Riot Games newest title “Valorant” installs kernel driver to run anti-cheat
old.reddit.com
old.reddit.com
Also, cheating really is so bad that most people will accept it anyways.
Unfortunately we don't have a software nor user culture of, for example, having an isolated partition for our important files and an isolated partition for "I just want to play some games" -- You can imagine how streamlined and effortless and by-default this could be in an alternate universe where it was a top priority.
So people can really get hosed under catastrophic conditions like the anti-cheat becoming a remote backdoor for an attacker. I think this is really where people are let down by modern computing.
I feel this is the part people miss. It's true that it's a cat and mouse game and these end up still being worked around, but cheating has crippled games before.
Search any popular game + "cheaters" and find thousands of posts complaining about these people.
Even if you explain this stuff to people, and admit it's still not foolproof, they will embrace it.
I think we see this mistake a lot in the tech bubble. People assume if only people knew their data was being used they'd be outraged, except if you give them a choice between that and paying for stuff they'll always take giving away their data.
People just don't care that much about the digital "realm". Their online presence, their "digital rights", to them it's all ethereal and a lot of the few who are even aware of this stuff assume the fight is lost anyways, further whittling down the number of people who care.
Facebook is the privacy boogeyman these days, jokes about Zuckerberg are in no short supply.
Yet if you told people you can pay $9 a month and Facebook never needs your data ever again except host it for you, they'd say no. In fact they might be insulted you had the audacity to ask for such a thing. You could ask for $1 and they'd still say no.
It's just the same way they don't value their digital presence, they don't value digital goods and services.
They'll pay $6 every morning for the same cup of coffee worth 30 cents of ingredients and 5 minutes of work, but balk at the idea of an app asking for 99 cents for a lifetime of development work.
I'm not saying that from a place of bitterness to be clear, it's just what I've found to be the inconvenient reality of things.
We are in a weird situation with PC gaming. PCs have always been a hackers friendly platform. Both Counterstrike and DOTA started as mods. Skyrim is more of a platform than a game now. Of course, it also means cheating, but it wasn't a big deal back then. Cheaters were just shunned, or sometimes encouraged, depending on the context. No big money at stake, no big deal.
But now, we want a standardized platform for high stakes competitive play, so why not bring back consoles. They are more than powerful enough for this, and you can hook up a keyboard and mouse if you want.
This is not actually the case. It's part of what makes Doom's aiming for (and, with Doom eternal actually hitting) 60fps an exception. Most AAA games (including competitive games like COD) prioritize visuals over frame rate, and so they are typically aiming for 25-30 FPS.
Also, a number of graphical workloads are still bound by the CPU - such as occlusion culling.
The only plausible attack scenario is if you steal my computer while I'm logged into my KeePassX. It has all my passwords visible. But that session times out as well.
Riot installing a kernel module is more like the latter.
Just request a password reset and change it to whatever you'd like.
Most platforms are edging towards sandboxing applications, with OS X app store, UWP, and the various Linux snap/flatpak/appimage etc things. Web apps and iOS/Android have their own tings.
They want to play the game.
> Are they aware they are giving away keys to the kindom wrt the OS/computing environment integrity just so game studios can take part in an unwinnable cat and mouse chase with cheaters?
They are aware that even if cheaters will always exist, they accept that the anti-cheating measures will stop most people from cheating. As for giving away the keys to the kingdom, everyone already accepts that from Microsoft, a company they apparently trust. Why wouldn't they accept that from another company they trust?
> Also why does Microsoft or AV products allow this without giant "you are giving away root on your box" warning signs?
Because people didn't like that, they were mocked for it, and people became numb to the requests. So they still have warning signs, they are just toned down.
It may be unwinnable, but it is "mitigateable". It is much better to have your game ruined once a week by a cheater instead of 5 times a day. It can be a perfectly reasonable trade off if the game is important to you.
No they're not. Not for cheating in a video game. The reason why cheat makers have advanced to shady rootkit level exploits is because game publishers started doing it first. Stopping cheating in your games is not more important than the security of my computer period. I don't care. Find better ways to manage your game or i'll play something else. I have no interest in your anti-cheat spyware being on my computer.
Pretty sure game companies don't care about the small minority who cares or even understands the implications of this.
But if you don’t want to have anti-cheat software installed, that’s OK! I’m a big proponent of informed-consent, and if you don’t consent, nobody is forcing you to. You just won’t be able to enjoy online multiplayer.
No, i'll be able to enjoy online multiplayer in one of the many, many games whose devs don't feel like they need to monitor and control my computer to provide a quality game.
cheating is very serious problem and there are no easy solutions
teams of skilled developers have been challenging it over decades and this is how it evolved
The market spoke. A few geeks with hangups about kernel drivers are irrelevant next to the masses of people who will happily buy entire dedicated gaming computers designed from the ground up to be physically tamperproof.
