> EA says kernel-level protection is “absolutely vital” for competitive games like FIFA 23, as existing cheats operate in the kernel space, so games running in regular user mode can’t detect that tampering or cheating is occurring.
There are soccer games from the 90s that didn't need to run in Ring 0.
Epic games has kernel level anticheat for fortnite and you hardly ever run into a cheater, I honestly cannot recall running into a single one in the last 2 years. Compare that to warzone that is rampant with cheaters. Comes with trade offs, but it is effective. Cheating ruins competitive games.
Fun fact: Early on into Vanguard, Valorant's Anticheat, some system monitoring software would not run at all - even with Valorant not running, because cheaters used a vulnerable kernel module included with that software to get their code into kernel mode.
As a "gamer", I have to say: We are running out of options for anti-cheat.
The cheaters are EVERYWHERE in games like Destiny 2, Fortnite, CS: GO, New World... any popular online game, the cheaters are in 1/10 matches ruining your fun.
Weather or not a kernel level anti-cheat will help? Probably not. It is unfortunate that a lot of lower information consumers are going to install this crap onto their PCs.
No. A cheat developer could still just sign a driver like every other developer and load a hypervisor. Then hook everything you want and youre gucci.
Another option: there are a lot of vulnerable drivers, such as intels LAN driver, or capcoms. Of course those are blacklisted and anti cheats usually don’t let you start the game when those are loaded, but you can use exploitable those to load your own driver, and then unload the vulnerable driver.
Other things you can do: DMA stuff, uefi payloads and more.
You will never be able to prevent cheating on user owned hardware which sits under their desk.
from a long time already running in VM is automatically detected as cheating. a lot of people lost their accounts because of that (with permanent bans)
[+] [-] smoldesu|3 years ago|reply
There are soccer games from the 90s that didn't need to run in Ring 0.
[+] [-] sensitivefrost|3 years ago|reply
[+] [-] modshatereality|3 years ago|reply
[+] [-] mackatap|3 years ago|reply
[+] [-] nradov|3 years ago|reply
[+] [-] josephcsible|3 years ago|reply
[+] [-] sascha_sl|3 years ago|reply
[+] [-] gjsman-1000|3 years ago|reply
[+] [-] stoicjumbotron|3 years ago|reply
[+] [-] honkycat|3 years ago|reply
As a "gamer", I have to say: We are running out of options for anti-cheat.
The cheaters are EVERYWHERE in games like Destiny 2, Fortnite, CS: GO, New World... any popular online game, the cheaters are in 1/10 matches ruining your fun.
Weather or not a kernel level anti-cheat will help? Probably not. It is unfortunate that a lot of lower information consumers are going to install this crap onto their PCs.
[+] [-] josephcsible|3 years ago|reply
[+] [-] sascha_sl|3 years ago|reply
[+] [-] pjmlp|3 years ago|reply
They manage on mobile devices without kernel level anti-cheat systems.
[+] [-] alex7734|3 years ago|reply
[+] [-] anvic|3 years ago|reply
[+] [-] rasz|3 years ago|reply
[+] [-] peanut_worm|3 years ago|reply
[+] [-] TylerH|3 years ago|reply
[+] [-] taskforcegemini|3 years ago|reply
[+] [-] lillecarl|3 years ago|reply
[+] [-] mccorrinall|3 years ago|reply
Another option: there are a lot of vulnerable drivers, such as intels LAN driver, or capcoms. Of course those are blacklisted and anti cheats usually don’t let you start the game when those are loaded, but you can use exploitable those to load your own driver, and then unload the vulnerable driver.
Other things you can do: DMA stuff, uefi payloads and more.
You will never be able to prevent cheating on user owned hardware which sits under their desk.
[+] [-] db48x|3 years ago|reply
[+] [-] whatsthatabout|3 years ago|reply
[+] [-] goosedragons|3 years ago|reply
EA at least said it won't be every game either so hopefully if they didn't it won't be a huge problem either way.
[+] [-] jbverschoor|3 years ago|reply
[+] [-] Szpadel|3 years ago|reply
[+] [-] ElfinTrousers|3 years ago|reply