13 ms·
How kernel anti-cheats work
- Retr0id 7mo agoThis got me wondering how easy it'd be to automate discovery of BYOVD vulns with LLMs (both offensively and defensively)
- not_a9 7mo agoProbably not too hard with the LLM side itself assuming latest models and good tooling. The harder thing probably is getting a dataset for “all x64/ARM64 Windows drivers that aren’t already considered vulnerable”. Also it depends what’s considered a vulnerability here.
- metalcrow 7mo ago>TPM-based measured boot, combined with UEFI Secure Boot, can generate a cryptographically signed attestation ... This is not a complete solution (a sufficiently sophisticated attacker can potentially manipulate attestation) I was not aware that attackers could potentially manipulate attestation! How could that be done? That would seemingly defeat the point of remote attestation.
- gruez 7mo agoThe comms between the motherboard and the TPM chip isn't secured, so an attacker can just do a MITM attack and substitute in the correct values.
- metalcrow 7mo agoThat's fair, although aren't most TPMs nowadays fTPMs? No interceptable communication that way.
- Retr0id 7mo agoUntil they require fTPMs, an attacker can just choose to use a regular TPM. A more sophisticated attacker could plausibly extract key material from the TPM itself via sidechannels, and sign their own attestations.
- Charon77 7mo agoI remember there's a PCI device that's meant to be snooping and manipulating RAM directly by using DMA. Pretty much one computer runs the game and one computer runs the cheat. I think kernel anti cheats are just raising the bar while pretty much being too intrusive
- int_19h 7mo agoTFA explicitly describes those devices, and how anti-cheat developers are trying to handle this. But the main point there is that this setup is prohibitively expensive for most cheaters.
- edoceo 7mo agoCan a TPM be faked in a QEMU VM?
- carefree-bob 7mo agoYes! https://github.com/stefanberger/swtpm https://github.com/stefanberger/swtpm
- invokestatic 7mo agoTechnically yes, but it would produce an untrusted remote attestation signature (quote). This is roughly equivalent to using TLS with a self-signed certificate — it’s not trusted by anyone else. TPMs have a signing key that’s endorsed by the TPM vendor’s CA.
- kay_o 7mo agoWe don't allow games to run in virtual machines and require TPM. Check TPM EK signing up to an approved manufacturer. It is not "fake", a software TPM is real TPM but not accepted/approved by anticheat due to inability to prove its provenance (Disclosure: I am not on the team that works on Vanguard, I do not make these decisions, I personally would like to play on my framework laptop)
- halayli 7mo agoThat doesn't sound accurate. The T in TPM stands for trust, the whole standard is about verifying and establishing trust between entities. The standard is designed with the assumption that anyone can bring in their scope and probe the ports. This is one of several reasons why the standard defines endorsement keys(EK).
- invokestatic 7mo agoActually, it is completely true. The TPM threat model has historically focused on software-based threats and physical attacks against the TPM chip itself - crucially NOT the communications between the chip and the CPU. In the over 20 year history of discrete TPMs, they are largely completely vulnerable to interposer (MITM) attacks and only within the last few years is it being addressed by vendors. Endorsement keys don’t matter because the TPM still has to trust the PCR commands sent to it by the CPU. An interposer can replace tampered PCR values with trusted values and the TPM would have no idea.
- srjek 7mo agoIt is correct, the measurement command to the TPM is not encrypted. So with MITM you can record the boot measurements, then reset and replay to any step of the boot process. Secrets locked to particular stages of boot are then exposed. There is guidance on "Active" attacks [1], which is to set up your TPM secrets so they additionally require a signature from a secret stored securely on the CPU. But that only addresses secret storage, and does nothing about the compromised measurements. I also don't know what would be capable of providing the CPU secret for x86 processors besides... an embedded/firmware TPM. [1] https://trustedcomputinggroup.org/wp-content/uploads/TCG_-CPU_-TPM_Bus_Protection_Guidance_Active_Attack_Mitigations-V1-R30_PUB-1.pdf https://trustedcomputinggroup.org/wp-content/uploads/TCG_-CP...
- matheusmoreira 7mo agoSee this for example: https://tee.fail/ https://tee.fail/ Defeating remote attestation will be a key capability in the future. We should be able to fully own our computers without others being able to discriminate against us for it.
