Anti-Cheat Expert: all your pixels are belong to us
invlpg.dev
invlpg.dev
I have been gaming my whole life and I miss the "old" days of having community run server as being the default.
You would go online one day pick a server and play on it in the mode you want (For context: I am talking about Counter Strike:Source). Over time you would get into talking with the regulars on the server and you form some bonds. And if someone does something the majority does not like the can be vote kicked/banned. We took care of cheaters/flamers/grievers that way. An admin on the server can still revoke the ban if the banned person explains why it was unjustified.
No it wasnt streamlined, and it was sometimes unfair, and establishing global leaderboards were difficult (see ESL company).
But you had community involvment and soooooo much content (game mods and skins; all for free btw.) and it felt good to be part of it.
The lack of communities is why it seems unlikely. I remember several times successfully making my case and being unbanned!
Usually some friend of the admins was given power, they abused it, then you could go on a forum they hosted/make your case. People would chime in and so on
Children managed to "work from home" decades before the industry did
It wasn't a hassle, it was the point. Curate a community worth spending time in/with
Being denied served a function too. You learned about a community you don't want to be part of!
These companies are so greed driven, that they lobby to make cheating a federal offence and for private police raids and private house searches, instead of making a healthy community based on previous experience. As has, disturbingly, already happened in Australia (https://torrentfreak.com/images/gtaorders-1.pdf)
Microsoft should blacklist these binaries, and revoke developer certificate.
For the paranoid, dual-booting to a games-only OS image would be a reasonable choice.
Wallhacks can be mitigated but can't be shut down completely. Valorant for example limits the information provided to clients based on pre-generated tile maps (for example, players in a tile won't have information about enemies on the other side of the map but will have information on the enemies on the adjacent tile within reasonable LoS) but wallhacks still exist because the LoS check has to be overly generous to account for ping and such
I don't follow. How does the game being server-authoritative stop clients from running software that automatically aims at people's heads?
This comment screams: I lack understanding and am overconfident because of it.
Ignoring games where all state is known to all parties (e.g. chess, racing, etc...), the fact of the matter is that servers are basically always authoritative... where they can be.
MOBAs, MMOs, RTSs, FPSs, Casino, etc... will all hide information not required to run the game on each client on the server to prevent cheaters from getting an advantage.
Turn based games or games with low tick rates (MMOs, MOBAs, RTSs) will run all player commands on the server with things that require immediate feedback (UI actions, current player position, animation triggers) smeared out to sync with the server's state and tweened to match the server state.
Fast paced games like racing sims will do client side determination with server side validation (to ensure that a player's speed never exceeds a certain value, turn speed/friction is inside a certain range, etc...).
FPS games are the trickiest:
- They can't do server side kill determination because the game requires a certain level of responsiveness that is faster than internet signals over fiber can allow for. So they use client-side kill determination that runs in real time with server side validation that runs when a server receives events from clients before passing those events to other players. For example: checking that a player didn't shoot another player through a wall, checking that another player wasn't moving too fast / through a wall / flying through the sky / etc...
- Components that require randomness are split into what requires syncing between client/server and what doesn't. Things like particle systems, ragdolls, etc... are handled entirely on the client. Things like random rolls in stores are handled entirely on the server. Things like physics systems, and recoil are handled by seeded PRNGs that are run on the client for instant feedback and validated on the server side using that seed.
- Depending on the type of FPS game, a client may need to see the positions of all (or a substantial amount) of the other player's characters. This is because a player may suddenly whip around the corner of a door and the client now seeing a new large area needs to be able to display the other characters in that area accurately without the characters only rendering by the time the server can inform the client of their position. This is mitigated by level design that can split a level into multiple chunks and the server only relaying the required info for the visible chunks. With extremely large levels where the groups of players are too far away to interact, the server can be sharded across multiple threads or offloaded to other servers. For types of FPS games that are built in a way that requires the server to not hold as much information hidden (e.g. an open arena level where everyone can see each-other anyway), the clients include replay systems where the players can report suspicious behavior.
