No game should require a kernel driver.
No game should require a kernel driver.
It's a security theater.
That in turn means you need some other way of "revoking" or "repudiating" that signature. In the case of TLS for example, it's a certificate revocation list.
I don't know if there's such a mechanism on Windows Kernel.
People always take the path of least resistance which is Windows on the laptop/desktop that they bought at Best Buy. They won't reinstall their OS because they don't know what it is.
Is this known behavior documented somewhere I can learn more about?
With proton a lot of games now run quite nicely asides from the ones that require anticheat systems.
(and no, already using linux as daily driver doesn't count, none of those folks were even remotely impacted by this windows-manufacturer-signed rootkit-on-windows problem.)
This is misleading IMO. The dashboard doesn't do a good job of letting me know what proportion of mainstream games (from Ubisoft, EA, etc) are supported. And what the performance delta is.
No matter if your game has crappy memory management and the escalation exploit roots your XBOX, an update will quash that. But people are banking and buying/mining crypto and then launching fortnite or whatever.
Game security is nuts. It's always been a training ground for RE/binary exploitation engineers, so thats a plus.
That doesn't seem plausible considering that a lot of games run under linux with wine/proton, so clearly they don't need direct hardware access.
Maybe low level hardware access is not the right term, versus excessive privileges that the hardware acceleration libraries require?
lol, no. The industry has converged on a small number of engines, which is why you see so many cross platform games - back in the day that usually required subcontracting out the task of porting. Also, what is it that you imagine they need to poke so deeply in hardware that they need to bypass the kernel?
Point taken, do you think there is any reason they can't run with locked down privileges or is it all anti-cheat?
https://doomwiki.org/wiki/Broadcast_packet_meltdown
Making software is hard, I’d not be so quick to judge the GTA devs, especially when GTA games are massively larger development undertakings. Doom was made by a handful of people in less than six months - GTA most certainly wasn’t. There is such a vast difference in complexity I’m not sure there is much value in comparing. The entire doom source code is likely smaller than a single grand theft auto save file.
hmm, having a hard time determining if I'm simply defending an entrenched position or if the fact that they were the first to write FPS netcode might excuse the fact that it didn't initially run super great on corporate IPX networks that wired everything together with hubs instead of switches :) I vaguely remember hearing about that bug, and I very likely played the game prior to getting my hands on a version with it patched out. Never noticed a problem in the computer lab, but then we were still on token ring - where collision lights weren't really a thing.
> The entire doom source code is likely smaller than a single grand theft auto save file.
Is that a defense of GTA, you think that "complexity" is needed? I don't think so, I think it is emblematic of something very wrong in not just software - but in the mentality one would need in order to look at the depth of our average stack traces and think "Meh, 25 calls deep isn't bad for text file pretty printer".
Doom is gloriously simple by today’s standards - it doesn’t even support “room over room”. That isn’t a criticism of today being over-complex either - the state of the art in gameplay systems has just moved on massively as compute power has increased. We take “room over room” for-granted in 2021 which we couldn’t in the 90s.
Separately, if you can manage a software release with 1000 human developers, multiple release platforms and millions of users over 5 years (like GTA 5) and not ship random little performance bugs, you need to tell the rest of the world the secret of how you did it.
That isn't what I said, it isn't even close enough to pretend that it isn't a bad faith interpretation designed to strawman an argument where you don't look totally ridiculous. Here, lemme help you get back on track - you said: "The entire doom source code is likely smaller than a single grand theft auto save file." You think I might have been addressing that?
> Maybe you are still ok with 640kb of memory too though? ;)
Oddly enough, I'm currently writing an (eventually) open source firmware for an ancient APC SmartUPS that used a variant of the 8051 MCU... I'm finding the 16K ROM and 256B RAM pretty roomy. I expect the other two people who eventually flash it onto their hardware in the next 30 years will be very pleased.
> random little performance bugs
lol, writing a microtransaction json parser that increases load times by an order of magnitude, for millions of customers, for years - and is so braindead that somebody with all the resources of a freeware decompiler and a stopwatch can do your job better than you... that isn't a "whoops, more seizure t-poses", that is a "I care so little about the quality of my work that I'm not even gonna bother dumping a flamegraph for that 10 minute freeze everyone has to sit through - for years."
You're confusing "this is necessary" with "there are no (horrible) problems with this".
Doom needed low-level access because it was (at the time) simply impossible to make the game run at a reasonable speed without low-level access. Separately, Doom had bugs, because all software is terrible.
