5 ms·
It is possible to have free anticheat software. I do not hate anticheat as a gamer, but I do hate DRMs.
by danamit 4y ago
It is possible to have free anticheat software.
I do not hate anticheat as a gamer, but I do hate DRMs.
- Gigachad 4y agoNo it isn’t. Anti cheat is basically DRM/malware. If you could fully understand how it works you could just modify it / work your cheats around it.
- Morgawr 4y agoI don't think this is really a given. I admit I'm not familiar with whether or not there exist some free and open source anti-cheat software out there but I can definitely imagine a world where if people put enough resources in developing such software it'd be totally possible to be as good as current proprietary anti-cheat techniques. Claiming that knowing how the code works lets you break the code is basically advocating for security by obscurity which I'm fairly sure we're all aware it's not the holy grail of a secure system. If you will allow me a bit of a hyperbole, it'd be like saying that since I have access to the entire code of my SSH client, that gives me the capability of modifying it so it lets me connect to every server (even those that I do not own) without a password. That's simply not how it works.
- charcircuit 4y agoIt'd be simple to develop stealth code to hide your cheats. >advocating for security by obscurity There is nothing wrong with this as long as you understand what you are doing. The goal of anticheat is to prevent cheat makers from being able to make cheats for your game for as long as possible. Increasing the time and skill needed to reverse engineer your anticheat increases the time it takes for someone to develop a cheat. >it'd be like saying that since I have access to the entire code of my SSH client, that gives me the capability of modifying it so it lets me connect to every server (even those that I do not own) without a password With this kind of problem of authentication it is simple to design the code such that the time it will take for an attacker to break the security to be impractical. Anticheat on the other hand is not a problem that has a solution like that. If you want to check if a click came from a mouse or a cheat program and you trust the client to tell you where it came from it's impossible to prevent the client from lying. Since it's trivial to lie you need to find a way to slow down attackers to make it harder to lie.
- Morgawr 4y agoStill, I'm not an expert and this might be entirely unfeasible but I can totally imagine some kind of trusted execution environment that cross checks specific instructions at the API level when the client communicates with the server using some kind of trusted operation (backed by cryptography). There are already VMs that are used to run trusted instructions on a target (read: client) machine and regardless of you knowing how the VM works and what the code does, if you don't "play by the rules" (as is the world of cryptography), your data will not be accepted and you will get kicked/banned/disconnected. Is it computationally expensive? Probably. Is it feasible? I don't know. Is it theoretically possible? I'd say so. >Increasing the time and skill needed to reverse engineer your anticheat increases the time it takes for someone to develop a cheat. This is the good ol' security by obscurity fallacy. Having it open increases the amount of people who have eyes on the code and contribute to the code and finds exploits to patch, etc. It's two sides of the same coin.
- charcircuit 4y agoA cheat would just look at the detection code and be sure it doesn't violate what the anticheat is checking for. >Having it open increases the amount of people who have eyes on the code and contribute to the code and finds exploits to patch, etc. If your detection is to collect the names of the open windows on a computer to check for a cheat's name and then send the anticheat server the hash of the binary that opened that window how is making that information public making the anticheat stronger. The more eyes that look at that code the more cheaters who know to name their cheat windows as "Notepad." To avoid being found. If you find an exploit there is no patch.
- hypertele-Xii 4y agoNothing you said has anything to do with security nor preventing cheating. If that's the sorry state of modern anti-cheat then it makes sense why TF2 is still plagued by incredibly obvious sniper bots. Detecting cheating by window names? Who is getting paid writing this crap?
- diffeomorphism 4y agoNo, not at all. You are making the same mistake as "security by obscurity". If fully understanding your anticheat breaks it, it was broken to begin with.
- Gigachad 4y agoAnti cheat is an impossible task like DRM. Fundamentally it can’t be perfect for most games. But continuing the cat and mouse obscurity game has been working pretty well. How can you possibly verify the mouse was moved by a human rather than a script when the script had the ability to lie about any check you put in place. In the end it comes to making the check so hard to understand that you can’t work it out fast enough to keep ahead.