- Really tricky things like vehicle physics are usually done with a mix of client side determination, server side validation + redetermination, and careful client side state tweening.
The fact of the matter is that cheaters are only a problem in:
1. A handful of games where the developers didn't do the right thing
2. Games where the only way they could ever be completely cheat-free would be on a physically impossible 0 latency network and instead they have to rely on mitigation instead of prevention where certain information can't be prevented from being available to clients.
----------------------------------------
Addendum: There is the possibility of hosting and processing hidden information client-side while keeping it hidden where needed by using homomorphic encryption but that requires a lot of processing power that's usually better spent on running the rest of the actual game, but it is something that more of the industry will be able to move towards as machines become more powerful.
Got any recommendations I can read? Watch? Listen to? Self teaching myself at the moment and looking for more info on topics like this.
Any tutorials with a tool that lets you simulate latency and packet loss will help you a lot.
Starting off with turn based games is going to help you a ton.
After you've got a handle on that it's worth looking into videos that are more specific to what you need, like fps, rts, etc... and the techniques that each kind of game uses. You'll also get an idea of how online cheating works because you'll be able to see what information each machine can read and set.
It doesn't appear to have. https://steamcharts.com/app/730#All
2. It doesn't even work!
So at each step, you weigh how much the cost is for the mitigation (in terms of upfront and ongoing dev costs, and player problems), and the benefit (in terms of how much higher you make the barrier).
For example, conceptually, you could sell a dedicated machine that requires gov't ID and credit card linked to your account to purchase and melts down if you ever are detected tampering with it, requires a mic and camera on 24/7 to make sure you're not tampering with it once purchased, dies if it loses internet ever once turned on, etc etc, but then nobody is going to buy it because you have made the cost in terms of disruption to players too high for anyone to bother.
I'm not sure you can usefully solve it other than trying to keep the barrier for entry higher than a lot of people will bother, and possibly making the barrier much higher for something like ranked play, b/c otherwise, if you do things like if you ever close their DRM after boot, you need to reboot to play the game, you're going to cannibalize your player base, because it's too much of a pain in the ass, and they will (correctly) blame you for this.
My only windows box is in an actual physical box right now and I cannot verify.
As a connoisseur of online game hacks, I'm utterly stunned at the level of sophistication that both parties partake in with respect to the cat-and-mouse game of cheat/anti-cheat.
Some are technically very interesting, like the hardware DMA device I previously used. The firmware was customized specifically for a subset of users specifically to avoid detection (it eventually failed). Others are very clever, like the hack that was dynamically compiled as an Xbox Game Bar module.
Nearly every competitive game game is going to be utilizing some form of anticheat like this, so single player games tend to not have this issue (drm is a separate conversation)
What's frustrating to me is that games will run the hyper invasive kernel level version of an anti cheat on Windows but will allow Linux plays, which has no such level of access. If we're trusting Linux players with no kernel level monitoring, why not windows players? Have cheater really not caught on that there's a lower bar on that platform? I hope they don't because I like being able to play competitive games with friends without having to reboot first.
I believe Valorant and Roblox have had devs/employees state that supporting Linux isn't worth it for the small proportion of the player base vs the increased cheat risk as well, although feel free to take that with a grain of salt
I suggest compartmentalization for games, for example a dedicated gaming machine. That way, anti-cheat doesn't have much to take over. You can connect it to guest wifi, so that it doesn't see the LAN either.
Should Magnus Carlsen have required Niemman to get a cavity search? When tons of kids have neuralink implants, should they be polygraphed before taking a spelling test?
Cheating is not a technical problem, it's a people problem.
Yes, and technical solutions are usually a bad sign. How nice is the neighborhood that locks pharmacy razors vs the one that doesn't?
>Anti cheat software because one needs to play with people one does not trust and so attempts to get good behavior from strangers by force.
Same could be said about laws. Goes to show that we don't have it solved it, at all. Every single system that we have has active bad actors in it, with no chance for us to catch them, by any means that we have, technological or not.
To add to this even more, it's not even a people problem, it's an animal problem - some of them also give out fake signals, in order to gain something.
