Live data from Hacker News

Reverse engineering Call of Duty anti-cheat

ssno.cc

161–170 of 223 posts

Re: Reverse engineering Call of Duty anti-cheat

#161

A 2-year legal battle with Activision to overturn a false permanent ban. Activision showed up with zero evidence of cheating and lost: https://antiblizzard.win/2025/01/18/my-two-year-fight-agains...

The exact same thing happened to me with League of Legends. I was inexplicably banned for cheating, despite never having done any such thing (and despite regularly playing on three accounts (this is fully permitted), the other two of which were not banned!) Their support people repeatedly said "we reviewed your case and the ban is correct", etc. all the while giving zero information about what I did so I could correc…

Maybe take it as a signal from universe that intense gaming is waste of life and a net loss for you? I know its harsh and double that in gaming thread, but I don't see any other way. We don't talk 3-5h a week, and it seems neither are you.

You will almost certainly badly regret when on that proverbial death bed and most probably well before that, life goes darn fast and the feeling of losing out in the most important aspect of our existence - how well we live our lives is soul crushing. Its not that gaming hard is bad per se (apart from addictions and abysmal effect on health), but you are losing on much better aspects of life which are just out there for the grab.

Or don't take my word, just check what old people regret in their lives. Sure gaming is not there yet, but it will find its place firmly among too much work and not spending enough time on family and relationships, which are consistently on top.

Re: Reverse engineering Call of Duty anti-cheat

#162

Earlier quoted context omitted.

> Yes, which is why the aim is to have 0 legitimate players getting caught by this, obviously. You can't just say that though, you have to actually do that , which is apparently not what's happening.

The problem is obviously the same as in many other industries - how do you distinguish honest legitimate players who swear they haven't cheated from people who will say anything to get you to unban them. I don't work in that department personally, but I've seen reports shared internally where the player literally went to local news station to say how unfairly they are treated and how we banned him without any info or…

> how do you distinguish honest legitimate players who swear they haven't cheated from people who will say anything to get you to unban them.

It's mostly not about the appeals process. You want to avoid the false positive accusations to begin with.

> and then we pull up the ban report for his account and we clearly see a screenshot from his machine where he's running cheat engine with cheats for our game enabled.

Hypothetically things like this can happen where someone is reusing passwords that end up in a data breach and then some script kiddie gets their hands on it and wants to dip their toes into some cheating without risking their own account. Then you have the original account holder screaming at you because they know they didn't cheat.

Or they could just be cheaters who doth protest too much.

But there are ways you can at least try to distinguish these things, e.g. did the cheating happen on the same PC or IP address the account normally uses?

> Does that mean the system is foolproof? No, of course not. But banning honest paying users is a huge risk to any business - so obviously no one wants to do that, every system like this errs on the side of caution by default for that reason alone.

It's apparently failing enough that this thread has multiple people saying they've experienced false positives, and it doesn't seem like they're interested in getting their accounts back.

Re: Reverse engineering Call of Duty anti-cheat

#163
post #160

Earlier quoted context omitted.

Apex had plenty of cheaters when I played it, if there's a cheater and they're not detecting it there's not much I can do, just 20-30 minutes wasted. If its a server with admins I can contact them on discord and get them banned pretty quickly. As a system it worked pretty well, had some badmins but there was plenty of servers so could just join another. Though its not really compatible with the matchmaking style game…

I don't think you appreciate: 1. How many active Apex/whatever games there are at any one time 2. How many users will just report anyone they die to as a cheater

That sounds great but there was still cheaters in my games.

Re: Reverse engineering Call of Duty anti-cheat

#164
post #149

Earlier quoted context omitted.

Cheating will not get you banned on steam though, at worst your account is publicly shamed if its a VAC game. People play multiplayer games to have fun and interact with others. If you behave badly, be it cheating or otherwise, you should be banned from using the multiplayer service because your behavior impacts other people.

> If you behave badly, be it cheating or otherwise, you should be banned from using the multiplayer service because your behavior impacts other people. What if you behaved great but some guy fresh out of code boot camp's algorithm bans you?

Bugs and mistakes happen, when that happens it's typically some misidentification of a process or driver so a group of players get banned. And in every one of those cases I've seen they've been unbanned. The call of duty case is probably the worst one I've read about, also an outlier.

Re: Reverse engineering Call of Duty anti-cheat

#165
post #64

A 2-year legal battle with Activision to overturn a false permanent ban. Activision showed up with zero evidence of cheating and lost: https://antiblizzard.win/2025/01/18/my-two-year-fight-agains...

