15 ms·
Anti-cheat kernel driver
- JohnFen 7y agoI understand why anticheat software exists, and why it's getting increasingly intrusive (and therefore risky). I'm not arguing that there's anything wrong with it. That said, the existence of cheaters is one of the big reasons why I don't play such games -- and that games include anticheating software is another one of the big reasons, equal to the existence of cheating in terms of how objectionable I find it. From my point of view, this situation is nothing but a massive train wreck.
- some-guy 7y agoThis is why I appreciate still being close high school LAN party friends close online--I can start a group chat and get a game going between each other, and maybe they can invite a friend of theirs to get the number of players up for a game. If you can manage to maintain these relationships then online gaming can be very rewarding without having to worry about the trainwreck you described. This doesn't work with all types of games obviously, and perhaps all online games from here on out will have kernel-level protection. In the meantime, I think we will keep running UT2004 in compatibility mode (or in my case, Wine).
- stealthascope 7y agoDid they ever release a version of 2k4 for linux? I can play the UT2003 native version for linux just fine (doesn't seem to play nice with amdgpu, but the intel driver seems to be fine).
- some-guy 7y agoI don’t think they ever did. I run mine in Steam using Proton without any configuration minus a widescreen fix, which has actually been a lot easier than trying to get it to work in Windows 10 (I use amdgpu)
- int_19h 7y agoIt came with the Linux installer on the DVD, same as UT2003.
- branon 7y agoUT2004 has a Linux port, I believe developed by Icculus[0] but it's pretty long in the tooth. Requires libc5, an old version of SDL, and OSS for sound. Regardless, it'll still run on modern systems if you acquire old libc binaries[1] (and preload them), use SDL 1.2 (possibly a patched version[2] which enables Alt+Tab) and start the game using aoss[3] for sound. [0] https://icculus.org https://icculus.org [1] https://www.unix-ag.uni-kl.de/~deusser/UT2004/ https://www.unix-ag.uni-kl.de/~deusser/UT2004/ [2] https://github.com/infertux/SDL-1.2.7 https://github.com/infertux/SDL-1.2.7 [3] https://alsa.opensrc.org/Aoss https://alsa.opensrc.org/Aoss
- matheusmoreira 7y agoThe fact is online multiplayer games are fundamentally broken. It depends on trust and that's rare because almost no one knows each other. Everyone's a stranger. It's just random people playing together. People find ways to cheat even on trusted platforms like game consoles. People should be playing online with others they personally know and trust.
- blotter_paper 7y agoThat's pretty much true for real-time games. There are turn-based games that can be played on a company-provided server, and some extreme cases where games are actually decentralised (like blockchain chess). The open source RTS 0ad used to have every client compute every game state, but I believe that's no longer the case. Without smart contracts you fundamentally can still have decentralised computation of game state, and even preserve some asymmetrical knowledge by having players encrypt orders and share keys after all players have submitted orders. A decentralised game of Diplomacy could be implemented this way. Have each player submit a seed and use the combined seed as the basis for a pseudorandom number, and you could implement something like Civilization in a trustworthy manner without a central server of any sort.
- comex 7y agoFundamentally broken in theory. In practice: - The percentage of people who want to cheat is not that high. - Any cheat that spreads widely enough can be obtained by the developers and detected. Cheat developers can and do sell exclusive cheats to smaller groups of people, but fewer people using the cheat also means less disruption. - With tactics like delayed ban waves, game developers can make cheating risky enough to create an effective deterrence, even if they don't actually catch all cheats. - If all else fails, game developers can have players manually review other players' replays for cheating, like with Overwatch for CS:GO (not to be confused with Overwatch the game). So obvious cheating will be caught, and if people make their cheating non-obvious, well, that also makes it less likely to annoy other players. These measures can't stop all cheating, but they don't have to; they just have to deter it enough that it doesn't unduly hamper most players' experiences. In practice, it seems like most games are able to accomplish this.
- crazypython 7y agoTitle should be changed to "League of Legends to use kernel driver to enforce anti-cheat." I thought the article had something to do with the device null.
- chungy 7y agoYeah, same. In fact the article seems to be talking specifically about a Windows-only game and "/dev/null" in the title doesn't appear to have any relation to the text.
- MuffinFlavored 7y agoDoes this mean the app will need to run as root while the user is playing?