- metalcrow 7mo agoThank you for that link, that's super interesting! It looks like it's actually an architectural vulnerability in modern fTPMs, and considered out of scope by both Intel and AMD. So that's a reliable way to break attestation on even the most modern systems!
- torginus 7mo agoSure, but the exploit presented doesn't really look practical for the everyman. And I'm not sure if it can be patched in HW/SW, and in any case this is just the first step to a fully fake secure boot.
- eddythompson80 7mo agoWhile I’m not really a gamer, I do think the conundrum of online games cheating is an interesting technical problem because I honestly can’t think of a “good” solution. The general simplistic answer from those who never had to design such a game or a system of “do everything on the server” is laughably bad.
- abofh 7mo agoI think it's somewhere between halting and turing - given infinite resources it's likely solvable, but lacking that it's just narrowing bounds
- hakkoru 7mo agoI think from a purely technical viewpoint, cheaters will always have the advantage since they control the machine the game and anti-cheat is running on. Anti-cheat just has to keep the barrier high enough so regular players don't think the game is infested with cheaters.
- akersten 7mo ago> Anti-cheat just has to keep the barrier high enough so regular players don't think the game is infested with cheaters. And even that's the (relatively) straightforward part. The hard part is doing this without injuring the kernel enough that the only sensible solution for the security conscious is a separate PC for gaming.
- cylemons 7mo agoI wonder if dual booting can be used as a middle ground, like have one OS for gaming and other OS for work. Problem is that only works if the two OSes are different (Windows vs Linux) or else they can just stomp each other
- eddythompson80 7mo agoI agree, but that’s precisely the interesting ‘technical’ problem. Like bitcoins “proof of work” in 2011 (it took me few years to comprehend) was an eye opening moment for me. While I do believe that it firmly failed to achieve its lofty goals, the idea of “proof of work” was a really captivating and interring technical idea. Can a video game client have a similar zero-trust proof of their authenticity? I personally can’t think of one. I can’t think of a way to have remote random agents (authenticates or not) to proof they are not cheating in a “game”, and like you, I suspect it’s not really possible. But what does that mean? I grew up with star trek and star wars wondering what a “I’ll transfer 20 units to you” meant. Bitcoin was an eye opener in the idea of “maybe this is possible” to me. But it shortly became true to me that it’s not the case. There is no way still for random agents to prove they are not malicious. It’s easier in a network within the confines of Bitcoin network. But maybe I’m not smart enough to come up with a more generalized concept. After all, I was one of the people who read the initial bitcoin white paper on HN and didn’t understand it back then and dismissed it.
- istillcantcode 7mo agoI could have sworn online gambling people fixed this years ago with just wifi. I thought I remembered reading a comment on here about the online gambling for kids no cheating people not talking to the online gambling for adults no cheating people.
- nichch 7mo agoThe "just wifi" is about getting your true geolocation so regulated gaming platforms can operate legally. Ironically, I bet whatever API they use can be intercepted by a kernel level process. They also have VM checks. I "accidentally" logged into MGM from a virtual machine. They put my account on hold and requested I write a "liability statement" stating I would delete all "location altering software" and not use it again. (Really!)
- Morromist 7mo agoThat would be interesting if they did. looking at cards is a way easier problem than rendering a 3d world with other players bouncing around. I imagine you could just send the card player basially a screenshot of what you want them to see and give them no other data to work with and that would mostly solve cheating. But gambling can be way more complicated than just looking at cards so maybe there's a lot more to it.
- matheusmoreira 7mo agoNever forget the risks of trusting game companies with this sort of access to your machine. https://www.vice.com/en/article/fs-labs-flight-simulator-password-malware-drm/ https://www.vice.com/en/article/fs-labs-flight-simulator-pas... Company decides to "catch pirates" as though it was police. Ships a browser stealer to consumers and exfiltrates data via unencrypted channels. https://old.reddit.com/r/Asmongold/comments/1cibw9r/valorant_now_takes_screenshots_of_your_pc/ https://old.reddit.com/r/Asmongold/comments/1cibw9r/valorant... https://www.unknowncheats.me/forum/anti-cheat-bypass/634974-vanguard-taking-screenshot-pc.html https://www.unknowncheats.me/forum/anti-cheat-bypass/634974-... Covertly screenshots your screen and sends the image to their servers. https://www.theregister.com/2016/09/23/capcom_street_fighter_v/ https://www.theregister.com/2016/09/23/capcom_street_fighter... https://twitter.com/TheWack0lian/status/779397840762245124 https://twitter.com/TheWack0lian/status/779397840762245124 https://fuzzysecurity.com/tutorials/28.html https://fuzzysecurity.com/tutorials/28.html https://github.com/FuzzySecurity/Capcom-Rootkit https://github.com/FuzzySecurity/Capcom-Rootkit Yes, a literal privilege escalation as a service "anticheat" driver. Trusting these companies is insane. Every video game you install is untrusted proprietary software that assumes you are a potential cheater and criminal. They are pretty much guaranteed to act adversarially to you. Video games should be sandboxed and virtualized to the fullest possible extent so that they can access nothing on the real system and ideally not even be able to touch each other. We really don't need kernel level anticheat complaining about virtualization.
