4 ms·
Kernel and hardware lockdown could be an extreme but effective solution against cheaters in online gaming. Too controversial to being put in use though.
by CodeArtisan 9y ago
Kernel and hardware lockdown could be an extreme but effective solution against cheaters in online gaming. Too controversial to being put in use though.
- mjg59 9y agoThat would still depend on a remote attestation solution that provided complete understanding of the state of the system during runtime, which isn't really close to possible with existing technology.
- dcow 9y agoWell imagine Blizzard and Apple made a deal where they worked together so that Blizzard games would only connect to verified servers if the hardware platform can cryptographically attest that the currently running kernel has been signed by Apple (doing so would prove it hasent been modified). Blizzard gets to distribute encrypted binaries and assets to users that only their registered Apple hardware running secure booted software can decrypt. Now replace Blizzard with any iOS application and you have the iOS AppStore ecosystem. We're already there. And I'm also pretty sure Blizzard and Apple have some dark back room deal like this, although it's more about Apple allowing Blizzards shit to do whatever it wants on its platform and less about methods of attestation considering everything is already in place for that.
- mjg59 9y agoWell, right now they couldn't do that because the Apple hardware platform doesn't allow it, and because the PC platform doesn't either any attempt on Apple's behalf to do so would result in gamers abandoning Apple?
- dcow 9y agoWhat do you mean? When you execute code on iOS you are executing signed binaries that the kernel verifies at install time and then user specific encrypted pages that the kernel decrypts/verifies as they're mapped into memory at execution time. I feel like we are not on the same (metaphoric) page. What I'm saying is this already exists today. iPhone hardware can attest to the integrity of the running system because Apple practices secure boot and maintains a PKI (supported by the kernel and TPM) responsible for verifying the integrity of software running on its system. Apple can say to a Blizzard "game" with certainty (barring security vulns), "there is no unauthorized software running on this system". And as far as Apple is concerned wrt their platform, Blizzard is just another app developer in their ecosystem. They don't have to pay a special "attestation premium".
- mjg59 9y agoAnd so can Nintendo on a Switch, but Apple can't do that on a Mac. This is clearly a theoretically possible scenario, the question is whether it's practical on something that's sold as a general purpose computing platform (which iOS devices aren't)
- dcow 9y agoSorry I'm not trying to split hairs. I don't see why it wouldn't be practical on a macOS device (agreed that on a Mac today this is not possible based on the state of publicly available macOS software). Apple has been slowly moving that direction and IMO the only reason they haven't dialed it up to 11 is because they don't want to break everything including users' workflows. But they could release a state of the art macOS laptop ~tomorrow that squeaks like iOS from a security angle. Anyway you're right that's besides the point now. My original point (rephrased to Linux) was that a desktop leveraging secure boot plus the recent work to harden the boundary between kernel and root plus something like (as you pointed out in the other thread) IMA could, I think, meet the original commenter's requirements.
- viraptor 9y ago> Apple can say to a Blizzard "game" with certainty (...), "there is no unauthorized software running on this system". What does that assertion even mean unless you completely lock down app signing keys though? Sure - this system doesn't run any unauthorised software, only "foobar test" signed by a valid developer key; everything is fine. It works for consoles, because you won't have the trusted signing keys.
- CodeArtisan 9y agoThe coupling of a cryptoprocessor[1] to avoid network packets and circuitry tampering with a locked kernel could stop people to use cheats. The CPU would only execute a signed kernel[2] while the kernel would only load signed modules. Today, each gaming studios/publishers are working on their own anticheat solution in their corner. Here, the anticheat would be the platform itself, you would only have to focus on keeping the kernel secure to turn all games cheats free (in theory). video game consoles are going this route with varying degrees of success[3] [1] https://en.wikipedia.org/wiki/Secure_cryptoprocessor https://en.wikipedia.org/wiki/Secure_cryptoprocessor [2] https://en.wikipedia.org/wiki/Code_signing https://en.wikipedia.org/wiki/Code_signing [3] https://en.wikipedia.org/wiki/PlayStation_Portable_homebrew https://en.wikipedia.org/wiki/PlayStation_Portable_homebrew https://en.wikipedia.org/wiki/PlayStation_3_homebrew https://en.wikipedia.org/wiki/PlayStation_3_homebrew https://fail0verflow.com/blog/2014/console-hacking-2013-omake/ https://fail0verflow.com/blog/2014/console-hacking-2013-omak...
- forgottenpass 9y agoWe have that. They're called consoles.