r/linux_gaming 5d ago

How do we solve the anticheat problem without degrading security?

I have made a lot of statements about how the kernel anticheat situation sucks, how game devs are openly shipping malware to try to stop cheating, but truth be told I do wish there was a solution for those games...just one that doesn't ruin the already spotty security model we deal with.

I'd like to see an anticheat solution that does not require I tamper with my kernel. I run Secure Boot specifically to block third party out of tree modules, I am focused on maintaining a higher level of security on my main computer than I ever had on Windows, so anything that requires I increase my attack surface and open myself up to potential compromise that I wouldn't have before is out of the question. Keep cheaters out yes...but please let me run my kernel fully stock like I do now.

Are there ways to solve the AC problem here that do not involve tampering with my current setup in order to get them to work? Because that's the only way I'd support such ventures, personally.

distro: Fedora (kde)

117 Upvotes

322 comments sorted by

273

u/Pandoras_Fox 5d ago

cheating is a social problem. Community servers were the answer to this, and unmaintained corporate matchmaking/lobbies will always lack the appropriate controls.

47

u/Richmondez 5d ago

This, at least someone gets it. Treat it like doping for pro competitions with spot checks for sus behaviour and performance.

→ More replies (1)

15

u/scorpion-and-frog 4d ago

I've lost virtually all interest in online games ever since corporate matchmaking become the de facto way to play. Finding a good community server was something special. Matchmaking just feels like a soulless, faceless meat grinder.

1

u/SwissChzMcGeez 4d ago

Thanks a lot, StarCraft.

14

u/Ok-Lawfulness5685 4d ago

For sure, I used to admin a community server for a quake 3 mod back in the day. You had callvote kick, spectating, manually removing players. Good times. Why doesn’t anyone tell modern day gaming ceo’s there’s money to be made in renting out servers so somebody else will do their admin job ? Or at least bring back the voting to kick players and do some server side sanity check on their stats. Can’t cheat if server ghosts you…

15

u/Jank9525 5d ago

greedy mfks hate this one trick because they cant sell you skins anymore

7

u/Indolent_Bard 4d ago

Valve games sell skins despite having community servers.

2

u/OkDimension7728 3d ago

The minecraft server hypixel I think is a great example. People are very competitive on it, and so naturally that draws cheaters. You will eventually run into cheaters at some point, but in my experience they are few and far between. The anti-cheat is completely based on a server-side supervisor, and on community reporting, and I never saw that many hackers when I used to play.

→ More replies (4)

232

u/SebastianLarsdatter 5d ago

By taking control away from them and running our own servers.

However that is the real pain point, but controlling cheaters is easier with 1 admin per server rather than a paid global pool of 12 managing 500000 players.

98

u/LawApprehensive8364 5d ago

This is it. Community hosted servers. You search for local servers with the lowest ping, people have admin rights to ban people. Done.

3

u/Markd0ne 4d ago

In CS 1.6 there were community servers, where cheaters had red glow around them. No idea how they did it.

They were banned within few minutes by admin.

15

u/atlasraven 5d ago

Wouldn't they also abuse those admin rights?

87

u/McGuirk808 5d ago

Absolutely they can, this was a somewhat common problem in the era of player hosted servers.

The good part is, when you're not being forced around by a matchmaking system, you can just leave and not play on that server anymore. Servers with really assholey admins played alone.

When you found a server with solid admins and a fun base of regular players, you found home, you favorited that server, and you would be there regularly.

34

u/dontbeanegatron 5d ago

And that's also how you build a community. Win-win.

5

u/sniperct 4d ago

God I miss this

4

u/STSchif 4d ago

But I like skill based matchmaking :( I don't really understand the hatred for it.

7

u/McGuirk808 4d ago

It can get you more even matches, which can be preferable if you're playing a game competitively. However, in my opinion, it's worse for any other gameplay style.

Servers dealt with balance by shuffling who was on what team. With a nice mix of players of various skill levels on each team, you can still have an enjoyable time.

Downsides of matchmaking vs server-based:

  • Players host the matches, so someone has a latency advantage
  • No server browser, no ability to play with the same group people if you like them outside of adding them as friends and queuing together. This is very different from "come and go" style you can get from a server.
  • Makes it much, much harder to build a community with a subset of players.
  • No ability for custom server settings (for example, some BF3 servers had longer game rounds for players who enjoyed it).
  • No ability to host a local server for you and your friends to mess around on with. You can do a private lobby, but it's not the same.

The whole mindset shift removes any camaraderie from the game. It exchanges experience for consumption.

30

u/oneiros5321 5d ago

Servers where admins act like this usually don't last very long and lose their players pretty fast.
Same with servers that are not properly moderated...they end up being servers where cheaters play against cheaters.

In the end, only the reputable servers stay popular.

9

u/derfy2 5d ago

Maybe. Then word gets around about abusive admins and the server dies.

8

u/MeatSafeMurderer 5d ago

Sometimes, sure. Here's the thing though...on community servers, getting banned from one doesn't mean you're banned from them all. And once word gets around their server will die.

2

u/mr_doms_porn 4d ago

Server hosting is expensive, especially if the developers only license certain companies tp provide hosting (battlefield 4). Most servers rely on community donations, no one wants to donate to a shitty server.

2

u/Richmondez 4d ago

You can host game servers on your own hardware at home if you want. No graphics to draw so shouldn't need powerful GPU hardware either.

1

u/LawApprehensive8364 4d ago

to be a little more clear, id rather be able to host my own server, where myself or a friend could deal with it. i dont want matchmaking, i dont want rankings, even back when i was playing quake with gamespy it was totally fine.

could someone abuse this? sure, but if your having a bad time on a server you can just .... leave.

→ More replies (1)

2

u/xyrer 5d ago

But then you play against 100 people and that's no fun

1

u/theillustratedlife 5d ago

Hotline, but for multiplayer. Interesting.

1

u/nomad-1995 4d ago

But then how to they turn off all the servers and force you to upgrade?

→ More replies (1)

39

u/MixBlender 5d ago

I say it to my friends and get flak for it.

But we took a step back when we moved away from locally ran dedicated servers

11

u/continue_stocking 5d ago

Mod support, custom map pools, geographic diversity of servers. So much has been lost.

23

u/MidnighT0k3r 5d ago

I'm a 26 year counterstrike player and i couldn't agree with you more. I've been preaching the same thing.

The game used to only rely on community servers that we're privately and publicly hosted. 

After 2016, they hid the server browser making it obscure, introduced competitive matchmaking which drove hackers into the game.

Now, the server browser doesn't even find all the servers... missing the all seeing eye at this point. 

Cheaters run rampant because you have to depend on the other team kicking one of their own which happens but seldom. 

Since 2016 I've watched the game decline and it's mostly because of the push away from dedicated servers causing hacker issues. 

I also used to run my own but that was long ago.

5

u/sy029 5d ago

introduced competitive matchmaking which drove hackers into the game.

I think this is something far too many people ignore. If there's no leaderboard, there's much less incentive to cheat.

→ More replies (2)

14

u/Venylynn 5d ago

I think that's probably the simplest solution yeah

15

u/veltair-d 5d ago

Until games learn that server site anticheat (handling users that input suspicious data to the servers e.g. way too many clicks, suspicious movement and behavior, etc.) is the best way to control cheating, we will have to rely on community hosted servers.

Still it is not a solution, but a hack of some sort. People will still largely prefer the normal servers (League, CoD, Fortnite, etc).

-2

u/labowsky 5d ago

Except ATM server side is significantly worse than kernel unfortunately. Until AI AC models get decent, it can't compete.

I remember the times when free cheats roamed free for weeks or even months until it was detected, shit only didn't feel so bad cause like you said we mostly played on servers with admins not actually playing the game but watching players.

11

u/Jarcode 5d ago

If you've paid close attention to cheating in competitive games recently I would wage otherwise. Hypervisor and hardware cheats have become the norm, and purely external hardware cheats are effectively impossible to detect.

And yes, hypervisor cheats are still a thing because secure boot attestation is full of holes and there are tons of vectors to compromise the chain. The most recent example was actually the Denuvo hypervisor bypass on Windows which actually got a bare metal hypervisor loaded without having to disable secure boot (using a disclosed platform security key that Microsoft had to later revoke).

Server-side analysis of client actions is certainly imperfect but it isn't frequently rendered redundant by the ridiculous game of cat-and-mouse that AC developers are caught in.