- invokestatic 7mo agoThe privacy points in general are valid, but what irritates me is using this rationale against kernel mode anti cheats specifically. You do not need kernel access to make spyware that takes screenshots. You do not need a privileged service to read the user’s browser history. You can do all of this, completely unprivileged on Windows. People always seem to conflate kernel access with privacy which is completely false. It would in fact be much harder to do any of these things from kernel mode.
- matheusmoreira 7mo agoThere is no need for irritation. I condemn all sorts of anticheating software. As far as I'm concerned, if the player wants to cheat he's just exercising his god given rights as the owner of the machine. The computer is ours, we can damn well edit any of its memory if we really want to. Attempts to stop it from happening are unacceptable affronts to our freedom as users. Simply put, the game companies want to own our machines and tell us what we can or can't do. That's offensive. The machine is ours and we make the rules. I single out kernel level anticheats because they are trying to defeat the very mitigations we're putting in place to deal with the exact problems you mentioned. Can't isolate games inside a fancy VFIO setup if you have kernel anticheat taking issue with your hypervisor.
- biang15343100 7mo ago[flagged]
- jrockway 7mo agoI still don't understand why people don't cheat in FPSes by looking at the video stream and having a USB mouse that emits the right mouse movements. (The simplest thing is to just click when someone's head is under your crosshair, in games with hitscan weapons.)
- raincole 7mo agoThey do. Cheats that read rendered pixels are nothing new.
- bob1029 7mo agoThe problem with these bots is that they are indiscriminate which makes them vulnerable to active detection methods. They can also introduce an amount of latency that begins to defeat the purpose for sufficiently skilled players. 100ms is an eternity when you are playing with shotguns in close quarters.
- throw10920 7mo agoI would love to see a modern competitive game with optional anticheat that, when enabled, allows you to queue for a separate matchmaking pool that is exclusive to other anticheat users. For players in the no-anticheat pool, there could be "community moderation" that anti-anticheat players advocate for. It'd be really interesting to see what would happen - for instance, what fraction of players would pick each pool during the first few weeks after launch, and then how many of them would switch after? What about players who joined a few months or a year after launch? Unfortunately, pretty much the only company that could make this work is Valve, because they're the only one who actually cares for players and is big enough that they could gather meaningful data. And I don't think that even Valve will see enough value in this to dedicate the substantial resources it'd take to try to implement.
- Cyph0n 7mo ago> I would love to see a modern competitive game with optional anticheat that, when enabled, allows you to queue for a separate matchmaking pool that is exclusive to other anticheat users. For players in the no-anticheat pool, there could be "community moderation" that anti-anticheat players advocate for. This is roughly what Valve does for CS2. But, as far as I understand, it's not very effective and unfortunately still results in higher cheating rates than e.g. Valorant.
- throw10920 7mo agoHuh. When you say that "it's not very effective" do you mean the segmentation between the pools, or the actual anticheat isn't very good? (I'm assuming the latter - I've heard that VAC is pretty bad as far as anticheat goes)
- Cyph0n 7mo agoOh sorry - I misread your suggestion! I thought you were talking about separate matchmaking logic for known cheaters, but you're asking about opt-in matchmaking for those willing to use invasive anticheat. The example still kind of applies. In the CS world, serious players use Faceit for matchmaking, which requires you to install a kernel-level anticheat. This is basically what you're suggesting, but operated by a 3rd party.
