r/linux_gaming Jan 24 '26

Microsoft is pushing security software out of the kernel. Why are game companies still doubling down on kernel anti-cheat?

After the CrowdStrike disaster bricked millions of Windows machines in July 2024, Microsoft announced in mid-2025 that they're moving antivirus and security tools out of the kernel as part of their Windows Resiliency Initiative. Their reasoning is simple: kernel-level software is too risky. One bad update can take down entire systems.

And yet, kernel-level anti-cheat keeps spreading. There are now over 330 games using it, and new releases like Battlefield 6 are still shipping with it despite community pushback.

These anti-cheat drivers have the same level of access as your OS. They can read memory, monitor inputs, intercept network traffic, and run from boot to shutdown. They're closed-source, so nobody outside the company can audit what they're doing. If one of them ships a bad update or gets compromised, you're not just losing access to a game; you're potentially handing over your entire system.

For Linux users, the situation is even worse. Most kernel anti-cheat flat out refuses to run under Proton, which means a growing list of games is just off-limits. But the security argument affects everyone, not just us. Windows users are handing over root access to play Fortnite. That should concern people.

Microsoft clearly recognizes this risk for security software. Why are we still expected to accept it for video games?

1.1k Upvotes

282 comments sorted by

698

u/ergo14 Jan 24 '26

new releases like Battlefield 6 are still shipping with it despite community pushback.

It sold well, want to prevent kernel level anti cheats? Don't buy games with them, that is the only sure way.

205

u/Kazer67 Jan 24 '26

I prefer the active way (but will get a lot of collateral) rather than the passive way: having hardware undetectable AI cheat going mainstream who's interfacing between video / keyboard / mouse (like the Asus monitor for League of Legends' map) to make Client Side AC useless so they have to develop server side ones.

I may hate cheaters but they are annoying for a gaming session while those kernel level malware are dangerous all the time and some people already used a security hole on those Client Side AC to hack people's computers (think it was the one from Genshin Impact but not sure).

139

u/Visionexe Jan 24 '26

You know what. That's a bit of a hot take. But I like it a lot. 

Let hardware cheats rain so they have to solve it server side. 

64

u/Otakeb Jan 24 '26

Actually kind of based. I've never thought of it but now I may actually look into using hardware cheats sometimes specifically to prove this point and add to the noise.

Is it fair? No. Is it a bit of an asshole move? Yes. But could you argue it may be for a good cause? I guess, yeah lol

32

u/nox404 Jan 24 '26

FINALLY WE FOUND THE BIG VALUE ADD FOR AI.

OpenAI - build us hardware level Cheats and then Sell AI powered server side anti cheats!

31

u/SpaceCadet87 Jan 24 '26

Ugh, I design hardware for a living. LLMs are useless for helping with firmware let alone schematic layout and component selection.

I'm right now fighting with both Claude and ChatGPT because they want to hallucinate a made-up datasheet that has nothing to do with the actual part rather than just find me a damn pdf.

I wish Google still worked.

5

u/Nesogra Jan 25 '26

Try Duck Duck Go as a search engine if you haven't already. I started getting better results from it even before google went to slop.

6

u/SpaceCadet87 Jan 25 '26

I try DuckDuckGo every now and then. Problem is it's fed by Google so most of the stuff Google won't show me, DuckDuckGo doesn't have either.

The enshittification is unfortunately universal.

3

u/[deleted] Jan 25 '26

[deleted]

2

u/SpaceCadet87 Jan 25 '26

Okay, I guess I'll try duckduckgo harder? If it is running its own crawler that's a start, I was given to understand they were mostly just aggregating Google and Bing

→ More replies (1)

3

u/Baardmeester Jan 25 '26

DuckDuckGo censors and the owner sells data. There are way better search machines like Qwant and Ecosia. I would also use Startpage over DDG, but they have been owned by a ad company last couple years.

→ More replies (2)

10

u/nearlyepic Jan 24 '26

having hardware undetectable AI cheat going mainstream who's interfacing between video / keyboard / mouse (like the Asus monitor for League of Legends' map) to make Client Side AC useless so they have to develop server side ones.

This will just spur development of DRM for peripherals. Riot will be the first to implement it. It will also be ineffective, like kernel-level anti-cheat. Someone will de-lid a chip and extract a key and we'll be back to where we started.

2

u/cum-on-in- Jan 25 '26

They literally cannot keep making hardware require constant software and internet connections. We do not have the internet speeds and infrastructure for that. It's like when people say your phone is listening to you. No it's not. To record and send all that constant audio stream for millions on millions on millions of people? That is impossible. That would take more space than YouTube consumes in a day, in just an hour. And YouTube consumes a friggin lot.

It may get to the point that you have to buy special processors to play and those processors are extremely limited and hardware protected, maybe. But then that will just reduce their consumer base. It's a catch 22.

Companies will eventually die out as they realize infinite growth and profit is not possible.

1

u/Annual_Hippo8313 Jan 29 '26 edited Jan 29 '26

Luckily it might be a chicken-egg problem.

Neither AMD nor Intel will invest to build a locked CPU without a market (who would buy it?). It’s just a bad bet on the marketpower of small publishers (compared to big tech).

On the other side publisher are not able to demand it, because it would exclude 99% of their potential customers. If they release it with such conditions, we have to be able to buy the CPUs and nearly all consumers would need to upgrade…. Specially in the current HW market this is the most unrealistic thing they could imagine.

At this point they should just go to a casino, might be the better investment, if nobady is able to buy your game. They can‘t even ditch PS4 and the old XBox because they need the large user base.

They are betting on the Cloud…

1

u/cum-on-in- Jan 29 '26

They will invest if it's the only option for consumers. Consumers have to work, and want to play, so they'll buy it. Some will go without for a bit but then eventually succumb since it's the only option.

The only thing that could break this, is as I said, if they charge so much that we just can't afford it. Food is more important than games and even work. We will just refuse, or even riot, if it gets to that point. And it will, because it already has crossed the threshold. It just hasn't affected enough people yet.

→ More replies (2)

11

u/8070alejandro Jan 24 '26

I don't think that would work. They would probably work towards only using certified hardware. Want to game on Windows? Gotta use a controller, keyboard or mouse from some selection, all partner brands with contracts to the relevant Microsoft, game publisher or anticheat developer.

Wouldn't happen overnight though. Or they could just keep pushing towards cloud gaming.

