know why comments here are so negative. PC gamers should be wary of installing this stuff, and PC users in general wary of attempts to lock down their computer. If game companies want a fully locked down PC, they already have one; it's called a console.
No but it has largely reduced it to where you can play competitively and not run into cheaters. Go play f2p csgo and enjoy a hacker in nearly every single game blatantly spinning in spawn head shotting everyone.
>The hardware requirements lock out Linux and the Steam Deck
Because their security is out of date. Meanwhile macOS has modern security good enough to not even require Vanguard to need kernel mode to be effective.
Avoiding to play games that take over my system on a low-level is a no go, I can live without LoL or BF6 and I live even better :)
ignoring this problems means you don't care about your identity, data, privacy and you prefer to keep ignoring this and play the games that hype abd you like, but inside you know that long term your are profiled and such profiling will be used against you!
I think there should be real world legal consequences for exploiting information systems like this. "Gaming" shouldn't magically exempt a business sector from reasonable protection against fraud and abuse. Just because it's easy to do or involves bits in a computer (that isn't physically on the game developer's premises) should not magically exempt bad actors from prosecution. Yes, it's your computer, those are technically your bits, but this is about how these things are used and the context within which they are.
We have the CFAA in the US, but you'd need a fairly loose interpretation to cover most forms of cheating today. I don't really see the distinction between client and server when the actions taken on the client side cause a dramatic loss in quality of service for other clients connected to that same server or p2p relay.
South Korea has laws on the books as of 2016.
https://dotesports.com/overwatch/news/ow-hacker-sentenced-pr...
If there were actual stakes to cheating, it would be less prevalent. Now you can create another account and keep playing. Often for free!
On a side note. How come replay analysis doesn’t catch more cheaters?
You’re not a gamer so you don’t have a word here. I was a competitive gamer and I would happily accept even the game where you need a government id to be allowed to play in ranked/matchmaking. I do dual boot for gaming/home stuff though.
> Unfortunately the install was legacy MBR
> I was forced to convert the disk with mbr2gpt and spent about an hour manually rebuilding the boot drive to work under UEFI.
I'm surprised Windows 11 even booted on MBR, I was under the impression that after 7 all Windows installs had to be GPT/EFI, regardless of whether secure boot was on or not.
You can already completely compromise the average user's privacy with an underprivileged process (nearly all of your personal information is accessible with zero privileges!), and you can already persist with administrator privileges (that is routinely given on Windows).
In regard to the "RCE attacker risk", attackers can RCE to escalate just as easily into vulnerable Windows services (there's too many to count). Kernel drivers aren't that special.
In regard to the "CrowdStrike risk", that's not privacy related and is extremely overblown.
What exactly does a kernel driver change regarding privacy? Nothing I can think of.
It's this simple: If games want your personal data, they don't need a kernel driver to get it.
It just sits nagging in the back of your mind. So why take the risk.
The article makes an argument that anti-cheat is not worth the trade-off, yet the author admits they are a non-gamer. Then they go on to present one example of anti-cheat that tells us all we need to know about actual gamers' preferences—FACEIT. For those who don't know, FACEIT is a third-party matchmaking service, primarily for CS2. People choose to go through the hoops of using third-party service that installs kernel-level anti-cheat on their computer because it helps to keep cheaters out of their games. This seems like pretty strong evidence that the author's argument is not a good representation of gamers' thoughts on this. I don't know what the actual solution is. I suspect if Valve made their own kernel-level anti-cheat people might trust it more, but it's still the same problem.
[1] https://en.wikipedia.org/wiki/Linux_for_PlayStation_2
Behavioral patterns are a much better target.
If your cheats make you play like a legit player, who cares? It's the same as in the gym. People are bothered by people who look like Ahnold, and still can't lift one plate. Not the fattie who takes t to look like a normal person.
I think that's the spirit of VAC.
The only issue is it can't —or won't— detect people helicopter–hopping no–scope sniping around the map or terrible players who shoot you in the face every time in 12ms.
Many people
A much better analogy would be showing up to a weightlifting competition with a construction crane and thinking competing with it against human lifters is fair.
Alarmingly the software for one popular operator has some very invasive features - verging on spyware - including harvesting screenshots of all screens (sent to some unknown biz in india, stored under "who-knows-what" security), hardware fingerprinting, and 'remote access' wired in for future releases.
https://pokerindustrynews.com/features/coinpoker-anti-cheat-...
I didn't buy Civ VII, because I don't buy malware. As long as it's got Denuvo, it's not a game I'm buying or playing.