Similarly, IMO it feels shoddy when Steam acts as a "launcher for another launcher" when starting a game.
Similarly, IMO it feels shoddy when Steam acts as a "launcher for another launcher" when starting a game.
But it would be nice if any single player game was sandboxed.
Likewise, it would also be nice for the option to exist for private servers. If the server admin trusts their users or is okay with anything goes, there is no need for anti-cheat.
I am ok with that market dying in a fire admittedly..
Usually when micro-transactions are present everything is validated server side, Leading to always online games like diablo 3+.
From my understanding kernel level anticheat is to detect things like aimbot, wallhack etc.
Street Fight 5 did the same thing; it was possible to unlock characters for local play using a trainer. They patched in a rootkit with known vulnerabilities in an attempt to prevent that.
() technically a lot of games have anti-piracy measures that are somewhat active, but they're rarely of the "phone home" variety
This is what I can't wrap my head around. Every multiplayer game I ever played on PC had cheaters in it. The anti-cheat stuff seems like it just inconveniences the good guys, and does little to stop the bad guys, so what's the actual point? I play on consoles now, and the fact that there are no cheaters is probably half the reasons why. I've seen video of Battlefield 1 on PC these days. It's comical, as long as it's not happening to me.
Similarly, I imagine the more effort you have to put in to get through anti-cheat software, the more likely you are you give up and play a different game. There'll still be some people determined enough to bypass it, but that number will be smaller than it would be otherwise.
Fwiw, I don't play these sorts of games, so I have no idea if this stuff is effective, but there's a comment somewhere in this thread saying that Valorant has fewer cheaters than other, similar games, in no small part due to their aggressive anti-cheating measures, so anecdotally it may well have an effect.
I'm sure there's some magic threshold where they say, "Eh, this kid only had it running for a week, and the account he was running it on was 8 years old, and gosh... we really don't want more customer support calls and complaints. Let's let a few slide." I'm sure there is some sort of "how serious is this offense" algorithm.
Video games have so many cheaters, but it's rare for the accounts to stay active for more than 3-6 months.
But you're right, they should ban faster, and they should do more to stomp out cheating. For people who play by the rules... it seems unjust that they don't ban faster.
One theory is that they time ban waves to increase sales. "Oh sales are down this month, better ban some more folks so they'll re-buy the game with new accounts."
Don't forget, in a lot of games, players buying in-game currency (or items) is what fuels bots / cheating. The game makers need this sort of behavior to keep some percentage of "legitimate" players (the indirect cheaters) happy and on the platform.
I'm sure they have all the math worked out. They ban at exactly the pace needed to maximize profit.
There are definitely fewer cheaters overall on console but there are more than you may think: https://www.youtube.com/watch?v=vC1dcQqCqFc / https://www.cronusmax.com/
Valve is the only organization that could pull that off, and it would further deepen the entrenchment of their position as the meta gamemaster of all PC play.
Take that whole tarkov meltdown for example (YouTube g0at tarkov cheater). Everybody is screaming "needs moar Anti-Cheat" left and right when the first thing I wonder is "why is the server sending every client the position, health and inventory of every other player all the time?" - obviously the answer is because it's the simplest approach. But it's by far not impossible to continuously run hitscan between all players on the server and not update any player positions for players that can't see each other. But of course that takes time and effort to make work reliably, so let's just install a ducking rootkit on every player's computer and use the developer resources to instead add microtransactions or whatever.
But when I try to play a battlefield game these days you often get hackers who can go really fast across the map. And detecting them sounds super easy server side.
After six months we were just good enough to approach Labs and Nikita's team pulled a Wipe out of the blue, the very next day.
The cheaters are openly coddled. The 'famous' streamers are avoided by cheaters because of the unwanted attention, so they make the game look good by accident.
It's a damn shame that a mechanically fine game like Tarkov is ruined by Nikita and his pals playing cowboy with the game's management. Tarkov costs more than equivalent FPS's (2x the price) just to be treated like trash by the devs.
Anti-cheat can't fix bad management.
I believe the only real alternative would be something at the hardware level. Your hardware should be able to get into a mode where an executable has a protected memory address space, and maybe even a protected relationship with GPU memory and displays. Otherwise I think all anti-cheat tends to be
(1) Fragile, relying on OS mechanisms that can be often bypassed;
(2) Extremely intrusive from a security and privacy standpoint: they need to monitor your system, almost everything it's doing for any attempts to read or modify relevant memory or control input to give unfair advantage (or say bots) to some players.
