RIOT requires users to enable TPM-enforced Secure Boot starting with Windows 11 to play Valorant: https://support-valorant.riotgames.com/hc/en-us/articles/100...
RIOT requires users to enable TPM-enforced Secure Boot starting with Windows 11 to play Valorant: https://support-valorant.riotgames.com/hc/en-us/articles/100...
Riot has a pretty indepth blogpost about their anti-cheat systems, they've had years to mature them on some of the most demanding competitive gaming platforms ever made. Requiring players install kernel anti-cheat was very far down the list of possible solutions, but that's what it came to. It was either this or stop being free to play.
It's impossible to tell in-game if a baseball player is using steroids, yet there's a laundry list of banned substances and players who got banned for taking them because the MLB believes it gives them an unfair advantage. It's called competitive integrity.
Since it sounds like you don't play games, at least not competitively, I'll clarify that "cheating" in this case isn't the obvious stuff like "my gun does 100x damage" or "I move around at 100mph" or "I'm using custom player models with big spikes so I know everyone's location" that you would've seen on public Counter-Strike 1.6 servers in 2002. Cheating is aim assistance that nudges your cursor to compensate for spray patterns in CS, it's automatic DPs and throw breaks in Street Fighter 6 that are just at the threshold of human reaction timing, it's firing off skillshots in League of Legends with an overlay that says if it's going to kill the enemy player or not. All of this stuff is doable by a sufficiently skilled/lucky human, but not with the level of consistency you get from cheating.
This is relative to meat-space, not videogame, but we could go there and say caffeine or Adderall use is cheating, thus making anti-cheat a little more invasive…
And there another difference, you're referring to professional sport. I have no problem with invasive anti-cheat for professional gamer, even better it the gaming device is provided by tournament organization.
But we're talking about anti-cheat used for all players, akin to asking people playing catch in their garden or playing baseball for fun an the local park to take a blood sample for drug test.
> All of this stuff is doable by a sufficiently skilled/lucky human, but not with the level of consistency you get from cheating.
That's the point, there no difference for the other players between playing against a cheater and playing against a better player. Any ELO-based matchmaking will solve this, cheater will end-up playing against each-other or against very skilled player.
You could argue that they could create new account or purposely cripple their ELO ratting, but this is the exact same problem as smurfing.
> Any ELO-based matchmaking will solve this, cheater will end-up playing against each-other or against very skilled player.
Well, first, you're wrong, because cheating only makes them good at one part of the game, not every part of the game. e.g. in League of Legends, a scripting Xerath or Karthus who hits every skillshot is going to win laning phase hard. However, scripting isn't going to help if they have bad macro and end up caught out in the middle of the game, causing their team to lose. Most cheaters don't end up at the top of the ladder, they end up firmly in the upper-middle.
Secondly, you're basically saying "cheating is OK because they'll end up at the top of the ladder." You don't realize how ridiculous this sounds?
Third, ranked and competition aside, playing against someone who's cheating isn't fun, even if you end up winning because they make mistakes that their cheats can't help them with.
You don't play competitive games, that's fine, but a lot of people do and they demand more competitive integrity than casual players.
Little difference : I don't play competitive game with completes strangers on company run servers.
I've played competitively on community based server, with people being screened by other players and the community able to regulate itself (ban or unban players).
The problem space is vastly different, you don't need intrusive ring 0 anti-cheat for this.
The whole kernel-level anticheat stuff is a poor solution to a self-made problem by the developer : they wanted to be the one in charge of the game and servers, so they needed to slash human moderation need. They also wanted to create a unique pool of player and didn't want the community to split between itself and play how they want.
People don't consider playing around with your friends to be competitive. You don't get to choose who else is competing in the game or what strategies they use. This is just an area that you are clearly not familiar with.
> The whole kernel-level anticheat stuff is a poor solution to a self-made problem by the developer : they wanted to be the one in charge of the game and servers, so they needed to slash human moderation need. They also wanted to create a unique pool of player and didn't want the community to split between itself and play how they want.
This wasn't self-made by the developer, it was demanded by the players. Competitive games have almost exclusively moved to online, skill-based matchmaking with a ladder system because that's what players want.
I didn't say friends. Please don't modify my argument to refute it.
> You don't get to choose who else is competing in the game or what strategies they use.
I, as a single player, no, but us, as a community, yes, and it's the same for any game or sport, different group run different tournament with different rules about who play and how.
