I honestly see both sides of it, but at the end of the day, I am always hesitant to trust software with black-box functionality deep access to my computer. When I see a sudo command
We are already at the point of computers being able to balance a ping pong ball on a flat surface using just cameras. I can't imagine we are far from cheaters using entirely decoupled computers to physically control devices.
The idea of a decoupled cheat would be to acquire the game state from outside the computer running it, either by filming the screen or taping into the video output or the network input, then analyze it and run some aimbot (or any other kind of cheat) on it and finally send the cheat commands as if it came from a legitimate controller, through usb.
These checks have in the past been notoriously buggy, and can interfere with other operations.
This kind of crud is what remote attestation is for, and Microsoft should be responsible for developing it, not every different gaming company competing with each other for kernel access.
Private cheats usually require being vouched in, sometimes with ID scans, sometimes physically shipping you hardware.
I get the sentiment here but we're specifically talking about a mechanism specifically designed to detect other software that is used for cheating.
The alternative is a world where games will only run on machines with SecureBoot, a signed kernel with kernel security on, and only whitelisted signed modules.
There isn't a good solution for how to run games where the clients have to be semi-trusted on a hardware and software stack controlled by the user. If you give me total control over the environment in which a program runs I can make it do and believe anything.
So you have two choices here. You either ban the best players or the aim bots just behave with a success rate close to the best players.
And when I'm talking about statistics here, I'm not referring to the kill/death ratio, but rather all input data received from a cheater.
If it is only as good as a real player than it won’t be invincible and will be equivalent to playing with a few AIs in a multiplayer game - which already happens.
Also, I believe the exact mouse movement will not be the same for a human and an aimbot - so not only statistics can be used to ban players
I recall seeing players hovering in the air and spinning while shooting rockets out at hundreds of rounds a second. There was also a way to modify your files such that you could crash a game just by joining it. The experience was as interesting and fun as it was awful.
In a way, it's true that it's none of their business which softwares you use, but it's also their business to make sure the multiplayer experience is fair for the entire userbase.
I guess that's the beauty of games consoles, where the execution of softwares is tightly controlled to minimize piracy and cheaters.
When games switched from server browsers to matchmaking, they just defaulted to using the anti-cheat system.
Everything that makes the game fun is defeated by a single cheater.
So people are just going to choose between playing with 0 cheaters or go play a different game.
You now maintain a list of potentially vulnerable drivers that can be used as a jumping off point (such as virtually every motherboard RGB or fan control system), and ban users that have these or hard-disable them at boot. There are some games that have caused machines to overheat by disabling cheat-jumpoffable fan controllers.
On top of that, you effectively have to maintain a whitelist of acceptable drivers, because cheat vendors are registering limited companies by the thousands (only $20 in the UK), getting an EV/codesigning cert, and signing their own drivers. Higher end cheats cost enough to offset this, and there might be less than 5-6 people using a particular certificate. Some of the people behind these also release vaguely-useful legal tools signed with the same certificates to get a large install base for them so they don't stick out.
That being said, IMO as a player, this is invasive as hell, and you should not be crawling through my flash drives, identifying my mouse, killing LogitechMacroSoftware.exe, etc. I'd rather you just collect snap/targetting/click timings server-side and run anomaly analysis on those rather than digging an asshole into my computer.
Also, now I have 5 different "kernel anticheats" running 24/7 simultaneously, half of them are horrifically written and known-insecure, and the other half need to figure out how to not explode spectacularly when the broken half tries to probe and kill it.
Korean MMOs are particularly bad for this and when forcefully uninstalled might permanently destroy disk access, make Windows non-genuine and deactivate it, and send all their data over plaintext (no TLS) with a bizarre, homegrown "encryption" method that is trivially breakable to a bare IP somewhere.
With KMMOs as an example (many of these reward you for staying logged in, have daily rewards, and similar; the game itself is fairly low resource when minimised), GameGuard and HackShield and XIGNCODE constantly have slap-fights where they bluescreen or flop over or die if you try to run multiple of them simultaneously and they try probing and killing each others' services for trying to tamper with themselves. It's like that ridiculous "what happens if three programs all try to demand Always On Top for their window", except give all of them heavy weaponry. These also have severe NIH syndrome for things like homemade shitty crypto and plaintext everything.
While other anti-cheats maintain white lists or blacklists of vulnerable drivers, I’ve chosen a different route that doesn’t have the same pitfalls you suggest. Our anti-cheat also doesn’t run 24/7, only when the game is running.
This type of BS is super common in Asian countries/published MMOs and a bit less acceptable in the west (you still have EAC and battleye, but at least they make an attempt to use TLS?)
Another insane example: xigncode has long since advertised a feature that the game developers can remote control into your PC like VNC. I don't know whether any developer has chosen to actually enable it, but the fact that they push it as a feature is some serious clown-egg-face.