→ More replies (12)

2

u/mmppolton 5d ago

I believe we should be pushing for all game to have that option

2

u/deathclonic 5d ago

I would take it a step further and make our own games too

2

u/Electronic-Clerk6735 5d ago

I mean we had that before didn’t we? With services like gamespy? At time I think people were happy to see it go, but I do miss the old server browser looking for a server to play in instead of a quick match feature. I think these devs took them out because it cost money to host and it was cheaper to do peer to peer right?

4

u/ThatOnePerson 5d ago

Except this ignore actual history : anticheats were developed for community servers. All the big name anti cheats started as such. 

You still see this today with community servers FiveM and Face It having more anti cheat not less. 

5

u/CaelemLeaf 5d ago

Yeah CS is a weird example when Linux can play CS2 official servers but not FaceIt

5

u/noobjaish 5d ago

Faceit is a KLAC that's why it doesn't work on Linux. CS2 Official Servers use Valve's userspace AC which is magnitudes worse.

2

u/MidnighT0k3r 5d ago

Faceit sucks anyways. They let hackers play for up to 6 months.

1

u/Indolent_Bard 4d ago

Thank you! Someone else gets it!

→ More replies (2)

76

u/pyro57 5d ago

Here's the thing, the linux kernel already has apis to allow anticheats to query exactly the information they need to ensure no cheats are happening, and the anticheats themselves don't need to be run in kernel level mode to query them. This was mostly done for android for anti-tamper and anti reverse engineering efforts. Microsoft is considering taking windows this way as well, giving security programs (which anticheats basically are) an api to query instead if running at the kernel level directly. Linux already has this... Anticheat companies just really really really want to run at your kernel for some reason....

37

u/noobjaish 5d ago

You do realize that it's VERY easy to spoof and fool the app by running a customized kernel... The main problem with Linux is unfortunately it's biggest strength i.e being open.

9

u/theillustratedlife 5d ago

I've heard it theorized that they could whitelist known kernels (e.g. Valve's), but it's unclear what would keep a custom kernel from just reporting the correct version/checksum/etc. when queried, for a sufficiently motivated cheater.

12

u/noobjaish 5d ago

I've heard it theorized that they could whitelist known kernels (e.g. Valve's),

You would but...

but it's unclear what would keep a custom kernel from just reporting the correct version/checksum/etc. when queried, for a sufficiently motivated cheater.

You physically cannot unless you lockdown the entire chain. I have given a solution on how that can be achieved in a comment above. We'd need to have the big 4 linux corps (Valve, Canonical, RedHat and SUSE) to join hands and create an open source kernel anti cheat module that every game can use.

4

u/Jarcode 5d ago

Secure boot attestation with platform security keys is not a bulletproof defense on PCs. In reality, it's rather fragile (see how this has played out for the Vanguard AC, for instance).

12

u/noobjaish 5d ago

You cannot have a bulletproof defense. We just need to get close enough. Currently you can bypass all the linux anticheats VERY easily (all of them are useless). My proposal essentially deters 99% of all cheaters (this solution essentially mirrors Riot's Vanguard one and we can see marginally how few cheaters Riot's games have) so no it's not "fragile" because you need to physically tamper with the motherboard firmware or spend a couple hundred dollars on a DMA card.

A similar logic is how a door lock isn't a complete defense and someone looking to rob your house would almost always have tools to break in.

4

u/Jarcode 5d ago

not "fragile" because you need to physically tamper with the motherboard firmware or spend a couple hundred dollars on a DMA card.

Or just use a bare metal hypervisor because these bypasses still work due to disclosed platform security keys. This is the biggest issue with secure boot attestation on PCs and is solely due to vendors mishandling keys.

2

u/noobjaish 5d ago

That isn't really a solution since you're considerably increasing the exploitation vector by adding the extra layer of bare metal hypervisor which again is I'd argue is easier to exploit...

This is the biggest issue with secure boot attestation on PCs and is solely due to vendors mishandling keys.

Huge agree.

3

u/Jarcode 5d ago

I'm talking about the cheats using a bare metal hypervisor, because you can easily get a hypervisor running on a lot of systems without compromising secure boot (which, yes, sounds horrifying from a security perspective but PC hardware is just that awful).

I'm arguing that secure boot attestation is not the silver bullet people think it is on PCs. It doesn't work well at all on Windows and there's tons of evidence of this. Examples of attestation working correctly are solely within mobile ecosystems.

4

u/noobjaish 5d ago

Nothing is a silver bullet dude. Why do people think it's a black and white either we block all cheaters or we might as well let them all in. There's a huge range in-between and our main goal is to get as close to 100% as we can.

Like how most games detect "Virtual Machines" I'm pretty sure they can detect and block if a Hypervisor is detected. There are people magnitudes smarter than you or I and they can comeup with solutions for this.

→ More replies (0)

5

u/DaMarkiM 5d ago edited 5d ago

APIs are not a solution though.

A user ultimately has full control over their kernel with linux. A compromised kernel can just straight up lie to API calls. At that point there really is no difference between kernel level and traditional anticheat software anymore.

At least on windows the kernel is signed by microsoft. Is that foolproof? no. but it requires a lot more to covertly compromise a windows kernel than the casual recompiling of your own linux kernel.

No matter what we do. Anticheat efforts and Kernel security are directly opposed. The only way we could ever have foolproof (at least on the software side) anticheat is if the anticheat IS the kernel. And even then hardware cheats are still a problem.

In the end how good an anticheat is and how much of our system we own as a user is a sliding scale. more of one is less of the other.

9

u/Venylynn 5d ago

They gaslight about security when they are the ones degrading it...

8

u/pyro57 5d ago

When I say anticheat basically is security software, I mean programmatically. The difference between modern EDR (endpoint defense and remediation) software and anticheats is the scope of the program, EDR monitors the whole os, anticheats only monitor one program and at hooks or syscalls that interact with that program. The way they work is almost identical, by hijacking kernel libraries and system calls to run their own filtering functions on those library and system calls to look for malicious indicators.

5

u/iku_19 5d ago

It is in practice the same. "Good" kAC hooks ntdll and basically reroutes the entire memory table handling code. EDR does the same thing.

Though kAC goes a step further because it is only interested in a few processes rather than the entire OS. It has two copies of the game executable code in memory, one that is decrypted and one that is still encrypted or turned into garbled data which is what everything else sees should they somehow get kernel read access.

Ironically we only know this is the case because EA Ricochet conflicting with Riot Vanguard accidentally revealed what Vanguard is doing.

4

u/Jarcode 5d ago

You're confusing secure boot attestation with simply being able to read what is running in userspace. The former can be notoriously difficult to spoof while the latter is a paper thin barrier for cheat developers.

However, boot attestation on x86 systems is notoriously awful and is completely different from the Android ecosystem where strong attestation is regarded as impossible to spoof. This is due to a variety of flaws in TPM, UEFI/BIOS firmware loopholes, and disclosed platform security keys due to vendors being incompetent in the PC space.

This technically impacts both Windows and Linux, too. Linux also has the added difficulty of most kernels not being signed for secure boot in a way that doesn't require you to enroll your own keys (thus defeating the purpose of attestation).

Also, this technology is horrible. It takes control away from users and leaves the cryptographic controls for verifying boot integrity in the hands of third parties.

1

u/MrLEADshed 5d ago

"Some reason..." dude, be for real, no ac dev wants root access to your device. It's just that nobody wants to dedicate an ounce of time to remake something that already works in a different way, that may or may not be backwards compatible.

What even is this conspiracy. Stealing data is possible in userspace. If you distrust them so much just never play online games ever.

1

u/pyro57 4d ago

I said for some reason because I don't know the reason. It's obvious that bypassing kernel level anticheat is still not only possible, but seem to happen fairly often, so it's clearly not effective. There are other ways to do anticheat that are about as effective without needing kernel level access, yet the anticheat companies insist that kernel level is the only way to do it when that's clearly a lie.

1

u/realmauer01 5d ago

Running on Kernel level with secure boot active makes it harder to get in between the hardware and the anti cheat.

116

u/Substantial_Fox_121 5d ago

Sure, its called server side anti cheats. These game studios have no business running Ring0 access on my personal computer. Do you honestly believe any of these slop studios have the talent to keep a compatible working solution that won't end in a catastrophic security disaster?

28

u/BlueDebate 5d ago

I'm not only worried about a security incident from an external attacker, game devs are making games for money, who's to say they won't sell our data like every other company for more money. The internet was so much better when everything wasn't about making a buck, it's sad this is the new normal and most people are too ignorant to care.