GTA does not need low-level access, because everything is has a legitimate reason to do runs at reasonable speeds on modern hardware (or if it doesn't, low-level access won't speed it up noticeably). Separately, GTA has bugs, because all software is terrible.
Just checked, "linuxdoom-1.10" (https://github.com/id-Software/DOOM) is 1.26 MB, my GTA save is a little over 500 kB. The GTA save files are actually quite small, likely because most things in the game world are emergent behavior of the game's systems and aren't permanent state (like in e.g. TES games, which are notorious for large save files, as well as save file corruption bugs due to "oops we didn't think saves would grow bigger than 16 MiB!").
That actually makes it more impressive, since the GTA game world is the result of all these systems working together to create a "living, breathing world" indeed, versus what you see in most other open world games (most recently: CP2077).
Modern hardware and modern operating systems usually take care to ensure that any hardware acceleration features are exposed in a way that doesn't create security risks. And, unlike on consoles with known hardware, it doesn't make sense anymore to try to talk to PC hardware directly from a game because things like GPUs are so varied and have so much "secret sauce" these days that trying to create custom drivers is an exercise in futility.
Edit: rather than downvoting can someone offer a reason as to why?
I'd also suggest that human moderation is definitely less consistent, and definitely less able to scale.
Nobody is trying to solve the halting problem in the kernel either. If a cheat runs as a kernel level driver, and anticheat doesnt you've lost the battle already.
It makes sense the cheat I wrote would run as admin. It's my PC after all. I also don't have access to the server in any meaningful way and modify other people's data, either. It's a good trade-off. Devs can also write arbitrarily good statistical analyses for the game. It's their responsibility.
The question is simple - is this person performing abnormally? Well, games gather tons of telemetry nowadays, and the harder-to-detect cheats like wallhacks or fluorescent player textures are also the least useful. I am a hard silver I in CSGO. With or without aids, when I see someone run around the corner, I'll duck and magdump. Any gold nova will overpower me either way.
If you're watching the game as a moderator you could never tell that's what's happening. Yet -20% recoil, especially for a competitive esports player, would be such a massive advantage as to make that player the best in the world, but a way that looks quite legitimate.
Especially since the cheats need to be available somewhere, so the developers should certainly be able to get their hands on them to test...
And if the response to that is ever more invasive surveillance technology then that's a security problem.
It's putting the collateral damage of these measures on the honest people to deter a few. These rootkits make everyone's systems less secure and less stable. Some even keep running after you close the game.
This is a hidden cost put on the consumers so that the game developers can profit without having to design a game that is safe when dealing with untrusted clients.
It's putting the collateral on _everyone_ to deter a few who have a substantial impact. It's completely different to DRM where there is no knock on impact to other legit customers.
> Some even keep running after you close the game.
They all do. If they don't, then the cheat just needs to run first.
> game developers can profit without having to design a game that is safe when dealing with untrusted clients.
This isn't about profit, and thinking it is is pushing your agenda. On the most extreme side you can just pixel stream a rendered video feed, but the latency is awful for many kinds of games. You inevitably need to let the client have some sort of say (I shot at X), and it _will_ be abused.
That is nonsense, otherwise the driver would have to be loaded at boot time, which in turn would mean installing a game would need a reboot which just isn't the case these days.
> It's completely different to DRM where there is no knock on impact to other legit customers.
The media industry claims that piracy cuts into their profit which would imply that it raises prices for everyone. So no, it very much is like DRM in many aspects.
> In the most extreme side you can just pixel stream a rendered video feed
Which is expensive since you now have to pay for the hardware instead of your customers paying for it, so that too is about profit. In a more extreme case you could put cloud gaming machines wherever CDNs put their edge acceleration boxes.
> You inevitably need to let the client have some sort of say (I shot at X), and it _will_ be abused.
No, not really. The client does not have to compute the canonical outcome of game mechanics, after all for any action they predict locally there might be an action taken by another player that is inconsistent with that prediction and they will only learn about that incompatibility once their lightcones intersect (which takes a few milliseconds). Something has to reconcile those, which might as well be the server rather than the client.
All a client has to do is to compute a tentative game state and the pixels that go along with it. That state will later be corrected once it learns about the canonical update, which can result in the infamous rubberbanding effect.
Most cheats that don't involve a broken game engine are of two flavors A) extracting information that the software has but the human shouldn't know (e.g. wallhacks) or B) having software perform inputs that the human should do (e.g. aimbots). A) Can be prevented by reducing the information the server sends to the client to the necessary amount to render their current view. B) cannot be prevented by any means as one could always hook up the output pixels of a GPU to an external computer and an emulated mouse via USB, this is analogous (heh) to the analog hole in DRM.
