Live data from Hacker News

Games using anti-cheats and their compatibility with GNU/Linux or Wine/Proton

areweanticheatyet.com

441–450 of 485 posts

Re: Games using anti-cheats and their compatibility with GNU/Linux or Wine/Proton

#441
As someone who never plays online games with randos - mostly single player, or multiplayer with friends -

I cannot stress enough how much I do not give a shit about anti-cheat, and how thoroughly fed up I am with poorly conceived and ill executed malware being installed on my computer, holding games I own hostage in the name of stopping cheaters that I don’t care about it.

Anti-cheat should be opt-in.

Re: Games using anti-cheats and their compatibility with GNU/Linux or Wine/Proton

#442

Earlier quoted context omitted.

Kernel anticheat is not really effective because it can be circumvented on the hardware level, for example using direct memory access with a second computer and screen to show the hidden game state. Cheating is a meat space problem and there is no technical solution to it. Thats why in tournaments there are referees standing behind the players. Ultimately it comes down to checking if metrics like reaction speed are h…

> Kernel anticheat is not really effective because it can be circumvented on the hardware level, for example using direct memory access with a second computer and screen to show the hidden game state. Incorrect. DMA (direct memory access) is and can be prevented [1] and detected [2]. [1] https://www.faceit.com/en/news/faceit-rollout-of-tpm-secure-... [2] https://community.osr.com/t/detecting-pcie-dma-based-cheatin...

Once again back to another arms race. Assuming that your operating system doesn't allow any bad drivers (Windows does NOT do this) physical access to the hardware is just a function of time and money to get direct access to the memory

https://x.com/danielgenkin/status/1989003973429268974?s=12

Something like TEE.fail can be used to read encryption keys for network traffic then a MITM proxy can display player information easily on a second PC, you will never be able to reliably detect this

Re: Games using anti-cheats and their compatibility with GNU/Linux or Wine/Proton

#443

Earlier quoted context omitted.

Rust is playable on Linux on servers that disable anticheat

Implying that Linux gamers have to play with cheaters. It may as well not be playable at all.

play on good servers. play with good people.

Re: Games using anti-cheats and their compatibility with GNU/Linux or Wine/Proton

#444

Earlier quoted context omitted.

You were not helpless if the admin wasn't on, votekick has existed for 25+ years. Believe it or not us old folks who played during this time had ways to address these issues.

Votekick still exists in modern games, too.

Then it's weird you weren't aware of it when you posted your previous comment.

Re: Games using anti-cheats and their compatibility with GNU/Linux or Wine/Proton

#445

At this point - you would think that cheaters could be detected on the server side by either training a model to flag abnormal behavior or do some type of statistics on the movement patterns over time - is a client-side anti-cheat really required?

Many forms of cheating revolve around modding the game locally so that certain textures can be seen through walls, so you always know where opponents are. So you aren't breaking any laws of physics, you are just able to make much better tactical decisions. The obvious solution would be, just don't send data to the player's client about enemies that are behind walls. But this is a surprisingly hard thing to engineer i…

In Minecraft one of the common ways to catch people using x-ray hacks or transparent texture packs is to run statistics on the blocks mined. If the ratio of stone-to-diamond gets significantly out of whack it's a sure sign someone is cheating.

In blackjack card counting is (probabilistically) caught by tracking player winnings. If someone is beating the odds a bit too much it's a fairly good indicator they are counting cards. Of course in this case getting it wrong isn't so bad from the casinos perspective either since then they'll just kick out a player that was costing them money anyhow.

When the enigma cypher got cracked they had to be very careful about when to act on information gained. If they started beating the odds too much the Germans would cotton on to enigma being broken.

My point being that cheating will almost by definition improve your odds. There are definitely ways to catch that sort of thing happening without installing rootkits. You just might need to hire a couple mathematicians to figure it out.

Re: Games using anti-cheats and their compatibility with GNU/Linux or Wine/Proton

#446

Earlier quoted context omitted.

> Kernel anticheat is not really effective because it can be circumvented on the hardware level, for example using direct memory access with a second computer and screen to show the hidden game state. Incorrect. DMA (direct memory access) is and can be prevented [1] and detected [2]. [1] https://www.faceit.com/en/news/faceit-rollout-of-tpm-secure-... [2] https://community.osr.com/t/detecting-pcie-dma-based-cheatin...

Once again back to another arms race. Assuming that your operating system doesn't allow any bad drivers (Windows does NOT do this) physical access to the hardware is just a function of time and money to get direct access to the memory https://x.com/danielgenkin/status/1989003973429268974?s=12 Something like TEE.fail can be used to read encryption keys for network traffic then a MITM proxy can display player informati…

> Assuming that your operating system doesn't allow any bad drivers (Windows does NOT do this)

Windows eventually tends to revoke the certificate of vulnerable drivers. And prior to that, anti-cheats will flag the signature and prevent booting or outright ban for egregious ones.