- outworlder 7y agoNo but the cheat software will run in the kernel. Which is > than root. In all likelihood – unless these guys are uncharacteristically careful – it will stay there even when you are not playing and become an attack vector.
- DoofusOfDeath 7y ago> In all likelihood – unless these guys are uncharacteristically careful – it will stay there even when you are not playing and become an attack vector. Might it be an attack vector even while the game is playing?
- dang 7y agoOk, we've nullified the /dev/null bit in the title above.
- mkj 7y agoI guess next step is for cheat software to run in a hypervisor. Now what're you gonna do!
- Moral_ 7y agoIt already exists. There is a aimbot for overwatch that runs in the hypervisor. If you're interested in the technical details you can read about it here: https://www.unknowncheats.me/forum/overwatch/361279-pareidoliatriggerbot-hypervisor-based-external-widowmaker-triggerbot.html https://www.unknowncheats.me/forum/overwatch/361279-pareidol...
- bawolff 7y agoEven further, appearently some people use hardware cards that use DMA to cheat. Which just seems incredible to me ( https://community.osr.com/discussion/291402/detecting-pcie-dma-based-cheating-hardware-in-online-games https://community.osr.com/discussion/291402/detecting-pcie-d... was the only reference i could find googling)
- akersten 7y agoYep. The article even smugly tries to boast about how they're adults and understand these things: > We haven’t needed both arms yet, primarily because we have the advantage of steady paychecks and the lack of strict bedtimes at our immediate disposal. But as much as we might like the idea of an ever-escalating appsec war with teenagers, And yet they fail to realize that they're playing in to the very cat-and-mouse game they deride. I can't wait until this escalates into "ok, well, now you need Intel TSX with Secure Enclave to verify that you're using the League video driver, and our proprietary USB dongle to play our game." Spoilers: the teenagers will always win; you can never trust a client no matter how many technical barriers you erect. Look to the entire legacy of DRM for how this strategy has been tried and has failed. Server-side statistics are the only hope against serial cheaters - they're barking up the wrong tree here.
- backupcavalry 7y agoI'm getting the same vibes from this article that I got from when LifeLock's CEO posted his SSN to taunt people / promote their own service... and frankly, I'm looking forward to the same schadenfreude. Never underestimate the resourcefulness of teenagers powered by spite and boredom.
- comex 7y agoSo what will they do for Wine users who don't have a Windows kernel to put a driver in?
- dyingkneepad 7y agoBan them, since they probably don't care about these 5 people. https://www.phoronix.com/scan.php?page=news_item&px=Blizzard-Banning-DXVK-Wine https://www.phoronix.com/scan.php?page=news_item&px=Blizzard... https://www.bleepingcomputer.com/news/gaming/linux-gamers-banned-in-battlefield-v-if-using-wine-and-dxvk/ https://www.bleepingcomputer.com/news/gaming/linux-gamers-ba...
- gpderetta 7y agoGames using invasive anticheats are already problematic under Wine unfortunately.
- DrStalker 7y agoPrevent you from playing the game.
- duskwuff 7y agoThere's a disappointing lack of any detail in this article.
- deleted 7y ago[deleted]
- madacol 7y ago404 response from link
- dyingkneepad 7y agoI wonder if we'll have a future where it's relatively easy to setup a camera to record your screen in another computer and a little custom mouse/keyboard pair to do actions based on the camera input.
- slezyr 7y agoMouse/Keyboard scripts already a thing. https://www.reddit.com/r/playrust/comments/c8h81n/please_facepunch_look_further_into_bloody_mouse/ https://www.reddit.com/r/playrust/comments/c8h81n/please_fac...
- e2le 7y agoIt's getting more and more risky to do gaming and everything else on the same computer. With how intrusive anti-cheat software is becoming, I feel less and less safe running these games.
- tomc1985 7y agoThese horrible analogies make me want to stab the writer with a pen How about he just writes technically and lets reddit comments translate? I'm so sick of writers' concerns for illiterate proles (along with, in this case, a seeming need to maintain the energy and punch of a memetastic for-12-year-olds YouTuber) ruining perfectly good technical writing
- jitl 7y agoI decided to downvote you for both a gate-keeping attitude (how dare a non-SWE else understand a bit of this stuff?) and for name calling, etc. Please consider learning some empathy.