Neither of those have to do with the client determining "I shot at X" on its own.
Riot Games' anti-cheat Vanguard (for LoL and Valorant) loads early during boot, requires a reboot after installing and if I recall correctly they now allow unloading it (because who wants to do banking with a rootkit loaded) but then require a reboot before playing again.
If they go further we'll end up with closed, console-like systems (secure boot only with microsoft's key, only signed apps allowed). And of course DRM vendors would follow their footsteps.
This is already common - see valorant as an example.
> Which is expensive since you now have to pay for the hardware instead of your customers paying for it, so that too is about profit. I
No, it's about latency. See the absolutely vehement reaction to streaming services for twitch shooters on gaming forums.
> Something has to reconcile those, which might as well be the server rather than the client.
The problem here is that the server is some distance away from all the players. Waiting for a round trip from two players with server frame times could be up to 250ms, so for a better experience, some element of that is usually left up to the client; you can spin that either way, either the shooter gets the advantage, or the defender gets the advantage.
> Most cheats that don't involve a broken game engine are of two flavors
Most game engines are broken. The reality of the situation is that 1) this stuff is _really hard_, and 2) there are tradeoffs to be made at every single step of the process that affect how the game plays and feels. Moving processing to the server means latency, predicting and correcting server-side calculations means rubber banding. Neither of these things feel good in a twitch shooter.
> A) Can be prevented by reducing the information the server sends to the client to the necessary amount to render their current view.
Not just their current view, but everything the client needs to know about the next X ms before it expects its next server update (which might even be adjusted at a later point in time). And that state is just sitting there in memory, waiting to be (ab)used.
> B) cannot be prevented by any means as one could always hook up the output pixels of a GPU to an external computer and an emulated mouse via USB,
The number of people who are willing to do that is drastically smaller than the number of people willing to pay $130 a month for a rootkit that they willing install [0]. As I said in my previous comment, this isn't about eliminating cheating 100% - it's a cat and mouse game. It's about raising the barrier to entry from credit card to specialised hardware.
[0] https://www.skycheats.com/store/category/6-overwatch/
> Neither of those have to do with the client determining "I shot at X" on its own.
Even if you send inputs, and allow for a small amount of correction (because both clients have different representations of the game state at the same time), all it takes is one client to send "I actually did shoot at that guy 50ms ago".
By putting trusted hardware close enough to the player you reduce the latency problem to a cost problem. This is more or less what game consoles currently happen do (of course the issue is that users still pay for it rather than the game company). Also, twitch shooters existed before rootkits. Choices made by game companies such as matchmaking with untrusted strangers probably exacerbated the problem over the years.
> Waiting for a round trip from two players with server frame times could be up to 250ms,
Only if they're living on different continents or have very high latency internet providers. Many games provide region-based servers for that reason.
And it's only a roundtrip that has to happen anyway. Clients stream their updates as they take actions, server reconciles them as they arrive and broadcasts the updates to all clients. This is the minimum amount of time it takes to get the information from player A to player B anyway unless you establish p2p connections between the clients and those happen to be lower latency than contacting the server.
> you can spin that either way, either the shooter gets the advantage, or the defender gets the advantage.
That doesn't matter, the point is that leaving reconciliation of some game actions to the client means clients can lie about something and claim that it was preempted by another action.
> Most game engines are broken. The reality of the situation is that 1) this stuff is _really hard_, and 2) there are tradeoffs to be made at every single step of the process that affect how the game plays and feels.
A problem being difficult is not a good justification for externalizing the costs, especially considering that hardware may be shared with other people and botnets that might use those weaknesses create further externalties.
> "I actually did shoot at that guy 50ms ago".
That would mean trusting the client's clock which quite obviously is something you shouldn't do. Arrival time should be the only thing that matters.
> The number of people who are willing to do that is drastically smaller than the number of people willing to pay $130 a month for a rootkit that they willing install [0]. As I said in my previous comment, this isn't about eliminating cheating 100% - it's a cat and mouse game. It's about raising the barrier to entry from credit card to specialised hardware.
That's only the tradeoff from the game dev perspective. It's totally ignoring the security or privacy implications of running these rootkits and the ever-escalating system restrictions that they demand. This is the crux of the argument. If we were only talking about game devs making tradeoffs between different game experiences, risk for themselves, profit and so on there wouldn't be a problem. But they're making a tradeoff with other assets that are not theirs.
I think at that point, it's turtles all the way down.
How many computers have Valorant's anti-cheat installed on some computer it shouldn't be installed on, that suddenly gives the ability to decrypt and monitor tls traffic on the device, without detection?