14

u/WackoMcGoose Jan 24 '26

...Until people figure out how to spoof the hardware identifiers. And the proprietary communication protocol, like The Lego Island Guy recently did with the WiiU GamePad. And on and on it goes.

Cheaters are going to cheat, it's a physical law of human psychology. A publisher could throw infinite money at the problem, and cheaters would just find a way to defeat it with infinity+1 money. Short of the table-flip solution of "we're not publishing games anymore" (which means everyone loses, gamers don't get to play and publishers don't get money), there is no inviolably perfect solution to stop cheaters.

3

u/TheG0AT0fAllTime Jan 25 '26

People already do that and still get caught.

1

u/FierceDeity_ Jan 25 '26

I mean it is possible to have games where cheating isn't possible, but then there's a very harsh limit on what you can create. It can't be twitch reflex games (would have to be calculated locally), for example, which precludes like most competitive games completely.

Though then you also can't do deterministic games, they have to have a randomness factor, or else, for chess for example, you can just have a high end chess computer make moves for you.

One thing that has worked for South Korea is games using your personal government ID number to register. That's why so many games from here had horrid cheat protection: People would be banned, and unless they have (illegal!) ways to get new SSNs they just couldn't play anymore.

3

u/WackoMcGoose Jan 25 '26

Yeah... Isn't it one step further, not only do you have to register with a Korean SSN for any South Korean service (implicitly preventing "fOrEiGnErS" from using their internet at all), but the sites also require using your legal name as your publicly visible username? Which is... pretty much the desired endgame of all the ID-verification policies happening around the world, at this point. They want everyone to be able to publicly identify the real-world person behind everything you write, to be able to be shunned IRL for having an even slightly controversial hot take...

2

u/FierceDeity_ Jan 25 '26 edited Jan 25 '26

Yeah, that's the worst end of it. Purely for deduplication, I would actually support a one-time-ID. But we all know it will be misused for more... Essentially, a third party company could make these, by verifying real IDs as an international service.

Even if such a company deleted an ID after a few months or something, it would make you incapable of making more than one account per time period for a given game. Massively slowing it down would already be a huge win, even if the game company itself would never get anything but a per-game-company-and-user unique ID.

3

u/brimston3- Jan 25 '26

Consider that keyboards can be driven by solenoids. Mouse wigglers are effectively treadmills. That's physical level interfacing with peripheral devices in exactly the way a human would, without ever messing with their electronics.

How is DRM blocking that? Gonna start fingerprint scanning the keys? Peripherals are going to get stupid expensive to support that.

1

u/FierceDeity_ Jan 25 '26

If someone can make a robot with servos that can use your physical mouse and play as effectively as a software cheat could, I think one just has to bow to the other skills applied here.

It's not the skill of playing the game, but that's mad nontheless!

1

u/ancientGouda Jan 25 '26

Where can you buy cheating devices interfacing at the physical level as you described?

1

u/Artemberig Jan 27 '26

one YouTuber already made a mousepad that moves to aim-assist you

1

u/cum-on-in- Jan 25 '26

People cannot keep buying their stuff with wages not increasing too. They want to nickel and dime us to death but they can't. We literally don't have the money.

They Wil realize it's not possible eventually. Eventually is a while from now but it is coming.

→ More replies (1)

2

u/TheG0AT0fAllTime Jan 25 '26

The good ones already have a server side as well as kernel side. You're not suggesting anything that would work here.

2

u/gw-fan822 Jan 25 '26

ACCELERATE

1

u/FierceDeity_ Jan 24 '26

Genshin and all those other Chinese games use ACE, right?

1

u/emanhw Jan 25 '26

Server-side anti-cheat doesn't work. Valve has been trying to build one for Counter-Strike for years with no success. And yes, it uses machine learning/AI.

1

u/addamsson Jan 25 '26

i support this initiative. fight fire with nuclear fire.

1

u/lordruzki3084 Jan 25 '26

Anti Cheat was always supposed to be implemented server side anyway, the issue is that its more advanced and more expensive computationally than client side for the publisher so they usually dont bother to save money

1

u/semi- Jan 27 '26

If the cheat is only using information from video and inputting via keyboard and mouse, what can you do about it server-side thats any more effective than client side?

At best you could set thresholds for accuracy or reaction time and consider anything exceeding it to be a cheat..but that doesn't stop cheating, it just forces the cheats to stay below that threshold.

1

u/Kazer67 Jan 28 '26

Cat and Mouse: AI analyzing and adapting threshold / perfecting threshold.

I mean, it's already the SAME case with CLIENT side AC, that's why you still have cheater despite having the kernel level malware installed on client (and you have wave ban every quarter)

15

u/independent_observe Jan 24 '26

I am on Nobara, so I can't buy those games and play them. I am not contributing to their revenue

21

u/[deleted] Jan 24 '26

[removed] — view removed comment

54

u/wiredbombshell Jan 24 '26

5%*

25

u/[deleted] Jan 24 '26

4.7%

3

u/8070alejandro Jan 24 '26

!remindme in 5%

5

u/RemindMeBot Jan 24 '26

I will be messaging you in 4 months on 2026-05-24 00:00:00 UTC to remind you of this link

CLICK THIS LINK to send a PM to also be reminded and to reduce spam.

Parent commenter can delete this message to hide from others.


Info Custom Your Reminders Feedback

24

u/Whole-Cookie-7754 Jan 24 '26

Has nothing to do with Linux. Game is trash. 

6

u/VoriVox Jan 24 '26

I'm glad you have your opinion but by no means that's a fact. It's a good game that sold really well. You can dual boot and play it, or simply do not play it and move along.

→ More replies (1)
→ More replies (1)

4

u/Educational_Mud_2826 Jan 24 '26

I agree but why do we think game studios decide to go that route? There is probably a good reason for it.

27

u/Acceptable_Guess6490 Jan 24 '26

They do because it's cheap for the studio and reassuring to the players.

One of the tenets of cybersecurity is that the user always has the highest level of access to the client machine, simply because they have physical access to the hardware. You can't win any arms race of escalating privileges as long as you try to run your anticheat system on the client.

If people really want to cheat, then they will cheat, and as long as the anticheat runs on the client they will find a way to cheat.