Vanguard I believe would intentionally bluescreen you if it detected you’ve disabled PatchGuard. They had very good reasoning to do so, but I wouldn’t do something like that since I believe it’s user-hostile. Battleye I believe actually doesn’t use TLS last time I checked, using some sort of home brewed XOR cipher which is a bit scary. And of course remoting into computers is unacceptable under any circumstance.
I've done both sides (largely MMO-stuff as a kid), and for me, I'm done dealing with all this invasive garbage, and just spin up a fresh EC2 GPU instance when I want to play something, and simply don't play the games that choose to disrespect and abuse players to the point of not even allowing GPU passthrough (I can somewhat understand banning emulated GPUs; have dealt with people farming referral accounts a hundred at a time each queuing for games at <5 FPS).
Keep doing what you're doing. Just, if you'd leave the anti-cheat off friend-to-friend-PvP games, that would be cool. I don't care if my younger brother 'cheats' against me. He's not going to and if he is 'cheating' it's probably some mod or something.
They've sort of fixed this now by letting you disable it, but it requires a reboot so I'm still avoiding Valorant for now.
You could tell they were cheating because if you watched replay from the cheaters point of view their mouse cursor would jump from current position to hovering over the target instantly and then immediately jump back to cursors original position all within a frame or two.
Yeah, I just don't see games needing access to such kernel level items.
If they're providing online servers for you to play on with other people, under the condition that you aren't cheating and they are responsible for stopping cheating for everyone, they very much do care and it is their business, if you want to use their servers.
Having custom drivers is how you get wallhacks or custom mouse control macros that eliminates some of the challenges imposed by the game (e.g. automatic recoil control).
For a single player game, I agree, who cares, but for online games that live and die by competitive play and stopping cheaters so people can enjoy it, there's only so many options of how to find cheaters and so much resources to put towards it, so you get stuff like this.
My own example: I have an xbox 360 dancemat, which is unusable with the official drivers (they map the arrows as axes, so treat left + right as nothing). So I have to use the open-source XBCD, which frankly I'd treat as more reputable and better code quality than most signed drivers. But since no-one's paying the $100+/year to sign it, it's not signed. And while I understand why Microsoft wants someone to have skin in the game before they issue a driver signing certificate, they really need to find a way to ensure that reputable, established open-source driver projects get signed if they want users to accept driver signing; I wouldn't even mind being stuck on an old "certified" version or something.
Hence I just stay away from AAA games with anti cheat at this point.
No doubt there will continue to be intrusive anti-cheat software in use with some games for a while because some people are disturbingly desperate to play those games and they use operating systems that are junk. Some people still pre-order games too, even though it's illogical to extend that old physical world idea to downloads.
But in the long run, this kind of software is a liability. Better operating systems and more gamers moving to them will eventually kill it for that reason if nothing else does first.
Given that cheating only matters if it actually affects gameplay unfairly, it has always made far more sense to look for cheating through its effects on gameplay anyway, which is something you can observe server-side in an online PvP game. Trusted client-side security checks make no more sense in this context than any other. So it's not even as if killing off the intrusive client-side anti-cheats will lose anything of value in the long run.
The best way to handle cheating is to give the players moderation powers.
Games for some reason today want single central server, instead of dedicated servers with user maintained communities is part of the problem. (E.g. cs:go vs older cs)
Especially with team gameplay, players want proper skill based matchmaking. So that they don't have someone on the other team who destroys them. Or someone on their own team that is dead weight.
As well as more structured games that are not 10v10, but rather smaller 5v5 or 6v6 games, where each player can make a difference.
Cheaters are better at hiding too. Toggling aimbot for a quick kill or two isn't enough to arouse suspicion, and can be passed off as a lucky headshot. Just because you think you've never run into a cheater doesn't mean you haven't.
On the other hand, a really skilled player might be good enough to make you believe he is cheating. Getting vote kicked or banned out for that is not good either.
It's another social problem that engineers try to solve with technology.
Consider game like Dark Souls 3, it has very simple anti-cheat system and trusts the client completely. Yet you rarely see actually cheaters online, this is purely a social problem.
You can search any rootkit based anti-cheat software and find just how many people have issues with them. Just some examples from the infamous riot vanguard which developers boast it being "user-friendly" rootkit.
* https://www.reddit.com/r/pcgaming/comments/gead0n/riot_vangu...
* https://www.reddit.com/r/VALORANT/comments/geqc73/have_you_d...
* https://www.reddit.com/r/VALORANT/comments/gbebt0/if_riot_is...
* https://www.reddit.com/r/VALORANT/comments/g5aem3/vanguard_a...
Anyway, it seems to me that most of those people just need to update their fan control programs. One example I saw was CPU-z which had a CVE in their driver a few years ago. They are using drivewrs with known vulnerabilities. You also need to consider that some cheaters will also spread mis-information.
Server browser is a hidden afterthought behind a dropdown.