9 ms·
Or you can recognize that app/game developers are starting to require Secure Boot enforcement if you want to continue to use their apps or play their games. RI
by nulld3v 2y ago
Or you can recognize that app/game developers are starting to require Secure Boot enforcement if you want to continue to use their apps or play their games.
RIOT requires users to enable TPM-enforced Secure Boot starting with Windows 11 to play Valorant: https://support-valorant.riotgames.com/hc/en-us/articles/10088435639571-Troubleshooting-the-VAN9001-or-VAN-9003-Error-on-Windows-11-VALORANT https://support-valorant.riotgames.com/hc/en-us/articles/100...
- dist-epoch 2y agoLet me tell you a secret: it's because the gamers are demanding that. The game companies couldn't care less if there are cheaters in the game, but it's the players which put huge pressure on the game companies to detect and ban cheaters.
- heraldgeezer 2y agoBut it allows Windows 10 without TPM.
- 71bw 2y agoIf your account gets flagged for ANY sort of irregular behaviour, you immediately get "upgraded" to requiring TPM and Secure Boot. Been there, done that - a crack for VEGAS Pro I used turned on test signing via registry for whatever reason and VALORANT REALLY didn't like that - and because of the PC I was using at the time that was the end of my VALORANT career.
- tpxl 2y agoGamers arent demanding this. There are tons of ways to detect cheaters, the most effective one being human moderation. But no, companies wont do MaNuAl WoRk because it doesnt sCaLe, even though they have more than enough cash in the bank.
- dgellow 2y agoHow do you do manual moderation on a massive fast-paced game like Valorant? It’s correct, that doesn’t scale
- scotty79 2y agomaybe not manual ... but ... log behavior, find outliers, make outliers play with outliers only
- mholm 2y agoThis absolutely happens already. The problem with finding statistical outliers is that plenty of legitimate players are outliers too. And if you're banning/segregating players for being outliers, you get a very angry player base. Riot has a pretty indepth blogpost about their anti-cheat systems, they've had years to mature them on some of the most demanding competitive gaming platforms ever made. Requiring players install kernel anti-cheat was very far down the list of possible solutions, but that's what it came to. It was either this or stop being free to play.
- choo-t 2y agoThe server is all-seeing, if there is no way for the server to discriminate cheater from other player, then no player can possibly know there a cheater on the server, thus cannot complain about cheating is either irrational or the server-side detection is severely flawed.
- mjr00 2y ago> The server is all-seeing, if there is no way for the server to discriminate cheater from other player, then no player can possibly know there a cheater on the server, thus cannot complain about cheating is either irrational or the server-side detection is severely flawed. It's impossible to tell in-game if a baseball player is using steroids, yet there's a laundry list of banned substances and players who got banned for taking them because the MLB believes it gives them an unfair advantage. It's called competitive integrity. Since it sounds like you don't play games, at least not competitively, I'll clarify that "cheating" in this case isn't the obvious stuff like "my gun does 100x damage" or "I move around at 100mph" or "I'm using custom player models with big spikes so I know everyone's location" that you would've seen on public Counter-Strike 1.6 servers in 2002. Cheating is aim assistance that nudges your cursor to compensate for spray patterns in CS, it's automatic DPs and throw breaks in Street Fighter 6 that are just at the threshold of human reaction timing, it's firing off skillshots in League of Legends with an overlay that says if it's going to kill the enemy player or not. All of this stuff is doable by a sufficiently skilled/lucky human, but not with the level of consistency you get from cheating.
- deleted 2y ago[deleted]
- choo-t 2y ago> Let me tell you a secret: it's because the gamers are demanding that. Citation needed. Whose these gamers ? I surely didn't ask for this neither any of the gamers I know, nor seen any demand about that in gaming forums. > The game companies couldn't care less if there are cheaters in the game, but it's the players which put huge pressure on the game companies to detect and ban cheaters. The jump from this to "requiring TPM" is quite a long one.
- eezurr 2y agoGo on steam and look at the recent reviews for older but still popular fps games. Gamers complain about cheaters constantly and will negatively review games cause of it
- choo-t 2y agoThey're demanding a way to handle or ban cheater, not requiring TPM, that's a non sequitur.
- RHSeeger 2y agoYou're being disingenuous here, or just missing the point. The point being made was the gamers are demanding game developers stop cheaters... and that secure boot (and related ways to lock down the computer) is one of the primary tools they know to use to do that.
- choo-t 2y ago> The point being made was the gamers are demanding game developers stop cheaters... and that secure boot (and related ways to lock down the computer) is one of the primary tools they know to use to do that. That's akin to saying that, as people want security on the street, mandatory strip search as soon as your exit your home is fair game. Asking for a result doesn't give a blank-check for all the measures taken toward this result.