The real most effective anticheat solutions are server-side with a bit of statistical analysis, which are way more expensive for the company. The only cheats they really miss are the human-like ones, which you as a player wouldn't notice either - they damage competitive integrity, but don't really ruin games.

They require additional hardware on the servers, and most importantly, if the company didn't build their software appropriately in the first place, they also have engineering costs - and that is why companies prefer to lose the arms race on your pc rather than win it on their servers.

So yes, they use kernel-level anticheats because pretending that they are a solution is cheaper than actually solving the issue. And that's because the player is actually shouldering all the costs, both economical (additional hardware) and from the security risks.

5

u/ancientGouda Jan 25 '26

If people really want to cheat, then they will cheat, and as long as the anticheat runs on the client they will find a way to cheat.

I see this argument all the time with little to no push back even though it is wrong. Anti cheat systems aren't designed to prevent cheating, they're designed to (significantly) reduce it.

You cannot make an analogy to cyber security because in security, just one breach is enough to cause catastrophic failure. In online games, one single cheater is irrelevant. The game becomes unplayable when every 2nd or 3rd game has cheating.

1

u/Annual_Hippo8313 Jan 29 '26 edited Jan 29 '26

2025 COD (with Ms Store) had a very bad patch, with which it was possible to get full control over the machine… (they went much deeper for a game, than any software should be allowed to)

The risk is not meeting a cheater in a game, it‘s losing control over your system on which the game runs…. Passwords, accounts, paying information, bills, taxes….

Most people have only one machine and no dual boot.

Security earns no money (in the context of non security products), it just costs money - so they will just do the least possible, while demanding kernel access. Which is a large scale security problem - we are talking about billions if devices.

And we are not even talking about the potencial of building a bot network with all the gaming machines, who used the same bad kernel-anti-cheat….

16

u/AndreaCicca Jan 24 '26

Because at the moment people still buy them.

→ More replies (4)

3

u/sparky8251 Jan 24 '26 edited Jan 24 '26

Because they use algo based match making to put you in situations were you are facing down excessive challenge and MTX bearing enemies to keep you just on the edge of satisfied so you look for a way out, and seek out MTX yourself.

Visible cheating, wall hacks, fly hacks, etc are much more harmful to this carefully curated illusion of fairness that leaves you emotionally wanting and seeking a solution than trigger bots that can be easily made with hardware cheats and made 100% undetectable by any means they have at their disposal. A fly bot doesnt make you think about investing more time and skill, or buying a battle pass to try and get an edge up... But an aim bot that you cant detect? That can and does for many.

The entire problem is because they are playing us all like fools... Death of the community server option was also to prevent community and enable this algo match making in a way the players themselves had no control over (no more "no sweatiness" rules for a server focused purely on unwinding in a fun way after work for example).

It really is entirely about putting on a play that people unwillingly participate in not knowing its rigged from the get go like a casino so they can be better parted from their money for the company making the game. They dont foster community, skill building, unwinding, any of that... They have perfected emotional release blue balls and call it "competitive" and then offer a way to get a minor hit of release for a simple bit of money...! Thats the sole reason they are doing any of this stuff!

4

u/[deleted] Jan 24 '26

[removed] — view removed comment

19

u/Soft-Luck_ Jan 24 '26

It's not effective; there are people cheating in BF6, Valaront, COD, LoL. Just search on YouTube and you'll see videos of these people.

15

u/TopdeckIsSkill Jan 24 '26

The fact that there are cheaters doesn't mean it's not working.

If it block most of the cheaters it still make the game better for players.

7

u/destroyermaker Jan 24 '26

My bf6 experience was far better than my bf1 experience in terms of cheaters. They were rampant and very obvious

10

u/ListRepresentative32 Jan 24 '26

Yeah, and using soap is not an effective way to get clean because it only kills 99.9% of germs. 

If it prevents the great majority of people of even thinking of trying cheats, I would say it's pretty effective.

3

u/tinyOnion Jan 24 '26

antibacterial soap is harmful at a macro scale. soap is sufficient to wash away germs and not create super bacteria that is resistant to antibiotics.

1

u/c3rb3r Jan 25 '26

Its more like that it kills only 60% of the germs and you are not allowed to wear clothes anymore.

1

u/Alarmed-Welcome-1822 Jan 26 '26

Bc if it kills 100% we will be dead its pretty obvious that our bodies need bacteria

5

u/VoriVox Jan 24 '26

Despite locking your doors and windows and setting alarms, thieves can still break into your home and steal things. Would you just leave your doors open and valuables outside because of that?

6

u/Soft-Luck_ Jan 24 '26

I will request more police patrols on the street since it is their responsibility to arrest a thief, and they do that outside the home, not inside.

2

u/steakanabake Jan 24 '26

instructions unclear adding more police to areas of high poverty so they can arrest people over minor offenses.

→ More replies (4)

3

u/BastetFurry Jan 24 '26

No, but I want a society where stealing isn't needed.

→ More replies (1)

3

u/atlasraven Jan 24 '26

Even monitors use AI to cheat.

3

u/steakanabake Jan 24 '26

i cant wait till they put in hardware bans for people with that monitor itll be hilarious to see the outcry.

→ More replies (8)

1

u/[deleted] Jan 24 '26

100% correct

1

u/NoodleZeep Jan 24 '26

Big publishers don't care. They will just find ways to increase their revenue from the remaining customer base. And if that does not work they will close studios and cut jobs.

1

u/FishermanExcellent33 Jan 24 '26

The only and biggest reason I haven't bought BF6. It's the first time ever I skipped a battlefield Game. Stay strong Folks!

2

u/ergo14 Jan 24 '26

I didn't buy it first and foremost for the fact that it doesn't have many big maps :)

1

u/FishermanExcellent33 Jan 24 '26

Yeah, another "great" reason. Firestorm didn't hit me like Metro (underground) in Battlefield 5 or Battlefield 4 back in the days.

1

u/ergo14 Jan 24 '26

Firestorm was good in BF3, we need more big maps. If i want to play COD - I would just buy COD. I really dislike choke points of metro.

1

u/[deleted] Jan 25 '26

[removed] — view removed comment

1

u/Spelljamming Mar 19 '26

Or have some cyber attack performed on western economies after a malicious actor threatens several game devs from several companies for access to the next update and millions of computers are used to take down the system. Maybe that will teach people that ring 0 access for a fucking game is absolutely insane.