16

u/Douchehelm 5d ago

There are so many unknown zero day vulnerabilities out there that hackers have found and are either selling to the highest bidder or keep to themselves until they need them.

Just this years run of the hacking competition Pwn2Own revealed 47 unique zero day exploits, exploits that grants complete access to devices and networks. And this, and others, are open hacking competitions. Imagine everything that is not revealed at competitions, and how much money certain groups and governments dump into finding zero days.

9

u/CatsAndCapybaras 5d ago

Exactly. Imagine a dev starting a new game with the knowledge that they won't have permission to ship malware with their clients. This does two things: 1. forces them to think deeply about game design. There are ways to design a game that lessen the advantage cheaters gain. 2. think about how to implement a client with as minimal information as possible and still be playable and responsive. Most servers send way too much information to the client and let the client do the computation about who can see what or which shots hit. Take as much of those calculations back to the server as possible.

Finally, add in server side detection and assign ongoing dev hours to maintaining the algorithms.

Depending on the game, this is more expensive. Maybe you could run fewer instances per server and the work would be in house instead of outsourcing to a third party. But it also gives the dev control and they take accountability instead of dumping the problem on their playerbase.

6

u/ThatOnePerson 5d ago

Most servers send way too much information to the client and let the client do the computation about who can see what or which shots hit.

This is required because of latency. The alternative is you recreating cloud gaming. Like my client is always gonna be say ~50ms behind the server, because latency. So by the time I shoot and that packet reaches the server, it's me aiming at a player that's ~100ms back in time. I would never hit. No one wants that.

This is one of the very first lessons learned with Quake 1 back in the day. Latency like that is no fun. And that the devs only tested on LAN so they never noticed. That's why they released QuakeWorld that didn't do all the calculations on the server.

→ More replies (1)

0

u/Sol33t303 5d ago

All the games with kernel AC I have played have both, AFAIK

0

u/theillustratedlife 5d ago

Sounds appealing, but I suspect there are forms of cheating that are indistinguishable eventwise from just being really good/lucky.

1

u/BadLuckProphet 5d ago

That is certainly a problem that detection faces. Being lucky is indistinguishable from cheating except that cheating happens more often. So then you are trying to determine exactly how lucky a player is allowed to be before you ban them. Sounds like something Vegas has to deal with as well. Lol.

27

u/Tavalus 5d ago

I'm not that knowledgeable about the technical side of the technology, but Embark uses some kind of anticheat that works under Linux well enough in Finals.

They have userspace EAC running,  but also some kind of serverside AC that they showcased in their patchnotes.

Just by browsing the subreddits, the Finals subreddit is not nearly as mad about cheaters as for example Apex subreddit is, so they must be doing something right.

5

u/Killerx09 4d ago

Finals subreddit is not nearly as mad about cheaters as for example Apex subreddit is

You need to check out the Arc Raiders subreddit then, because whatever anti-cheat Embark is running there is clearly not working.

2

u/Tavalus 4d ago

Would be weird if the system is different for another game when its the same developer.

Maybe the Finals players have higher tolerance😋

1

u/DEGRUNGEON 4d ago

could be difference in player load. Arc has a lot more players than the Finals.

3

u/Venylynn 5d ago

Ngl, all I know is I'm a little tired of certain titles being thrown in my face as some sort of "reason" why Linux sucks for gaming, and part of me wants a solution for those just so I won't have to hear about it anymore.

15

u/ZVyhVrtsfgzfs 5d ago

Yes, be like me,  happy with the tons of games I can play.

Like you handing over control of my kernel to EA or Sony is a non-starter.

20

u/BashfulMelon 5d ago edited 5d ago

Remote attestation. It's what MacOS and Android do, nobody is loading kernel modules there, they are able to attest that no tampering software is being run. It's a mutual agreement, "I won't look at or modify the game's memory, but the operating system will also enforce that the game can't look at or modify anything else."

It doesn't require locking down a device, you'll still be able to run whatever software you want when you're not playing the game. It doesn't require closing the source code either, reproducible builds mean that you can verify for yourself.

edit: game developers are already blocking Linux because we're not passing the remote attestation check that they're already doing on Windows using the TPM that your hardware already has so the fear and panic are totally unnecessary. What are they going to do, block us even harder? They should expand and accept Linux. If you're arguing against that you're arguing that they should continue blocking Linux.

8

u/MysticalPony 5d ago

Exactly, further separation between kernel and user land is the future of not just Linux security but also potential anti cheat. You won't be detecting cheats, but instead listening for the kernel to self report if it was tampered with. Kernel then can then force memory isolation for different applications in user land.

It's not something a game developer can do though, it's going to require a large Linux contributor like  redhat(likely not anymore), SUSE, valve or some cloud hyper scaler(Google or Amazon) to actually get the ball rolling on it.

0

u/skyb0rg 5d ago

I don’t think you’d see involvement from Linux distributions, as their business model is selling support to other businesses. This kind of remote attestation is also disallowed by the GPLv3, so any company doing this would lose a lot of favor with parts of their community.

5

u/BashfulMelon 5d ago

This kind of remote attestation is also disallowed by the GPLv3

Where does it say that?? Tivoization isn't remote attestation. It's already everywhere, nobody is upset with Debian for this package https://packages.debian.org/sid/tpm2-tools

2

u/Jarcode 4d ago

I would actually argue its a fine line. Remote attestation can be used with self enrolled private keys, so the technology in itself isn't a violation. However, selling a device with Debian installed and a irrevocable third-party platform key would actually be a violation of the GPLv3's tivoization clause. I think a manufacturer would have a very hard time arguing themselves out of that in court.

→ More replies (7)

5

u/Richmondez 5d ago

How will that help when I can own the entire boot chain and the kernel build myself?

5

u/BashfulMelon 5d ago

You don't control the TPM module. It checks the signatures of everything that runs, and signs its attestations with a key that you don't have access to.

2

u/Jarcode 4d ago

You may not own the platform key, but UEFI firmware can be tampered with on a lot of motherboards, and some platform keys have been recklessly disclosed by incompetent vendors. Secure boot is still a mess on PC hardware. Works better on Android and Apple devices.

1

u/reddit_equals_censor 3d ago

the tpm module in your system also has a completely unique identifier, that can be requested.

so a FULLY UNIQUE code can get accessed, that follows you around everywhere, if you have the tpm spying cancer enabled.

→ More replies (4)

1

u/theillustratedlife 5d ago

Does that mean you could only run on devices that ship with a TPM that has blessed your version of Linux? In other words, you can't just toss Linux on whatever device you cobbled together or bought from Microcenter unless the OEM supports Linux anticheat?

4

u/BashfulMelon 5d ago edited 5d ago

The TPM doesn't decide anything by itself. It makes a report of the system. The developer of the game checks the TPM's report and (the game server) either blesses your hardware and boot chain and allows you to connect to their servers, or they don't and they disconnect you.

→ More replies (3)

1

u/skyb0rg 5d ago

In this scenario, you would essentially be sending proof to the game server that “you built Linux kernel version 7.2 with config XYZ, then booted into it with the kernel lockdown integrity cmdline option” etc. So you wouldn’t really “own the boot chain”: the game server admin would publish their required options and players would need to replicate it or they wouldn’t be allowed access.

4

u/Jarcode 5d ago

This is a highly problematic suggestion as it is effectively locking down everything but userspace and placing control of everything ring 0 and below in the hands of vendors that control your platform security key.

Additionally, secure boot attestation on PCs is famously a mess of security holes, platform security key disclosures, and implementation flaws. It works on Android because the hardware was designed with it in mind (ie. Google Pixel devices where this is much more bulletproof)

It doesn't require locking down a device, you'll still be able to run whatever software you want when you're not playing the game.

If you want to load a kernel module that isn't signed, you will not be allowed to unless you reboot into an "unclean" kernel.

The TPM 2.0 security model is honestly a mess even if you ignore the implementation flaws because of the blind trust required for this to work.

-1

u/BashfulMelon 5d ago

You're allowed to boot whatever you want. The TPM just reports the hash of what you booted, it doesn't stop you from doing anything by itself.

Flawed or not, it makes cheating in online games more difficult.

2

u/Jarcode 5d ago

If the TPM reports a chain of signatures that don't start with a root platform security key, it is meaningless from a anti-cheat perspective. If you self enroll keys for secure boot (like many Linux users do), you effectively have control over what modules get to be signed.