- 2y ago
- realusername 2y agoThere's cheaters even on consoles which are vastly more locked-down than a PC. Those technical shenanigans clearly aren't working, be ready to be disappointed if you thought that a TPM would help against cheaters. Cheaters always find a way, what those game needs is proper moderation. Yes that does cost money but that's the only known thing that works in the long run.
- brookst 2y agoThis seems like the old “any imperfect solution is no better than doing nothing” argument. Moderation is expensive, hard to scale, and can only address problems after other users have bad experiences. It’s like saying seatbelts are useless because some people still get hurt, so instead of seatbelts we need a lot more ambulances and hospitals. Like any complex system, games have a funnel. These technical measures reduce (but not to zero) the number of cheaters. Then moderation can be more effective operating against a smaller population with a lower percentage of abuse.
- realusername 2y agoSince the technical measures like TPM are very heavy, there's some better evidence needed that it reduces the number of cheaters, personally I don't buy it. On the other hand, all the games / servers I've seen which are successful against cheater have some very good moderation.
- vel0city 2y agoJust see Valorent vs Counterstrike. Similar levels of popularity, similar kinds of cheat concepts. One has a kernel level anti cheat and has few cheaters, one doesn't and is overrun by cheaters. Look at Counterstrike with regular VAC based matchmaking and then with kernel level anti cheat in FACEIT. One is overrun with cheaters and one isn't. It's the same game.
- choo-t 2y ago> This seems like the old “any imperfect solution is no better than doing nothing” argument. Isn't this the argument used against non-kernel-level anticheat and server-side anticheat in the first place ?
- bogwog 2y agoGamers don't want cheaters, but gamers also don't want malware. Some people won't care, others will care. The real problem is that publishers don't give anybody a choice on this. They sneak these invasive anti-piracy measures into their games without asking since they don't want to fragment their player base. The reasonable, fair, common-sense pro-consumer thing to do is to split the online play in two: a non-anticheat server and an anti-cheat server. Players can opt-in to installing a rootkit/sharing their SSN/whatever if they want to play on the hardened server. This costs nothing, and makes all types of gamers happy. But doing this has less upside for the publisher than forcing anti-cheat on everyone. The only risk is that they might get dragged through the mud by a handful of influencers peddling impotent rage to viewers who are just looking for background noise while sleepwalking on their Temu dopamine treadmill live service of the month.
- throw10920 2y ago> The reasonable, fair, common-sense pro-consumer thing to do is to split the online play in two: a non-anticheat server and an anti-cheat server. Players can opt-in to installing a rootkit/sharing their SSN/whatever if they want to play on the hardened server. This costs nothing, and makes all types of gamers happy. This is a very good point! And I'd like to point out that there is an analogue to the problem of smurfing in online video games, and the corresponding solution, which is to require semi-unique ID to play (e.g. a phone number which can only be tied to one account at a time with a cool-off period when transferring between accounts). Valve does this for Dota 2, and smurfing is far, far less common than it is in League of Legends. Some League players complain that they don't want to give their phone number to Riot (which is entirely reasonable given that it's a subsidiary of Tencent), but if enough people don't want that, then Riot could simply split the ranked queue into two: one where (soft, ie phone #) identity verification is required, and one where it isn't. Riot won't do this, though, not because it wouldn't fix the problem (it would, as demonstrated by Valve), but because they profit from smurf accounts buying skins.
- 71bw 2y ago>but if enough people don't want that, then Riot could simply split the ranked queue into two: one where (soft, ie phone #) identity verification is required, and one where it isn't. The phone number requirement is only there if you want to play Clash. Normal ranked play works flawlessly with no number.
- lupusreal 2y agoIf it's software your job requires, that's one thing. But games? Just play different games, or get a different hobby. You have a choice so exercise it.
- AshamedCaptain 2y agoSoftware doesn't require it so far because these devices are "uncommon" (i.e. for example, not on server hardware, not usually virtualized). But guess what is happening now that MS requires TPM for Windows? All virtualizers now have some support for TPM. The time will come.
- deleted 2y ago[deleted]
- beeboobaa3 2y agoFirst they came for the socialists, and I did not speak out— Because I was not a socialist. Then they came for the trade unionists, and I did not speak out— Because I was not a trade unionist. Then they came for the Jews, and I did not speak out— Because I was not a Jew. Then they came for me—and there was no one left to speak for me.
- lupusreal 2y agoFinancially supporting games which do a thing you disapprove of is so counter productive it defies rational explaination. You aren't "speaking out", you're joining the party and paying membership dues. How could you get so twisted around? Brain damage, that must be it.
- beeboobaa3 2y agoSure and today it's games, and tomorrow it'll be something you care about.
- lupusreal 2y agoYeah so give money to the companies that do it, that'll show them! Boycotting those products is capitulation somehow, because brain damage.