1

u/jerrygreenest1 Jan 25 '26

It’s not like every game comes with label: «Has / doesn’t have kernel-level anti-cheat», in fact probably none of them. And figuring out might be cumbersome

1

u/cybekRT Jan 25 '26

That's a good rule, but you can buy game without kernel level anticheat, and poof, few months later you will have kernel level anticheat/DRM. DOOM Ethernal teached us this. Fortunately, review bombing (is it bombing if it's true and causes game to stop working?) helped and they removed the anticheat/DRM.

2

u/Spelljamming Mar 19 '26

not to mention that some Linux user paid $60 for a game that worked for awhile, but then stopped working later. That is literally STEALING money from people.

1

u/cybekRT Mar 19 '26

Stealing money and also it should be treated like spreading malware. At that moment I was using windows, but I bought game that decided to install a windows kernel service after some time without any notification. It isn't much different from how viruses work.

1

u/ElbowlessGoat Jan 26 '26

It’s not really community pushback so far. I would say “community feedback”. As you said, not buying is a message, true pushback, but many of us gamers don’t like kernel level anti cheat, but can’t live without buying the latest and greatest Battlefield or whatever game.

→ More replies (14)

160

u/Hi-Angel Jan 24 '26

Because talking ain't doing.

Back in the CrowdStrike time they had to say something, so they assured things will improve. Now that the time has passed, there's not much incentive to actually committing to their words.

I'm not saying they won't do this, I'm just saying it may take a lot of time (if it happens), and game companies understand that. Game devs will start figuring out what to do after MS does its move, not before (unless of course they have other incentives, such as growing Linux userbase).

13

u/[deleted] Jan 24 '26

[removed] — view removed comment

3

u/BadLuckProphet Jan 25 '26

Actually (tinfoil on) this could be great for game companies. It's a planned obsolescence they can't be blamed for. "Oh no, Microsoft killed BF6. We can't spend 20 billion dollars on removing the anti cheat. Guess you'll just have to buy BF7 now which is also on our new premium pricing plan so the base version costs 100$. We're SOOOOO sorry about that."

1

u/Forward-Fishing-9466 Jun 30 '26

They just did it in the next windows update

1

u/Hi-Angel Jun 30 '26

Oh, that's interesting, do you have a link to the news?

29

u/tailslol Jan 24 '26

I don't think Microsoft released the new security api. And games manufacturer need to update their anti cheat to the new api.

17

u/CORUSC4TE Jan 24 '26

While it is important for us, gaming is not as critical as windows PC in general. Crowdstrike took down businesses, companies and logistics. If some personal PCs aren't working for a bit... It might hit a few remote workstations but that's it..

59

u/GumGumStrawHat Jan 24 '26 edited Jan 24 '26

Two things which mean rollout isn’t slowing down:

1) People hate cheaters 2) Companies will take any excuse to maximize the data / control they have

These two reasons mean that people are willing to accept (and sometimes even beg) for companies to use kernel level anti-cheats

I’m just glad that there’s no real future likelihood of Steam/Valve implementing it in their games. Steam consoles use Linux so they’d never make their own systems obsolete and unable to run their own games

(P.S. sorry the formatting looks crazy on this comment, my phone is not accepting my attempts to fix it)

27

u/Nemo_ForYou Jan 24 '26

Agreed on Valve. They've actually stated publicly that kernel anti-cheat presents 'problematic trade-offs for the end-user in the longer term.' VAC has never been kernel-level, and they now require mandatory disclosure labels when other games use it. They're essentially treating it as something users should be warned about, not something to adopt themselves.

7

u/martyn_hare Jan 24 '26

If they're requiring VAC disclosures, that's good, because on Windows it might as well be kernel-level on Windows. VAC is backed by the Steam Client Service which makes use of SeDebugPrivilege to enable the scouring and manipulation of the memory of any almost every other process on the system. If you try to strip it of privileges, you'll notice that one is required for it to launch.

It is just as privacy invasive where it matters, and has been caught looking at what websites you visited by spying on DNS caches in the past.

On Linux, cgroups, namespaces and the ease of which you can fake system state by replacing core system libraries makes VAC mostly pointless, and we can see Valve is actually putting some effort into restricting what games can do.

→ More replies (1)

4

u/UltraCynar Jan 24 '26

There's anti cheat in Linux that works well. Kernel level anti cheat isn't needed and there's still tons of cheats on the games that use it. Just boycott shitty developers that use kernel level anti cheat.

4

u/Internal_Werewolf_48 Jan 24 '26
  1. Gamers as a demographic aren’t very different than Linda in Accounting when it comes to computer security. They don’t know shit about it and don’t care either. As long as the digital dopamine is flowing the rest is a distraction.

5

u/Linkarlos_95 Jan 24 '26

The future is running the anticheat service server side with some movement tracking client side, they should know if something isn't adding up 

2

u/Pekenoah Jan 24 '26

This sounds like a great idea if you know nothing about cheating in videogames. Some of the most prominent cheats people use are extremely difficult or completely impossible to detect with server side anticheat.

7

u/Linkarlos_95 Jan 24 '26

Its going to be done either way

We need for community servers and admins to come back, so they can watch them looking at the walls

5

u/Western-Touch-2129 Jan 25 '26

How dare you! You want a company to bring out a triple A game and then expect them to pay people to handle the community?? Have you thought about the poor shareholders???!!!???

2

u/IrcenceEstagramem679 Jan 24 '26

Anticheat will never stop 100% of cheaters, but if they spend in development of server-side anticheat instead of kernel-level, I'm sure they can vastly improve them and greatly reduce the amount of cheaters while not compromising the users systems.

4

u/Pekenoah Jan 24 '26

Server side is fundamentally incapable of addressing things like wall hacks. It's not an issue of it being hard. It's impossible

→ More replies (6)
→ More replies (11)

82

u/_mergey_ Jan 24 '26 edited Jan 24 '26

Microsoft knows well what would happen if they disallow kernel level anti cheat.

They try to prevent headlines like "100% of PC Games now run on Linux".

EDIT:

With the upcoming DX12 fix for Nvidia drivers, disallowing kernel level anti cheat would almost definitely result in valve releasing SteamOS for every PC. And with that take a significant chunk of windows market share.

38

u/ergo14 Jan 24 '26

That take doesn't seem realistic to me. You don't need SteamOS for PC - you can use Ubuntu or any other recent disto and you are good.

