21 ms·
Now I'm biased because I'm an anti-cheat developer, but I really can't see how checking the integrity of your installed kernel device drivers is at all invasive
by invokestatic 6y ago
Now I'm biased because I'm an anti-cheat developer, but I really can't see how checking the integrity of your installed kernel device drivers is at all invasive.
- jasonjayr 6y agoIt's none of the game's business what other software my computer is running. These checks have in the past been notoriously buggy, and can interfere with other operations. This kind of crud is what remote attestation is for, and Microsoft should be responsible for developing it, not every different gaming company competing with each other for kernel access.
- invokestatic 6y agoFwiw, my solution does actually take advantage of remote attestation, and if that is validated, a large part of kernel integrity checks are skipped. The problem is that many “gaming” consumer motherboards don’t ship with TPMv2 or secure boot, and we still have to support those computers.
- devwastaken 6y agoHow does tpm or secureboot assist in anti cheat?
- invokestatic 6y agoWhen you can remotely prove that the entire boot chain has not been tampered with, it’s much harder to load cheat software in the kernel layer. Of course, still possible, just harder and easier to detect.
- deleted 6y ago[deleted]
- google234123 6y agoHow does this address the fact that windows has 100s of badly written drivers that allow r/w to kernel? This seems to only stop the most advance cheats that actually execute at or before boot.
- invokestatic 6y agoSecure boot addresses other specific security concerns that are unrelated to exploitable drivers. For instance, it eliminates a whole class of PatchGuard bypasses.
- kortilla 6y agoSorry to derail, but how often does anti-cheat development involve buying access to a cheat just for the purpose of reverse engineering it? Is that pretty much most of the time or is there enough evidence collected from logs to be able to infer what was happening?
- dylz 6y agoNot parent, but have seen this before, or some competitor/pissed off outed person/partner in crime/etc hands it to anticheat team. Private cheats usually require being vouched in, sometimes with ID scans, sometimes physically shipping you hardware.
- invokestatic 6y agoThis is largely dependent on the passive collection capabilities of a particular anti-cheat. Sometimes getting a copy is useful to just to make 100% sure the detection you wrote works as intended. Sometimes it's because the techniques used are novel. Most anti-cheat vendors do this.
- ajnin 6y agoI understand that, fundamentally, anti-cheat involves taking some form of control away from the player. But when the solution involves deeply embedded hardware modules that take that control away globally, introducing their own host of problems, I think that goes too far, and the cure might be worse than the disease. As a player, I wish there was a way to make sure that the anti-cheat only runs when the game runs, and only checks stuff related to the game and nothing else.
- Spivak 6y ago> It's none of the game's business what other software my computer is running. I get the sentiment here but we're specifically talking about a mechanism specifically designed to detect other software that is used for cheating. The alternative is a world where games will only run on machines with SecureBoot, a signed kernel with kernel security on, and only whitelisted signed modules. There isn't a good solution for how to run games where the clients have to be semi-trusted on a hardware and software stack controlled by the user. If you give me total control over the environment in which a program runs I can make it do and believe anything.
- eptcyka 6y agoMaybe the game servers could not send the whole game state to each client and validate input it receives from each client? Banning blatant aimbots is just a pure statistics thing. Also, you could just train ai to detect patterns of cheating via an adversarial model where you pit normal ai against ai that uses the cheats you currently detect via rootkits. Games should not be part of my ring 0.
- kortilla 6y ago> Banning blatant aimbots is just a pure statistics thing. So you have two choices here. You either ban the best players or the aim bots just behave with a success rate close to the best players.
- krageon 6y agoIf a player consistently has a sub 100ms response time, it is a bot. There are plenty such values to be found that have clear superhuman markers (100ms on average is already realistically too low, so I'm being mild), and you can use those to detect cheaters.
- eptcyka 6y agoIf you can't distinguish between cheaters and the best players statistically, can the regular players tell the difference? Does it matter at all then? And when I'm talking about statistics here, I'm not referring to the kill/death ratio, but rather all input data received from a cheater.
- m-p-3 6y agoI agree, but at some point you have to decide if the tradeoff between the freedom to run whatever you want is worth the invasiveness of having an anticheat software analysing your system in-depth for cheating softwares is worth it. In a way, it's true that it's none of their business which softwares you use, but it's also their business to make sure the multiplayer experience is fair for the entire userbase. I guess that's the beauty of games consoles, where the execution of softwares is tightly controlled to minimize piracy and cheaters.
