Live data from Hacker News

Steam games will need to disclose kernel-level anti-cheat on store pages

gamingonlinux.com

201–210 of 660 posts

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#201
post #47

Earlier quoted context omitted.

Cheats and bots are ruining online games though.

Back when communities hosted servers instead of companies, it seemed less common, even though it was easier to do.

Because those were community servers often built around community. There weren't a lot of them either.

If admins allow cheating - people that want to play would leave the server

If live in a non-metro area, you probably have a handful of server your latency allows you to play on - getting banned would be a big suck

Now you just click "play game" and you get match with some strangers you might never play ever again with. Financially, those privately hosted servers no longer make economical sense for game publishers.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#202

I hate to say this but a large percentage (in fact, I believe a majority) of gamers simply do not care about invasive anti-cheats. Right now CounterStrike players are mostly begging Valve for kernel-level anti-cheat since their current solution isn't working at all. If anything, this warning will actually make many player's more impressed with the game. That said, more consumer information is almost always better in…

Prop 65 went great! Let's get a warning out for every game with peer to peer networking while we're at it.

I get the argument, but if that is more than a strawman argument to you, I am bewildered. Making a network connection is infinitely less problematic than having root level access to a kernel (translate to windows language for NT)

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#203

Earlier quoted context omitted.

It's closed source and the assembly is obfuscated. You don't even need to bother with plausible debiability.

Surely the NSA has tools, people, resources etc to figure that out?

The NSA just needs a call to Riot headquarters to ensure their rootkit is also included.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#204
post #47

Earlier quoted context omitted.

Cheats and bots are ruining online games though.

Perhaps, but it's far better to have cheaters and bots than to have games require a rootkit to play them.

You definitely don't play games, this is one of the reasons why people stop playing games.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#205
post #188

Earlier quoted context omitted.

Doesn’t matter in a world of AI powered hacks. Kernel level anti cheat isn’t detecting the yolov8 model fine tuned on the head of my enemies.

This video suggests you can catch this type of cheater without even a kernel level anti cheat: https://youtube.com/watch?v=x-EbjGSRyKA There’s a lot of other stuff in the video but if you skip the robot building parts at the beginning he talks about an anti cheat system he developed with another person.

Behavioral analysis (the thing he's talking about) doesn't work that well and has a hard precision limit due to the nature of online gaming. What the player sees, what the server sees, and what other players see are entirely different things. I'm not even talking about plausibly deniable things like visual sound location.

Nobody's using complicated stuff like this in practice though, as there are easier methods. But of course this path can be taken, and it's not possible to block easily.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#206
post #163

Earlier quoted context omitted.

As Gabe Newell said "piracy is a service problem" I could pirate every game I have on my Steam account. I don't do it because the added value that Steam gives me.

> I could pirate every game I have on my Steam account. According to the CrackWatch subreddit, there were 29 games released with Denuvo in 2024. Of those, only one has been cracked and it was done via a demo bypass [1]. You can pirate many games but not, for example, Final Fantasy XVI. [1] https://old.reddit.com/r/CrackWatch/comments/p9ak4n/crack_wa...

Maybe I should clarify, I personally can see the value to cooperations of having protections in place during the initial sales period, when these meassures have been shown to make an impact. My comment was more pointed at the fact that of the people I personally know that are very much opposed to the use of Denuvo specifically, very few wouldn't buy a game they want because of its use, yet they still very consistently complain about the presence of Denuvo. Essentially, my point was that from where I am sitting, a large contingent of gamers complain about things without adjusting their behavior accordingly. I also feel (again, purely subjective) that the less someone complains about pre-ordering, the less likely they are to actually engage in pre-ordering.

That being said, beyond the first few months, I remain convinced that overly aggressive DRM does negatively impact game preservation, which is why I like the compromise some studios started engaging in of removing certain DRM meassures a few months post release. I recently bought two racing games from my childhood on eBay as new-old-stock physical media. One of the twos aggressive and no longer maintained DRMs made my Windows VM unbootable and I cannot access the game without relying on the work of pirates in circumventing that.

Also, I will point out that defending DRM as something that protects artists as you did doesn't fully track considering one of the uncracked Denuvo games in the list you linked is Hi-Fi Rush, an exceptional game and financial success that was critically acclaimed and made by talented creatives who are now out of a job [0], not because of piracy, but because of corporate mismanagement.

Whether and by how much DRM can protect profits, we can discuss that for days, but I have yet to see evidence that it ever directly benefits the creatives you mention, not least because outside of corporate games studios, where ones job security doesn't appear linked to game quality or sales, in the indie scene, few if any can afford solutions like Denuvo, so the one place where developers could directly benefit from it, they can't either.

Circling back to preservation, artists generally want to be able to learn from eachother and games outside the current generation can have immense value for that. Even and sometimes especially those games that are unlikely to ever receive a re-release (which often do make changes from the original experience), so I very much feel it isn't optimal if future generations of artist will have a hard time accessing past media due to overly agressive DRM meassures protecting corporate profits within only the first few months past release.

[0] https://www.pcgamer.com/gaming-industry/microsoft-announces-...

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#207
post #11

Earlier quoted context omitted.

What decides critical or non-critical. One could argue that a game isn't critical but one could say it's critical to stop hackers. If you were to take the stance that gaming isn't critical than with that logic you're then claiming multiplayer hacking is a feature of the game. Doesn't do well for the community or the company. But nor do the rootkits do good for the consumer.

If they worked to any acceptable level of efficacy then they could be tolerated. They're only tolerated by people who think they work as well as they claim to work (security theater) but anyone who knows about the performance impacts and/or are tech-savvy enough to understand it is a rootkit and potential exploit (that would fully pwn your device) hates them. Some cheats are getting rather sophisticated now. There's…

Performance impact is overblown, it was proven that the lost of perf is marginal when implemented properly.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#208
post #163

Earlier quoted context omitted.

As Gabe Newell said "piracy is a service problem" I could pirate every game I have on my Steam account. I don't do it because the added value that Steam gives me.

> I could pirate every game I have on my Steam account. According to the CrackWatch subreddit, there were 29 games released with Denuvo in 2024. Of those, only one has been cracked and it was done via a demo bypass [1]. You can pirate many games but not, for example, Final Fantasy XVI. [1] https://old.reddit.com/r/CrackWatch/comments/p9ak4n/crack_wa...

I could pirate every game on my collection but one, EA FC 24, wich uses Denuvo.

It also runs very bad, brings my CPU to its knees, and can't keep 60 FPS with a 500$ GPU, maybe cause Denuvo maybe not, but I will think twice the next time I buy a game with Denuvo.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#209
post #47

Earlier quoted context omitted.

Cheats and bots are ruining online games though.

Back when communities hosted servers instead of companies, it seemed less common, even though it was easier to do.

Back then you could just quit the server/match if somebody was obviously cheating (or they got banned).

With competitive matchmaking cheaters can hold players hostage until the end of the match, as leaving incurs penalties and cooldowns that temporarily ban you from playing.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#210

The anti-cheat problem is long-running and complicated. If you choose not to run anti-cheat because you understand that these are opaque rootkits, good for you! That's a totally, 100% valid choice. But please keep in mind: - you are a tiny minority and not the target customer - online multiplayer games are an absurdly big business (i.e. there are huge incentives here) - no, you can't completely solve this server side…

Why isn't server-side anticheat a possible solution? Cheats can spoof inputs purely through visual output as well, meaning there cannot be full trust client-side.

Oh it's a solution, it's just worse than kernel-level - as it's much easier to bypass.
Post reply on HN