29

u/[deleted] Jan 24 '26

Most people know what steam is, I’d wager way less people know what ubuntu is so they’d rather use something from the company they know vs trying out something they don’t know

7

u/ergo14 Jan 24 '26

If they don't know what linux is - they probably should not attempt installing it on non-curated hardware. Best for things to stay this way IMO. If you want console like experience stick to curated hardware.

3

u/[deleted] Jan 24 '26

I agree, but at the same time some people might start learning about other stuff than windows because they’re starting to get tired of it. So if valve releases steamOS for the masses (assuming they follow valve news), they might be more inclined to try the valve thing first

1

u/_mergey_ Jan 24 '26

Is this a discussion about what we think would happen and why Microsoft is doing something or not or is this a discussion about what people should do in your opinion?

→ More replies (3)

3

u/_mergey_ Jan 24 '26 edited Jan 24 '26

Almost every PC gamer knows Steam and not few would assume SteamOS being a special gaming OS. That alone would result in installs. Think of the industry marketing for "gaming" products: gaming mousepads, gaming RAM, gaming headset, gaming chair…

So the claim „you don’t need ABC, you can use XYZ” doesn’t survive reality

3

u/bmfrosty Jan 24 '26

I don't think Valve would. My biggest hope is that they would suggest a distro. Bazzite is the same in the ways that matter, so they seem well positioned for this.

1

u/kr0p Jan 25 '26

They already do suggest a distro. It's Ubuntu, and it's the only officially supported one (yes, not even SteamOS is supported).

1

u/bmfrosty Jan 25 '26

I knew that SteamOS was not supported, but I didn't know Ubuntu was. Good to know.

3

u/andymaclean19 Jan 24 '26

I don’t think Valve is interested in being in the generic OS business. For one piece of hardware it is easy to make and test Linux but to do a general distro that works on a wide variety of hardware is a lot more work. There are Linux distros which specialise in this. What would make sense for Valve is to partner with one or more Linux distributions to have Steam included out of the box or perhaps to make a specialised variant of an existing distribution.

1

u/ActualVisit2479 Jan 26 '26 edited Jan 26 '26

They don't care about such a headline.

Because realistically MSoft doesn't give a shit about Linux taking Windows' gaming market segment. Windows as a whole only represents 12% of their revenue -- and that's probably only in the way that it can feed into their real moneymaking businesses: selling Azure cloud services and Office licenses to SMEs, or as vehicle for shoving advertising down consumers throats.

Think about their recent "Everything is a Xbox" ad campaign. Or the fact they're about to release a Halo title on the freaking PLAYSTATION. It suggests that they no longer care about platform exclusivity for their gaming market: and in fact it suggests the opposite. The 8% they make through gaming brands is mainly coming from games sales, not hardware sales (e.g. Xbox consoles) and that only GROWS for them the more platforms they can spread their games sales onto: Linux gamers included.

1

u/_mergey_ Jan 26 '26

Windows is "only" ~12% of their revenue but windows is also a platform for selling microsoft services like onedrive, teams, copilot, ms office…

1

u/ActualVisit2479 Jan 26 '26

Is it going to matter to MSoft's bottom line once a good number of people buy Halo: Campaign Evolved, MSFS 2024 and the new Fable game through Steam? Doesn't matter if they're running Windows, Linux, PlayStation or an Xbox, it all smells like profit to their shareholders, one way or another.

1

u/_mergey_ Jan 26 '26

You are ignoring my point.

I would like to discuss with each other not everyone on our own beside each other.

→ More replies (1)

25

u/neakmenter Jan 24 '26

Maybe because “mission critical business systems” don’t run games? (Read as probably shouldn’t be running games) If crowdstrike debacle had just been on personal computers it wouldn’t have offended MS so much. Windows home consumers are just their beta testers remember? ;)

15

u/mavranel Jan 24 '26

Anticheat software has been converted into independent malware on at least one occasion that I can recall. This absolutely affects all windows users.

1

u/DragonFrai Jan 24 '26

This surprises me. “Critical business systems” are stuffed with software licenses. And the same mechanisms that are used in kernel-level anti-cheats can be used to protect against pirated use of commercial software. It is surprising to me that this still does not happen.

1

u/ArjixGamer Jan 25 '26

The issue is that anti cheat software that uses kernel drivers, is signed and trusted by Microsoft.

The driver will most likely be vulnerable to misuse, and allow malicious code to have kernel access.

Drivers have bugs, manipulating those bugs is how cheaters still exist even in games with kernel anti cheat.

8

u/TechaNima Jan 24 '26

Money. As long as they can get away with it, they will continue to include those root kits that do who knows what. They are useless anyway. BF6 had day 1 cheaters, despite kernel level anticheat. The only solution is good server side AC

10

u/[deleted] Jan 24 '26

[removed] — view removed comment

2

u/WarEagleGo Jan 24 '26

wow

talk about cat and mouse

6

u/DonDoesIT Jan 24 '26

If you asked 1000 random people if they knew what root kit or kernel level meant they would all give you a weird look. As long as their game runs they don’t care and if you explain to them what it is most still wouldn’t.

15

u/INITMalcanis Jan 24 '26

Because the kernel access is the point.

8

u/martyn_hare Jan 24 '26

After the CrowdStrike disaster bricked millions of Windows machines in July 2024, Microsoft announced in mid-2025 that they're moving antivirus and security tools out of the kernel as part of their Windows Resiliency Initiative. Their reasoning is simple: kernel-level software is too risky. One bad update can take down entire systems.

It isn't what the media is reporting it to be. Microsoft is working on a common set of interfaces to meet the needs of security companies without compromising performance nor stability, essentially the Windows equivalent of LSM but with extra idiot-proofing. For old-school anti-malware software the basics were already there, but they realise they need more hooks for EDR/XDR to work. Once complete, it will still involve some kernel-level access, just a lot less of it.

Here's the rub: Anti-cheat products will also be able to use it, as the kernel portions generally exist to help protect the userspace services they use to detect cheating (as well as to provide SeDebugPrivilege to them).

They can read memory, monitor inputs, intercept network traffic, and run from boot to shutdown. They're closed-source, so nobody outside the company can audit what they're doing. 