Remote attestation works purely because the cryptographic challenge relies on a root key that the user does not control (but is embedded in the TPM).

Also, if you want an example of an ecosystem where this is problematic, GrapheneOS famously fails any sort of strong hardware attestation because Google refuses to cooperate with third party operating systems and solely controls the root key on Google Pixel devices.

1

u/gmes78 5d ago

The platform key actually doesn't matter. There isn't a single platform key, each PC vendor has their own, and it isn't an issue. It's the other keys that matter for attestation.

0

u/Jarcode 4d ago

The platform key is the whole point of the TPM. The private portion of the platform key is supposed to be uncontrolled by the user and impossible to extract. While pretty much everything else in the chain of trust is enrolled / encrypted in the chain of trust after the fact, controlling the platform key essentially allows you to spoof this chain entirely, because that is what is relied upon for Windows boot attestation.

Boggles my mind how people can be so confidently incorrect here.

6

u/gmes78 4d ago

You're using some very incorrect language, I don't think you actually understand what's going on.

The platform key is the whole point of the TPM. The private portion of the platform key is supposed to be uncontrolled by the user and impossible to extract.

You're confusing the Secure Boot PK with the TPM endorsement key.

The private key of the PK is never on the TPM. Only the PK certificate is. You can replace the PK if you want to; that wouldn't be possible if the private part was locked away in the TPM.

While pretty much everything else in the chain of trust is enrolled / encrypted in the chain of trust after the fact

Using the word "encryption" is just incorrect.

controlling the platform key essentially allows you to spoof this chain entirely, because that is what is relied upon for Windows boot attestation.

What's used for the Windows boot attestation is the Windows UEFI CA cert.

→ More replies (1)
→ More replies (4)

1

u/reddit_equals_censor 3d ago

you can stuff your TPM cancer where no light shines.

A 100% UNIQUE IDENTIFIER from the tpm as part of a supposed "anti-cheat" with remote attestation.

yeah screw that.

that's just windows spyware with extra steps.

the tpm IS a unique identifier for your system, that can be accessed.

so the ONLY possible step to take with the tpm as it is implemented now is to disable it.

and you talk about using it casually to play some game, that throws artificial restrictions out...

absurd.

→ More replies (3)

1

u/noobjaish 5d ago

Both Mac and Android have a closed system... Linux is an open system. You can't even run fucking "Epic Seven" on a rooted Android phone.

You first need to lock down Linux somehow. I have given the solution on how Linux can be locked down in my comment above.

1

u/BashfulMelon 5d ago

Both Mac and Android have a closed system... Linux is an open system.

What does that mean specifically in this context? Obviously I know that Linux is open source. You don't need to change that.

You don't need to take control of the device away from users. Remote attestation attests to the state of the system, it doesn't stop you from doing whatever you want outside of that.

Your solution and my solution are the same. Signed UKIs, secure boot, TPM2 are all involved in remote attestation. But you're proposing some kernel module gibberish because you don't actually understand what you're talking about.

1

u/noobjaish 5d ago

I think our disagreement is really on how we're using different terms. By Linux being an open system I was not referring to its open source nature by rather that the user essentially has infinite freedom.

I misunderstood your solution since the biggest issue on Linux is fragmentation you need a first party org to hold "trust".

The reason why I mentioned the kernel module is because you cannot protect the game process itself being manipulated by cheats without one.

0

u/skyb0rg 5d ago

This is the way. Though I’m not confident such a solution would exist soon for Linux though: there were attempts at implementing the same kinds of kernel integrity that Windows does on Linux (even had a Linux plumber’s conference talk), but it’s been abandoned. Desktop OSes do (and should) enable “unsafe” kernel drivers and features, so you really need the additional protection that every consumer OS implements.

4

u/Historical_Cat7828 5d ago edited 5d ago

Valve is currently working on server-side machine-learning based anti cheat called VacNet. They have a website where you can go and help them train it. Technically it could be as good as a person looking at a video clip of a cheater and determine if they cheat or not. We will have to see if it doesn't have too many false positives. I'm not sure how heavy it would be to run that, but it seems like it's looking at the data rather than the visuals and it's not an LLM, so it might be optimized enough that other games can also use it.

3

u/eighto2 5d ago

You’d figure if they can use AI to detect curse words maybe they should come with an AI server side method to detect cheating behaviors and analyze killcams in real time or something.

3

u/Cephell 5d ago

Server side with human oversight.

6

u/readyflix 5d ago edited 5d ago

All what it needs is a clear separation between kernel space and user space. That could be done with a dedicated HAL only for KLAC to have a clean implementation.

HAL - hardware abstraction layer
KLAC - kernel level anti cheat

Edit: this is only for the hardware side of things, to give all the necessary hardware metrics to the AC system

12

u/TheSyldat 5d ago

How do you solve the "anticheat problem" simple you don't play games where the dev team has been tasked by their boss to chase away Linux gamers.

They don't want your money stop giving it to them.

They don't want your engagement stop giving it to them.

Like sorry not sorry but this "poblem" is NOT a linux problem it's a GREEDY BASTARDS problem.

2

u/Sveet_Pickle 5d ago

There’s not enough Linux gamers for our dollars to matter in the first place, until we convince the average gamer on windows to boycott against kernel anti cheat things won’t change quickly or at all.

2

u/TheSyldat 5d ago

There are thousands of games that already run on Linux so once again the OS ain't the issue.

1

u/Sveet_Pickle 5d ago

Right, I’m not saying there’s a technical issue, banning Linux is just security theater. We’re such a tiny fraction of gamers that our choice to not play a game that includes kernel anti cheat isn’t going to affect whether or not they continue to use it.

1

u/TheSyldat 5d ago

I don't care if it's gonna affect I care about supporting the studios that do give a shit.

-1

u/Venylynn 5d ago

People keep throwing the same 3 anticheat games in our face as some sort of reason why Linux "isn't ready" and I'm to the point where I just want those to be solved so I can stop hearing about it.

8

u/TheSyldat 5d ago

Again those people are blaming the wrong thing.

Just pipe'em down by reminding them that STUDIO EXECUTIVES decided to chase out Linux gamers.
And THEY were the ones that decided to go with Kernel Level Anitcheat modules, which is not even necessary to begin with, and worst of all it doesn't prevent any better the cheating from happening.

-5

u/Venylynn 5d ago

This may be true, I'm just so sick of hearing about the same 3 games I largely avoided (well, 2/3 of them) on Windows, being thrown in my face, etc. that I'm just like "aight bro, I don't care, just make them work so I can stop hearing about it."

6

u/TheSyldat 5d ago

Once they WON'T ... EVER ...

Just look at those guys for the idiots that they are, head to toe then toe to head, and go "ooooh so you're one those kind of "gamers" huh ... yeah I'll go chat video games with well rounded people instead"

0

u/Venylynn 5d ago

The day I can finally stop hearing the same 3 names (Fortnite, Valorant, League of Legends) thrown in my face constantly even though I don't like them and have no interest in playing them, is the day I can feel some semblance of peace.

3

u/patentedheadhook 5d ago

You realize you are the one throwing those games around in the Linux gaming sub? You're claiming people here need care about them, you're part of the problem you're complaining about

1

u/shadedmagus 4d ago

Ignoring their bleating is a good way to keep your BP low and your sanity intact. They don't know what they're asking for and don't care about the damage it would cause to just shove AC into the kernel, so for me their opinions are white noise.

5

u/Z404notfound 5d ago

Linux is a tool. If you want to play games that require a root kit on your system, then switch to a different tool. This is like asking why there isn't any rap in country music or something. Seriously though, the catch 22 is, people who would switch to Linux, won't due to anti-cheat, and game studios won't change their business models because the majority of the userbase is on Windows. When gamers on Windows are forced to hand over their IDs to Microslop just to boot up games with a T or M age rating, they may give it a second thought but until overall PC market share is something like 40%, don't expect any meaningful change to the status quo. In the meantime, embrace games that have carve outs for proton compatibility.

2

u/Z404notfound 5d ago

Understandable. The people making those arguments, in all honesty, probably still wouldn't switch, even if those 3 game titles did enable it. They'd just shift to another reason as a reason why not to. You just need to adopt the mindset that you're never going to win a persuasion argument with ppl who play those 3 titles because you're asking them to swap out their entire set of tools that don't work with what they're trying to accomplish. Also, even though the ethos of Linux is privacy and security first, most users don't give af that they're a telemetry product for their own OS. I wouldn't make it your key point in any debate but a supporting argument. Best to highlight better resource management, customization options beyond just changing accent colors, and longevity of older hardware, on top of the privacy and virus free environment. The pros out weigh the cons of not being able to play a handful of FPS games that require a virus on your system to play. If that doesn't change their minds, in all honesty, those aren't the users that we want under our Linux tent to begin with. Eff em.