- adambyrtek 6y agoMaybe that trade-off should be more flexible and dependent on the "league" a given player wants to play in. The criteria could be more strict for the "pros" where cheating can lead to significant gains, like professional athletes who have to pass regular anti-doping tests, but you wouldn't expect the same invasive checks from (for example) people participating in a charity run.
- tapoxi 6y agoHistorically this is what game developers did, and the servers without anti-cheat enabled were rife with cheating. When games switched from server browsers to matchmaking, they just defaulted to using the anti-cheat system.
- hombre_fatal 6y agoThe problem with your idea is that nobody wants to play with cheaters. Everything that makes the game fun is defeated by a single cheater. So people are just going to choose between playing with 0 cheaters or go play a different game.
- adambyrtek 6y agoGood point, I haven't played games much since the late 90s and I'm returning to gaming only now (partially thanks to Proton), so my experience with multi-player is based mostly on modem or LAN parties with friends, where the social aspect helped to prevent cheating. I guess it's very different now when you can play with random people on the other side of the world.
- google234123 6y agoIt's the game'd business what you are running if you are ruining the game for other players.
- pkaye 6y agoWhat if they gave you the ability to disable anti-cheat checks but put you up against others who do the same?
- rkangel 6y agoI play various games where they developers try hard to prevent cheaters and they still get through and ruin a small but significant percentage of the games. I can't imagine how crappy an experience it would be if there was no cheat protection at all.
- aaomidi 6y agoThat's one of the less invasive things, but I also don't see why a game needs to know what drivers I have. Hence I just stay away from AAA games with anti cheat at this point.
- Spivak 6y agoBecause the preferred deployment method of a lot of these cheats is via drivers so they look transparent to the game and are harder to detect from a userspace application.
- krageon 6y agoThe preferred deployment method of real cheats is outside of a virtualisation boundary. Driver-based is essentially entry level.
- realusername 6y agoBecause anti-cheat software is buggy, triggering a kernel crash which makes the whole machine unusable is a real possibility, additionally by running in kernel mode, the software bypasses all the OS protections, this can end up terribly if there's an exploit.
- google234123 6y agoMost drivers suffer from this. There's nothing special about anti cheat drivers. It's probably much better tested than the random driver that a hardware manufacture might provide to control some random fan LEDs.
- realusername 6y agoThe difference being that a graphic driver is essential to make the hardware work whereas anti-cheat software isn't.
- google234123 6y agoAnti cheat is essential to keep multiplayer games fun
- dghlsakjg 6y agoI use a generic xbox 360 wireless receiver for my PC. The device drivers are an unsigned version of microsoft's drivers. Should I really have to buy the identical dongle for double the price, so that developers can dig into the depths of my OS to confirm that I'm not using a clone receiver? I honestly see both sides of it, but at the end of the day, I am always hesitant to trust software with black-box functionality deep access to my computer. When I see a sudo command We are already at the point of computers being able to balance a ping pong ball on a flat surface using just cameras. I can't imagine we are far from cheaters using entirely decoupled computers to physically control devices.
- arilotter 6y agoWe're already there! See hardware like the EvilController or the ConsoleTuner Titan
- ivann 6y agoIt doesn't seem those take the game output into account, maybe I missed something but they just seems to be controllers with scripting capabilities. The idea of a decoupled cheat would be to acquire the game state from outside the computer running it, either by filming the screen or taping into the video output or the network input, then analyze it and run some aimbot (or any other kind of cheat) on it and finally send the cheat commands as if it came from a legitimate controller, through usb.
- karatchov 6y agoI have a similar generic receiver, with some "not genuine" hardware ID. I just force select & install the signed microsoft drivers. The trick works in all versions of windows that I tried.
