Live data from Hacker News

I reversed Tower of Fantasy's anti-cheat driver: a BYOVD toolkit never loaded

vespalec.com

21–30 of 52 posts

Re: I reversed Tower of Fantasy's anti-cheat driver: a BYOVD toolkit never loaded

#21
post #16

Earlier quoted context omitted.

>I believe Minecraft has a system similar to what I described Except every big server has to run an anticheat. Some servers required clients with client side anticheats even. Some servers required you to screen share with a moderator and they would go through the files on your computer to look for cheats. Exploiting people for free labor to moderate servers was never enough to stop the issues cheating had. Even with…

> Except every big server has to run an anticheat. Some servers required clients with client side anticheats even. I am fine with anticheat on the server-side to help volunteers/moderators find issues, since it does not force the user to install any sketchy kernel-level software. As for the servers that require client-side anticheats, I was unaware there are Minecraft servers that do this (though I do not doubt you,…

>the same way someone would contribute to open source or moderate a forum in their spare time

It would be like open source business where the owner makes millions of dollars a month off the software and then tries to get people to work for him for free to make him even more money. The volunteers do all the work and the owner makes all of the money.

Re: I reversed Tower of Fantasy's anti-cheat driver: a BYOVD toolkit never loaded

#22
post #10
post #8

Earlier quoted context omitted.

> they should provide built-in anti-cheat support in the OS. As much as I dislike anti-cheat in general (why incorporate it instead of just having proper moderation and/or private servers? Do you need a sketchy third-party kernel level driver to police you to make sure you're "browsing the internet properly in a way that is compliant with company XYZ's policies", or even when running other software like a photo edito…

> I agree that having some first-party or reputable anti-cheat driver or system, is probably preferable than having different studios roll out their own anticheat drivers. (I am aware there are studio-level or common third party common anti-cheat solutions already, such as Denuvo or Vanguard. But I would prefer something better) Only Apple really has enough platform lockdown to achieve that. Whatever Microsoft ships…

> Whatever Microsoft ships would have more holes than swiss cheese

The current execution environment with IOMMU and TPM requirements is changing this rapidly.

Try disabling Windows Defender - good luck.

Re: I reversed Tower of Fantasy's anti-cheat driver: a BYOVD toolkit never loaded

#23

Earlier quoted context omitted.

If a surgeon does not have the expertise to perform a surgery, they probably shouldn’t cut into you. If the company lacks the competency to write secure driers, they should outsource the work or have it validated externally. These things could be solved by spending money. Stop excusing dangerous actions performed in the name of greed.

Exactly, which is why Microsoft should be writing the one writing the kernel code needed for ensuring integrity of games. Microsoft needs to develop ways to allow games to run in an isolated VM that is hardware protected from the main operating system and ensures strong hardware security so cheaters can not simply attach malicious devices to the PCI bus to DMA sensitive data.

> attach malicious devices to the PCI bus to DMA sensitive data

How do you do this in modern system with TPMs and IOMMU enabled?

Re: I reversed Tower of Fantasy's anti-cheat driver: a BYOVD toolkit never loaded

#24
post #23

Earlier quoted context omitted.

Exactly, which is why Microsoft should be writing the one writing the kernel code needed for ensuring integrity of games. Microsoft needs to develop ways to allow games to run in an isolated VM that is hardware protected from the main operating system and ensures strong hardware security so cheaters can not simply attach malicious devices to the PCI bus to DMA sensitive data.

> attach malicious devices to the PCI bus to DMA sensitive data How do you do this in modern system with TPMs and IOMMU enabled?

Sadly not all Windows machines are able to use kernel DMA protection, so for those machines nothing will stop you.

Re: I reversed Tower of Fantasy's anti-cheat driver: a BYOVD toolkit never loaded

#25
Not related to the main contents of the post, but

> For the life of me, I couldn’t find a way to do it without having the game installed. There was no web portal and no obvious support route.

They have am email in their privacy policy, which is generally where you should look if you want to delete your account

Re: I reversed Tower of Fantasy's anti-cheat driver: a BYOVD toolkit never loaded

#27
post #22
post #10

Earlier quoted context omitted.

> I agree that having some first-party or reputable anti-cheat driver or system, is probably preferable than having different studios roll out their own anticheat drivers. (I am aware there are studio-level or common third party common anti-cheat solutions already, such as Denuvo or Vanguard. But I would prefer something better) Only Apple really has enough platform lockdown to achieve that. Whatever Microsoft ships…

> Whatever Microsoft ships would have more holes than swiss cheese The current execution environment with IOMMU and TPM requirements is changing this rapidly. Try disabling Windows Defender - good luck.

This is done for the benefit of Hollywood.

Re: I reversed Tower of Fantasy's anti-cheat driver: a BYOVD toolkit never loaded

#28

Earlier quoted context omitted.

If a surgeon does not have the expertise to perform a surgery, they probably shouldn’t cut into you. If the company lacks the competency to write secure driers, they should outsource the work or have it validated externally. These things could be solved by spending money. Stop excusing dangerous actions performed in the name of greed.

Exactly, which is why Microsoft should be writing the one writing the kernel code needed for ensuring integrity of games. Microsoft needs to develop ways to allow games to run in an isolated VM that is hardware protected from the main operating system and ensures strong hardware security so cheaters can not simply attach malicious devices to the PCI bus to DMA sensitive data.

As an indie game developer, how do I get my game into this system and how do I debug it?

Re: I reversed Tower of Fantasy's anti-cheat driver: a BYOVD toolkit never loaded

#29
post #23

Earlier quoted context omitted.

Exactly, which is why Microsoft should be writing the one writing the kernel code needed for ensuring integrity of games. Microsoft needs to develop ways to allow games to run in an isolated VM that is hardware protected from the main operating system and ensures strong hardware security so cheaters can not simply attach malicious devices to the PCI bus to DMA sensitive data.

> attach malicious devices to the PCI bus to DMA sensitive data How do you do this in modern system with TPMs and IOMMU enabled?

You pretend to be a device with a driver not compatible with IOMMU

Re: I reversed Tower of Fantasy's anti-cheat driver: a BYOVD toolkit never loaded

#30
post #9

Earlier quoted context omitted.

It is not realistic to expect every game developer to invest a lot of money into security. It's like asking every apartment building to run its own fire department. The responsibility of securing a platform should not fall on application developers anyway.

The problem is that general purpose computing platforms are not supposed to be secured against the user. That's a WONTFIX.

User ownership of their devices has been fixed on every platform except PCs.
Post reply on HN