289
submitted 2 months ago by alessandro@lemmy.ca to c/pcgaming@lemmy.ca
top 50 comments
sorted by: hot top controversial new old
[-] renegadespork 185 points 2 months ago

That kernel level anti-cheat is really working out well, eh?

[-] ILikeBoobies@lemmy.ca 54 points 2 months ago

Kernel level isn’t about stopping cheaters, it’s about gaining system access

[-] Revan343@lemmy.ca 14 points 2 months ago

Naw, it's about pretending to stop cheaters. It's security theatre, same as the TSA

[-] maccentric@sh.itjust.works 9 points 2 months ago
[-] kopasz7@lemmy.world 27 points 2 months ago* (last edited 2 months ago)

Any mention of data collection in the ToS?

[-] Sas@beehaw.org 6 points 2 months ago

And about putting a buzzword on your game that makes people think they're safe from cheaters

[-] GetOffMyLan@programming.dev 5 points 2 months ago
[-] KeenFlame@feddit.nu 9 points 2 months ago

Their source comes from it giving system access and that is what they want.

[-] GetOffMyLan@programming.dev 2 points 2 months ago

Why would they want that? Are there any cases of it being abused?

[-] KeenFlame@feddit.nu 2 points 2 months ago

Yeah why would any mega conglomerate corporate entity want the most valuable and easy to harvest resource on earth

load more comments (3 replies)
[-] SomethingBurger@jlai.lu 7 points 2 months ago

It has system access yet doesn't prevent cheating.

[-] lud@lemm.ee 2 points 2 months ago

Nothing is perfect bruh.

[-] CalcProgrammer1@lemmy.ml 130 points 2 months ago

Honestly, not even mad. Sucks for the victims, but we need hackers poking holes in kernel anticheats. Show the game companies that kernel anticheat is a waste of effort and maybe this horrific plague of gaming will die off.

[-] GetOffMyLan@programming.dev 3 points 2 months ago

The issue is that without it cheating is so much easier in many games. So then people just get pissed at all the hackers.

[-] dontgooglefinderscult@lemmings.world 23 points 2 months ago

No, not really. That's the point. Kernel level anticheat has no real advantages and is easily bypassed. It's the laziest possible solution that only detects and blocks the laziest possible implementations of cheats.

Good game design eliminates the possibility of cheating. Cheats are only ever possible if you take enough stupid and lazy shortcuts that it's easy to take advantage.

[-] lorty@lemmy.ml 3 points 2 months ago

So what are these easy anti-cheat solutions that can detect aim-hacking?

That's super easy. Aim hacks hit the same point. Record the event with the exact point aimed at to cause the guy (assuming hit scan system instead of projectile), and compare the last x number of hits. If the last x hits are all the same location(s), suspend or flag for human review depending on resources.

Alternatively, track last x seconds before the fire button was pressed, compare to last several shots.

Scripts do not behave like humans, they aim predictably. After x number of shots, you can always programmatically detect them.

[-] untimed@lemm.ee 8 points 2 months ago

First of all, I‘m not a fan of kernel level anti cheats either. I think your point shows the never ending cat and mouse game that game developers have to deal with. Implement what you described, catch a few cheaters. Now cheats developers add pseudo random deviations within the hitbox to their aim hack. From what I understood, the kernel level anti cheats aimed to abstract and attack at the single point that all cheats have in common. I am not up to date but I believe that single point is code, that is being injected into the game process, or another program messing with the allocated memory of the game process. At least that would make sense to me as to why such an intrusive implementation of anti cheat is necessary.

Anyway, in my opinion the gains do not justify it.

To your first point pseudorandom variations don't actually change the method of detection or it's effectiveness. Heuristic pattern matching as described will work until the movement and shots are no longer accurate enough or fast enough to matter.

To your second point, all anticheats do that. Kernel level anticheat looks at the running memory of all other programs. That's the difference. It can detect and scan anything that is open on your machine. Got a Firefox tab open with your bank details? Kernel level anti cheat knows it. Running obs and streaming? Hope obs has active encryption for your stream key in memory, because the anti cheat can grab it otherwise.

If it just looked at the memory of the affected game literally no one would have a problem with it, that's all anticheats.

Kernel level anticheat means you trust the entirety of your computer and everything running on it to at least the game publisher, if not an additional anticheat company.

[-] Sas@beehaw.org 5 points 2 months ago

Interestingly enough valve has tried your method of catching cheaters your way by pattern matching with a neutral network in csgo. Sadly they never got to the confidence level where they made it automatically ban people because they didn't want to catch really good players in the crossfire. Instead they send them to overwatch, a system where sufficiently good players could judge the case and determine if the person is cheating.