- dylz 6y agoI'm going to point out that if you want to go down this route, it is insufficient to just check that the base drivers are untampered with and signed by Microsoft or whatever vendor still. You now maintain a list of potentially vulnerable drivers that can be used as a jumping off point (such as virtually every motherboard RGB or fan control system), and ban users that have these or hard-disable them at boot. There are some games that have caused machines to overheat by disabling cheat-jumpoffable fan controllers. On top of that, you effectively have to maintain a whitelist of acceptable drivers, because cheat vendors are registering limited companies by the thousands (only $20 in the UK), getting an EV/codesigning cert, and signing their own drivers. Higher end cheats cost enough to offset this, and there might be less than 5-6 people using a particular certificate. Some of the people behind these also release vaguely-useful legal tools signed with the same certificates to get a large install base for them so they don't stick out. That being said, IMO as a player, this is invasive as hell, and you should not be crawling through my flash drives, identifying my mouse, killing LogitechMacroSoftware.exe, etc. I'd rather you just collect snap/targetting/click timings server-side and run anomaly analysis on those rather than digging an asshole into my computer. Also, now I have 5 different "kernel anticheats" running 24/7 simultaneously, half of them are horrifically written and known-insecure, and the other half need to figure out how to not explode spectacularly when the broken half tries to probe and kill it. Korean MMOs are particularly bad for this and when forcefully uninstalled might permanently destroy disk access, make Windows non-genuine and deactivate it, and send all their data over plaintext (no TLS) with a bizarre, homegrown "encryption" method that is trivially breakable to a bare IP somewhere. With KMMOs as an example (many of these reward you for staying logged in, have daily rewards, and similar; the game itself is fairly low resource when minimised), GameGuard and HackShield and XIGNCODE constantly have slap-fights where they bluescreen or flop over or die if you try to run multiple of them simultaneously and they try probing and killing each others' services for trying to tamper with themselves. It's like that ridiculous "what happens if three programs all try to demand Always On Top for their window", except give all of them heavy weaponry. These also have severe NIH syndrome for things like homemade shitty crypto and plaintext everything.
- invokestatic 6y agoBefore I “switched sides” to anti-cheat, I used to write and sell cheat software for CS:GO. I had a registered company and purchased an EV code signing certificate just as your post suggests, even getting my cheat drivers signed by Microsoft. I am very familiar with the process given than I’ve seen both sides now. While other anti-cheats maintain white lists or blacklists of vulnerable drivers, I’ve chosen a different route that doesn’t have the same pitfalls you suggest. Our anti-cheat also doesn’t run 24/7, only when the game is running.
- deleted 6y ago[deleted]
- Silhouette 6y agoUnfortunately, your model is just fundamentally broken. Non-system software should never have that level of access to the whole system, and a good operating system should block it for stability, security and privacy reasons, just like any other malware. No doubt there will continue to be intrusive anti-cheat software in use with some games for a while because some people are disturbingly desperate to play those games and they use operating systems that are junk. Some people still pre-order games too, even though it's illogical to extend that old physical world idea to downloads. But in the long run, this kind of software is a liability. Better operating systems and more gamers moving to them will eventually kill it for that reason if nothing else does first. Given that cheating only matters if it actually affects gameplay unfairly, it has always made far more sense to look for cheating through its effects on gameplay anyway, which is something you can observe server-side in an online PvP game. Trusted client-side security checks make no more sense in this context than any other. So it's not even as if killing off the intrusive client-side anti-cheats will lose anything of value in the long run.
- PointyFluff 6y agoWhat if I use open source drivers? How are you going to do that? What business is it of yours that I might write my own? Or (more likely) patch my own? What about my HID drivers? Sensitive keystrokes? Yeah, I just don't see games needing access to such kernel level items.
- kbenson 6y ago> What business is it of yours that I might write my own? If they're providing online servers for you to play on with other people, under the condition that you aren't cheating and they are responsible for stopping cheating for everyone, they very much do care and it is their business, if you want to use their servers. Having custom drivers is how you get wallhacks or custom mouse control macros that eliminates some of the challenges imposed by the game (e.g. automatic recoil control). For a single player game, I agree, who cares, but for online games that live and die by competitive play and stopping cheaters so people can enjoy it, there's only so many options of how to find cheaters and so much resources to put towards it, so you get stuff like this.
- invokestatic 6y agoThere’s nothing stopping you from using open source drivers, actually. Plenty of open-source projects like Dokan will typically run fine with an anti-cheat (ours will, certainly). What stops you from running a patched version is actually Windows itself, since Windows requires drivers to be signed with an authenticode codesigning certificate. Plenty of open-source projects and people have one, though. So it’s not an anti-cheat blocking you, it’s Windows itself. Of course, if you go out of your way to disable driver signature enforcement, most anti-cheats will prevent you from playing, but this is a mode strongly discouraged from Microsoft and does weaken your computer’s security.
- lmm 6y agoIf anti-cheat is the thing that cares about whether windows is running without driver signature enforcement then anti-cheat is the thing that's blocking me. My own example: I have an xbox 360 dancemat, which is unusable with the official drivers (they map the arrows as axes, so treat left + right as nothing). So I have to use the open-source XBCD, which frankly I'd treat as more reputable and better code quality than most signed drivers. But since no-one's paying the $100+/year to sign it, it's not signed. And while I understand why Microsoft wants someone to have skin in the game before they issue a driver signing certificate, they really need to find a way to ensure that reputable, established open-source driver projects get signed if they want users to accept driver signing; I wouldn't even mind being stuck on an old "certified" version or something.