- tomc1985 7y agoHow is desiring technical depth in a technical post "gatekeeping"? The ananlogies are horribly pained. It is an excess of empathy that ruins technical writing that could otherwise be quite rich with information. This attitude of writers having to do all the work needs to end; let the reader do some of it edit- its reductivist to think that only SWEs would understand this stuff. Have you forgotten about the legions of IT professionals and computer nerds that many SWEs came from? The rich history of hacking, much of which this post laments? Or is that kind of nerditry simply unfashionable nowadays?
- gclawes 7y agoUnfortunately, richness of information is probably something they want to avoid, lest they give cheat programmers any help. Not that I'm defending this crap, in my mind it's basically a rootkit that can snoop on anything in your system. Currently trying to figure out how to run games in a hypervisor.
- tomc1985 7y agoI get that, but it's not like a dedicated attacker can't find relevant information elsewhere. If your adversary controls the hardware, you've already lost Which explains why most of the moneymen in this industry push so hard to control hardware we've bought and paid for -- and in many cases built.
- dmitrygr 7y ago> This isn’t giving us any surveillance capability we didn’t already have. If we cared about grandma’s secret recipe for the perfect Christmas casserole, we’d find no issue in obtaining it strictly from user-mode and then selling it to The Food Network. The purpose of this upgrade is to monitor system state for integrity (so we can trust our data) and to make it harder for cheaters to tamper with our games (so you can’t blame aimbots for personal failure). these guys are pretty cavalier about shoving themselves into the kernel...
- Andhurati 7y agoI don't think any of the management of that company respects its fans.
- matheusmoreira 7y agoYes. It betrays a fundamental lack of respect for the user of the computer. They don't think of themselves as guests who have the privilege of being installed on people's computers. They actually think they own our machines. In their opinion, the mere existence of cheats is an affront to their divine authority over our domains. To them, we are merely an adversary who must be attacked and defeated preemptively before we do something we aren't supposed to do. Our power, freedom and autonomy must be taken away for the sake of their security and the integrity of their video game. This is unacceptable. Game companies don't get to decide what we can or can't do with our computers. Users are free and they own the machine. If they want to run client-side cheats, so be it. It's not like they're cracking and taking over the game company's servers. If they disrespect users by messing with their computers, they should not be surprised when users show them who's really in charge. We have quality and trust issues with drivers written by hardware manufacturers and we're finally getting them to contribute free or open source versions. The situation is finally improving. Proprietary cheating prevention software is the last thing we need running in kernel mode right now. Besides, the video games industry doesn't deserve our trust. For example, capcom.sys had privilege escalation as a feature: https://twitter.com/TheWack0lian/status/779397840762245124/ https://twitter.com/TheWack0lian/status/779397840762245124/ https://www.theregister.co.uk/2016/09/23/capcom_street_fighter_v/ https://www.theregister.co.uk/2016/09/23/capcom_street_fight... The privacy policies and terms of service associated with existing cheating prevention software don't exactly inspire confidence either. They collect and transmit a lot of personal information and will even take screen shots. It's unwise to run this software in anything but a completely isolated environment, to say nothing of kernel mode. Unfortunately, the ability to run the game in a completely isolated and controlled environment is exactly what enables us to hack it and cheat. They're going to have to live with that.
- Franciscouzo 7y agoPermalink: https://na.leagueoflegends.com/en-us/news/dev/dev-null-anti-cheat-kernel-driver/ https://na.leagueoflegends.com/en-us/news/dev/dev-null-anti-... If you don't live in north america, you'll get redirected to a local subdomain and get a 404
- dang 7y agoOK, we've changed to that from https://leagueoflegends.com/news/dev/dev-null-anti-cheat-kernel-driver/ https://leagueoflegends.com/news/dev/dev-null-anti-cheat-ker.... Thanks!
- shmerl 7y agoSounds like malware to me. Justifying this level of intrusion in your system with "preventing cheating" is unacceptable. If they want anti-cheats, let them develop AI that looks for non human and unnatural behavior on the server side. They should have no business snooping on the user, let alone having kernel access while doing it.
- aey 7y agoWhy not a trusted boot into a live CD that only runs the game?