Game consoles are toys. Even if the game screwed up the game console, it wouldn't be very intrusive.
There is no such thing as implied consent. There is either explicit consent, or there is an absence of consent.
I honestly wish OS companies would grow a pair and start classifying these systems as malware and removing them.
If OS companies did that then competitive online multiplayer would effectively be dead. That may be fine to you but it's a very selfish opinion considering it would completely destroy the hobby of hundreds of millions of gamers.
So the flip-side of this feeling seems to be just as common.
I pay for ESEA, an external service, which installs a kernel mode anticheat. ESEA also got sued for running a bitcoin miner on users computer several years ago. But it’s the only way to get any semblance of real, high level, competitive play.
This is the context for Riots anticheat. They need to provide a solid AC from the start to pull over players and provide a competitive matchmaking system that isn’t a total joke like Valve MM. It sucks, but I know who I’d trust more between Riot and ESEA. I just run my games in a separate partition and bitlocker my primary OS install.
Another example, GTA online is practically unplayable on the PC whilst it's almost impossible to find cheaters on consoles.
It is impossible to win by playing by the rules if your opponent is not playing by the rules.
An iOS model could help but not because it limits the legit app makers but because it limits what users can easily do, like a gaming console.
There is a universal way to do so, and it is to provide whatever feature the "cheat" programs are offering directly in the official client (either with first-party code or by providing an API that third parties can use).
In general, the way a networked FPS works is by using the server as an authoritative source for information, but doing extrapolation on the client-side. This means that enemies which are not visible to a player must still be known by the client, since the camera and enemy may move into a position where the enemy is visible more quickly than the server can respond. So the client must know the location and velocity of some opponents which are otherwise not visible to the player (because they might become visible).
But, let’s suppose we solve latency problems, and don’t use client-side prediction.
You would need some perfect visibility algorithm for determining which opponents should be transmitted to each client. Those visibility algorithms make a tradeoff between accuracy and computational expense. They are conservative, because it is always an error to fail to draw something which is visible, but it is never an error to draw something which is occluded.
But, let’s suppose we solve visibility perfectly, and only transmit to clients the locations of models which are actually visible, and only the parts of those models which have pixels on-screen.
Consider an opponent hiding behind a wall, but with a small part of the opponent poking out. The game is going to need to draw that part poking out, but if you look inside the game’s memory, you can find that those textures and vertices belong to a model used by an opponent.
Beyond that—we are transmitting a video stream to the client. Basically, we can solve cheating if everyone uses Stadia.
Anyway, the “fancy advanced algorithms” are not really fancy or advanced. They are de rigueur in FPS games.
Every game should have instantaneous snapping of the crosshairs to the target and firing without player intervention? Doesn't sound very fun.
If the resulting game is too simplistic, slowing limitations can be added, such as limiting the maximum speed at which the crosshair can move, or making weapon fire deal little damage relative to health so the target can move out of range if near cover before they die.
Impede the gameplay however you want, in pure mechanical aspects a program will always have the benefit of perfect accuracy and near-zero reaction time (as opposed to the >200ms average of a human)
If people thought that way, nobody would ever play any real world sports. There's always somebody better out there. Yet here we are...
> "If the resulting game is too simplistic, slowing limitations can be added, such as limiting the maximum speed at which the crosshair can move, or making weapon fire deal little damage relative to health so the target can move out of range if near cover before they die."
Again, doesn't sound very fun.
It’s cheating to try and remove for yourself only that reflex-based competition from games that are built on it, and it’s draconian (and not fun) to suggest removing all reflex-based competition from all games.
this is a very reductive view of fps gameplay. in all but the twitchiest arena-style games, anticipating the opponents position is much more important than being able to do a 45 degree flick faster than the other person.
But people can and still make AI- or CV- cheat software that would still work in this situation. Any time there is any sort of user-input there is a way to exploit it for cheat purposes.
On the other hand, it seems naive (from my own naive perspective) to assume your own drivers won't be reversed and defeated, given you already know your opposition is this advanced. So why still go down that path? Most of what I've read has been pretty down on anti-cheat, so I'm quite interested to get the other perspective from someone who personally finds it worthwhile to work on it.
I take a fundamentally different, “zero trust” approach and built my anti-cheat with the assumption that it has already been fully reverse-engineered and figured out. I think if your software relies on security by obscurity you’ve already lost.
But if your interested, https://h6ntechnologies.com/.
Then how do you prevent it from being circumvented?
(1) often justified as necessity to reduce cost of running servers
But take a look at CS:GO. That has some of the best designed networking code from a security perspective. Your keyboard and mouse input is sent to the server, and it figures out where you move or if you shot another player, not the client. And yet there is still widespread cheating on that game.