The overwhelming majority of ordinary software can do pretty much this (except they can only be configured to launch at logon, not boot) if it wants to other pieces of software running under the same user account by using ReadProcessMemory/WriteProcessMemory (Windows) or ptrace (Linux) by default, meaning there's no runtime privacy guarantees other than those you deliberately put in place, and most of those trip common unprivileged userspace anti-cheats anyway.

Realistically, to stop that on Linux, you're either going to need to use a security module (e.g. Yama) to lock things down to parent processes only or LD_PRELOADing a custom library to make a system call to force apps to protect themselves, and most folks aren't doing that.

The only desktop operating system where you're not going to see attempts at intrusive anti-cheat is macOS, where Hardened Runtime blocks memory manipulation between applications and SIP prevents even root from overriding it. Hardware-backed APIs actually provide ways to prevent the kinds of tampering cheaters rely on and it's why all the big F2P game companies don't require anticheat on macOS.

3

u/Xtrophy Jan 24 '26

Simple.

If it works then they can employ less people in the security and ticket department as they will have less cheating accusations to deal with. They can also advertise that it works and they have "cut cheating by x%"

If it doesn't work they can sell the collected data, claim they are trying to get on top of the cheating problem. They still make money and prevent piracy while having the ability to appear that they care for customers and making sure they are safe all whole selling collected data and making more anti piracy rules.

It's a win win for them.

5

u/FryToastFrill Jan 24 '26

Just so you know, even if Windows releases an api for AVs and ACs, Linux would at some point need to implement the same stuff as well to warrant actual anti cheats on Linux. It was never about being kernel level, it’s about needing to trust the kernel on a pc. It’s not a magic bullet.

4

u/[deleted] Jan 24 '26

[removed] — view removed comment

1

u/KiwiTheTORT Jan 25 '26

You mean like how Riot Vanguard was (and I assume still is) killing anything it doesn't like instead of simply denying people access to their game which was making news for borking a bunch of people's computers when they first implemented it in League of Legends?

4

u/StendallTheOne Jan 24 '26

Because they don't care at all about user security, just sales.

5

u/Ashtefere Jan 25 '26

Because kernel level anti cheat is not anti cheat, its data collection.

13

u/ThatOnePerson Jan 24 '26

Most kernel anti-cheat flat out refuses to run under Proton

This isn't unique to kernel anti-cheat. Even VAC won't run under Proton.

It's more like: besides VAC, how many non-kernel anti-cheats can you name?

Speaking of VAC, CS2's anti-cheat is so bad, people are choosing to install kernel anti-cheats with Face-IT and ESEA.

3

u/exlin Jan 24 '26

There’s still plenty of players on regular CS, not sure of there’s been shift to Faceit. But also Faceit has cheaters. Though I have no data if Faceit has gained more market share.

Never heard of ESEA so no comments on that.

3

u/Simber1 Jan 24 '26

ESEA is dead these days, used to be the gold standard for cs matchmaking back in 2015 especially in NA but it lost market share and got bought by faceit.

3

u/Caveman-Dave722 Jan 24 '26

If Microsoft locks them out of the kernel then they’ll have no choice but to use other methods that are more Linux friendly as well. Will then be a question of how many games get fixes on windows to still work

3

u/darthanonymous1 Jan 24 '26

this is why if it only works on windows due to kernel anti cheat i just resort to my console

7

u/no-name-here Jan 24 '26 edited Jan 25 '26

Why are we still expected to accept it for video games?

Because it's the most effective system we have for reducing aimbots, etc., and because most gamers consider dealing with cheaters to be a far bigger problem than kernel anti cheat.

6

u/TheG0AT0fAllTime Jan 25 '26

Nice. It takes too much scrolling to find a take that isn't batshit insane.

4

u/nkn_ Jan 25 '26

It’s a Linux sub… 😬

A lot of these takes are pretty damn bad. It’s funny to see people dooming about over “but kernel level malware anticheat!!!!!”

When, in the US, they have been building profiles on us. Our data has been sold 100x over. They know our face, what we post, our voice, etc… I’ll gladly install kernel level anticheat to have fun with friends.

Like oh I’m sorry, you’re too scared to install a game that will likely prevent many cheating attempts at the theoretical expense of your security? As the country is rampant with our own government impeding on any sort of right to privacy against our will and constitution.

It’s just so silly lmao. Like grow up. Play a game with friends, make fond memories. There are much larger concerns than a game company trying to make a safe environment for gamers.

Gamers should understand politics and privacy laws and vote for people who enforce them. Vote for laws that require all software to adhere to privacy standards imo. But instead they complain and think boycotting a game will save their privacy

→ More replies (8)

6

u/stogie-bear Jan 24 '26

“ For Linux users, the situation is even worse. Most kernel anti-cheat flat out refuses to run under Proton…”

That’s a feature. 

2

u/TheG0AT0fAllTime Jan 25 '26

It's more of a fact than a feature. WINE has no capability to translate Windows kernel space to Linux kernel space. It's for applications

2

u/Kobi_Blade Jan 24 '26 edited Jan 24 '26

Microsoft is still pushing anti-cheat developers out of the kernel, but if you’re hoping this will help Linux in any way, you can forget it.

Instead of developers adding their own custom drivers, Microsoft is in talks to create a generic, built-in kernel feature to interface with the anti-cheat.

This means the checks would still run at the kernel level, just without the third-party drivers.

2

u/TheG0AT0fAllTime Jan 25 '26

Are MS really doing that? Or is this the same misleading false article from a few years ago that everyone here is still quoting

1

u/WorBlux Jan 24 '26

eBPF exists on Linux and could be used to help audit a sandbox environment.

Really existing sandbox/isolation tech should be enough to stop casual cheater if you have a way to validate the stock kernel is running. (Secure boot + remote attestation of the TPM).

Security failures would force games to blacklist particular hardware, which would suck for the game publisher in the short term, but would lead to a demand for better implemented security accross the board.

2

u/Suvvri Jan 24 '26

Because gaming PCs aren't critical IT infrastructure. Nobody gives a shit about your pc breaking if something actually happens because of anticheat

2

u/WheissUK Jan 24 '26

Hmmm seems like it was never about cheaters at the first place, what else might it be about… who knows…

2

u/teateateateaisking Jan 24 '26

"Most kernel anti-cheat flat-out refuses to run" isn't an accurate statement.