- EPWN3D 7mo ago> Modern kernel anti-cheat systems are, without exaggeration, among the most sophisticated pieces of software running on consumer Windows machines. They operate at the highest privilege level available to software, they intercept kernel callbacks that were designed for legitimate security products, they scan memory structures that most programmers never touch in their entire careers, and they do all of this transparently while a game is running. Okay, chill. I'm willing to believe that anti-cheat software is "sophisticated", but intercepting system calls doesn't make it so. There is plenty of software that operates at elevated privilege and runs transparently while other software is running, while intentionally being unsophisticated. It's called a kernel subsystem.
- unclad5968 7mo agoBut they scan memory structures most programmers never touch in their entire careers!
- coppsilgold 7mo agoThere is a solution to cheating, but it's not clear how hard it would be to implement. Cheaters are by definition anomalies, they operate with information regular players do not have. And when they use aimbots they have skills other players don't have. If you log every single action a player takes server-side and apply machine learning methods it should be possible to identify these anomalies. Anomaly detection is a subfield of machine learning. It will ultimately prove to be the solution, because only the most clever of cheaters will be able to blend in while still looking like great players. And only the most competently made aimbots will be able to appear like great player skills. In either of those cases the cheating isn't a problem because the victims themselves will never be sure. There is also another method that the server can employ: Players can be actively probed with game world entities designed for them to react to only if they have cheats. Every such event would add probability weight onto the cheaters. Ultimately, the game world isn't delivered to the client in full so if done well the cheats will not be able to filter. For example: as a potential cheater enters entity broadcast range of a fake entity camping in an invisible corner that only appears to them, their reaction to it is evaluated (mouse movements, strategy shift, etc). Then when it disappears another evaluation can take place (cheats would likely offer mitigations for this part). Over time, cheaters will stand out from the noise, most will likely out themselves very quickly.
- bob1029 7mo agoI've been advocating for a statistical honeypot model for a while now. This is a much more robust anti cheat measure than even streaming/LAN gaming provides. If someone figures out a way to obtain access to information they shouldn't have on a regular basis, they will be eventually be found with these techniques. It doesn't matter the exact mechanism of cheating. This even catches the "undetectable" screen scraping mouse robot AI wizard stuff. Any amount of signal integrated over enough time can provide damning evidence. > With that goal in mind, we released a patch as soon as we understood the method these cheats were using. This patch created a honeypot: a section of data inside the game client that would never be read during normal gameplay, but that could be read by these exploits. Each of the accounts banned today read from this "secret" area in the client, giving us extremely high confidence that every ban was well-deserved. https://www.dota2.com/newsentry/3677788723152833273 https://www.dota2.com/newsentry/3677788723152833273
- dxuh 7mo agoI feel like this whole problem is just made up. Back in the day, when I played lots of Counter Strike, we had community servers. If a cheater joined, some admin was already online and kicked them right away. I'm sure we hit some people that were not actually cheaters, but they would just go to another server. And since there was no rank, no league, no rewards (like skins, drops, etc.), there was no external reward for cheating. It annoys me that cheating in competitive video games seems like a bigger problem than it has been in the past for no good reason.
- denalii 7mo agoManually managing one cheater in a 20 person server is obviously very different than managing games between multiple millions of concurrent players
- NoPicklez 7mo agoWell its because we don't use community servers anymore. Lobbies are created in real time, particularly where SBMM is involved. It's a bigger problem because in a lobby of 100 people, 1 person cheating ruins it for 99 players. Whereas in a 20 person lobby you can just boot that one person and it only ruins the game for 19 others.
- 152334H 7mo agoIt's AI-assisted content, but has good reference links.
- quailfarmer 7mo agoThe real “competitive” game is not players playing against other players, but hackers playing against anti-cheat. “Billiards is not as good a game as Physics” (https://mag.uchicago.edu/billiards https://mag.uchicago.edu/billiards)
- compsciphd 7mo agoi've said it before, but is anti-cheat mechanisms needed on consoles? If not, (presumambly due to their locked down nature), what's the problem with having a locked down mode (trusted secure boot path that doesn't allow other programs to run, ala "the xbox mode" that microsoft has started to implement), that is similar to a console. This seems much more doable today than in the past as machines boot in moments. Switching from secure "xbox mode" to free form PC mode, would be barely a bump. Now, I see one major difference, heterogenous vs homogenous hardware (and the associated drivers that come with that). In the xbox world, one is dealing with a very specific hardware platform and a single set of drivers. In the PC world (even in a trusted secure boot path), one is dealing with lots of different hardware and drivers that can all have their exploits. If users are more easily able to modify their PCs and set of drivers one, I'd imagine serious cheaters would gravitate to combinations they know they can exploit to break the secure/trusted boot boundary. I wonder if there are other problems.