To address a nuance: You might here object that players in Diplomacy and Civilization have private state. Kind of? The agents that are playing the game do not have private state in the game, and they cannot submit actions which rely crucially on some special state of the game board which is only visible to them. They can, of course, do whatever they like outside the game, because actions taken outside the game cannot affect the effect of actions inside the game. This is the distinction between the game and the metagame [3], or the ludic and narrative perspectives [4].
So, then, when one plays a game like Hearthstone or League of Legends, one might hope that, because there is an adjudicating trusted server, and because submitted actions are limited to those possible within the game, one doesn't need to worry about cheating. The worst a cheater could do, again, is dishonestly choose the wrong action and get a suboptimal result which harms their position.
At this point, some folks might want to get irritated at the poor quality of some game servers. Sure, but there's something more important for games like Counter-Strike or Fortnite, which we cannot overlook: In free-for-all or battle-royale mode, all participants have the same goal. Thus, in the revealed game, all participants would submit identical agents. So, which agent should win? The one with the best randomly-generated starting position? That's no better than a lottery. Instead, we must realize that we are looking at these games as athletic contests.
And now the problem is obvious! You are asking athletes to compete at home and submit proxy scores. All of the spyware in the world won't fix this; the correct answer is to set up stadiums and officiate matches. Sure, it's expensive, but it's the better way to make a competitive spectacle out of measuring things like whose hands twitch faster or whose eyes track tiny dots more accurately. Speedrunners already figured this out, with more and more communities requiring hand-cams and complete splits, and with live runs at events being considered more attested than pre-recorded at-home runs.
Edit: "stadia" -> "stadiums" after reading neighbor comments. I mean that you need arenas, not that you need to purchase Google products. Like, the folks converting paintball and laser-tag rooms into VR rooms are onto something.
[0] https://en.wikipedia.org/wiki/Revelation_principle
[1] https://en.wikipedia.org/wiki/Diplomacy_(game)
[2] https://en.wikipedia.org/wiki/Civilization_(series)
[3] https://en.wikipedia.org/wiki/Metagaming
[4] https://en.wikipedia.org/wiki/Game_studies#%22Ludology%22_vs...
It really means nothing when a company audits itself.
Can you describe a method of detecting binary patching that wouldn’t also detect a changed fork being compiled?
Cheating really ruins online games for many of us.
EDIT: Official comments from Riot: https://www.reddit.com/r/VALORANT/comments/fzxdl7/anticheat_...
They mention they've had multiple external audits of the driver code.
Until it is impossible to cheat it will always be a casual experience only. Maybe this is what it takes to actually prevent cheaters, but I doubt it. It's an arms race and they will always find a way around it.
I think these physical types of cheating systems already exist for smartphones. Last time I mentioned it, some people hinted at systems you can setup for phones - https://news.ycombinator.com/item?id=21991775.
Perhaps we're just waiting on the right software for this type of revolution to occur in PC gaming. I can't think of what's lacking right now though - all the pieces seem to be in place.
They also talk about in more detail here:
https://na.leagueoflegends.com/en-us/news/dev/dev-null-anti-...
None of that came without problems for the users...
I stopped playing when they started forcing you to install something so intrusive.
>In August 2017, Chinese holding company Tencent announced that it had, following a rejected acquisition bid, invested an undisclosed amount of money into Bluehole.[4] Bluehole initially denied that any investment had been made,[5] but later stated that they were in talks with Tencent in multiple partnerships, including the acquisition of an equity stake in Bluehole by Tencent.[6] Subsequently, Tencent acquired 1.5% of Bluehole for a total of ₩70 billion.[7] Tencent reaffirmed their intents to fully acquire Bluehole in November 2017.[8][9] Korean magazine The Korea Times suggested that an initial public offering, through which Bluehole would become a public company, was "out of question" due to Chang Byung-gyu's position as chairman of both Bluehole and the Fourth Industrial Revolution committee.[10] At the time, 38 Communications, a company that tracks unlisted Korean stocks, valued the company at ₩5.2 trillion.[11][12] Tencent plans to invest further ₩500 billion to acquire further 10% ownership, raising their total stake to 11.5%[13] Through the acquisition, Tencent is set to become Bluehole's second-largest single shareholder, following Chang Byung-gyu, Bluehole's founder and chairman, who owns 20.6% of the company.[14]
Thanks for confirming I was right, btw.
> PlayerUnknown's Battlegrounds (PUBG) is an online multiplayer battle royale game developed and published by PUBG Corporation, a subsidiary of South Korean video game company Bluehole.
https://en.wikipedia.org/wiki/PlayerUnknown's_Battlegrounds
I said I didn't know if it was ultimately owned by China. Apparently, it looks like Bluehole is in part owned by Tencent.