I agree on a theoretical level, like, if it's my general purpose computer, then everything that runs on it should also answer to me, not other parties. This applies to anti-cheat, and also to DRM and other concepts like Trusted Computing and Secure Boot even, to a degree.
I don't see how one could prevent cheating, if one allows a software abstraction layer between the game, and the user. If a software is allowed to manipulate another software, then that other software cannot have proof that it's not being manipulated. On one hand, this is the beauty of computing, but on a practical level, this makes cheating in online games very easy and undetectable. So, because I like playing online, I made the compromise that somehow this level of intrusion is okay.
I believe there are AI anti-cheats being developed and used in China so maybe we'll end up with a Recall-esque anti-cheat everywhere in the future :)
For people watching esports, they need to believe that the game isn't rigged and people aren't cheating. A couple more scandals and the sponsors are going to require cloud-gaming just to keep viewers.
And even if I disregard all this, cloud gaming wouldn't solve the problem, as hardware cheats that don't run on the gaming machine would still be usable.
I'm pretty far from the multiplayer game dev scene, but isn't this close to how a lot of multi player sync works anyway? Just* distribute everyone's control inputs and have them all run a deterministic simulation. And then I guess you would run the same input cheat detection on all the honest clients, which are hopefully the majority... Is this impossible or did I just reinvent something that already exists?
* Yes, I know. But at least I know determinism is possible.
These sort of cheats are often entirely out of band, running on a mirror of the video stream on a second machine, and transmitting user input back via USB. Clientside snooping won’t catch it either.
The google term is "hardware cheats"
(As an aside, hearing about this kind of setup really makes me wonder what the point is of cheating. Prestige? Among what set of peers?)
But if you give up, and your game's competitors don't, players will switch games. The way I see it, a game developer anti-cheat goals isn't necessarily to have no cheaters, but definitely to have less cheaters than your competitor.
Imagine all the things that would be possible. Truly decentralised servers, where the end user can run server side logic.
Gonna keep an eye on it, but I'm not to sure if it'll be the solution to this issue...
The better solution is often live admins with a cheat-report button, server-side physics reconciliation trip-wires/audits (no time-travelers), and using clipped areas for character buffering (x-ray vision attempts floods buffers and crashes the client.)
The only information an online game-engine should be pulling is the hashed GPU chip serial-number for account ban enforcement.
The worst part about cheats is they ruin the fun for themselves too, as a game becomes pointless and boring.
Installing a RAT has no justification on hardware people didn't pay for...
There are better solutions, but as you stated they are not cheap or easy to monetize. =)
Isn't that literally client-side security enforcement?
2. Spoofing a signature will still force you to re-register, lose your current rankings, and zero your nontransferable e-store account balance.
3. Most people don't account for the other system signatures that will also get randomly audited over several months
4. Remember part of offline audits is comparing each clients game-log to look for suspicious glitches like inhuman aim behind occluded objects, and "weird" physics. Hope they find it is a QA issue on replay... =)
Have a nice day, =)
And I don't understand which cheating behaviours this restriction is supposed to prevent.
If multiple user accounts are tainted by the same flagged signatures, than you risk getting everyone on that hardware banned. It is usually clearly stated in the EULA expected fair play section, and it is at the admins discretion... Buy that used cheap rtx3090 at your own risk... ;)
"two instances of the game can't run on the same machine at once?"
In general, most performance heavy platforms are not going to support multi-account mode anyways.
"what if I upgrade my graphics card?"
Your associated hardware signature would simply be updated upon login. However, accounts associated with flagged signatures often remain inactive to block logins/new-account-registration/store-access.
"What if my friend wants to play too, and remotes into my machine to do so?"
Depends how the admins enforce the signature collision events. In most cases, all users will get a 1 week ban, and a warning a 1 year ban will follow. Again, the admins usually have discretion about believing users stories...
"And I don't understand which cheating behaviours this restriction is supposed to prevent"
It helps prevent persistent cheats returning their hardware purchases, re-registering, and continuing to annoy other players.
