7 ms·
I also always hear a lot of people complain about cheaters in Valorant, so all of that compromised personal security doesn't actually stop cheaters. Honestly I
by mitkebes 1y ago
I also always hear a lot of people complain about cheaters in Valorant, so all of that compromised personal security doesn't actually stop cheaters.
Honestly I feel like you should only use kernel anticheat on a dedicated machine that's kept 100% separate from any of your personal data. That's a lot to ask of people, but you really shouldn't have anything you don't consider public data on the same hardware.
- pfooti 1y agoA dedicated machine with no other general purpose apps that has minimal private data on it sounds like a gaming console.
- wakawaka28 1y agoOr a virtual machine...
- superb_dev 1y agoAnd with PCIe pass through you can get near bare metal performance. You won’t be able to play Valorant though
- Gigachad 1y agoAnti cheat won't run in a VM
- wakawaka28 1y agoWhy not?
- dandersch 1y agoIt can work on a vm, but for Valorant specifically it seems that detecting a vm triggers the anticheat and gets you banned. I believe this is the case for most anticheats except VAC. You can try to evade the detection, but then you just enter the same cat & mouse game as a cheater. Whether allowing/disallowing VMs actually cuts down on cheaters? I don't know.
- kaladin-jasnah 1y agoI've read that they specifically look for this by finding RDTSC timestamps, which would include (?) the overhead of the hypercall or something.
- Gigachad 1y agoBecause anti cheat want's to verify that the highest levels of the system are not being tampered with. When contained within a VM it's impossible to tell if some cheating script on the host OS is reading or tampering with the game memory. Probably the only workable solution is for windows to provide some kind of secure game mode where the game and only the game runs and can have windows attest nothing else is running. But that anti cheat has no access to the data in the real work OS which is currently not running. Ruins multi tasking, but assuming you can switch over fast enough it might not be too bad.
- thayne 1y agoHow does it know it is in a VM? Couldn't the host system make it look enough like real hardware, possibly with hardware passthroughs that the AC can't tell it is a VM?
- Gigachad 1y agoIt’s pretty complex. To start with, off the shelf VMs make absolutely no attempt to hide the fact that they are VMs but even if you do, there are tons of tricks you can do to work it out. Things like timing api response times, finding quirks in the emulation, boot chain attestations from the hardware, etc.
- dylan604 1y agoFlip it. Run the games on bare metal with nothing on it but games and a VM. use the VM for your personal system.
- Hackbraten 1y agoThat achieves nothing. A hypervisor can see and manipulate any VM it runs. By extension, a compromised kernel can do the same.
- QuaternionsBhop 1y agoHow about with homomorphic encryption?
- Hackbraten 1y agoI’m not aware of any OS that supports it for this use case.
- charcircuit 1y agoOn Android this isn't true with support for protected virtual machines.
- beeflet 1y agoNot with that attitude!
- Scramblejams 1y ago> doesn't actually stop cheaters. doesn't actually stop all cheaters. We could have a better discussion around this if we recognize that failing to stop 100% of something isn't a prerequisite to rigorously evaluating the tradeoffs.
- gellybeans 1y agoI think the problem with this line of reasoning is that it's one-sided. Essentially you are saying "Just trust me bro" on behalf of a self-evaluating company. I'd argue the potential for abuse is a perfectly reasonable discussion to have, and doesn't have much bearing on the effectiveness of anticheat, but I understand that's not the point you are trying to make.
- Scramblejams 1y agoSorry, my writing should have been clearer, I put one too many negatives in. :-) I didn't claim we should trust the company. Whether we can trust the anticheat maker is certainly part of the rigorous evaluation of the tradeoffs I mentioned. My point was that saying "it doesn't stop cheaters" is both incorrect and stifling to a more productive conversation, because it implies anticheat has no value and is therefore worth no risk. As for me, if Gabe said "now you can opt your Steam Deck in to a trusted kernel we ship with anticheat and play PUBG," I'd probably do it. But that's because I, for better or worse, tend to trust Gabe. If Tencent were shipping it, I'd probably feel differently.
- YokoZar 1y agoCompare: "I still get spam, therefore all these anti-spam measures are worthless" It is absolutely the case that there would be more cheating if we turned off the only partially effective systems. We know this because they are regularly stopping and banning people!
- Mindwipe 1y agoPeople are going to to be upset when it happens but it is absolutely inevitable at some point Steam ships a Steam Deck with hardware based attestation of the OS being a signed version of SteamOS, feeding back to a Steam API, that can be used as the basis of an anti-cheat solution.
- sounds 1y agoAbout halfway in the article, there's a brief nod to CS:GO. It uses a tick system and the server controls what is possible, such as physics or awarding kills. Fighting genre games use the same server-based game logic. Cheating is a big draw to Windows for semi-pro gamers and mid streamers. What else is there to do except grind? Windows gives the illusion of "kernel level anti-cheat," which filters out the simplest ones, and fools most people some of the time.