It would make a lot more sense to detect cheating based on user input. Even stochastic cheats are possible to detect (where you say improve your aim in more subtle ways), yet, the most egregious auto-lock-on go on for years.
Kernel level anti-cheats are attractive, because you suddenly have a rootkit installed on millions of computers that you control. Monitoring the behaviour of them is also no good, because a targeted update can make it do whatever.
They’re also very much required, because a user mode anti-cheat is trivially circumvented by a kernel mode cheat. The only way to defeat cheats is to wage continuous war with them, adapting to their tactics and stamping them out. It’s like collecting trash; trash will keep accumulating, your goal is to keep homes and streets clean in spite of that.
I don't give trash collectors access to my bank account so that they can better estimate the amount of plastic I'm about to produce and better prepare themselves to make streets even cleaner
You'll never completely stop people cheating, but that doesn't mean that game developers should just give up. Thankfully the people clamouring for less, rather than more, anticheat is relegated to a vocal minority.
That's a weird notion of "required". Very few things are "required", notably food and oxygen. Saying "no" to bullshit like rootkits is very easy in comparison.
Of course, it still makes me avoid such games, but saying the argument is invalid because required only means air and water is absurd.
Instead, we get security theater and everything must be F2P to get the maximum number of people in the door.
https://win.gg/news/8115/is-ai-the-future-of-csgo's-anti-che...
1) if you want a challenging game sign into normal game server
2) i you want a cheat game sign into cheat server
3) if you cheat on a normal server, you are banned for life no questions asked from ever using a non cheat game server
Or accounts with the Prime upgrade that makes cheaters less common are often stolen ("cracked primes") and sold to cheaters for a few bucks.
If a 13-year-old cheats at a game, do you really think they should still be banned when they're 30? Permanent punishments for things people did as minors are essentially unheard of for anything less serious than murder or rape.
Whatever type of anti-cheat you want, you can implement it at server-side with today’s hardware capabilities. However, that would increase server requirements and bandwidth considerably, and as companies don’t want to pay for that they install rootkits to people’s computers.
(I agree though that low-level anticheat also doesn't 100% solve cheating, and causes lots of problems for legitimate players. Just that cheating is always going to be a game of cat and mouse)
You don't need a hack for this; the whole point[0] of having footstep sound effects is that the player can detect the location of the audio sources playing footstep clips.
Edit: 0: well, and ambiance, but if your ambiance is impacting your tactical considerations, that's a game design issue in and of itself.
Will I see enemies behind the corner instantly, or do I have to wait for round-trip time for the server to acknowledge that I stepped out of the corner and tell me where the enemies are?
Can this happen in the game you make? If yes, do you consider this a vulnerability?
1. There is no such thing as perfect anti-cheat solution with today’s resources. Even client side rootkit based solutions can be overcome.
2. My solution completely eliminates wall hacking at 90% of the cases, same can’t be said for the rootkit anti-cheat solutions.
3. Game can be designed to put corner campers to disadvantage. But honestly no need to think extremely deep about such cases, you would first release the game then check the player complaints about wall hackers. If it is a major issue then you can implement a double ray-cast solution for most reported players, use correct size wall for their ray-casts and ban them statistically. Even if you can ban players accidentally it wouldn’t be a huge portion of your player base.
It is true that there is no silver bullet. Anti-cheating solutions are all about compromises. Ring-0 anti-cheats are just another compromise that enable anti-cheat developers to scan for cheats efficiently, with some risk of privacy abuse added (and not as big risk as some may think - I believe Microsoft would revoke driver signatures from any anti-cheat developer that tried doing shady stuff, after which the developer would go bankrupt, most likely). This is not a compromise that most of HN would take, but I don't see a problem if users are well-informed about the risks.
False-positive bans of legitimate players can become a legal liability, especially for users that paid real money for the game.
If you mean they can implement a fully server-side anti-cheat without compromising gameplay experience and without requiring the player to have a super-duper fiber connection with 5ms ping to the game server - no. They certainly can’t do it, not for fast-paced online shooters at least, not in this day and age.
In any case, I'd argued the integrity of the OS is far more important than a game's anticheat. Game devs could ship kernel mode anticheat but user's should be at least more aware that they giving full control over to these programs.
The games I play don't have these sort of anti-cheat features; the anti-cheat is handled entirely on the server side. A server admin who is attentive and ready to rollback griefs helps a lot too. But kernel-mode anticheat on the players' computers is not "very much required."
(The game I play most is minecraft, and I think it's more popular than any of the games with this sort of invasive anticheat.)