This is a very common practice on Desktops, but rare on console games for obvious reasons. =3
Which is why this is completely unreasonable.
I think 2 strikes is quite reasonable to remove people breaking the game for other users. And I only know of 1 company that bans the hardware signatures on all of their game titles at once.
The probability one will experience problems before a legitimate purchase return window period expires is very low.
Have a wonderful day, and maybe try a card game like MTG. =3
I'm glad we agree that this is unreliable and therefore not a defense of the approach.
> The probability one will experience problems before a legitimate purchase return window period expires is very low.
Okay, so I buy a card I can actually afford on eBay, put it in my machine, buy a game, and get my account permabanned. What refund am I asking for that makes this okay?
> Have a wonderful day, and maybe try a card game like MTG. =3
This reads as condescending. If you don't mean it that way, then you should consider a different way to try and be friendly lest it undermine your argument. If you do mean it that way, please stop being rude.
One would have to prove they are a different person/account-location to IT admin support. It is rare, but some companies will simply watch your game-play for a bit to see what you are up to compared to the prior ban details. Note one will likely have to gamble on the compassion of each firms IT admins.
"What refund am I asking for that makes this okay?"
These sellers are almost always knowingly trying to evade the consequences of their behavior, and trying to recoup their money to buy un-flagged hardware. This is pointless, as there are several anti-cheat queries companies can run, and like any antisocial behavior they usually just make the situation worse for themselves by contaminating the market with more flagged hardware. Eventually their sellers reputation score will warn buyers what they are doing.
Getting a refund for the "broken" equipment is a standard ebay RMA process, and Craigslist/meta-Marketplace returns can be a bit more complex.
Keep in mind a ban may eventually lift after 12 months, but IT admins may be less convinced of your intent if a user keeps popping up as a problem.
"This reads as condescending"
It is not my call what companies do with problematic users. And MTG events also bans cheats for marked decks, and pulling unfair tricks that violate the rules. The difference is people will be upset with such antics at the same table. Personally I prefer the Royal Game of Ur over tea, and am always keen to share a good laugh with folks interested in such classics.
if one chooses to be miserable/upset, than that is their right too... But it doesn't sound like much fun. =3
But the equipment isn't broken: it's perfectly-functional. Some third-party putting the GPU's serial number on a naughty list is no reason to demand (nor approve) a return. Even assuming that spoofing is impossible (it's not) and the GPU was involved in illegal behaviour, why assume the seller knows that? Not everyone plays your video game.
> This is pointless, as there are several anti-cheat queries companies can run,
I'd say it's pointless because you can just instruct your computer to report a different GPU serial number. There's no reason for a cheater to replace the hardware: the only reason to replace a GPU is if it's faulty, or you want a different GPU.
> > This reads as condescending
> It is not my call what companies do with problematic users.
That too, but: what you've written reads as condescending.
> And MTG events also bans cheats for marked decks, and pulling unfair tricks that violate the rules.
Every time someone writes a criticism of the ban methods, you start defending the bans. There's some kind of miscommunication going on here.
GPU serial numbers are not a good proxy for people you want to ban. The burden of this fact should fall on the decision-makers, not everybody else. "Guilty until proven innocent" is not usually considered just.
"GPU serial numbers are not a good proxy for people you want to ban"
In your opinion, and that is fine for your use-case needs. Note most habitual cheats usually lie or get aggressive when they are repeatedly busted for attempting to sneak back on the servers while under a ban. The 30% that immediately fess up at least have some integrity.
We will have to agree to disagree on whether it is morally justified. Yet it is _very_ effective at dealing with that 0.05% problem user, and is already active in many ecosystems. It would be nice seeing a better solution in action... that obviously wouldn't require DRM/rooting a users computer.
In my opinion, it is the lesser of two evils. =3
A lot of these mitigations are table stakes, even cs1.6 had server-side physics reconciliation. Aimbots are a type of cheat that cannot be detected by the above and completely ruin games. If cheaters proliferate in your game, you end up with a dead game.
Have an awesome day, =)
Have a great day, and let the ban-hammer fall =)
“Admin! He’s doing it sideways!”
