Live data from Hacker News

Steam games will need to disclose kernel-level anti-cheat on store pages

gamingonlinux.com

121–130 of 660 posts

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#121

Earlier quoted context omitted.

China's national security assistance law came up in the TikTok hearings. There's no reason to believe that the CCP doesn't have the legal authority to compel Riot to push an update with a backdoor to a few select high value targets.

Companies rule the United States. Companies that do business in China are ruled by China. Therefore, the United States is ruled by China.

The same line of thinking leads me to conclude that the world is ruled by the United States.

Can we stop with the nationalistic hyperbole already, and discuss acute issues, instead of vague fingerwaving at the foreign boogieman?

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#122

Earlier quoted context omitted.

It's not about prevention, but detection.

I'm not sure what point you're trying to make but in this context there is no difference. If you know someone is cheating, you prevent further cheating by banning them. Now I'll ask: how do you detect someone wall hacking automatically? No human review and no false flags. Go!

> If you know someone is cheating, you prevent further cheating by banning them.

If you think it's statistically likely that someone might be cheating, but you're not sure, you can matchmake them with other people who might be cheating.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#123
post #22

Earlier quoted context omitted.

If I wanted to deploy a trojan horse then the last place I would try to hide it is in an anti-cheat driver that will without any doubt be exhaustively analysed by people attempting to bypass it.

Gamers are great targets. They'll disable security for higher polling rates. Not discerning, gladly walk to the slaughterhouse.

Ah, yes, for most of us, getting our computer pwned is just like being murdered.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#124

Earlier quoted context omitted.

I think the problem is that that kind of work requires a good deal of developer resources for a long time. What company wants to pay upkeep on a shipped product? You could save hundreds of thousands of dollars a year by shipping a rootkit to players and not worrying about server security.

I suppose Valve, who trained a neural network to detect/ban cheaters exhibiting unnatural behavior.

It hasn't paid off very much, CS2 still has a rampant cheating problem. VAC has been a joke for years at this point.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#125

Earlier quoted context omitted.

It's not about prevention, but detection.

I'm not sure what point you're trying to make but in this context there is no difference. If you know someone is cheating, you prevent further cheating by banning them. Now I'll ask: how do you detect someone wall hacking automatically? No human review and no false flags. Go!

> how do you detect someone wall hacking automatically?

You don't tell the client the location of anything they can't see.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#126
post #115

Earlier quoted context omitted.

> They expose a kernel API to allow games to verify the state of the system And that API has root access... thus it's a rootkit.

The API doesn't provide root access, it's typically a simple "is this game running in a secure environment" read API. I really hate "it's a rootkit!" posts like this because it diminishes the severity of actual rootkits.

Can you please clarify how an API which runs in the kernel does not have root access? Because I don't believe that's possible, but perhaps I'm wrong.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#127
post #123

Earlier quoted context omitted.

Gamers are great targets. They'll disable security for higher polling rates. Not discerning, gladly walk to the slaughterhouse.

Ah, yes, for most of us, getting our computer pwned is just like being murdered .

l o l

Fine, they'll gladly eat shit

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#128

Earlier quoted context omitted.

It's going on a tangent, but one naive take which continues to amuse me when it comes up is community/third party servers and policing of cheating. As though delegating that responsibility is the goal or that it would scale to handle the size of modern playerbases including the ratio of admins to players to be able to monitor and respond to (alleged) cheaters

With community servers an admin only has to police their server, which is a fixed number. More players, more servers, more admins.

But as gaming has grown and become more mainstream, the ratio of enthusiasts who are willing to admin to casual players who don't has changed. Server sizes have changed over time with smaller games like 5v5 becoming way more common.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#129
post #59
post #47

Earlier quoted context omitted.

Cheats and bots are ruining online games though.

Yeah life sucks when everything and everyone has to be untrusted (applies not just video games). The solution is to build trusted spaces again IMO. For video games assume that each user is trusted by default. As soon as they violate that trust by cheating, they are banned permanently for that copy of the game. If they want to be trusted again they have to buy another copy of the game to get another license. Make it h…

Talking just about games, this really doesn't work with free games. Even if there is a lengthy 'lockout' period from the real game, many games have rampant and cheap accounts for sale and doing so will make the game experience worse.

Re: Steam games will need to disclose kernel-level anti-cheat on store pages

#130
post #115

Earlier quoted context omitted.

> They expose a kernel API to allow games to verify the state of the system And that API has root access... thus it's a rootkit.

The API doesn't provide root access, it's typically a simple "is this game running in a secure environment" read API. I really hate "it's a rootkit!" posts like this because it diminishes the severity of actual rootkits.

How do you think it is able to tell if the game is "running in a secure environment" without having root access itself?
Post reply on HN