- ThatPlayer 7mo agoNot sure if they are considered anti-cheats, but there are some measures to detect usage of input devices like XIM that allow keyboard and mouse inputs which allow for superior aim over controllers. Well it's definitely not game developer written kernel anti-cheat on consoles.
- rhim 7mo agoKernel level anti cheat is really the maximum effort of locking down a client from doing something suspicious. But today we still see cheaters in those games running these system. Which proofs that a game server just cannot trust a random client out there. I know it's about costs, what to compute on client and what to compute in server side. But as long as a game trusts computation and 'inputs' of clients we will see those cheating issues.
- maccard 7mo agoIt’s not about costs, it’s about tradeoffs. In an online shooter game (for example) there is latency, and both clients are going to have slightly different viewpoints of the world when they take an action. No amount of netcode can solve the fact that if I see you on my screen and you didn’t see me, it’s going to feel unfair.
- afpx 7mo agoPlus, if I was a motivated cheater, I'd just use a camera, a separate computer, and automate the input devices.
- torginus 7mo agoAll of this is beyond horrific. Mucking about in the kernel basically bypasses the entire security and stability model of the OS. And this is not theoretical, people have been rooted through buggy anticheats software, where the game sent malicious calls to the kernel, and hijacked to anti cheat to gain root access. Even in a more benign case, people often get 'gremlins', weird failures and BSOD due to some kernel apis being intercepted and overridden incorrectly. The solution here is to establish root of trust from boot, and use the OSes sandboxing features (like Job Objects on NT and other stuff). Providing a secure execution environment is the OS developers' job. Every sane approach to security relies on keeping the bad guys out, not mitigating the damage they can do once they're in.
- stavros 7mo agoAre you saying that the solution here is to sell computers so locked down that no user can install anything other than verified software?
- torginus 7mo agoNo. I'm saying we should all drink the blood of babies to stay eternally youthful. You didn't read between the lines deeply enough.
- deleted 7mo ago[deleted]
- pta2002 7mo agoThat’s not really incompatible with this? That’s just how secure boot works. You can re-enlist keys for a different root of trust, or disable it and accept the trade-off there.
- alkonaut 7mo agoThat’s what I want as a gamer. I want a PC that works as a console. Whether I want that for other use cases or this machine doesn’t matter. I’m happy to sandbox _everything else_, boot into a specific OS to game etc. The thing about gaming is that it’s not acceptable to leave 5% performance on the table whereas for other uses it usually is.
- lionkor 7mo agoThere is hardware that you can simply plug into your PC, which can read and write arbitrary kernel memory. I have a feeling that kernel level anticheat isn't stopping someone who really wants to cheat. See https://github.com/ufrisk/pcileech https://github.com/ufrisk/pcileech
- stavros 7mo agoThis was mentioned in the article.
- himata4113 7mo agoI'll simplify for everyone: They don't. Although I do appreciate the author delving into this beyond surface level analysis. Modern cheats use hypervisors or just compromise hyper-v and because hyper-v protects itself so it automatically protects your cheat. Another option that is becoming super popular is bios patching, most motherboards will never support boot guard and direct bios flashing will always be an option since the chipset fuse only protects against flashing from the chipset. DMA is probably the most popular by far with fusers. However, the cost of good ones has been increasing due to vanguard fighting the common methods which is bleeding into other anticheats (some EAC versions and ricochet). These are not assumptions, every time anticheats go up a level so do the cheats. In the end the weakest link will be exploited and it doesn't matter how sophisticated your anticheat is. What does make cheat developers afraid is AI, primarily in overwatch. It's quite literally impossible to cheat anymore (in a way that disturbs normal players for more than a few games) and they only have a usermode anticheat! They heavily rely on spoofing detection and gameplay analysis including community reports. Instead of detecting cheats, they detect cheaters themselves and then clamp down on them by capturing as much information about their system as possible (all from usermode!!!). Of course you could argue that you could just take advantage that they have to go through usermode to capture all this information and just sit in the kernel, but hardware attestation is making this increasily more difficult. The future is usermode anticheats and gameplay analysis, drop kernel mode anticheats. No secure boot doesn't work if you patch SMM in bios, you run before TPM attestation happens.