> Something like TEE.fail can be used to read encryption keys for network traffic

So, encrypt the memory well then? Also, that attack slows down RAM to 3200 MT/S and is infeasible for game cheating. Maybe if you could make a custom ram stick with an ASIC on it, which would cost millions on millions of dollars to keep up with DDR5, you could capture encrypted bits and crash your system pretty often.

I don't consider it an arms race if you can prevent cheating to 10s of people in a million-player game. That's noise at best.

Re: Games using anti-cheats and their compatibility with GNU/Linux or Wine/Proton

#447

As most of you know, these anti-cheat systems are functionally equivalent to rootkits. There is zero visibility into how these privileges are used for targeted attacks. Due to geographic location of the large game companies this has a geopolitical angle. Fingerprinting of devices and the networks they are in provides a lot of metadata that is most definitely fed into their intelligence apparatus.

Unpopular opinion, but we would be better off with a single open trusted implementation of anti cheat (aka drm) which can attest whatever requirements are desired by the game is met. The only real problem is that it would likely be limited to approved kernel images and someone would need to own that validation and signing infrastructure, but you could imagine having multiple trusted entities have this role.

I'm not sure this is an unpopular opinion. I've seen it suggested multiple times, and IF done correctly (open/transparent) would solve most of the complaints with the ring-zero anti cheats. Still won't solve every cheat, especially hardware, social and perhaps good VMs. I would require the app/game to disclose what it requires to be true.

Re: Games using anti-cheats and their compatibility with GNU/Linux or Wine/Proton

#448
post #357

Earlier quoted context omitted.

>"Try playing Rust [...] and you will immediately change your tune." In general, really.

Yea, that's one game that's more fun to watch than play I will admit, so mostly I'm a "pro rust watcher with over 300 hours watching rust" (this is a bit of an in-joke, sorry) who sees the annoyance and lack of fun people have when they get destroyed by cheaters. I did play one wipe, and spent 25 hours over 3 days in the game, so I chose to quit right there instead of doing that on a regular basis.

Oh for sure, and even now I occasionally watch videos as background noise during work - but it's just not a fun game for the vast majority of times I log in. I'm about 175 hours in now; and for the one time a month I play, I can't be assed joining anything besides a 3x anymore with a wipe at least 10 days away, it's just too much sunk cost and wasted time even getting a 2x1 down in official or vanilla servers.

It's fun when I get something down (and fully use a starter kit, if a server has it) and have neighbors to dick around with, or there's not enough traffic to actually enjoy landmarks and underground, or occasionally when I meet someone that's down to team up or just talk on mic while pacing around one of our bases. But when that doesn't happen, I'm just not having fun haha

Re: Games using anti-cheats and their compatibility with GNU/Linux or Wine/Proton

#449

Earlier quoted context omitted.

Rust is playable on Linux on servers that disable anticheat

Implying that Linux gamers have to play with cheaters. It may as well not be playable at all.

Actually it kind of works out because cheaters want to play with people who aren't cheating. The few servers that run with anti-cheat disabled would have small communities that aren't attractive to cheaters.

Re: Games using anti-cheats and their compatibility with GNU/Linux or Wine/Proton

#450

Earlier quoted context omitted.

Once again back to another arms race. Assuming that your operating system doesn't allow any bad drivers (Windows does NOT do this) physical access to the hardware is just a function of time and money to get direct access to the memory https://x.com/danielgenkin/status/1989003973429268974?s=12 Something like TEE.fail can be used to read encryption keys for network traffic then a MITM proxy can display player informati…

> Assuming that your operating system doesn't allow any bad drivers (Windows does NOT do this) Windows eventually tends to revoke the certificate of vulnerable drivers. And prior to that, anti-cheats will flag the signature and prevent booting or outright ban for egregious ones. > Something like TEE.fail can be used to read encryption keys for network traffic So, encrypt the memory well then? Also, that attack slows…

> Windows eventually tends to revoke the certificate of vulnerable drivers. And prior to that, anti-cheats will flag the signature and prevent booting or outright ban for egregious ones.

I have been loading and using the WinIO driver on windows all the way up to the latest version to read and write any memory I want. I also have a few drivers that are lesser known that are not even flagged by most anti-cheats

> So, encrypt the memory well then? Also, that attack slows down RAM to 3200 MT/S and is infeasible for game cheating. Maybe if you could make a custom ram stick with an ASIC on it, which would cost millions on millions of dollars to keep up with DDR5, you could capture encrypted bits and crash your system pretty often.

You are going to have to decrypt the memory eventually. Even TEE.fail can get around AMD SEV and Intel's TEE. Reading memory speed doesn't really matter as long as you can find an encryption key for network traffic. Once you can intercept network traffic and decrypt its game over!

You do not need an ASIC to interpose DDR5 and steal all the traffic, there are FPGAs that are powerful enough. Once PCIE DMA cards go the way of the dino with IOMMU people will just switch to memory interposers with FPGAs

A few years ago, DMA cards cost upwards of $500. Now you can buy cards from china preloaded with pcieleech firmware for around $100. and there are thousands of customers. If you can afford the latest gen gaming gear and afford to spend money on cheats you can certainly fork over a couple hundred dollars for the latest undetected solution

Post reply on HN