It's almost the same as saying "you don't need a password on your phone" or something like that.
It's almost the same as saying "you don't need a password on your phone" or something like that.
False, people that have information they shouldn't have will act in detectable ways, even if they try their hardest not to.
ESP is a lot more obvious to a machine than one might think, the subtle behavior differences are obvious to a human and even more so for a model. Of course none of that can be proven, but it can increase the scrutiny of such players from player reports.
> you can achieve the same with user mode anticheats
A user mode anti cheat is immediately defeated by a kernel mode cheat, and cheaters have already moved past this in practice.
A user mode anti cheat (on windows) with admin privileges has pretty much full system access anyway, so presumably if you have a problem with kernel AC you also have a problem with user mode.
Lastly, cheating is an arms race. While in theory, the cheaters will always win, the only thing that actually matters is what the cheaters are doing in practice. Kernel mode is default even for free cheats you download, so the defaults have to cover that.
First, point of ingress: registry, file caches, dns, vulnerable driver logs.
Memory probe detection: workingsets, page guards, non trivial obfuscation, atoms, fibers.
Detection: usermode exposes a lot of kernel internals: raw access to window and process handles, 'undocumented' syscalls, win32, user32, kiucd, apcs.
Loss of functionality: no hooks, limited point of ingress, hardened obfuscation, encrypted pages, tamper protection.
I could go on, but generally "lol go kernelmode" is sometimes way more difficult than just hiding yourself among the legitimate functionality of 3rd party applications.
This is everything used by anticheats today, from usermode. The kernel module is more often than not used for integrity checks, vm detection and walking physical memory.
So let me summarize the above thread:
Yes, there will always be workarounds for ANY level of anti-cheat. Yes, kernel-mode anti-cheat detects a higher number of cheats in practice, and that superiority seems durable going forward.
There, I think we can all agree on those. No need to reiterate what has already been posted.
source: observation of games implying stronger anti-cheat measures over time and customer count staying exactly the same or growing. league of legends is a prime example, although it did create a crater for awhile. this all comes from people who actively sell cheats.
Taking the defence in depth argument - kernel AC is another layer that helps and makes it more difficult for the cheaters. But some defences are more crucial than others - you don’t use MD5 anymore for security because it’s just broken. IMO, the same can be said about user mode anti cheat.
anyway: I already edited with the source.
nothing I can give solid foundations for so you'll just have to take my word for it.
An anecdote of one game isn’t proof that they don’t help - you’re not comparing it against a game that kept user mode AC to see what the impact was there. The fact that vanguard “cratered” the cheats for a while shows it’s effective, right? The actual goal isn’t 0 cheats (that’s impossible), it’s keep pushing back the cheaters.