> This is just an area that you are clearly not familiar with.
Please refrain to use ad hominem, especially when you have no idea who you are talking with.
> This wasn't self-made by the developer, it was demanded by the players.
I don't know any players who asked for the disappearance of community run server or human moderation, neither that wanted do lose agency on the way they play. I don't they these players doesn't exist, but I don't make gross generality about players.
> Competitive games have almost exclusively moved to online, skill-based matchmaking with a ladder system because that's what players want.
They're not a hive mind, lots of them didn't or doesn't like matchmaking in any form, and even for the ones that wanted it, that doesn't mean developers have to remove other mean of play, like server browser and private server.
The state of game cheating has professionalized A LOT, it is extremely competitive and cheating companies produce extremely good quality tools compared to what we had 20 years ago. There is a lot of money to be made, we are at the point where you can just pay a cheap monthly subscription and you get access to actively maintained cheating tools. I know people working on the anti-cheat side, it is a really messy, highly dynamic (the bad actors are constantly adapting), complicated problem that isn't solved once and for all. We are far from the situation where just a few people are using some hacked-together software that will obviously be spotted as cheaters.
Game dev companies (at least US/European ones) have zero interest in developing or paying for kernel-level anti-cheat. That's a massive barrier of entry for the player base and they know this. It's also far from being cheap.
(Note: ignoring geopolitical factors, Chinese companies such as Tencent or Russian companies could definitely have interests in developing kernel-level anti-cheat for information gathering)
I will comment on a game I used to play though: Escape from Tarkov. The game costs somewhere between 40$ and 250$+tax, depending on what pack you buy. Banning cheaters for this game is literally a profit center. Every time you ban a cheater and they re-buy the game, you made at least 40$. The majority of cheating in the game was due to real money trading - cheaters would make in-game millions quickly, sell them, get banned, buy the game again at a profit.
The solution to this is brain-dead simple - more manual moderation (these cheaters are very obvious to spot). What the developers did instead just killed the game.
Citation needed.
Whose these gamers ? I surely didn't ask for this neither any of the gamers I know, nor seen any demand about that in gaming forums.
> The game companies couldn't care less if there are cheaters in the game, but it's the players which put huge pressure on the game companies to detect and ban cheaters.
The jump from this to "requiring TPM" is quite a long one.
That's akin to saying that, as people want security on the street, mandatory strip search as soon as your exit your home is fair game.
Asking for a result doesn't give a blank-check for all the measures taken toward this result.
Hell, blatant cheaters literally stream themselves cheating and their own communities do not recognize the cheating till the stream makes a mistake and selects the wrong scene. This also means that VAC methods of sending footage to random players is ineffective, as some streamers who are very obviously actually cheating do so in front of tens of thousands of people, and those people do not recognize the obvious cheating happening.
We also know game companies don’t care about cheating, as activision admitted in their lawsuit that they leave cheaters on a safe list so long as the cheaters have any semblance of an audience streaming.
That is absolutely wild, and completely characteristic of Activision.
Do you have a link that I can share with my CoD-playing friends?
It really doesn’t even take that many viewers. Zemie, for example, is a straight up cheater that runs a button activated aimbot and wall hacks. He only averages a couple thousand viewers and is safe listed by a number of game companies.
Truth be told, if the exploiter-class of your game would even consider a kernel-level exploit, your game is fucked from the start. Seriously, go Google "valorant cheating tool" and your results page will get flooded with options. You cannot pretend like it's entirely the audience's fault when there are axiomatically better ways to do anticheat that developers actively ignore.
Those technical shenanigans clearly aren't working, be ready to be disappointed if you thought that a TPM would help against cheaters. Cheaters always find a way, what those game needs is proper moderation.
Yes that does cost money but that's the only known thing that works in the long run.
It’s like saying seatbelts are useless because some people still get hurt, so instead of seatbelts we need a lot more ambulances and hospitals.
Like any complex system, games have a funnel. These technical measures reduce (but not to zero) the number of cheaters. Then moderation can be more effective operating against a smaller population with a lower percentage of abuse.
On the other hand, all the games / servers I've seen which are successful against cheater have some very good moderation.
Look at Counterstrike with regular VAC based matchmaking and then with kernel level anti cheat in FACEIT. One is overrun with cheaters and one isn't. It's the same game.