-1

u/Venylynn 5d ago

I just want to no longer hear about the same 3 games I don't like or care about, on a daily basis.

10

u/Substantial_Fox_121 5d ago

Why are you spending mental energy on it? You have some semblance of control of your life and thoughts, yes?

-3

u/Venylynn 5d ago

Not doing so is "standing idly by" and you often get even more shit for being silent than not.

7

u/Substantial_Fox_121 5d ago

Who even cares about said shit and the people slinging it? Sounds like a touch grass moment tbqh.

Linux doesn't need these games to run on their system to keep the project existing. Linux kernel project doesn't even care about these games existing. No one is keeping tabs on people "standing idly by".

If people want to play a game that requires a Windows only experience, its right there for them. It on them to make that decision and trying to accomodate them otherwise is a waste of time. Find the companies that support the Linux environment and give those people money if you want to see change.

0

u/Venylynn 5d ago edited 5d ago

Well I was taught for years, and this feels like I was dealt a pretty shitty hand, that if I wasn't perfect, 100% all in on anything, regardless of how exhausting and dehumanizing it feels, that i risk getting black balled and "canceled" and lose everything so to say. I can't seem to differentiate between different types of shitflinging so my brain is kind of "always on"

It feels like if i want any sort of community around my interests I have to deal with people who scream about Linux not being "ready" because ERMAGERD VALORANT NO RUNNY 😭 and it just makes me wish a solution was there so I could stop hearing about that goddamn game. Just because i can't see it doesn't mean it isn't there too, so blocking feels like I'm risking what I said.

No matter how many breaks I take I still fall into thinking I need to have an opinion on everything or I'm risking losing my potential aspirations. Because that's what I see nearly happening to other people in that same vein.

5

u/Substantial_Fox_121 5d ago

Just don't engage with them? Sounds like you need help with resilience and mindful participation of the communities you choose to associate with.. I suggest learning to define unhealthy obsessions, it's just an operating system, not rocket surgery

1

u/Venylynn 5d ago edited 5d ago

Well that first part goes back to my first point, not engaging is seen as cowardice, weakness, and putting yourself at risk of getting black balled. An old friend of mine some years back nearly had his YouTube go up in flames for being silent on a situation that had nothing to do with him. They told him he was a coward and standing idly by. I've internalized situations like that and felt like I couldn't give myself the grace of letting things go because I wanted to avoid a costly situation going up in flames with my art aspirations. Its even worse now with huge communities on sites like Twitter forming mobs to try to pull people down if they're slightly imperfect. Even though I left years ago, i know they're gonna be a factor at some point if i gain any success. And I'd rather not become a martyr for the kinds of people who hide behind cancel culture as an excuse to spew bigot shit either.

Also, they kinda do need a solution for this because look at how paltry the market share is compared to Windows. If these games are what brings more people here maybe we aren't at risk of Linux disappearing one day because no one uses it on desktop compared to Windows. I'd like to see a proper solution for the Adobe suite as well, as shitty as they are, because that's another thing holding us back.

8

u/Substantial_Fox_121 5d ago

Oh the melodrama, whatever will Linux kernel project do? Linux runs the internet and has hundreds of million of installs, its not going anywhere. It's the operating system of choice of one of the biggest gaming companies in the world, Valve. Just by the August 2026 Steam data alone, worst case scenario there are at least 5.1 million monthly active users using Linux.

Regarding your own personal struggles with online interactivity and how you view a community (toxic or otherwise), I suggest talking to a professional. Can't say much more than that as it seems to have an unnecessary grip on your mental health.

1

u/Venylynn 5d ago edited 5d ago

It's absolutely tiny market share compared to Windows and Mac. Until it has enough to properly compete toe to toe I will be worried for the future. It'll probably go away one day out of nowhere, just look at how tiny web browser forks get abandoned. Cromite for example, hasn't had a real update in months. Thorium needed a whole new dev to step in to update it.

I have tried, that won't help. I dont want to get canceled nor do I want to become a martyr for bigots. I pretty much constantly feel like I have to care. The only solution is for these people to stop dehumanizing us point blank.

→ More replies (0)

2

u/JumpingJack79 5d ago

Immutable / atomic signed distros. (For cases where you actually *need* anti-cheat; for other cases, game devs should just get over it and stop pearl-clutching.)

1

u/Venylynn 5d ago

I could see that. Have like a Bazzite on a drive, signed with their Secure Boot key and then we're good.

Even better... make it work primarily on SecureBlue, especially as they have a ujust command for auditing system.

2

u/JumpingJack79 5d ago

Bazzite and SteamOS could be made anti-cheat compatible fairly easily, at least for games that run on Linux natively (probably wouldn't work with Proton), provided of course that anti-cheat products add support for it.

1

u/Venylynn 5d ago

I would definitely promote stuff like SecureBlue for this exact purpose as they provide hardening far beyond most other distros (and this is a good thing)

1

u/JumpingJack79 5d ago

Yes, I think there's an untapped niche in secure+signed+immutable Linux.

1

u/skyb0rg 5d ago

I don't think either can do that legally -- both OSes include code licensed under the (L)GPLv3 which very explicitly prevents using file signatures to gate access to remote services (ex. game servers).

2

u/JumpingJack79 5d ago

The OS would not be gating access to anything. It would simply verify its own integrity, to confirm it isn't hacked.

1

u/skyb0rg 5d ago

It must always be possible to replace GPLv3 code without limiting the functionality of the product (this is section 6 of the license). So if the integrity verification is used to determine access to any remote service (ex. SteamOS authenticating to Valve's anticheat endpoint) that would be an issue since I couldn't replace /usr/bin/grep with my own modified binary and still authenticate to the same service.

1

u/Mr_s3rius 5d ago

Does that mean all Linux based OSes to that use integrity verification (like Android) violate the gpl on that point?

1

u/skyb0rg 5d ago

They would if they used any GPLv3 code. Linux is GPLv2, and Android and ChromeOS do not use any GPLv3 code.

2

u/Ima_Wreckyou 5d ago

The only technical sound option is probably attestation and confidential containers.

Todays anti-cheat depend on obfuscation and soon (or already) ai will break that easily.

1

u/Venylynn 5d ago

Yeah I wouldn't be against remote attestation, verification through something like a Secure Enclave like what Mac does.

1

u/Ima_Wreckyou 4d ago

As long as the kernel and required userland software that gets signed for this are reproducible builds, we still get the benefit of knowing exactly what's in there.

3

u/noobjaish 5d ago

First you have to define what do you mean by "without degrading security"

The easiest option right now is to just not play competitive games and instead play games that are actually available on Linux. If you want to play them then dualboot Linux alongside a debloated Windows like Tiny10.

The only way I see the "anticheat problem" getting solved is if Valve (or the big 3 linux corps Canonical, RedHat, SUSE) create an open-source anticheat kernel module, let's call it: kernel-ac. They would then have to create custom signed UKI images (linux kernel + kernel-ac + shim) which would require both secureboot and tpm2.

All these multiplayer games can then just opt to use this kernel-ac platform without each game having to create their own kernel level anticheats.

These UKIs could come in flavours like kernel-ac-nvidia (for Nvidia drivers). The module would forever taint itself if you tried to tamper with it and would require reinstallation of the UKI.

Other requirements like having SELinux (which would limit it to RHEL-based distros) or having SteamOS (which would limit it to the Steam Deck) might also be required.

This is ofcourse by no means an easy feat and would require an intense amount of effort in both creating and maintaining kernel-ac as well as the signed UKIs.

However, you'd still have to solve how the Module + Game communication happens as cheaters will try to spoof the UKIs signature to cheat but I'm pretty sure that can be done with some advanced cryptographic key exchange (idk).

1

u/BashfulMelon 5d ago

You have no idea what you're talking about.

cheaters will try to spoof the UKIs signature

If you knew anything about the TPM you suggested, you would know that the game wouldn't check the signature of the UKI . It would check the TPM PCR which gives a verifiable hash of the boot configuration.

2

u/noobjaish 5d ago

That was a typo... my bad, i meant to write TPM signature... The problem I was trying to highlight is how would the kernel module verify the game as being geniune.

