Live data from Hacker News

Why anti-cheat software utilizes kernel drivers (2020)

secret.club

21–30 of 68 posts

Re: Why anti-cheat software utilizes kernel drivers (2020)

#21
post #3

Vanguard runs on Ring 0. -> Ring 3 software can also read your hdd so is not a problem. Why load on boot? -> Because we need to, don't worry. Why is scanning my serial port -> Is a bug, don't worry is not a problem. What if Riot is hacked? -> If Microsoft gets hacked is even worse, so is not a problem.

The same style of argument used by ChatControl proponents. I mean, what's another backdoor going to do in the swiss cheese that is Whatsapp/$INSERT_IM_PLATFORM_HERE security ?

Point is that it doesn't need ring 0 access to to bad stuff.

Re: Why anti-cheat software utilizes kernel drivers (2020)

#22
post #17

Earlier quoted context omitted.

This is the main issue I have with these. Microsoft should be providing this at the platform level, give developers "Xbox Anti-Cheat" and ship it with Windows.

How much of Xbox anti cheat is "can only run signed code"? Might not be compatible with regular PC use but maybe if we had a gaming mode we could boot into.

[deleted]

Re: Why anti-cheat software utilizes kernel drivers (2020)

#23
post #18
post #12

HN has a lot of very clever people. Solving online game cheating is a billion dollar business.

SK has it under control but people would never implement the same measures in the US and EU

Having to register with your personal id number? Remember getting those to play Korean WoW beta.

Re: Why anti-cheat software utilizes kernel drivers (2020)

#24
post #3

Vanguard runs on Ring 0. -> Ring 3 software can also read your hdd so is not a problem. Why load on boot? -> Because we need to, don't worry. Why is scanning my serial port -> Is a bug, don't worry is not a problem. What if Riot is hacked? -> If Microsoft gets hacked is even worse, so is not a problem.

>Vanguard runs on Ring 0. -> Ring 3 software can also read your hdd so is not a problem. Can also read process memory of the same user.

Can't read files or access memory of other users though, which is kind of the point. It's trivially easy to run games as a different user than the one you use for e.g. banking, and operating systems have had fast user switching for decades.

Re: Why anti-cheat software utilizes kernel drivers (2020)

#26
post #17

Earlier quoted context omitted.

This is the main issue I have with these. Microsoft should be providing this at the platform level, give developers "Xbox Anti-Cheat" and ship it with Windows.

How much of Xbox anti cheat is "can only run signed code"? Might not be compatible with regular PC use but maybe if we had a gaming mode we could boot into.

Not talking about Xbox the console, but Microsoft has been treating Xbox as a general gaming brand (Xbox Game Pass for PC).

Basically just an anti-cheat service that ships with Windows.

Re: Why anti-cheat software utilizes kernel drivers (2020)

#27
post #3

Vanguard runs on Ring 0. -> Ring 3 software can also read your hdd so is not a problem. Why load on boot? -> Because we need to, don't worry. Why is scanning my serial port -> Is a bug, don't worry is not a problem. What if Riot is hacked? -> If Microsoft gets hacked is even worse, so is not a problem.

> Why load on boot? -> Because we need to, don't worry.

I believe the reason stated was "because we know it will not be tampered with after boot". Not saying it's a good or bad reason, but this is dishonest paraphrasing.

Re: Why anti-cheat software utilizes kernel drivers (2020)

#28

Earlier quoted context omitted.

The same style of argument used by ChatControl proponents. I mean, what's another backdoor going to do in the swiss cheese that is Whatsapp/$INSERT_IM_PLATFORM_HERE security ?

Point is that it doesn't need ring 0 access to to bad stuff.

Ring 3 and Ring 0 can try to do the same bad stuff.

But the point is that in one the OS security layers or antivirus will catch it.

Re: Why anti-cheat software utilizes kernel drivers (2020)

#29
Valorant (game using kernel anti-cheat) is made by Riot Games, which is owned by Tencent (since 2011) a Chinese company with heavy ties to the Chinese Communist Party.

[1] "According to a report by Sina Tech in October 2017, Tencent employed over 7,000 members of the Chinese Communist Party (CCP) ... "With over 7,000 CCP members, accounting for approximately 23% of the total workforce, and more than 60% of whom are core technical personnel, the number of CCP members at Tencent is increasing by nearly a thousand every year." [2] "The Tencent Party Member Activity Center has a dedicated CCP member activity area of more than 6,000 square meters. More than 1 million yuan is allocated for CCP activities per year."

As someone who plays games every day, with ~3000 hours in Counter Strike at a decently high level. I've only ever encountered blatant hackers maybe 3 times in the last 10 years. I definitely do not care enough to start allowing random companies Kernel level access to my machine.

[1] https://archive.md/20230323012647/https://tech.sina.cn/2017-... [2] http://dangjian.people.com.cn/n1/2016/0630/c117092-28513326....

Re: Why anti-cheat software utilizes kernel drivers (2020)

#30
post #3

Vanguard runs on Ring 0. -> Ring 3 software can also read your hdd so is not a problem. Why load on boot? -> Because we need to, don't worry. Why is scanning my serial port -> Is a bug, don't worry is not a problem. What if Riot is hacked? -> If Microsoft gets hacked is even worse, so is not a problem.

> Why load on boot? -> Because we need to, don't worry. I believe the reason stated was "because we know it will not be tampered with after boot". Not saying it's a good or bad reason, but this is dishonest paraphrasing.

I said it because I think other kernel level anticheat don't do it.

If I remember correctly I can just enable/disable the easy anticheat service, sane with the EA thing, I don't need to reboot the machine like with Vanguard.

But thanks for pointing it out.

Post reply on HN