Isn't this the argument used against non-kernel-level anticheat and server-side anticheat in the first place ?
Alternatively, it's like saying poisoning your customers is a bad way to reduce complaints, because some of them survive. Matter of perspective.
The reasonable, fair, common-sense pro-consumer thing to do is to split the online play in two: a non-anticheat server and an anti-cheat server. Players can opt-in to installing a rootkit/sharing their SSN/whatever if they want to play on the hardened server. This costs nothing, and makes all types of gamers happy.
But doing this has less upside for the publisher than forcing anti-cheat on everyone. The only risk is that they might get dragged through the mud by a handful of influencers peddling impotent rage to viewers who are just looking for background noise while sleepwalking on their Temu dopamine treadmill live service of the month.
This is a very good point! And I'd like to point out that there is an analogue to the problem of smurfing in online video games, and the corresponding solution, which is to require semi-unique ID to play (e.g. a phone number which can only be tied to one account at a time with a cool-off period when transferring between accounts). Valve does this for Dota 2, and smurfing is far, far less common than it is in League of Legends.
Some League players complain that they don't want to give their phone number to Riot (which is entirely reasonable given that it's a subsidiary of Tencent), but if enough people don't want that, then Riot could simply split the ranked queue into two: one where (soft, ie phone #) identity verification is required, and one where it isn't.
Riot won't do this, though, not because it wouldn't fix the problem (it would, as demonstrated by Valve), but because they profit from smurf accounts buying skins.
The phone number requirement is only there if you want to play Clash. Normal ranked play works flawlessly with no number.
But guess what is happening now that MS requires TPM for Windows? All virtualizers now have some support for TPM. The time will come.
Because I was not a socialist.
Then they came for the trade unionists, and I did not speak out—
Because I was not a trade unionist.
Then they came for the Jews, and I did not speak out—
Because I was not a Jew.
Then they came for me—and there was no one left to speak for me.
> and I did not speak out
bit. They're going to keep coming for stuff until it's something you care about.
For more information please refer to this wikipedia article: https://en.wikipedia.org/wiki/First_they_came_...
The libertarian maximalist i-can-do-what-i-want-with-my-computer ignore the many use cases where I want to trust something about someone else's computer, and trusted computing enables those use cases.
How is it great? Vanguard is extremely invasive; having kernel access, you have to relinquish your PC to this chinese-owned company at all times (whether you're playing the game or not), and just trust in their good faith.
And for what? Cheaters are more rampant than ever, now that they have moved to DMA type cheats, which can't (and never will) be detected by Vanguard.
So you give away complete control of your PC to play a game with as many cheaters as any other game. I wouldn't call that "great".
Now, the amount of DMA cheaters may still be unacceptably high, but that’s a different statement than “the same amount as”.
So, it’s not “giving up something for nothing”, it’s giving up something for something, whether that something is adequate for the trade offs required will of course be subjective.
You're right, a game with no anti-cheat or a bad one will have more cheaters. But as you said, it's about the tradeoff, and that's what isn't "great". It was for a period of two years or so, since the tradeoff was "lose all control of your PC by installing a rootkit, play a game completely free of cheats", which was compelling, but now that the game isn't sterile anymore it's hardly worth it, at least for me.
We gave up something real. But it has not been proven whether we got anything. Maybe we got nothing, maybe we stopped a few of the laziest cheaters, but we still see tons of cheaters. The number of possible cheaters is based off the quality of the software. No amount of aftermarket software will magically improve the quality of your game in a way that 100% deters cheaters. I’m positive that their marketing claims they reduce cheaters by an order of magnitude, but I have not observed them successfully catching cheaters with these tools.
I don't really buy the gaming one, in every other domain where a community of people are gathering to do a thing they enjoy together it's on the community and not the tool maker to figure out how to avoid bad behavior. If you don't wanna play with cheaters then just play with somebody else.
Relying on the community to police cheaters is not an effective strategy for online skill-based matchmaking games. There's a reason game companies spend money and effort on anti-cheat and it's not because they're ignoring cheaper alternatives.
This requirement will only hit multiplayer games where cheating and security threats are rampant.
Also, if you have a PC with secure boot enabled, there are popular Linux distributions like Ubuntu that have a signed key. Or, you can add a signing key to the firmware, depending on your hardware. And of course, most commercially available PCs will let you disable secure boot entirely.