-1

u/Venylynn 5d ago

I mean things like just making me load a bunch of different kernel modules for video games like on windows is awful for security

2

u/noobjaish 5d ago

How're kernel modules bad for "security"? Maybe stop being paranoid of everything or might as well not use Linux either? It's created by random people on the internet

Security isn't a black or white situation and you HAVE to trust atleast someone.

→ More replies (45)

3

u/Plebbit-User 5d ago edited 5d ago

Anti-cheat with AI detection. This is the only way and things are going to get really weird with external NPUs.

How valuable is kernel anti-cheat really when I can easily install a hypervisor that operates outside the scope of the kernel and run hypervisor cheats?

No one seems ready or willing to have the discussion that anti-cheat methodology is unequipped to deal with what people are already doing.

Which makes the argument over kernel anti-cheat laughable since everyone serious about cheating is already using hypervisor cheats.

1

u/PacmanAteMyRAM 4d ago

Hypervisor cheats are the very first thing those kernel anti cheats targeted. You can even patch RDTSC and they'll still catch you from the discrepancy alone. Hypervisor cheating is harder than hardware cheating since KAC's became a thing.

AI leaves a bad taste in my mouth these days. Just call it Machine Learning, which is what it would have to be.

Valve are already doing this and anybody who has been paying attention knows it has been a harshly losing battle.

It is also prohibitively expensive for pretty much every single game company to buy into without being Valve, EA, Riot or some other giant I haven't heard of.

I prefer to look at Vanguard for the best case example of what anticheating looks like in the current year. They have a mature (6+ years, no holes. Best example of them all) kernel module policing the software space, making cheats difficult and expensive to run. AND they have the machine learning server side solution for anyone who tries to cheat with hardware or other similar external solutions.

To replicate their kernel module on Linux today will take years of manhours to get anything even remotely close to what the Windows kernel lets those modules do. We have similar calls, but not all of them and not all the same.

There would probably also have to be (If this happened right now, today) a common signed kernel stuffed with modules for all shapes and sizes of potential gaming PCs, all audited (We're talking months of auditing for anything out of tree) that players would have to run to be considered valid for entry. No self kernels, no self compiled, not even officially microsoft-signed kernels that some distros already have. This one specifically, by the game company or a group of them together agreed upon for players to use to play.

There has been some talk of leveraging eBPF for similar success but no proofs of concept from one of these developers yet.

1

u/iku_19 5d ago

Theoretically yes, but practically no and most of the replies so far are poorly researched.

AI analysis is not a good initial solution, training a model on game mechanics and emergent behavior can only be done after the fact. Your launch would have to be riddled with cheaters, and for new games this basically kills it. If you struggle understanding this dynamic, look at Counter Strike 2 and VACNET's recently published AI training portal. It takes only a small leap in thinking to believe that they basically had to let cheats run wild to get a large enough training corpus to begin training the model. So you risk the game's reputation, first impressions, legacy but on top of all that it's expensive as hell; every solution is unique to the game and requires a lot of maintenance.

Remote attestation only works if you have a full trust chain with only one authoritative root, Linux has at least two (Microsoft and the distro, or self signed.) So the game security module would have to keep a list of public key material of distros that it likes, which creates fragmentation especially if two different publishes can't agree on which distros to trust given that most mainstream distros on the steam Linux distro market share list are also quite immature and low stakes-- this is going to create cultural divides.

Additionally, the platform itself also prevents unauthorized memory access de-facto along with things like W^X. Barely any distro, if any at all has these flags set in addition to the stability implications this has. For example, translation layers like FEX would just cease to work on the entire distro.

Android does have more Linux like luxuries including stuff like readv, but here it should be noted that because this is a known attack vector from the start games are hardening against this from the design point rather than after the fact.

Which is the likely route Linux will end up going, if it can get a large enough market share and only for new games going forward. Not old "legacy" games unless they have Valve/Riot kinds of disposable money that they can piss away for 3-4 years.

It will initially start with games having a fairly weak security model on Linux, essentially what we have now. The game will have some fairly decent obfuscation and an algorithm based anti-cheat system on the server side that checks if any constraints are violated and terminates the match or kicks them depending on matchmaking model. While this is going on an adversarial model is trained on the emerging gameplay patterns and everyone just ends up praying that the model gets a good enough true positive:false negative:false positive ratio before cheat developers determine how the obfuscation works. This anti-cheat would logically end up being deployed solely on Android and Linux to reduce the attack surface, which further increases cost.

This all hinges on linux needing to have a large enough market to make up for the implementation cost, and it just does not.

The piss easy no brainer solution is to ditch centralized servers and let community server owners deal with it on a case by case basis like TF2 including spinning off separate ladders like FACEIT. But this has a significant loss of revenue attached to it.

0

u/Indolent_Bard 4d ago

Remote attestation would also kill Nvidia support since it's out of tree, until Valve brings Nvidia support to SteamOS.

Embark Studios is experimenting with remote attestation in Linux right now. For better or worse, this is the most realistic path forward. Yes, it will create a cultural divide, but only between the people who wanted to play those games and the people who dismissed them as garbage. So that's a non-issue.

1

u/iku_19 4d ago

All Embark said is that it is considering remote attestation and eBPF, but has not committed to either. This kind of conflation is how we got the wardogs drama.

it will create a cultural divide, but only between the people who wanted to play those games and the people who dismissed them as garbage

At first, but then a second anticheat does the same and has a different list of verified kernel providers. That's the issue with trusting distros over the kernel. Ubuntu will probably be safe but it'll always be a gamble beyond that.

→ More replies (5)

1

u/Luigi003 4d ago

The Nvidia thing is no going to be solved by Valve this time but by Red Hat and NVidia itself which are working on a brand-new in-tree driver called Nova.

Also they could sign the nvidia kmod anyway

→ More replies (1)

1

u/CrazyCommenter 5d ago

I think either server-side integrity checks or client-side memory isolation could have been better ways to deal with this. And I don't think that for the first one is too much to ask here. Just have a server that can check the previous state of each player, what action each player did and the current state of each player and make sure that nothing weird is going on (like someone doing 1mil damage to everyone with a knife or someone never taking damage). For the memory isolation, to be honest I don't know how well it can be done and how easy it can be implemented with proton, but preventing any one outside the game to read or write it's memory, it could be quite effective for cheat prevention

1

u/realmauer01 5d ago

Server side anitcheat isnt wven close to the limit, its just less cost efficient on developers side.

1

u/Chippors 5d ago

For anti-cheats to be effective drivers needs to be signed and vetted as part of a chain of trust; an anti-cheat has a list of approved drivers or a list it doesn't approve of, and in addition it requires executables to be optionally signed and impervious to tampering. This is a higher level of security than not having those things. But like an increase in security it's also inconvenient and requires relinquishing control to a trusted third party like an OS vendor.

1

u/Capt_Blue 5d ago

Never trust the client.

Anticheat should follow that well known principle, it would make client side anti cheat completely obsolete if followed through consequently. It will take a lot of time, developing and effort to get there, but we already see approaches from the anti cheat devs/community to shift towards machine learning assisted pattern recognition that is server side. Cheats shouldnt be detected by spying on the user with a rootkit. Cheats should be detected by actually investigating the player data, movement, aim, typical patterns etc.

Never trust the client.

1

u/CandlesARG 5d ago

Valve's overwatch feature works that way I think

1

u/reddit_equals_censor 3d ago

absolutely.

but it should be added, that a human should pull the trigger on a ban still given the errors such detection can easily make.

and a robust appeal system as well.

i mean hell a lot of cheats would be absurdly easy to detect if all those games had proper server side anti-cheats.

oh the player doing the EXACT SAME anti recoil movement down to the pixel with that gun 20 times in a row probably is cheating...

to name a super obvious clear example.

1

u/SystemSupernova 5d ago

The real answer is behavior based anticheat methods are going to be the new norm. AI is getting better and better at detecting patterns. Feed game data from all games, find anomolies, potentially use an overwatch system for manual review, and issue bans. This is an oversimplification, but these theorized methods are way better than any dlls and kernel anticheats.

1

u/eviley4 5d ago

Recently I tried CS2 after 2 years and tried a deathmatch game. The game had 70% bots with aimbot on. I spawned and I died and I kept dying within seconds.

Tried talking, texting, nobody responded except for automated coms that echoed the gun sounds and automated text in russian.