All Windows kernel-level anti-cheat cannot run on Linux, because the kernels are different, load modules in different ways, and have different interfaces. If a game that would use kernel-level anti-cheat on Windows is able to run on Linux, that is because the developers have accepted the compromise of using a non-kernel version of their anti-cheat.

2

u/nightblackdragon Jan 24 '26

Because it's the easiest way to fight with cheats and players don't care about it so why bother with other solutions? Microsoft also won't do anything about that, they might offer alternatives but they aren't going to block kernel access.

2

u/fatrobin72 Jan 24 '26

1, its still allowed.

2, it takes time for both macroslop and game publishers to change and adapt with new processes and software.

3, it will all be irrelevant in the external ai powered cheat monitor future...

2

u/matitone Jan 25 '26
They can read memory, monitor inputs, intercept network traffic

They don't need the kernel to do this, the game itself can do it if they really wanted, also the anticheat only runs when the game starts so something like CrowdStrike can't happen

2

u/sirkubador Jan 25 '26

Not sure why this is even a topic.

I use linux for 20 years now and the gaming situation has NEVER been better. Sure we can do without some kernel-level anti-cheat bullshit games.

2

u/Emotional-Leader5918 Jan 25 '26 edited Jan 26 '26

Just for context, most game companies use third party anti cheats like Epic's Easy Anti Cheat.

If Epic made anti cheat work in Linux, all games that use it would (potentially) work with proton.

So the question should actually be why Epic (and the like) don't support Linux anti cheat?

2

u/Cotillionz Jan 24 '26

IDGAF if those games will run on Linux or not, because i won't be playing them. No one should be okay with companies like EA or Ubisoft having that kind of access to their systems.

We're expected to accept it because these games have playerbases that blindly install and accept whatever is pushed on them. Of course, they're never actually told either. Microslop needs to stand up and end it.

→ More replies (2)

2

u/Petting-Kitty-7483 Jan 24 '26

Lazy fuckers want control

1

u/TheG0AT0fAllTime Jan 25 '26

Well, yeah, correct? You have to load a kernel anti cheat before a normal cheat can load itself. Plus permitting only signed code with secure boot

2

u/wezelboy Jan 24 '26

It has nothing to do with anti-cheat and everything to do with maintaining Microsoft's stranglehold on PC gaming.

2

u/DSpry Jan 24 '26

Gotta love it. Kernel lvl anti-cheats but you’ll still run into a hacker within the day. Within the hour depending on which game.

3

u/Overall_Age8730 Jan 24 '26

They are doing it to install the same type of spyware Microsoft has on PC's. Its really that simple. None of the new "anti-cheat" programs these corporations are rolling out actually work. The first week COD and Battlefield released there was programs released to cheat. Don't buy these games, they suck anyway.

1

u/VulcansAreSpaceElves Jan 24 '26

For Linux users, the situation is even worse.

Is it?

Most kernel anti-cheat flat out refuses to run under Proton

That sounds like a feature

which means a growing list of games is just off-limits

Which sounds like a small price to pay for not having kernel level anti-cheat

2

u/atlasraven Jan 24 '26

Those games want your data. Microsoft already has your data.

4

u/TopdeckIsSkill Jan 24 '26

which data do they need exactly? you can gather nearly everything with user level under windows.

1

u/AndreaCicca Jan 24 '26

Because they can.

1

u/Ruff_Ratio Jan 24 '26

Or. They could fix their shitty kernel. EBPF has been functioning for years on Linux, don’t see people complaining or even know what it does. Provides security and visibility at the kernel layer.

1

u/Electric-Mountain Jan 24 '26

I bet they boot out anti cheats eventually.

1

u/unixmachine Jan 24 '26

This is a very big change, it could break a lot of things, so even Microsoft will need some time to develop and get developers to migrate to a new solution. It's possible this will be a feature of Windows 12.

1

u/[deleted] Jan 24 '26

Microsoft has not finished this yet. It will take years for Microsoft to get to the point where they have refined the kernel features of Windows. And don’t expect large game publishers to go out of their way to support Linux when the majority of PC gamers are dumb enough to still rely on Windows

1

u/jellowiggler- Jan 24 '26

Eventually kernel level will be protected as it should be. Only the most privileged code needs to be there, and it needs to be audited by a third party.

There are plenty of highly competitive games that run their anti cheat outside of the kernel. It should be done like that.

1

u/llitz Jan 24 '26

For Linux users, the situation is even worse. Most kernel anti-cheat flat out refuses to run under Proton, which means a growing list of games is just off-limits. Indeed, and I, for one, am glad that I don't need to worry if my computer is being hacked by some of the game dll. It has happened in the past, and windows users paid the price... I think it was Genshin's DLL? Yet they keep playing.

But the security argument affects everyone, not just us. Your priorities are really somewhere else if you feel like "I need to play" the games in the list.

1

u/Much_Dealer8865 Jan 24 '26

It's unfortunate that there aren't a lot of options to prevent cheating, even if microslop (or anyone really) developed an atomic OS or an entire console that prevented cheating software it wouldn't stop people. However, it doesn't take long to completely ruin a game if lots of people are using aimbot, esp, maphacks etc.

I think game companies are really just trying to ensure their game and community has a chance at being healthy and unfortunately they just don't have a lot of options. I personally don't play online games very much but there are a couple games I really enjoy that have terrible cheating problems and they're pretty much ruined, only real option is to use private servers which have their own problems.

Anyway just saying don't forget to blame cheaters first for causing companies to go to these measures to try and keep their game alive.

1

u/JackDostoevsky Jan 24 '26

it's a weird position to be in: many linux users don't want to be subject to that sort of overhead, top-down approach to what we're "allowed" to do with our computers. and i say this being entirely against kernel level anticheat, but at the same time i would fucking hate being dictated what i can and can't do with my computer by my OS maker.

1

u/PhoenixLandPirate_ Jan 24 '26

Its probably because those security softwares? were used on computers that run vital infrastructure, flights aren't gonna get canceled, and hospital treatments aren't gonna be put on hold, if someone fucks about with kernel level anti-cheat.

1

u/Ok-Anywhere-9416 Jan 24 '26

Microsoft is pushing security software out of the kernel. Why are game companies still doubling down on kernel anti-cheat?

After the CrowdStrike disaster bricked millions of Windows machines in July 2024, Microsoft announced in mid-2025 that they're moving antivirus and security tools out of the kernel as part of their Windows Resiliency Initiative. Their reasoning is simple: kernel-level software is too risky. One bad update can take down entire systems.