Finally, I guess we should remember there's always the famous 'analog hole' (a-hole) that defeats all mechanisms from simply capturing output and feeding it to another machine (that's very hard to plug). But because it really need dedicated hardware and significant effort, a hardware level anti-cheat would generally be a very significant solution to cheating without sacrificing users rights.
Something Awful did this with their forum and it does a pretty good job at keeping spammers and other irritants out.
Matchmaking killed off that option, so we're left with controlling technical solutions like kernel code and relinquishing the client-side benefits entirely in favour of cloud gaming.
Honestly, I have no idea why people think Anti-cheat can work anymore than you can stop 0days or secure a bank account. Computers were fundamentally designed to be open machines that accept input on every possible level. We've locked ourselves into chasing a horse that's already bolted. Trying to secure the multi-headed hydra.
The day anti-cheat is possible, is the same day you end piracy, kill the cybersecurity industry and shut down 'unauthorized' code of any kind.
Do we really want that? Better to make cheater-policing the job of gamers themselves, with community servers and better tools.
Outright manipulation of game-state is a classic computer security issue. Just don't trust the client, calculate that on the server. I believe many games are doing this properly already but especially mobile games still suffer from it because they trust the client more to paper over intermittent connectivity problems.
The information-disclosure kind of cheat, wallhacks and such, can be addressed by game design that minimizes the amount of information exposed to the client.
There is https://learn.microsoft.com/en-us/windows/security/threat-pr...
However it isn’t available in the Home release.
Also unlike macOS or iOS/Android sandboxes, it’s not a process level thing, but rather a VM of some kind.
Plus, if it did introduce sandboxing like macOS, you’d see so many people getting pissed off when their applications start asking for permissions, as can be seen in every single thread that comes up here with regards to macOS.
Personally I think every OS should have sandboxing by default (perhaps as an opt out) because no amount of being cautious as a user is enough to prevent application overreach.
macOS takes a much more hardline approach to this, which is what’s needed for things like this.
- Android apps - Chrome extensions - System apps ... etc.
These should be capable of providing fake data to the app (e.g. simulating no contacts, no working internet, or a fake GPS location), and trying to break out should be an app store ToS violation.
Still keeping windows as dual boot but I only switch to play multiplayer but since I run it only occasionnaly I care a bit less which crap get installed.
Also I'm not sure if sandboxing on Windows even exists.
https://chromium.googlesource.com/chromium/src/+/HEAD/docs/d...
it's not as simple as unshare() for namespaces on Linux, but works pretty well
Chromium's sandbox on Windows is built on top of Windows features (tokens, jobs, desktops, integrity levels, app containers)
Just like how their sandbox on Linux is built on top of Linux features (setuid, user namespaces, seccomp, SELinux, AppArmor)
For both Linux and Windows, the OS kernel gives you a bunch of features you can use to construct sandboxes, but the choice of exactly which of those features you use, and how you put them together, is up to you. Chromium worked out how to combine those features to meet their own security requirements, and has documented that in detail, and open sourced the implementation – there's nothing stopping you from copying the same approach, assuming your requirements are sufficiently similar
With macOS, Apple ships a sandboxing mechanism in the OS, known as "sandbox" or "seatbelt", which is what Chromium uses there
1: https://github.com/sandboxie-plus/Sandboxie
2: https://learn.microsoft.com/en-us/windows/security/threat-pr...
2b: https://learn.microsoft.com/en-us/windows/security/threat-pr...
I'm at a loss as to why the debate here is on Valve and the devs, when I can't get past the initial step: you can install THAT on Windows?
Path of lesser resistance: sandbox games. And have weak (serverside)/no anticheat. Cheating in games isn't as big of a deal as malware in your kernel[0,1]. It's just not that important.
0: https://hackaday.com/2022/08/29/genshin-security-impact/
1: https://www.pcgamer.com/doom-eternals-first-update-includes-...
https://www.ign.com/articles/team-fortress-2-players-protest...
So having some form of preventing cheating is important. Doing it right is tricky I guess
Also, we should not confuse anti-cheat software with malicious software: if you purchase commercial software from an editor who wants to bundle anti-cheat technology in its product, this is not a malicious installation. The security mechanisms you described are aimed at preventing the malicious deployment of code in your system, not the installation of intrusive software on behalf of the consenting user.