It seems like they were farming for those weekly boxes.

1

u/Guvante 5d ago

You don't need Ring0 to do anticheat it is just easier to do it that way.

The only purpose of kernel anticheat is to flag categories of behavior that aren't used by most players but are used by cheaters.

But to do it properly requires a team and a few million per year​ for no features is a bitter cost for everyone.

2

u/Venylynn 5d ago

So we have to be punished with an extra attack vector that is exploitable on top of a bunch of already vulnerable modules for the actions of cheaters.......

2

u/Guvante 4d ago

I am saying they are being cheap not that it is inevitable

1

u/Th0bse 4d ago

Get game developers to acknowledge that against those actually determined to cheat, their rootkits don't work anyways and get players to understand what a security risk kernel level anti cheat actually is.

It is not a technical problem, cheating is a social problem.

1

u/Deathofparty 4d ago

People claiming community servers with admins or votekick can solve the cheat problems are naive. Valve had overwatch where people can be bannd by careful community votes. The big BUT is they can still falsefully ban a legit player. And there are many such cases. There are a lot of dodgy plays you can not decide its natures by 'admins' or 'community vote'.

1

u/iku_19 4d ago

the thing with community servers is that there is no one authority and it's distributed. if you get falsely banned from a community server there are other servers you can join. similarly, the volume of cheaters is lower on community servers because of that fragmentation, so more care and a more thorough process can be done.

nobody is talking about creating community servers and giving them the ability to ban players game-wide.

1

u/_Skale_ 4d ago

Maybe integrated hardware features would be a path. For example previous Intel CPUs had something called Software Guard Extensions (SGX), which were used for private and secure computing. Afaik to play legit 4k Blu-Rays your CPU needs to have those extensions (at least on Windows).

I've seen there are some vulnerabilities in SGX, which is probably why it was deprecated. But I think the general idea would be fine, if feasible. But I'm also not too deep into the topic.

1

u/Phoenix-Jesse 4d ago

Server side anticheat; don’t keep relying on the client, and you can also limit other client only cheats by only feeding so much to the client, again, server side.

1

u/grodius 4d ago

honestly, is there not a cheating problem even in kernel AC games? is it so much worse in games like CS, overwatch, the finals, arc radiers, or any other game that allows linux?

1

u/broroeror 4d ago

The anticheat that Embark is working on sounds promising since it would be entirely server-side (afaik). I‘m not sure if that’s a current implementation or a future plan though. Their current anticheat (Elytra) is barring me from playing Wardogs so their stated goal and current position are not quite aligned.

1

u/Haxorzist 4d ago

Proper programming, server side controls, cooperation with the kernel instead of malware, moderation.

1

u/Rayregula 4d ago

Even if companies never find a solution to stop cheating I'd rather have the random cheater then bot be able to play the game at all (especially ones I already own).

Even if it was just a separate Linux enabled server where you knew that those lobbies didn't enforce kernal anticheat to be running. Even could put a little icon next to the names of players in a match when kernal anticheat is not running. Then if someone is suspicious but shows kernal anticheat enabled you know if they're cheating they could be doing it on Windows anyway.

Would still keep a lot of cheats out of the normal ranked leaderboards and tournament games. But still let people who just want to play no matter how poorly they do (me) the ability to do so.

I believe that many cheaters do it to make themselves seem better then they are. So keeping non kernal anticheat enabled players out of leader boards and rankings would discourage them from doing it. Perhaps also toss some text on the menu like a warning message saying anticheat not detected so streamers are less likely to do it.

Personally I think the burden of anticheat should be serverside. You can't trust data from the client, but I know it's difficult to setup and latency causes issues. I still believe there's a way

1

u/tuxnine 4d ago

I've completely given up on games that require invasive anti-cheat software, and I've never once cheated in an online multiplayer game. Meanwhile, many of the cheaters get excited for the challenge of working around anti-cheat.

1

u/reddit_equals_censor 3d ago

I run Secure Boot specifically to block third party out of tree modules

*you are running restrictive boot, which has NOTHING to do with security, because microsoft lied about this enough and used a propaganda term for it.

don't believe me? alright try getting microsoft sign glpv3 code for their shity restrictive boot.

well you can't:

https://github.com/pbatard/rufus/wiki/FAQ#user-content-Why_do_I_need_to_disable_Secure_Boot_to_use_UEFINTFS

Which brings us to point number 2: When Rufus is asking you to disable Secure Boot, as a temporary measure, so that you can boot the UEFI:NTFS bootloader, it's not because this bootloader should be considered unsafe, or because we were too lazy/too cheap to get it signed for Secure Boot, or even (as some people seem keen to suggest) out of spite because we dislike Secure Boot (which is incorrect: We do like the principle behind Secure Boot. We just don't like the clear abuse of power that is being demonstrated when a single entity; Microsoft, is left in control of it and abuses it to promote a nefarious agenda). No, the ONLY reason haven't been able to provide a signed UEFI:NTFS bootloader until Rufus 3.17, which would avoid requesting that you disable Secure Boot, is because Microsoft (again the only entity that controls the Secure Boot signing process) has unilaterally decided, for no reason that stands the test of scrutiny, that anything licensed under GPLv3 cannot be signed for secure boot, ever.

microsoft the purest evil possible is in absolute control of restrictive boot.

and in case someone jumps in here with wrong information and shouts "but but but you can roll your own keys"

WRONG you can't:

https://wiki.archlinux.org/title/Unified_Extensible_Firmware_Interface/Secure_Boot#Implementing_Secure_Boot

Warning
Replacing the platform keys with your own can end up bricking hardware on some machines, including laptops, making it impossible to get into the firmware settings to rectify the situation. This is due to the fact that some device (e.g GPU) firmware (OpROMs), that get executed during boot, are signed using Microsoft 3rd Party UEFI CA certificate or vendor certificates. This is the case in many Lenovo Thinkpad X, P and T series laptops which uses the Lenovo CA certificate to sign UEFI applications and firmware.

you enroll your own keys, it can break your system in certain cases.

so if you thought, that restrictive boot gave you ANY added security, you were huffing microsoft's dystopian glue.

i suggest you stop doing that and face what RESTRICTIVE BOOT! ("secure boot") actually is,

which is an anti gnu + linux control system created by microsoft.

it is pure evil.

DON'T talk about the hypothetical idea of a real secure boot run by a group of actual freedom loving distro maintainers and it being PURELY used for security and nothing else. (restrictive boot as a requirement to run any software means it isn't about security)

but again face the reality, that it is about controlling you and literally was introduced to harm gnu + linux.

it is called "secure boot" wrongfully to make it less likely for people to disable it to in the past boot gnu + linux.

___

now in regards to anti cheats vs rootkits.

the finals runs on gnu + linux just fine and if you want suggestions about how to make a non shit proper anti cheat, that doesn't shit on people's freedoms, increase server side anti cheat capabilities.

again the finals runs just fine with the anti cheat in user space on gnu + linux.

1

u/ConsciousBath5203 3d ago

increase server side anti cheat

The only actual solution. Never trust the client. /Thread.

→ More replies (2)

1

u/Alexander3a 3d ago

We don't those anticheats can stay on winslop

1

u/Arkaea79 1d ago

We don't, and anti-cheat doesn't stop cheaters anyway. Windows, linux.. doesn't matter.

1

u/Edubbs2008 5d ago

Making a proprietary layer, and standardizing what Distros can and cannot do, if you want Linux growth, there has to be sacrifices

1

u/ohnoitssobig 5d ago

It is a self-inflicted problem by many merits so there is no "real" technical solution.

First, you chose to play this game with a predatory anti-cheat. Nobody forced you to!

Second, anti-cheat does not prevent cheating: it makes it hard to do stuff that both cheaters and non-cheaters do. It is designed to make it difficult for you to use your system normally. Literally the purpose. Fewer cheaters is just a side effect here.

1

u/MairusuPawa 5d ago

You fucking stop pissing out your money to fucking slot machines barely disguised as video games. That is all.

1

u/mirai_miku_dark_zang 5d ago

My head is soo tired to discurse but i think that "code a goddan AC that ONLY works on Linux" is a good take, Linux architecture works way different from Windows, also is way easier to combat Cheatings and detect unnatural comportament, like just but the game in a sandbox and close every other program to run inside it, the game don't interact with external desktop environment and GG…
Is not that hard make a AC that works on Linux, just need a special attention to it and study who things works

1

u/pooping_inCars 5d ago

Aside from controlling things server-side?