- bob1029 7y agoAh yes. A kernel-level security feature provided by a software company wholly-owned by a Chinese conglomerate. I do not think I will continue running their software on my machines. Also, many other posters here have commented that kernel-level mitigations are futile in the face of hypervisor or hardware attacks. What's to stop me from altering system memory arbitrarily using a PCIe device I control externally? How would you even detect this from the perspective of the OS kernel? What if I compromise the private key in the game's network "security" layer and start reading & altering packets? Unless you 100% control the hardware (including mouse, keyboard and monitor, network, internet backbone, etc), you will always have this problem. The only way to have a cheat-proof gaming experience is to set up a LAN tournament and have all hardware provided to players (and even then, you should pour epoxy into the USB ports). At some point you are going to have to start looking in other directions for solutions to this problem. I believe other games have started using statistical and machine learning systems to detect cheaters rather than trying to match arbitrary binary hashes on my machine (which is what I presume Riot is going to do here). I feel statistical soft-ban systems are a much more reasonable way to handle this problem than the 100% confirmed binary signature permaban systems that seem an obsessive fantasy for some in the industry. Statistical methods directly deal with the impact of the problem whereas perfect match only gets at one of an infinite number of possible causes.
- deleted 7y ago[deleted]
- Fire-Dragon-DoL 7y agoProblem with those systems are the forums full of completely innocent people being banned
- floatingatoll 7y agoMany will read “completely innocent” as sarcasm. Do you intend it as such?
- Fire-Dragon-DoL 7y ago
- exikyut 7y agoTwo points: 1. I'm reminded of the exploitability of the rootkits folded into games like MapleStory a few years ago. Anybody with the rootkits installed had kernel-level authority available for the taking. Unfortunately don't remember exact details, but my vague memory suggests this was unfixed for years. 2. Link-chaining a bit I got to https://www.youtube.com/watch?v=rj6ukLPiY10 https://www.youtube.com/watch?v=rj6ukLPiY10, "The Norwegian CS Cheating Scandal". I didn't watch the video but I did read the top comment, which rightfully highlighted the utter inability for software to detect cheating via DMA (in the noted case over PCI-e, but potentially theoretically doable over ThunderBolt and FireWire too). Hopefully these rootkits are a bit better at doing one thing and doing it better than the iPhone SecureROM ;) Most seem to not realize that poking PCI-e isn't that expensive, but thankfully the specialist reverse engineering skills required are still well outside the 14-year-old script kiddie attention span.
- sudosysgen 7y agoYou know that most cheats aren't free to begin with? They can actually get quite expensive. No reason you couldn't buy the device. Cheat production is a very big and very profitable industry.
- lisk1 7y agoOn the brights side devs can massively profit from cheaters for example EFT , over the past 5-6 months they banned several thousands of accounts for cheating pretty sure at least 50% of the banned cheaters bought new accounts until the next time their account will get banned. So it can be profitable cat and mouse game if the devs play smart.
- HelloNurse 7y agoI planned to set aside one evening this week to update and play League of Legends, but I'll uninstall it instead.
- qalmakka 7y agoIsn't it ironic that this article starts with /dev/null, clearly a UNIX reference, while they actively ban people running their game under Wine?
- Spivak 7y agoI'm not exactly sure what studios to do in this situation -- WINE looks like cheating. It's not like there's some secret council that's like "mruhahaha Fortinte will be the destruction of gaming on Linux" -- it's that having stronger cheating protections is worth more than the losing the revenue of Linux gamers. The number of Linux gamers who can't/won't boot into Windows for a game is a tiny portion of an already tiny market.
- qalmakka 7y agoDon't call your mailing list "/dev/null" then, because it does not sound very appropriate given the recent policies Riot has chosen to apply? To me, it makes zero sense to showcase a Windows-specific product by writing a blog post starting "/dev/null", right after openly saying Linux/macOS/BSD users can go screw themselves.. It just feels like an improper appropriation of sort.
- ryuukk_ 7y agoaim your hate towards linux distro developpers who are unable to provide decent desktop / decent app ecosystem / decent drivers / decent graphics stack
- wrmsr 7y agoBack in the day someone figured out that punkbuster blindly scanned physmem for illegal string literals and banned on detecting them no matter what process they belonged to. They then posted one of those strings to #findscrim on gamesurge (or whichever it was at the time) and the channel quickly exploded with hundreds of people saying they just got pb banned for no reason. It was magical. Short of baking it directly into silicon clientside security is an oxymoron.