(Most multiplayer games with anti-cheat software don’t really work on Linux anyway.)
They have shipped ARM Surfaces where alternative operating systems could not get installed, enforced with Secure Boot permanently on. Have they been through any such "antitrust ringer" in the past 10 years?
> Also, if you have a PC with secure boot enabled, there are popular Linux distributions like Ubuntu that have a signed key
Note that there's one key MS uses for Windows and one key they use for everything else. They actually advise OEMs not to install this second key by default ("Secured Core" PCs), and some vendors have followed the advice, such as Lenovo. Resulting in yet another hoop to install non-MS OSes.
Even recently, a Windows update added a number of Linux distributions to the Secure Boot blacklist, resulting in working dual boot systems being suddenly cripped. Of course, even _ancient_ MS OSes are never going to be blacklisted.
True, 3rd party not trusted by default is a "Secured-Core PC" requirement, but so is the BIOS option for enabling that trust [0]. On my "Secured-Core" ARM ThinkPad T14s it's a simple toggle option.
> Even recently, a Windows updated added a number of Linux distributions to the Secure Boot blacklist, resulting in working dual boot systems being suddenly cripped. Of course, _ancient_ MS OSes are never going to be blacklisted.
Actually they are in the process of blacklisting their currently used 2011 Windows certificate, i.e. the Microsoft cert installed on every pre-~2024 machine, also invalidating all Windows boot media not explicitly created with the new cert. It's a manually initiated process for now, with an automatic rollout coming later [1].
It'll be very interesting to watch how well that's going to work on such a massive scale. :)
[0] https://learn.microsoft.com/en-us/windows-hardware/design/de...
[1] https://support.microsoft.com/en-us/topic/kb5025885-how-to-m...
As I said, yet another increase in the number of hops for no reason.
Before you say anything else: until this you could install _signed_ Linux distributions without even knowing how to enter your computer's firmware setup. Now you can't.
The trend is obviously there. First, MS forced Linux distributions to go through arbitrary "security" hoops in order to be signed. Then, MS arbitrary altered the deal anyway. Even mjg59 ranted about this. And the only recourse MS offers to Linux distributions is to pray MS doesn't alter the deal any further.
Maybe at no point they will make it impossible on x86 PCs, but they just have to keep making it scary enough. And in the meanwhile keep advertising how WSL fits all your Linux-desktop computing needs. While at the same time claim they have nothing against opensource.
> Actually they are in the process of blacklisting their currently used 2011 Windows certificate
No, they are NOT in the process, and that is precisely what I was referring to. They have not even announced when they are going to even start doing the process. All you quoted is instructions to do it manually. So I'll believe it when I see it.
And besides, just clearing the CMOS is likely to get you a nice ancient DBX containing only some grub hashes on it, and the Windows MS signature on DB. Not so much luck for the MS UEFI CA signature, as discussed above. So "recovery" will be trivial for Windows, not so much for anyone else..
The problem is nobody really has put enough effort to port Linux to it. Some people started but haven't gotten very far
https://github.com/orgs/linux-surface/projects/1 https://github.com/linux-surface/aarch64-firmware https://github.com/linux-surface/aarch64-packages
>, a Windows update added a number of Linux distributions to the Secure Boot blacklist
It was due to a bug/and or not being able to detect all manners of dual boot correctly.
The goal was not to blacklist old distros, it was to blacklist vulnerable boot managers
Microsoft's response and fixes were provided: https://learn.microsoft.com/en-us/windows/release-health/sta...
Not all. I know for a fact you could not in the RT/2.
This is despite the fact that people _do put effort_. This is how I know, for example, that some Linux workarounds for "funny" ACPI interpretations had to be also "ported" to the ARM architecture in ACPI ARM Linux because Windows is literally making the same "bugs" all over again. Except, this time, Windows hardware is in the _minority_, and there's plenty of ARM ACPI devices that do not require these workarounds...
> It was due to a bug/and or not being able to detect all manners of dual boot correctly.
Sure. It is also a bug they just applied these blacklists automatically in the first place? It is also a bug that the list of blacklisted bootloaders mostly comprises non-MS oses, despite the fact there are well-known issues in many Windows versions?
Hell I can't even reformat it with a fresh copy of Win11 for ARM because it isn't offered. The only way to download windows for ARM is a virtual machine file for windows insiders. Then use third party tools to crack that open and extract the OS.