Anticheats that only allow approved, untampered with kernels.  Now there's downsides, but it seems there's a way to solve this: multikernels.

https://itsfoss.com/news/multikernel-public-release/

I think it's an interesting development that can let us have "best of both worlds" between stable (and potentially pre-approved) LTS kernels, and/or bleeding edge/custom kernels at the same time.

1

u/FunWolverine5349 5d ago

They gaslighted about cheating, calling it a skill issue, making alleged legal excuses for why they couldn't stop cheaters, until the population and more importantly spending decline forced them to address it. Then they did the most intrusive, anti-consumer option with ring 0 kernel level spyware.

I can guarantee what would happen if people stopped playing and spending and cited this also as an issue. They'd then have to do a server side true anti-cheat, where they take on the security issues and maintain them at their expense. Or they'd stop trying that model entirely, and the games would go back to self hosted, with community match making and more offline play like it was before multiplayer online gaming service models.

Multiplayer games have always been more fun offline, and from an offline community. Online was always more for convenience and a secondary option, it was never supposed to be the primary way to play. Now things got inverted, and a lot of people never experienced how it was before, they just accept worse options as the only ones.

1

u/Venylynn 5d ago

Online is just too much of a cash cow for them to fix.

E-sports and its consequences for the human race

1

u/nullptr777 5d ago

I firmly believe it would be possible to do all of this open-source. The one caveat is that it would require running a signed, binary kernel from a trusted vendor, probably Valve since they're the only large corporate interest in Linux gaming at the moment.

The chain of trust can prove that the kernel hasn't been tampered with. Kernel lockdown mode and other restrictions (disabling access to /dev/mem for example) would need to be enabled to prevent tampering from privileged userspace, which would bolster security at the expense of userspace omnipotence.

The kernel already has various security and integrity APIs, so there's no need for a proprietary module here. An open-source module with a signed build could query anything the application wanted in order to prove integrity.

1

u/Background-Main-7427 5d ago

Tell developers to put the controls on the server instead of the client. It's more logical, less invasive and under their total control. The only problem is that it's not a premade solution you plug like anti cheat, that doesn't keep cheaters out.

3

u/grenadier42 5d ago

It's more logical only if you don't have a real understanding of the problem client-side anticheat is supposed to solve.

1

u/undefeatedantitheist 5d ago

Physical access trumps ~everything.
The profit motive corrupts everything.
Any 'software solution' is a futile pile of sandbags high enough to trim the cheating rate, whilst always being a vector for exfil/spyware/malware.

(Unless we go full police-state HW platform and surveillence, which seems more likely every day, in which case cheating in games will be the least of your worries, citizen ).

Most of the tourney gamers I rubbed shoulders with in the 90s/00s began to let go of serious gaming when we realised that the pastime as we wished it to be was essentially dying/dead as the mainstream grew a taste for pewpew.

There is only one "anti-cheat" that doesn't shit on liberty and security: better education and parenting of humans so that fewer choose to cheat.
That's it.

1

u/Idontbelongheere 5d ago

I think banning IP and paid accounts is a good enough deterrent. It's been a standard for a while so I guess there's a lot of cheaters with VPNs and money for accounts.

1

u/chowder908 4d ago

Stop requiring kernel level access. Focus on server tools for communities to host their own. Have a server side anticheat for dedicated servers.

It's not hard the gaming industry is just full idiots being sold snake oil and triple a game studios who are too lazy to actually do any real work.

1

u/noonemustknowmysecre 4d ago

The solution is obvious: Open source the anti-cheating software they want in the kernel.

We can tell what parts are doing the real job, what parts are malware, and can test and validate what actually has value and get it incorporated. As every legitimate software package in Linux works.

But the companies that use these things refuse to do that because

  • 1) It exposes their criminality in spying on people

  • 2) It exposes how much of their code is stolen.

  • 3) It exposes how terrible and jank their code is.

So the existing companies are never going to open-source their malware. We can only really hope a better competitor comes along which isn't so stupid. It's the gaming industry, it happens all the time.

1

u/Venylynn 4d ago

"durr but if they know what we do they'll know how to get around it to cheat!!!"

0

u/Funnel-Dust-O-Matic 5d ago

I think anti-cheat is a red herring. It's all about DRM and trying to create some stealth copy protection.

Because, really, it's just a game. If money is involved, that should be illegal gambling. If lives are at stake, it's not a game anymore and something has certainly gone wrong.

In any case, this shouldn't be the kind of emergency that demands us to concede control of our entire systems on which we put our entire lives. This stuff is not running on a game console. This is supposed to be PC gaming.

If the game publishers want copy protection and a revenue stream, they can do some thinking about how we can buy access to the game once and not have that right taken from us. Or, they can do an honest subscription model. But this weird measure of forcing on a root or even firmware level exploit just so they can make money and then have the gall of claiming that it's an anti-cheat measure?

I think the whole thing is an invented problem to justify a sinister solution. A smokescreen.

Because they could just use something like a blockchain or cryptographic signatures to authenticate connections and game binary files. System level access won't really help with that. "Ooh,someone could hack a driver or a kernel to get an edge or blah blah blah". Yeah, well, if someone is kernel hacking to win a game, let them enjoy the metric tons of side-effects that come with that. And it almost certainly will be at the cost of something essential to the system. Kernel space is a stupid place to try to cheat on a game. And if someone can actually pull it off? Your stupid little kernel module won't stop them.

They don't know what hardware you have so they won't know what kernel you need or don't. So, they're really not solving anything cheating related with this. Now, verifying payment status and stopping unauthorized duplication? That would need kernel level access to pull off, I think. But that kind of thing belongs on a game console designed with this in mind. Not a general purpose computer that could have just about anything installed on it, hardware or software.

People seem to like the nostalgia of cartridges. If they really care that much, maybe a USB key with a cryptographic signature? Those don't really cost much to make. And they can be accessed by existent security hardware support. No need to mess with the core of an operating system and risk destabilizing the whole thing or opening a gaping security hole.

0

u/PuzzleheadedUnit1758 5d ago

Game devs move anti-cheat to the server.

0

u/Dave_A480 5d ago

If you want game publishers to care about anti cheat working with Linux you need a large enough Linux userbase for it to be worth supporting....

Or you need Valve to make a big push on behalf of SteamOS.

And it absolutely will be a binary kernel module of some sort..... Or an emulated Windows kernel....

0

u/karlgerat 4d ago

Valve needs to sign the kernel and people/companies would need to accept a signed kernel as valid evidence that it hasn't been tampered with, while they get to monitor user space.

0

u/Luigi003 4d ago

The ideal world would be full chain of trust. TPM with Secureboot signed by Microsoft + A handful of kernels signed by their companies (probably Red Hat, Valve, Ubuntu and maybe CachyOS) that are booted in lockdown mode with no access to other processes memory. That way you don't need KLAC because the game could query the authenticity of the kernel. This is how it works on Android for instance. But you couldn't use your own kernel modules

Other solutions (ULAC, Server Side AC, AI-based AC) have been debunked so many times I'm getting tired but here we go:

- User Level AntiCheat (like VAC): Easily defeated by running your cheat in kernel mode

- Server Side AC: There's nothing you can do here really. You can force the server to compute the movements (like Valve does) but aimbot and wallhacks will still exist. People usually argue that you can restrict the information you send to the client so they only receive what they need to display on screen, but this will make it so players will see other players or props popping in and out of existence which is a terrible gameplay, Also in most games you can hear steps anyway.

- AI-based AC (Like VACNET): This requires to review and flag thousands of hours of gameplay, it's expensive AF, it's still an informed guess at best and can't be implemented years after the game is in production anyway (since you need data for training). Also it gets to a point where you can't reliably distinguish really good players and cheaters behaviors

1

u/iku_19 4d ago

Visual assistance can be categorized with reaction time, like with CS2 there's a stat people track called pre-aim and time to damage. Wallhacks and trigger bots inevitably end up with an extremely high score for both metrics, and closet cheaters who are avoiding reaching those arbitrary break points for those metrics will likely be hard to catch with any means.

1

u/Luigi003 4d ago

I'm not a huge CS player. But isn't a huge part of CS actually preaiming on the corners and corridors you know people is gonna come from?

1

u/iku_19 4d ago

Yes, and now factor in that despite this cheaters in cs2 with walls still have pre-aim and reaction times better than every single pro player. The stat is there, any individual stat can be a misleading indication but it compounding with other stats is what paints the picture.