But also there's many different types of cheats and that will only gets you so far. Information plays a big role in cs so wall hacks can go undetected if the player masks then which they do since they know they're probably watched. There's also subtle aim bot for that reason that doesn't snap your aim to your enemy precisely but corrects your manual aim by just correcting it a tiny bit.

As the other user described, it is an arms race and so far the cheaters keep finding ways to trick the algorithm after each ban wave. I still admire valve for not going kernel level with their anti cheat and trying the complicated and interesting route instead. However i think that is because valve tried kernel level when it was still resisted by gamers so they got big backlash at the time and went back to regular anti cheat.

I think what worked best for me was trust factor, which rates the trustworthiness of your steam account and since i have a legit account I've not played against cheaters since they implemented it and until i stopped playing. It sucks for new players with new steam accounts tho as they get matched with a lot of cheaters.

[-] GetOffMyLan@programming.dev 3 points 2 months ago

Bots just get around that by adding random amounts. We learnt this with RuneScape lol

Also in a fast paced FPS they aren't going to hit the same spot from the same position repeatedly.

I covered that, there is no real RNG. It will always be able to be programmatically detected over enough shots.

To your second part, yes, they will. They aim at the same point. Even if there's variance in the points there won't be enough variance in moving to the points that they'll be able hide the unnatural movement.

[-] GetOffMyLan@programming.dev 4 points 2 months ago

Again this happened in RuneScape with the auto clickers. Every time they get better at detecting them the hackers get better at hiding them. You just start throwing on a few miss fires and they're back to square one. It really isn't as simple as you describe or they would do it.

load more comments (3 replies)
[-] Avatar_of_Self@lemmy.world 8 points 2 months ago

Yes, if they offload all of the compute for anti-cheat to the customer's hardware, then you are right for current operating systems.

Client side anti-cheat is not the only way but it is the cheapest way for the game industry.

[-] GammaGames@beehaw.org 71 points 2 months ago* (last edited 2 months ago)

Vizor explained that Ricochet uses a list of hardcoded strings of text to detect cheaters and that they then exploited this to ban innocent players by simply sending one of these strings via an in-game whisper. To test the exploit the day they found it, they sent an in-game message containing one of these strings to themselves and promptly got banned.

Vizor elaborates, "I realized that Ricochet anti-cheat was likely scanning players’ devices for strings to determine who was a cheater or not. This is fairly normal to do but scanning this much memory space with just an ASCII string and banning off of that is extremely prone to false positives."

This is insane, they had an automatic script to connect to games and ban random people on loop so they could do it while away

[-] renegadespork 27 points 2 months ago

a list of hardcoded strings

Violating a core programming tenet right off the bat. I wonder how much money Activision payed for this software...

[-] ramjambamalam@lemmy.ca 14 points 2 months ago

We and the hacker have no idea if this list is config driven or truly "hard coded" i.e. a const in the source code. It's hardly an indicator of violating a core programming tenet.

[-] ICastFist@programming.dev 61 points 2 months ago

So, simply receiving "aim bot" as a whisper (private) message was enough to get permabanned. FUCKING JEE-NIUS ANTICHEAT, GREAT JOB, GUYS!!!

[-] blindbunny@lemmy.ml 34 points 2 months ago
[-] YeetPics@mander.xyz 23 points 2 months ago

Shitting your pants is punk, too.

All the punkest punks shit their pants.

[-] misterdoctor@lemmy.world 14 points 2 months ago

If hacking call of duty is cool, consider me miles davis

[-] Duamerthrax@lemmy.world 3 points 2 months ago

I thought that was the gas station hotdog.

load more comments (1 replies)
[-] thisbenzingring@lemmy.sdf.org 2 points 2 months ago
[-] Kolanaki@yiffit.net 14 points 2 months ago

Is stopping cheaters in most video games even possible?

[-] jerkface@lemmy.ca 13 points 2 months ago

When I was at my peak effectiveness in Urban Terror, I could hold my own against them...

[-] Kolanaki@yiffit.net 19 points 2 months ago* (last edited 2 months ago)

Heh. GTA V used to be fun even when a cheater would show up and because you could just use a rocket launcher on them to keep them ragdolled forever so they couldn't use their cheat menu (or any menu). They'd have to alt-F4 to quit since being ragdolled closes any open menus.

[-] TheDorkfromYork@lemm.ee 5 points 2 months ago

Yes, but not through standard methods. Even AI aimbot can be filtered, but the amount of RND required is likely to much for a single studio to bear alone. I believe we are more likely to see neural network trained bots largly replacing real players using an off the shielf model. Just a guess, not an expert.