> This ban also ruined other games for me. If I ever did well in a game, someone would look at my profile to see how many hours I have and instantly see the red marker that shows “I am a cheater”. I wonder if that label can be considered to be libel. Probably harder in the US, but from what I understand in UK (or just England?) the defendant must prove that it's true.

On the UK though, computer data is proof. If the computer says you cheated, it’s proven.

This is about to change though, since the national postal services got a whole bunch of people convicted of fraud based on a system they knew buggy.

Re: Reverse engineering Call of Duty anti-cheat

#166
post #83

Earlier quoted context omitted.

The money loss is kinda the point. Cheaters can fake a new identity but if they get caught fast enough cheating becomes unaffordable.

Not sure it applies with CoD in particular but my impression is a lot of these games with super invasive anti-cheat went F2P which reduces the punishment of getting caught to wasting time. Combined with the no dedicated servers resulting in little manual admin being possible with new games you've basically created the perfect environment to cheat entirely for business reasons. So then they started adding things like…

If there's a thing that's worse than over-priced stuff is free stuff. No free lunch

Re: Reverse engineering Call of Duty anti-cheat

#167
post #104

A 2-year legal battle with Activision to overturn a false permanent ban. Activision showed up with zero evidence of cheating and lost: https://antiblizzard.win/2025/01/18/my-two-year-fight-agains...

Interesting stuff! Though I don’t get why b00lin would have to prove that they weren’t cheating. This is not a criminal case, but still. Activision was denying access to a service that was paid for.

Cheating was not allowed according to the terms and conditions.

Re: Reverse engineering Call of Duty anti-cheat

#168

Earlier quoted context omitted.

He does respond to minor inquiries frequently, but do remember that his company supports a gigantic predatory underage gambling market.

You could say “support a virtual market with insufficient controls” and be more truthful and engender a more productive discussion. They’ve come down pretty heavily on the gambling side, no?

> They’ve come down pretty heavily on the gambling side, no?

Not really. Back when this was a big story (around 2016-2017) they sent out some cease and desists to a number of the big CS:GO gambling websites but many did not comply and there was no follow-up. To this day many of those original sites are still around and have since grown. Essentially Valve (and the skin market as a whole) benefit so greatly from this grey-market that there is no incentive for them to stop it. This is covered in part 2 of Coffeezilla's latest series investigating CS:GO gambling [1]

[1] https://youtu.be/13eiDhuvM6Y?t=493

Re: Reverse engineering Call of Duty anti-cheat

#169

Earlier quoted context omitted.

Why is that different from speeding while driving ? Be a nuisance to society -> get fucked. That's a pretty universal principle

Because there is no court, just algorithm flagging people with some false positives For "get fucked" measures you need pretty low rate of false convictions

imo the problem would be solved if there was the ability and a culture of running your own game servers. Because I agree, being softlocked from a game you paid for sucks.

But also, cheaters suck, and whoever's running the server should be allowed to kick you out.

Re: Reverse engineering Call of Duty anti-cheat

#170
post #118

Earlier quoted context omitted.

Good luck ensuring every PCIe device with DMA access is "trusted."

IOMMU defeats DMA attacks. There is no reason for a GPU or network driver, or anything to have arbitrary physical memory access. If a GPU needs space for a draw-calls, allocate it in the kernel and explicitly give permission to the GPU to access it.

IOMMU gives the PCIe device access to whatever range of memory it's assigned. That doesn't prevent it from being assigned memory within the address space of the process, which can even be the common case because it's what allows for zero-copy I/O. Both network cards and GPUs do that.

An even better example might be virtual memory. Some memory page gets swapped out or back in, so the storage controller is going to do DMA to that page. This could be basically any memory page on the machine. And that's just the super common one.

We already have enterprise GPUs with CPU cores attached to them. This is currently using custom interconnects, but as that comes down to consumer systems it's plausibly going to be something like a PCIe GPU with a medium core count CPU on it with unified access to the GPU's VRAM. Meanwhile the system still has the normal CPU with its normal memory, so you now have a NUMA system where one of the nodes goes over the PCIe bus and they both need full access to the other's memory because any given process could be scheduled on either processor.

We haven't even gotten into exotic hardware that wants to do some kind of shared memory clustering between machines, or cache cards (something like Optane) which are PCIe cards that can be used as system memory via DMA, or dedicated security processors intended to scan memory for malware etc.

There are lots of reasons for PCIe devices to have arbitrary physical memory access.

Post reply on HN