- chowells 1y agoFighting games do not use server-mediated simulation, in general. Cheating is actually a huge problem in popular games. And in fact, even running a server-mediated simulation wouldn't help with any of the common cheating in fighting games. For instance, a common cheat in Street Fighter 6 is to trigger a drive impact in response to the startup of a move that is unsafe to a drive impact. That is recognizing the opponent's animation and triggering an input. There's no part of that which cares where the game simulation is being done. In fact, this kind of cheating can only be detected statistically. And the cheats have tools to combat that by adding random triggering chances and delays. It's pretty easy to tune a cheat to be approximately as effective as a high-level player. Kernel-level anticheat isn't a perfect solution, but there are people asking for it. It would make cheating a lot harder, at least.
- ben-schaaf 1y ago> About halfway in the article, there's a brief nod to CS:GO. It uses a tick system and the server controls what is possible, As does Valorant and virtually every other first person shooter. The cheats aren't people flying around or nocliping, it's wallhacks and aim assists/bots.
- JoshTriplett 1y agoWallhacks depend on the server giving the client information the client shouldn't have.
- joha4270 1y ago
- pxc 1y ago> you should only use kernel anticheat on a dedicated machine that's kept 100% separate from any of your personal data. Correct. Unfortunately, what you've just described is a gaming console rather than a PC. This problem fundamentally undermines the appeal of PC gaming in a significant way, imo.
- thewebguyd 1y ago> This problem fundamentally undermines the appeal of PC gaming in a significant way, imo. Yes, game publishers are trying to turn PCs into a gaming console, which IMO will always be a futile effort, and is quite frankly annoying. I don't game on PC to have a locked down console-like experience. Just embrace the PC for what it is and stop trying to turn it into a trusted execution platform with spyware and rootkits. Look at BF6 - for all the secure boot and TPM required anti-cheat they stuffed it with, there were cheaters day 1, so why abuse your users when it's clearly ineffective anyway.
- ryandrake 1y agoThat's what gets me! If these rootkit anti-cheat systems actually stopped cheating then maybe, just maybe, I'd accept them as a necessary evil. But every game that has these things... still has cheaters! So as a user, you're consenting to ripping a security hole through your system, and in return you are still playing games with cheaters. The game companies keep saying these things are necessary, yet they don't fully do the very thing they claim to do on the label.
- Propelloni 1y agoI can't put a finger on it but that tastes like the copyright/DRM situation in reverse.
- balamatom 1y agoNot even in reverse, this is literally DRM. Can't help but ask myself sometimes... why would users want to pay in the first place, for the content of someone who invests more money and leverage that some people see in their entire lives, in delivering user-hostile technical countermeasures that most of the time are ultimately futile? What is the so valuable thing that one is supposed to get out of the work of someone who treats their audience this way, awesomely as their stuff might've been made? That's what doesn't make the most sense to me. But then I remember how most people aren't very intentional about most of their preferences and will accept whatever as long as it's served by an unaccountable industry into everyone's lives at the same time in a predictable manner, and I despair.
- tzs 1y ago> Honestly I feel like you should only use kernel anticheat on a dedicated machine that's kept 100% separate from any of your personal data. That's a lot to ask of people, but you really shouldn't have anything you don't consider public data on the same hardware. Wouldn't it be sufficient to simply have a minimal system installed on a separate partition or on a separate drive (internal or external). Boot that for gaming, and never give it the password for the encryption of your non-gaming volumes.
- 0xDEAFBEAD 1y agoWhy not dual boot, and keep your files on an encrypted partition?
- y7 1y ago> Honestly I feel like you should only use kernel anticheat on a dedicated machine that's kept 100% separate from any of your personal data. That's a lot to ask of people, but you really shouldn't have anything you don't consider public data on the same hardware. Yes, and at that point, you may as well use Windows for that machine.
- asabla 1y agoI fundamentally agree with you. But anti-cheat hasn't been about blocking every possible way of cheating for some time now. It's been about making it as in convenient as possible, thus reducing the amount of cheaters. Is the current fad of using kernel level anti-cheats what we want? hell nah. The responsibility of keeping a multi-player session clean of cheaters, was previously shared between the developers and server owners. While today this responsibility has fallen mostly on developers (or rather game studios) since they want to own the whole experience.
- torginus 1y agoThis is why (even though everybody hates my for saying this) - the only way to do security is by enforcing root of trust - which is why Windows 11 forcing secure boot and TPM is a necessary change. The idea that we should allow arbitrary code execution at some point, then we claw back security by running mass surveillance on your PC is clearly insane. The only way to go forward is what BF6 has done - ensure the PC is in a pristine state, and nothing bad was loaded in the kernel - which is ironically why their anticheats conflicted - they don't allow loading random crap in the kernel. Not to mention, people who develop these invasive security modules don't have the expertise, resources or testing culture to muck about in the kernel to the degree they do. As to how dangerous this actually got actually showcased by Crowdstrike last year.
- safety1st 1y agoSounds great! Guess who I trust? Me. The root of trust should be a key I generate. I do not trust this to any government, any private company or really any 3rd party, except perhaps a member of my family or my lawyer. It can just be me and maybe someone I grant a digital equivalent of power of attorney to. For a company like Microsoft to try and get involved is in my view a form of aggression.
- torginus 1y agoI hope you run a globally recognized certificate authorithy then...