[-] Doomsider@lemmy.world 8 points 2 months ago

There is already a solution using relatively simple analytics and building a profile of the player. It becomes very easy to find cheaters because it is easy to analyze how fast and directionally they aim. It is obvious when someone is using macros for instance or a aimbot.

The problem is this does not require intrusive programs that are essentially spyware for your OS. This is what attracts the big studios to these solutions not their effectiveness.

There is a workable solution but let's be honest. Cheaters are often whales and spend a lot of time and money on the game. It is bad engagement to send them away.

Big studios already recognize this. So to be blunt they allow a certain amount of cheating because they don't want to really solve the problem.

[-] TheDorkfromYork@lemm.ee 3 points 2 months ago

I was speaking to the long term, 5-10 year in.the future. Analytics is a current solution and as far as I know works well. I was just talking vaguely about long term problems and solutions.

[-] CleoTheWizard@lemmy.world 5 points 2 months ago

I think the best thing I’ve heard for long term solutions is to fix a lot of the cheating using server side solutions. In a game like CoD, that means the server doesn’t send you player positions unless you absolutely need to know them.

The other thing honestly is just increasing the investment required to cheat. That could mean that in order to play competitive game modes, you need to have signed in at least once for 4 weeks straight and played the game. Or you need to be a certain level. Issue hardware bans and IP bans to people. Require phone number verification.

What those things do as barriers is actually increase the potency of current detection methods. This should also carry over to accounts. I’m not sure why steams VAC ban system isn’t more popular. As in accounts need to be flagged as a whole when cheating in just one game is found.

There are many solutions but it’s just not a big deal for companies as the prior person said. Plenty could be done to at least make cheating harder and cost more time/money. But that won’t happen

[-] jerkface@lemmy.ca 2 points 2 months ago

I’m not sure why steams VAC ban system isn’t more popular. As in accounts need to be flagged as a whole when cheating in just one game is found.

Presumably because this opens players to significantly damaging abuse from server operators. Players aren't the only ones who fuck around.

load more comments (1 replies)
[-] Evotech@lemmy.world 1 points 2 months ago

Cod is peer to peer. Clients host the game server.

[-] CleoTheWizard@lemmy.world 1 points 2 months ago

They use a hybrid system now and only use peer to peer when dedicated servers aren’t enough, so they could just swap to purely dedicated servers.

However ignoring that, even a peer to peer system can do similar tricks if you don’t isolate the host peer to just one machine. That can even be done by spot checking with a company owned server. You use the server as a verification peer and have it as a backup host to the assigned peer. If your verification peer gets different ram values or what not, you shut the server down at the very least and place that peer on a suspicion list.

But even if they went the cheap route, just distribute the peer network. Let’s say that you have a game of 12 people. You could make it so that each peer is only assigned a certain part of the simulation and players (with overlap on assignments) and cannot track the entire simulation. It’s more complicated than a single server hiding info from you, but they could at least make it to where you’d need multiple infected peers to take over a lobby.

[-] Doomsider@lemmy.world 2 points 2 months ago

I think you were spot on about training a neural network with player data. It is already happening without a doubt.

[-] Evotech@lemmy.world 3 points 2 months ago* (last edited 2 months ago)

It requires the server to verify all inputs. It's doable, path of exile does that and most arpgs. But it leaves them very open to lag and desync issues, most games will prioritize a smooth experience.

Cod is peer to peer I think, clients host the server, very cheap for the company. But obviously you need to give the client a lot more information.

[-] upandatom@lemmy.world 2 points 2 months ago

I doubt COD is peer to peer anymore. Maybe like 10 years ago. No way they are giving up that much control over the game

load more comments (2 replies)
[-] Defaced@lemmy.world 5 points 2 months ago

But you know, according to EA Linux is worse than guys like this deliberately causing disruptions in service to legit players.

load more comments
view more: next ›
this post was submitted on 08 Nov 2024
289 points (100.0% liked)

PC Gaming

8932 readers
540 users here now

For PC gaming news and discussion. PCGamingWiki

Rules:

  1. Be Respectful.
  2. No Spam or Porn.
  3. No Advertising.
  4. No Memes.
  5. No Tech Support.
  6. No questions about buying/building computers.
  7. No game suggestions, friend requests, surveys, or begging.
  8. No Let's Plays, streams, highlight reels/montages, random videos or shorts.
  9. No off-topic posts/comments, within reason.
  10. Use the original source, no clickbait titles, no duplicates. (Submissions should be from the original source if possible, unless from paywalled or non-english sources. If the title is clickbait or lacks context you may lightly edit the title.)

founded 2 years ago
MODERATORS