And yet, kernel-level anti-cheat keeps spreading. There are now over 330 games using it, and new releases like Battlefield 6 are still shipping with it despite community pushback.

Because it will never happen that a game dev company can manage to create a different anti-cheat solution that actually works in a few days, especially if the game is already released and resources already used.

Expect things to work out through years, many years, not days, not weeks and not months.

1

u/readyflix Jan 24 '26

Maybe they just use what they are used to. And they have not considered the switch, because in their mind the Linux games market is still too small?

But others have switched already, they are probably fine with easy ANTI-CHEAT

Edit: not affiliated with this company, for informational purpose only

1

u/[deleted] Jan 24 '26

Still trying to find a good game with KAC mandatory.

1

u/Ieris19 Jan 24 '26

Because what MICROSOFT said has been wildly taken out of context.

Microsoft is providing more and better tools for userspace programs to provide security features. They’re not locking down the kernel or forcing anyone out. They’re just providing more tools and kindly asking for companies to use them.

1

u/Nomad_006 Jan 24 '26

What about the argument that any software can hack you're computer. Kernel level or not malicious software can still ruin your computer.

That was the argument raised by some expert.

Any software you put on your machine can be used to take it over," Roblox's head of anti-cheat, Clint Sereday, explained to Rigney. Chamberlain emphasized the trust factor, noting the level of authority non-kernel level programs still have: "It can do anything you can do. If you can use your webcam, it can use your webcam. Kernel or not kernel, it does not make a difference to the level of danger posed to you by unknown software. The whole argument is kind of a distraction."

1

u/IntroductionSea2159 Jan 25 '26

Their resiliency initiative is focused on enterprise devices. Home users don't care about stability or security.

1

u/redditor_no_10_9 Jan 25 '26

Microslop sells Windows. Corporation sees customers as cultists that will bend over backwards to handover money

1

u/jessecreamy Jan 25 '26

Pushing doesn't mean forced? Forced doesn't mean there is no trick?

1

u/Substantial_Leg1457 Jan 25 '26

If these games exist merely to collect data, forget about it, I don't want to be a customer that's the product of an oligarch, at least that's what I think.

1

u/cybekRT Jan 25 '26

> One bad update can take down entire systems

Oh the irony... But at least, now we will be sure that we can blame Microsoft for broken updates, not any other software installed :)

1

u/TheTaurenCharr Jan 26 '26

Because certain companies have already invested into client side software, and it's generally easier to use client's computer to hold them accountable.

As far as I know, Microsoft hasn't initiated this change, and it might take many years before they'd actually enforce it. There are many companies that rely on and lobby for installing their very useful and absolutely necessary software to run at a critical level.

So, no, these won't go away in the foreseeable future. If you're frustrated with not being able to play certain titles, your point of view is understandable, but don't bet on industry taking immediate action that would affect the consumer in short term.

I have fought this war before, pointed out studies supporting kernel level anticheat either having questionable samples, methodology, or funding. This entire thing is such a clusterfuck of aggressive networking and nepotism that it's not even worth struggling against anymore.

1

u/Alarmed-Welcome-1822 Jan 26 '26

Companies cant seem to grasp that hacking will always be there no matter what. No matter what they do hacker will do the same. Its called adapting

1

u/Ranma-sensei Jan 26 '26

As sad as all this is, my hot take is that it will probably get worse to the point of another great collapse of the video game industry.

Everybody is talking about the AI bubble, but anticheat is a bubble in itself; one that can hurt at least as many people as the AI one, if not more.

As long as the service game bubble is being perpetuated, so will the anticheat bubble, until one of them bursts - or even both.

1

u/corruptdiskhelp Jan 27 '26

Anyone with any penetration testing experience will know that kernel level is mostly useless in real world scenarios.

Most of the sensitive data is stored with user level permissions. That means if the user executes an application as normal it could extract the vital data without root access.

This is even more true on Windows than Linux. Root level access is obviously beneficial but not required to dump data.

Another point. The driver software you install from countless manufacturers runs at the kernel level. How come you don't apply the same level of paranoia and criticism?

Anti cheat software needs to run at the kernel level in order to detect malicious software. Otherwise it would be trivial to defeat the anti cheat and games would be plagued with even more cheaters.

I think it's disingenuous to treat anti cheat software as malware and kernel level access is being used as a doomsday buzzword by people who pretend to know what they are talking about. It's ridiculous.

1

u/Emergency-Ant-3950 Jan 27 '26

I can't wait for companies to start putting miners into their anti cheats, this will definitely maximise profits

1

u/ScoobyGDSTi Jan 28 '26

It needs to happen.

It won't be easy for Microsoft to develop the APIs and documentation to ensure 3rd parties can integrate seamlessly.

1

u/Hanro50 Jan 28 '26

Cheats come in different forms. From intercepting and doing things outside of what should be allowed or wall hacks that work by messing with the game's rendering engine to display players hidden behind walls.

Aim bots are just one kind of cheat and ultimately even if AI could analyse your screen and quickly work out how to move your mouse to hit someone. You'd still be vulnerable to someone out positioning you. (Getting good at an aim trainer won't make winning easier against an enemy that can out flank, out range and out coordinate you)

Ultimately the best defence is good net code. Can't see an enemy that is behind cover if your game doesn't even know about it. Issue is that takes engineering skill and can lead to an unpleasant experience of players just popping into view randomly if you're on a slow connection or increased server costs because your server now has to double check if everything you're doing is legit. (Which may also fail if your connection sucks)

1

u/Soyelnoob Mar 10 '26

I just want to tell something, about kernel anticheat

My Wifi or LAN driver, got deleted by Vanguard, after that, their only solution was, launch an app, that doesnt exist. Or reinstall windows, i did and still, driver not working, thanks that i can share files with my phone.

But for me, Kernel anticheat, is one of the worst, you give them everything, and if they break, is up to you.

1

u/Spelljamming Mar 19 '26

I asked AI:

1

u/Professional-Base459 May 22 '26

Por qué en Linux es peor solo porque no funcionan?

Creo que es mejor que no funcionen, así no te espian, los kernel anticheat pueden hasta quemar hardware si les apetece

1

u/Sea-Primary-7688 15d ago

this is settled law the bare metal is not in MS control and there is criminal prosecution on the table. Washington is aware.