Valve announced a change for Steam today that will make things a lot clearer for everyone, as developers will now need to clearly list the kernel-level anti-cheat used on Steam store pages.

Now if only they could more clearly communicate when games are playable offline.

@[email protected]
link
fedilink
English
417M

Can someone explain like I’m stupid on kernel level anti cheat and why I should watch out for it? Not a dig at all, a genuine question!

@[email protected]
link
fedilink
English
27M

Imagine a game having higher privileges than what you get with “Run as administrator”

@[email protected]
link
fedilink
English
157M

Easy, a bug in battle eye forced me to reinstall windows, this kernel access has to go.

ℍ𝕂-𝟞𝟝
link
fedilink
English
36
edit-2
7M

Making it super simple, it runs with full access on your machine, always. It can fuck anything up, and see everything. It can get your browser history, banking details or private messages you enter, activate your webcam or mic without you knowing, or brick your computer even.

And you can’t even check what it’s really doing on your computer because it’s a crime under US law.

Finally, it can get hacked and other people than the creator can do all these to your computer as well,as it already happened once.

@[email protected]
link
fedilink
English
47M

And you can’t even check what it’s really doing on your computer because it’s a crime under US law.

Is this specifically for kernel level anticheat? Because this isn’t a thing for software in general right??

ℍ𝕂-𝟞𝟝
link
fedilink
English
47M

It’s a thing for any measure said to enforce copyright under the DMCA.

So it’s a thing for most proprietary software.

@[email protected]
link
fedilink
English
17M

If anything reverse engineering is more permissible in the USA than many other places, IIRC

ℍ𝕂-𝟞𝟝
link
fedilink
English
47M

Not if you’re running afoul of the DMCA.

LoboAureo
link
fedilink
English
87M

Also, the most games that don’t work in linux is for this reason (and steamdeck works in linux)

ArchRecord
link
fedilink
English
102
edit-2
7M

To put it very simply, the ‘kernel’ has significant control over your OS as it essentially runs above everything else in terms of system privileges.

It can (but not always) run at startup, so this means if you install a game with kernel-level anticheat, the moment your system turns on, the game’s publisher can have software running on your system that can restrict the installation of a particular driver, stop certain software from running, or, even insidiously spy on your system’s activity if they wished to. (and reverse-engineering the code to figure out if they are spying on you is a felony because of DRM-related laws)

It basically means trusting every single game publisher with kernel-level anticheat in their games to have a full view into your system, and the ability to effectively control it, without any legal recourse or transparency, all to try (and usually fail) to stop cheating in games.

@[email protected]
link
fedilink
English
107M

Not all anti cheats run at startup. Some only run when you play a game. I think vanguard for valorant ran all the time at first and people were pissed. Meanwhile easy anti cheat runs only with a game. So it depends. It all sucks though.

ArchRecord
link
fedilink
English
57M

That’s definitely true, I probably should have been a little more clear in my response, specifying that it can run at startup, but doesn’t always do so.

I’ll edit my comment so nobody gets the wrong idea. Thanks for pointing that out!

@[email protected]
creator
link
fedilink
English
647M

And it’s worth noting that trusting the game developer isn’t really enough. Far too many of them have been hacked, so who’s to say it’s always your favorite game developer behind the wheel?

sp3ctr4l
link
fedilink
English
207M

Or, even better, when you let a whole bunch of devs have acces to the kernel…

sometimes they just accidentally fuck up and push a bad update, unintentionally.

This is how CrowdStrike managed to Y2K an absurd number of enterprise computers fairly recently.

Its also why its … you know, generally bad practice to have your kernel just open to fucking whoever instead of having it be locked down and rigorously tested.

Funnily enough, MSFT now appears to be shifting toward offering much less direct access to its kernel to 3rd party software devs.

@[email protected]
link
fedilink
English
607M

More importantly, if traditional anticheat has a bug, your game dies. Oh no.

If kernel level anticheat has a bug, your computer blue screens (that’s specifically what the blue screen is: a bug in the kernel, not just an ordinary bug that the system can recover from). Much worse. Sure hope that bug only crashes your computer when the game is running and not just whenever, because remember a kernel-level program can be running the moment your computer boots as above poster said

@[email protected]
link
fedilink
English
47M

It’s not just trust of the game developer. I honestly believe most of them just want to put out profitable games. It’s trust that a hacker won’t ever learn how to sign their code in a way that causes it to be respected as part of the game’s code instructions.

There was some old article about how a black hat found a vulnerability in a signed virtual driver used by Genshin Impact. So, they deployed their whole infection package together with that plain driver to computers that had never been used for video games at all; and because Microsoft chose to trust that driver, it worked.

I wish I could find an article on it, since a paraphrased summary isn’t a great source. This is coming from memory.

@[email protected]
link
fedilink
English
27M

It’s trust that a hacker won’t ever learn how to sign their code in a way that causes it to be respected as part of the game’s code instructions.

That’s not an accurate description of the exploit you describe. It sounds like the attacker bundled a signed and trusted but known vulnerable version of the module, then used a known exploit in that module to run their own unsigned, untrusted code with high privileges.

This can be resolved by marking that signature as untrusted, but that requires the user to pull an update, and we all know how much people hate updating their PC.

@[email protected]
link
fedilink
English
47M

Thank you! Really clear and appreciate you taking the time to explain!

Create a post

Welcome to the largest gaming community on Lemmy! Discussion for all kinds of games. Video games, tabletop games, card games etc.

Rules

1. Submissions have to be related to games

Video games, tabletop, or otherwise. Posts not related to games will be deleted.

This community is focused on games, of all kinds. Any news item or discussion should be related to gaming in some way.

2. No bigotry or harassment, be civil

No bigotry, hardline stance. Try not to get too heated when entering into a discussion or debate.

We are here to talk and discuss about one of our passions, not fight or be exposed to hate. Posts or responses that are hateful will be deleted to keep the atmosphere good. If repeatedly violated, not only will the comment be deleted but a ban will be handed out as well. We judge each case individually.

3. No excessive self-promotion

Try to keep it to 10% self-promotion / 90% other stuff in your post history.

This is to prevent people from posting for the sole purpose of promoting their own website or social media account.

4. Stay on-topic; no memes, funny videos, giveaways, reposts, or low-effort posts

This community is mostly for discussion and news. Remember to search for the thing you’re submitting before posting to see if it’s already been posted.

We want to keep the quality of posts high. Therefore, memes, funny videos, low-effort posts and reposts are not allowed. We prohibit giveaways because we cannot be sure that the person holding the giveaway will actually do what they promise.

5. Mark Spoilers and NSFW

Make sure to mark your stuff or it may be removed.

No one wants to be spoiled. Therefore, always mark spoilers. Similarly mark NSFW, in case anyone is browsing in a public space or at work.

6. No linking to piracy

Don’t share it here, there are other places to find it. Discussion of piracy is fine.

We don’t want us moderators or the admins of lemmy.world to get in trouble for linking to piracy. Therefore, any link to piracy will be removed. Discussion of it is of course allowed.

Authorized Regular Threads

Related communities

PM a mod to add your own

Video games

Generic

Help and suggestions

By platform
By type
By games
Language specific
  • 1 user online
  • 248 users / day
  • 668 users / week
  • 2.48K users / month
  • 6.53K users / 6 months
  • 1 subscriber
  • 6.23K Posts
  • 127K Comments
  • Modlog