13 ms·
I never really got the outrage. Or rather, I don't understand why it's directed at the principle of a ring-0 anticheat. I feel that security minded folks are a
by niam 2y ago
I never really got the outrage. Or rather, I don't understand why it's directed at the principle of a ring-0 anticheat.
I feel that security minded folks are apt to avoid installing software from notably untrusted vendors on important machines. If Riot ends up malicious then I'm not sure that kernel level access is capable of _that_ much more damage than what's required for a 'regular' anticheat to function. My bank account is unsafe either way. Obviously less access is better, but it feels like discussion around Vanguard always distills into an argument that would also suggest Riot's software to be untrustworthy even without a ring-0 anticheat.
- kebokyo 2y agoThey want to have their cake and eat it too. If you don’t want Tencent software to potentially one day turn your computer into a zombie that DDOS’s the pentagon or something… why are you still putting League on your computer? They’re running it down mid in more ways than one.
- Cody-99 2y agoA lot of the outrage is because how riot has acted. They have repeatedly dismissed the concerns of security experts and their community in offhand/very dismissive ways. I don't think the outrage would be anywhere nearly as bad if they took the time to address the legitimate concerns raised and took steps to ease everyone mind (they could be more transparent about it and release the source for example).
- sodality2 2y agoRelease the source? I can assure you that would render the anticheat useless in a matter of weeks. Opaqueness is a feature, to stop reverse engineers.
- Cody-99 2y agoYes..? Why would that render it useless? I don't see how vanguard would be any less effective by publishing the source code.
- sodality2 2y agoBecause people will find exploits that allow them to bypass it. Anti cheats in general rely on tons of factors but mainly a lack of knowledge on exactly how HWID bans are enacted, what injections by what processes are put under scrutiny, etc. With source available, all of that stuff is going to be a cake walk for cheaters to bypass. It’s not just a matter of “here’s the source but we are running as ring -n so it doesn’t matter”. full knowledge of AC behavior is a huge boon to bypassing, because there’s almost certainly problems with the implementation that a 15 year old will go on to discover and exploit.