- fleroviumna 7mo ago[dead]
- uhx 7mo agoEverything you described increases the cost of attack (creating a cheat), and as a result, not everyone can afford it, which means anti-cheats work. They don't have to be a panacea. Gameplay analysis will only help against blatant cheaters, but will miss players with simple ESP. It's almost the same as saying "you don't need a password on your phone" or something like that.
- 7mo ago
- denalii 7mo agoThe amount of people in this thread who very clearly don't play competitive video games, let alone at a remotely high level, is astounding. The comment "it's your god given right to cheat in multiplayer games" might legitimately be one of the most insane takes I've ever read. Kernel anticheat does work. It takes 5 seconds to look at Valve's record of both VAC (client based, signature analysis) and VACNet (machine learning) to know the cheating problem with those technologies is far more prevalent than platforms that use kernel level anticheat (e.g. FACEIT, vanguard). Of course, KLAC is not infallible - this is known. Yes, cheats do (and will continue to) exist. However, it greatly raises the bar to entry. Kernel cheats that are undetected by FACEIT or vanguard are expensive, and often recurring subscriptions (some even going down to intervals as low as per day or week). Cheat developers will 99% of the time not release these publicly because it would be picked up and detected instantly where they could be making serious money selling privately. As mentioned in the article, with DMA devices you're looking at a minimum of a couple hundred dollars just for hardware, not including the cheat itself. These are video games. No one is forcing you to play them. If you are morally opposed to KLAC, simply don't play the game. If you don't want KLAC, prepare to have your experience consistently and repeatedly ruined.
- pixxel 7mo ago[dead]
- Razengan 7mo agoHear me out: How about this: Instead of third-party companies installing their custom code to fuck with my operating system, How about just having the OS offer an API that a game can request to reboot the OS into "console mode": A single-user, single-application mode that just runs that game only. Similar to how consoles work. That mode could be reserved for competitive ranked multiplayer only.
- raziefx 7mo ago[dead]
- RobotToaster 7mo agoRemember when sony got a huge pushback for putting rootkits on CDs? Now industry propaganda has gamers installing them voluntarily.
- AlyssaRowan 7mo agoIt is, of course, only a matter of time - just like kernel-level copy protection and Sony's XCP - before something like Vanguard in particular is exploited and abused by malware. Himata is correct, too. After DMA-based stuff, it'll be CPU debugging mode exploits like DCI-OOB, some of which can be made detectable in kernel mode; or, stealthier hypervisors.
- glelellnngn 7mo agoThis has already happened.
- sholladay 7mo agoA lot of the techniques that both sides use would be much harder on macOS. Of course, Hackintoshes have always existed and where there’s a will, there’s a way. But it makes me wonder how this would evolve if Apple eventually gets its act together and makes a real push into gaming.
- sylware 7mo agoKernel anti-cheats are weaponized by hackers. It is all over HN. Play games which are beyond that: dota2, cs2 for instance. On linux, there is a new syscall which allows a process to mmap into itself the pages of another process (I guess ~same effective UID and GID). That is more than enough to give hell to cheats... But any of that can work only with a permanent and hard working "security" team. If some game devs do not want to do that, they should keep their game offline.
- not_a9 7mo agoUh, isn’t the IDT one of these things that PatchGuard explicitly checks? Mind you, anticheats keep PatchGuard corralled these days because they want their own KiPageFault hooks assuming HVCI is not in place. The article doesn’t go too in depth on the actually interesting things modern anticheats do. In addition: - you can’t really expect .text section of game/any modules except maybe your own to be 100% matching one on disk, because overlays will hook stuff like render crap (fun fact for you: Steam will also aggressively hook various WinAPI stuff presumably for VAC, at least on CS2)
- mikkupikku 7mo agoIt's a whole lot of effort to go through just so corporations can get gamers playing with strangers instead of friends, while taking the whole thing way too seriously. You need anticheat when you want competitive rankings and esports leagues, but is any of that actually any better than just playing casual games with people you know and trust to play fair?
- trostaft 7mo agoYes it can be? This is a very strange statement to me. Many genuinely like testing themselves against other people, improving over time, and seeing how they stack up. Competition is a pretty basic human thing, e.g. sports, chess, card games, and therefore video games. And competing with the world is a far grander challenge than those you explicitly know. Not everyone enjoys that, and that’s fine, but acting like it’s somehow unnatural or pointless feels way off.