- jnwatson 2y agoAnd why is that? It isn't for DRM (the game is free). It is for anti-cheat, and it is great. The libertarian maximalist i-can-do-what-i-want-with-my-computer ignore the many use cases where I want to trust something about someone else's computer, and trusted computing enables those use cases.
- Unai 2y ago> It is for anti-cheat, and it is great. How is it great? Vanguard is extremely invasive; having kernel access, you have to relinquish your PC to this chinese-owned company at all times (whether you're playing the game or not), and just trust in their good faith. And for what? Cheaters are more rampant than ever, now that they have moved to DMA type cheats, which can't (and never will) be detected by Vanguard. So you give away complete control of your PC to play a game with as many cheaters as any other game. I wouldn't call that "great".
- notdisliked 2y agoI don’t think you can make the argument that the amount of cheaters using DMA is “just as many” as in a game with a less restrictive anti cheat, allowing cheaters to simply download a program off the internet and run it to acquire cheats. The accessibility of DMA cheats is meaningfully reduced to the point that I would guess (only conjecture here, sorry) the amount of cheaters is orders of magnitude less in an otherwise equivalent comparison. Now, the amount of DMA cheaters may still be unacceptably high, but that’s a different statement than “the same amount as”. So, it’s not “giving up something for nothing”, it’s giving up something for something, whether that something is adequate for the trade offs required will of course be subjective.
- Unai 2y agoYeah, valid point. You're right, a game with no anti-cheat or a bad one will have more cheaters. But as you said, it's about the tradeoff, and that's what isn't "great". It was for a period of two years or so, since the tradeoff was "lose all control of your PC by installing a rootkit, play a game completely free of cheats", which was compelling, but now that the game isn't sterile anymore it's hardly worth it, at least for me.
- dangus 2y agoPeople who are concerned about this should realize: Microsoft will never create a situation where alternative operating systems can’t be installed. They already went through the antitrust ringer on that issue. They don’t even control what hardware vendors do for the most part. This requirement will only hit multiplayer games where cheating and security threats are rampant. Also, if you have a PC with secure boot enabled, there are popular Linux distributions like Ubuntu that have a signed key. Or, you can add a signing key to the firmware, depending on your hardware. And of course, most commercially available PCs will let you disable secure boot entirely. (Most multiplayer games with anti-cheat software don’t really work on Linux anyway.)
- AshamedCaptain 2y ago> Microsoft will never create a situation where alternative operating systems can’t be installed. They already went through the antitrust ringer on that issue. They have shipped ARM Surfaces where alternative operating systems could not get installed, enforced with Secure Boot permanently on. Have they been through any such "antitrust ringer" in the past 10 years? > Also, if you have a PC with secure boot enabled, there are popular Linux distributions like Ubuntu that have a signed key Note that there's one key MS uses for Windows and one key they use for everything else. They actually advise OEMs not to install this second key by default ("Secured Core" PCs), and some vendors have followed the advice, such as Lenovo. Resulting in yet another hoop to install non-MS OSes. Even recently, a Windows update added a number of Linux distributions to the Secure Boot blacklist, resulting in working dual boot systems being suddenly cripped. Of course, even _ancient_ MS OSes are never going to be blacklisted.
- ZeroWidthJoiner 2y ago> They actually advise OEMs not to install this second key by default ("Secured Core" PCs), and some vendors have followed the advice, such as Lenovo. Resulting in yet another hoop to install non-MS OSes. True, 3rd party not trusted by default is a "Secured-Core PC" requirement, but so is the BIOS option for enabling that trust [0]. On my "Secured-Core" ARM ThinkPad T14s it's a simple toggle option. > Even recently, a Windows updated added a number of Linux distributions to the Secure Boot blacklist, resulting in working dual boot systems being suddenly cripped. Of course, _ancient_ MS OSes are never going to be blacklisted. Actually they are in the process of blacklisting their currently used 2011 Windows certificate, i.e. the Microsoft cert installed on every pre-~2024 machine, also invalidating all Windows boot media not explicitly created with the new cert. It's a manually initiated process for now, with an automatic rollout coming later [1]. It'll be very interesting to watch how well that's going to work on such a massive scale. :) [0] https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-highly-secure-11 https://learn.microsoft.com/en-us/windows-hardware/design/de... [1] https://support.microsoft.com/en-us/topic/kb5025885-how-to-manage-the-windows-boot-manager-revocations-for-secure-boot-changes-associated-with-cve-2023-24932-41a975df-beb2-40c1-99a3-b3ff139f832d https://support.microsoft.com/en-us/topic/kb5025885-how-to-m...
- dfox 2y agoOne thing that I do not understand is how an app can determine whether secure boot is enabled in any kind of secure way. The TPM and Secure boot system is not designed for that.
- beeboobaa3 2y agohttps://learn.microsoft.com/en-us/azure/attestation/tpm-attestation-concepts https://learn.microsoft.com/en-us/azure/attestation/tpm-atte...