Live data from Hacker News

/dev/null: Anti-Cheat Kernel Driver (2020)

leagueoflegends.com

31–40 of 142 posts

Re: /dev/null: Anti-Cheat Kernel Driver (2020)

#31
post #3

Of course, this is just a blog post by a gaming company for their gamer audience, but lots of this stuff is downright dishonest. For example: > Now, while most players might find the idea of a corrupted Windows installation objectionable, a disturbing number of cheaters have shown themselves to be downright enthusiastic about the opportunity to jump onto some guy’s botnet in exchange for the ability to orbwalk Kernel…

>DMA cheats keep getting better every day

These require buying physical harder instead of someone being able to just download a cheat for free. Also if you are writing memory to cheat / sending weird packets you can detect that and ban them.

Re: /dev/null: Anti-Cheat Kernel Driver (2020)

#33

You basically can't have a PC game in 2022 without a kernel rootkit to detect cheating.

They’ve never actually rolled this out for League. I’ve played hundreds if not thousands of hours of competitive matches over a decade and never seen a blatant cheater (maybe 1-2 cass botters, but couldn’t be sure).

Given that it’s one of the biggest online PvP games around, I don’t think you or Riot are really making a strong case here.

Re: /dev/null: Anti-Cheat Kernel Driver (2020)

#34

> Now, while most players might find the idea of a corrupted Windows installation objectionable, a disturbing number of cheaters have shown themselves to be downright enthusiastic about the opportunity to jump onto some guy’s botnet in exchange for the ability to orbwalk. So they acknowledge that running third-party stuff in kernel mode increases the likelihood your machine gets owned by malware, in the very same blo…

No they acknowledge that cheat Trojans exist.

Re: /dev/null: Anti-Cheat Kernel Driver (2020)

#35
post #16

> Now, while most players might find the idea of a corrupted Windows installation objectionable, a disturbing number of cheaters have shown themselves to be downright enthusiastic about the opportunity to jump onto some guy’s botnet in exchange for the ability to orbwalk. So they acknowledge that running third-party stuff in kernel mode increases the likelihood your machine gets owned by malware, in the very same blo…

> So they acknowledge that running third-party stuff in kernel mode increases the likelihood your machine gets owned by malware Which is utter nonsense. Nothing will touch this kernel mode stuff unless they’ve already owned your machine. All the data you care about is accessible from usermode anyway. The risks of kernel mode anticheat have been wildly overstated, Riot is engaging in the same to spread silly FUD regar…

At least on Linux, a bug on the kernel module could lead to injection of other kernel modules, packages being installed, core binaries being tampered with, which are not impossible to do in userland but require deceiving the user in entering its credentials.

I think on Windows, such actions lead to an overlay that ask for authorization and can't be auto-clicked ? If so, I think having such a prompt when not expected will rise attention from the tech-savy users which may report the culprit binary. A bug in the driver being exploited would lead to the absence of the symptom, potentially increasing the time before a first user notices it.

Re: /dev/null: Anti-Cheat Kernel Driver (2020)

#36
post #16

> Now, while most players might find the idea of a corrupted Windows installation objectionable, a disturbing number of cheaters have shown themselves to be downright enthusiastic about the opportunity to jump onto some guy’s botnet in exchange for the ability to orbwalk. So they acknowledge that running third-party stuff in kernel mode increases the likelihood your machine gets owned by malware, in the very same blo…

> So they acknowledge that running third-party stuff in kernel mode increases the likelihood your machine gets owned by malware Which is utter nonsense. Nothing will touch this kernel mode stuff unless they’ve already owned your machine. All the data you care about is accessible from usermode anyway. The risks of kernel mode anticheat have been wildly overstated, Riot is engaging in the same to spread silly FUD regar…

> The risks of kernel mode anticheat have been wildly overstated

How many things like https://github.com/Luohuayu/evil-mhyprot-cli and https://mobile.twitter.com/TheWack0lian/status/7793978407622... have to happen before you'll believe that there really is a significant amount of risk here?

Re: /dev/null: Anti-Cheat Kernel Driver (2020)

#37
post #3

Of course, this is just a blog post by a gaming company for their gamer audience, but lots of this stuff is downright dishonest. For example: > Now, while most players might find the idea of a corrupted Windows installation objectionable, a disturbing number of cheaters have shown themselves to be downright enthusiastic about the opportunity to jump onto some guy’s botnet in exchange for the ability to orbwalk Kernel…

>DMA cheats keep getting better every day These require buying physical harder instead of someone being able to just download a cheat for free. Also if you are writing memory to cheat / sending weird packets you can detect that and ban them.

> instead of someone being able to just download a cheat for free

Decent hacks are already rather expensive, it’s not unusual for people to pay above $100/mo.

> Also if you are writing memory to cheat […] you can detect that and ban them.

There is no generic way to detect this.

Re: /dev/null: Anti-Cheat Kernel Driver (2020)

#38
post #11

Earlier quoted context omitted.

I could see a webcam pointed at your hand/keyboard to verify input being something legit players would happily opt into.

Okay, but you couldn't just have a linux computer procedurally generating that video, then exposing itself to the host computer as a webcam over usb gadget driver? Not to mention that you would have to comb through all this footage to detect cheaters... It is honestly a laughable solution.

Yes, but writing a program to synthetically generate correct images will take a while to come out in which players can play without cheaters ruining games.

Re: /dev/null: Anti-Cheat Kernel Driver (2020)

#39
post #3

Of course, this is just a blog post by a gaming company for their gamer audience, but lots of this stuff is downright dishonest. For example: > Now, while most players might find the idea of a corrupted Windows installation objectionable, a disturbing number of cheaters have shown themselves to be downright enthusiastic about the opportunity to jump onto some guy’s botnet in exchange for the ability to orbwalk Kernel…

> DMA cheats

Oh, thanks for mentioning those! I wasn't keeping track of what's going on with "cheats/anti-cheats" and I've just learned those are finally a thing. The concept was obvious since forever, of course, but I've searched for the phrase and realized it had actually materialized and seem to became fairly mainstream (mass production PCI Express cards, neat!) rather than just a theoretical idea or proof-of-concept hardware.

Re: /dev/null: Anti-Cheat Kernel Driver (2020)

#40

> This isn’t giving us any surveillance capability we didn’t already have. I think this is an important line. Regardless of how people feel about anti-cheating efforts, I don't believe many people realize how much access games already have to their system to the point where it's kind of a miracle there aren't more malicious games out in the wild.

Games? You mean literally every piece of software on (most) computers? Most default Windows, Linux, Mac single user setups are vulnerable to having everything be intercepted/exfiltrated by every program installed. Why would games be of concern specifically?

Unless someone is 'that friend' that always tries to download shady programs and has tons of malicious extensions (previously toolbars) installed, I imagine most people are naive to the amount of potential harm desktop software can do; using common sense when browsing and sticking to typical programs (for games, Steam/third party big-name publishers' launchers) is very low-risk, so eventually you forget that any program could be stealing your browser cookies in an instant.

Discord currently has this problem[0] where people send DMs stating 'will you playtest my game' and that exe just steals the user's stored Discord login token and uses it to proliferate the scam to more people, and/or uses the token to buy tons of gifted nitro.

0: https://www.reddit.com/r/discordapp/comments/s1f1vs/the_rece...

Post reply on HN