- mikkupikku 7mo agoI know gamers are drawn to it, that's why the game corps like it so much. But is this actually good? So very often with these hyper competitive games played between strangers competing for global ranking, the whole thing turns very toxic, with gamers often seeming to not even enjoy the moment to moment process, often raging at their incompetent team mates or raging at their opponents for supposedly cheating, or whathaveyou. All the while, not developing relationships as they could be if they were playing something with friends. Elevated cortisol levels, when they could be chilling out. Obviously it's profitable, but is it good?
- trostaft 7mo agoRespectfully, I think you're missing my point. > So very often with these hyper competitive games played between strangers competing for global ranking, the whole thing turns very toxic, with gamers often seeming to not even enjoy the moment to moment process, often raging at their incompetent team mates or raging at their opponents for supposedly cheating, or whathaveyou. This is very true! I'll further grant that many competitive video games have pain points that fester this. Competition, facing failure, and recognizing that what they perceived to be a fair challenge wasn't so (e.g. cheating) does sometimes out the worst in people. However, my point is that competition, and enjoying it, is something that's been fundamentally human for all our recorded history. The sensation of straining against the edge of your capabilities, to overcome a wall, and then succeeding even just barely is supreme. Competitive video games are just a subset of activities that appeal to this. And I think just as much as they are infuriating, they are also good! Moreover, competitive video games can also be fairly social. Playing a chiller game with friends is one way to socialize, that I have nothing against. But there's also special bonds that are forged through shared struggle, even minor. For example, the fighting game community has a very strong local scene. If you can play fighting games, in most major cities in NA you can attend your local and make friends. With team competitive games, invite your homies. Once again, I definitely do not dispute that competitive video games can be toxic. Especially in today's online culture. Taking fighting games as an example again, the online, anonymous, communities can be quite toxic. Ah, now that I've written this far, I'm realizing that maybe I've missed your point? Are you saying that it's specifically the strangers, that you never get to know and therefore trust, that makes this worse off?
- alstonite 7mo agoIt’s crazy to me how hard people work to effectively ruin a game for themselves… Imagine putting in this much effort to play Minecraft survival but on creative mode. It just doesn’t sound fun
- gzread 7mo agoThey're getting some actual reward from having a big win/loss ratio. I don't know if that's monetary or just the feeling of being the best but I'd expect the latter group to realise this is all nonsense before spending money on hardware.
- davispeck 7mo ago[flagged]
- samgranieri 7mo agoremember when Sony put a rootkit an an audio cd to prevent people from ripping the cd?
- samgranieri 7mo agoI think I'll just stick to simple games on iOS/iPadOS or just use my Nintendo Switch. These anti-cheat systems are far too invasive for my liking. I also worry about those things being hacked! The last time i built a gaming pc was 20 years ago, and i was playing Doom, FEAR, and Half Life Two.. Then i did some simple gaming on macOS
- snvzz 7mo agoSo they are full-on rootkits. Question being: Why aren't they all blacklisted? Why does Microsoft allow known malware to run?
- cedws 7mo agoI know that Counter Strike has the Overwatch system so that the community can review the gameplay to determine if somebody is cheating. Could this be turned into a bounty system for developers? You could give developers access to gameplay data through an API and they would write their own algorithms to detect cheaters. If they are correct then they’re rewarded, if they’re wrong they’re penalised. Kind of like CAPTCHA. Using a diversity of algorithms developed by the community could make detection a lot more accurate and more difficult to evade.
- Hackbraten 7mo ago> A baseline hash is computed at game start, and periodic re-hashes are compared against the baseline. In 2015, Apple briefly used this “hall monitor” technique for iOS 9 [0] but abandoned it when they learned that the whole approach is fundamentally flawed. Looks like anti-cheat developers reinvented this old trick even though it doesn’t work. [0]: https://xerub.github.io/ios/kpp/2017/04/13/tick-tock.html https://xerub.github.io/ios/kpp/2017/04/13/tick-tock.html
- kwar13 7mo agoWhile I don't think I have any first-hand use for this, the article did and excellent job in teaching me about anti-cheat tech
- pandaforce 7mo agoCheaters are always 2 steps ahead, all that developers can do is to trim the less willing ones.
- ddactic 7mo ago[dead]