Now there's gonna be a guy that does this specifically just to prove us wrong... lol =)
I, too, consider it a benefit of gaming on Linux.
I bought Marauders to play with my son, and had maybe 4 months of excellent fun play with him. Then the dev's enabled EAC... now I cant play it anymore :-(
I cant blame the mods, they never wrote the game to work on linux it was just a happy happenstance that i could use proton to play it before the EAC transition.
Every game i have in my steam catalogue is at risk of this (except for the native ones obviously)
They used to be about having fun. If you wanted to put gravity at 10% and make everyone use only rocket launchers with unlimited ammo, that fell within the parameters of having fun:
The freedom afforded in personal computing by Windows and Linux is fundamentally mutually exclusive to the security that multiplayer game operators and proper players legitimately need.
It's why game consoles and mobile gaming are the core gaming platforms. Note how Sony and Microsoft blacklist consoles suspected to be used by cheaters, and how games (and also banking) absolutely hate rooted smartphones because it breaks the assumption of a locked down and secured system.
Unironically, Cloud gaming. Stadia had a terrible business model, but the tech worked. Microsoft's XCloud together with GamePass could be a winning ticket for that. (I think there's also GeForce Now)
Of course, that wouldn't prevent anyone from capturing the screen, running image recognition software on the screen and sending USB Controller inputs to create an Aim Bot, but then again, that's not something anti-cheat software can stop these days anyway.
Ironically, cloud gaming is the perfect solution for single-player game, where input lag and high FPS doesn't matter much.
On the other hand, you have issues like smurfers who cause the same disruption without actually running any cheat software.
Ultimately your problem is uneven matchmaking and the perception of cheating, not cheating itself.
Especially with gaming becoming mainstream compared to early 2000s. The majority of players are now casual gamers who are not interested in a job as a server admin/hoster.
I got VACd on Linux the other day. Not cos I was cheating, just blocking VAC from network access. And not because I was blocking VAC deliberately, just blocking arbitrary code running from random /tmp steam binaries.
It is a pretty fucked situation that in order to allow anti cheat, you have to abandon securing your machine.
It's a cliche, but XKCD shows this really succinctly: https://xkcd.com/1200/
I think this is terribly myopic. Gaming and game modding/development resulted from it hugely contributed to general purpose computing in general, possibly more than any other activity. And it was only possible with games running on a general-purpose platform, not a gaming appliance.
How can you reliably ensure someone's machine is not running a cheat without having access to what it's running?
Anti cheat is not easy and just the perception of cheaters will nuke pvp games. But personally I want better anti cheat, the only question is at what cost?
It's a much higher price than I'm willing to pay.
But it has been estimated that the illegal market of cheats is worth about 100 million.
Many cheaters don't even intend on playing against legitimate players, looking for so called "hack vs hack" games.
At some point CS2 didn't really act on cheaters for a while and it got really ugly.
Anti-Cheats do work, there will always be ways around it but as long as these alternative paths are inconvenient enough to prevent a consumer from buying the cheat then it works.
Without Anti-Cheat modern competitive games are unplayable.
Seems like a smart way to catch inexperienced/up and coming cheat devs. How many non-cheat devs really have IDA on their gaming PC? I did and it was for developing cheats
( To everybody reading this : if you like computer and puzzles, you should absolutly try to reverse-engineer a simple binary at least once. It's fun !)
Honestly, banning players because they have RE tools feels like a generally counter-productive idea. Best-case scenario is that it'll require an engineer who was actually going to RE game files to get another account, stalling them very briefly. Worst-case scenario is getting someone with technical skills and free time pissed off enough to actually start messing with the game (potentially, in a less respectful way than your average cheat developer might - looking for game-breaking exploits than just automating things or providing extra information to the player), even if they didn't mean to.
You can basically patch the executable to skip the function that locks you out
Specifically those for single player games, I've used them to finish games so I can view the story/endings.
A less permanently-severe but real example: A Windows game which terminates (with no message) if the user opens "git bash" (cygwin).