- renewiltord 6y agoAs a guy who plays games that have a lot of cheaters, it is incredibly frustrating. Riot's rootkit shit is a small price to play enjoyably with friends. I care more about the experience than I do about the risk of Riot fucking up my Windows install. Keep doing what you're doing. Just, if you'd leave the anti-cheat off friend-to-friend-PvP games, that would be cool. I don't care if my younger brother 'cheats' against me. He's not going to and if he is 'cheating' it's probably some mod or something.
- invokestatic 6y agoIt’s usually down to the game developer to implement features like that.
- renewiltord 6y agoAh, you're a vendor of the product, not an in-house shop. Makes sense makes sense.
- p1necone 6y agoThe problem with Riots anti-cheat (at least to me) was that it runs all the time not just when you're playing the game. This is completely unnecessary and a pretty huge security issue. They've sort of fixed this now by letting you disable it, but it requires a reboot so I'm still avoiding Valorant for now.
- eptcyka 6y agoI've not had issues with cheaters on Dots 2.
- bigger_cheese 6y agoAssuming you mean Dota 2 I haven't played for some time but it used to be somewhat common 3 or 4 years ago for people to run scripts to instantly cast hex as soon as opponent appeared on their screen this effectively gave people inhuman reflex times. You could tell they were cheating because if you watched replay from the cheaters point of view their mouse cursor would jump from current position to hovering over the target instantly and then immediately jump back to cursors original position all within a frame or two.
- b0rsuk 6y agoDoes anyone know a PC gaming website that regularly reviews anti-cheat software? I know review websites get free sample copies and stuff from game publishers... are there any review websites which serve gamers first??
- Cloudef 6y agohttps://www.reddit.com/r/VALORANT/comments/g3yqxd/comment/fnupgsd https://www.reddit.com/r/VALORANT/comments/g3yqxd/comment/fn... when the anti-cheat developers dictate what you can install and run on your computer, i would argue thats invasive. Running kernel level rootkit for this purpose is also insane. These things are very easy for cheaters to bypass anyways, and only cause problems to the honest players ironically , in addition to blocking out players using wine. The best way to handle cheating is to give the players moderation powers.
- ThatPlayer 6y agoPlayers have a hard time telling if someone is cheating or not. Especially in game when you're not spectating. Did they see you through a wall, or is it just good game sense? Did they use an aimbot, or is their aim that good, or they did they get lucky?
- Cloudef 6y agoHas worked well ages for games that had replay and spectating capabilities. MMOs are usually slower paced than fps games so in those server-side checks alone are enough. (Most asian mmos are lazy though and just trust the client and hope their shitty anti-cheat keeps cheaters away, of course it doesnt) Games for some reason today want single central server, instead of dedicated servers with user maintained communities is part of the problem. (E.g. cs:go vs older cs)
- ThatPlayer 6y agoUser maintained communities are not friendly to new users. CS:GO has user maintained communities, but most players do not use it. You can't build a community without new users, and new users want to play the game, not build a community. Especially with team gameplay, players want proper skill based matchmaking. So that they don't have someone on the other team who destroys them. Or someone on their own team that is dead weight.
- Cloudef 6y ago
- YawningAngel 6y agoI think the reason why anticheat gets a very unsympathetic hearing is because it's frequently buggy or unpermissive, and people fundamentally don't like being locked out of their games. As a Linux gamer who's just unable to play some titles that run fine on my PC because the anticheat doesn't, any perceived flaw in anticheat immediately winds me up.
- Conan_Kudo 6y agoOn Linux, you can check to see if the kernel is operating in lockdown mode to verify the integrity of the system. Lockdown mode forces all modules to be digitally signed and trusted by the kernel keyring before they can be loaded. This would functionally be equivalent to what you do on Windows.
- iso8859-1 6y agoDon't you mean tainted? https://unix.stackexchange.com/a/118117/14305 https://unix.stackexchange.com/a/118117/14305
- CorrectHorseBat 6y agoNo, that's something completely different. The kernel is tainted when you load out of tree modules and only means they won't look at your bug reports. Lockdown mode is something similar to the Windows driver signing https://www.phoronix.com/scan.php?page=news_item&px=Linux-5.4-Adds-Lockdown https://www.phoronix.com/scan.php?page=news_item&px=Linux-5....
- deleted 6y ago[deleted]
- krageon 6y agoYou literally have rootkit privileges and exist by the grace of most people not realising you get installed. Most EULAs that concern "anti-cheat" have big explicit entries in them about transmitting personal information. Anti-cheat software is the condoned malware of the modern age, similar to browser toolbars a decade or so ago.