this post was submitted on 18 Mar 2024
94 points (97.0% liked)

Games

16751 readers
577 users here now

Video game news oriented community. No NanoUFO is not a bot :)

Posts.

  1. News oriented content (general reviews, previews or retrospectives allowed).
  2. Broad discussion posts (preferably not only about a specific game).
  3. No humor/memes etc..
  4. No affiliate links
  5. No advertising.
  6. No clickbait, editorialized, sensational titles. State the game in question in the title. No all caps.
  7. No self promotion.
  8. No duplicate posts, newer post will be deleted unless there is more discussion in one of the posts.
  9. No politics.

Comments.

  1. No personal attacks.
  2. Obey instance rules.
  3. No low effort comments(one or two words, emoji etc..)
  4. Please use spoiler tags for spoilers.

My goal is just to have a community where people can go and see what new game news is out for the day and comment on it.

Other communities:

Beehaw.org gaming

Lemmy.ml gaming

lemmy.ca pcgaming

founded 1 year ago
MODERATORS
 

all 26 comments
sorted by: hot top controversial new old
[–] [email protected] 8 points 8 months ago (1 children)

So if it isn't a RCE vulnerability, what vulnerability is it?

[–] [email protected] 17 points 8 months ago (2 children)

Their wording is actually quite deliberate. They say there isn't one being exploited, but they do not explicitly say that there isn't a RCE vulnerability.

It kinda stinks of ass coverage.

"I did not have sexual relations with that woman"

[–] [email protected] 4 points 8 months ago

Yeah, it stood out to me.

It's always in what they don't say.

If they say it's not a RCE vulnerability, it could still be a privilege escalation vulnerability etc. They avoided saying their software isn't being exploited or "we have seen no evidence our software has been compromised", or "there is no clear signs...".

Which gives a little wriggle room.

[–] [email protected] 7 points 8 months ago

It stinks of lawyers checking the press release. They can't say "there is none" in the offchance that someone, sometime finds one. Then clients could point to this press release saying "SEE, YOU TOLD US THERE WAS NONE AND 25 YEARS LATER WE FOUND ONE". I bet they are telling the truth, just ran through a lawyer and PR team.

[–] [email protected] 67 points 8 months ago (2 children)

It's really disturbing how popular the notion that rootkit-based anti-cheat is a good thing is on the internet at large.

I love it when a thread like this comes up on Lemmy every single comment condemns EAC's whole anti-cheat model.

Y'all are all right.

[–] [email protected] -4 points 8 months ago

Kernel level and root kit are two different things. Please don't confuse them.

[–] [email protected] 16 points 8 months ago

While I am sceptical of rootkit based anti-cheat as well, I am also not a fan of how quickly everyone has jumped to assuming this is EAC's problem and not a problem with Apex Legends, is there some solid evidence for that that I'm just unaware of?

[–] [email protected] 7 points 8 months ago (3 children)

I don't know much about anti-cheat development, but it can't possibly be that hard to at least implement something that checks whether a player even could have done something in a certain amount of time which would eliminate a lot of speed related cheats, and for the rest, why not look at data averages to try to weed out cheaters?

I know combing through the data is probably complicated, but so is installing kernel level anti cheat software that has to monitor every single process running on a person's computer.

[–] [email protected] 5 points 8 months ago

Not how it works, and it is a huge science behind it all. First of all, you don't want false positives. People would ruin your game for it. The reviews would be awful and it would breed more cheaters (angry at a game that banned you for no reason? Make it ban you for a reason, ruining people's fun in the process and costing them money). Second, most of what you are talking about is already done on server side. Third, the concept of banwaves is a thing. You want to catch as many cheaters at once with a single detected cheat. If you ban someone at first sight, the cheatmaker will refund that first person and think up something worse immediately. If you ban 30k people, all of them flock to the cheatmaker asking for refunds. Which he can't obviously provide, since they already spent that money over the course of the time the cheat was active, etc. Fourth, lots of cheats are subtle enough to be "invisible" to any sort of detection. Guy has an overlay that shows people through walls. You can't ban overlays and the client needs to know where people are on the server, it just hides them. All you can see is what a human would see - a guy looking at people through walls, but trying to hide it. A guy with "incredible gamesense" basing their tactics on info he couldn't have gotten. A moderator that knows what to look for would see it. An admin that abuses power and bans everyone that's too highly skilled would also ban the cheater. But try writing anything that checks for the "averages" and you ban actually good players that use sound, etc. Same thing with aimbot - it's very obvious to someone looking at gameplay. But going off of statistics you ban everyone who "has a good day".

The way to do it, was how Valve handled it in CSGO. No idea if the system is still in. They basically tasked their community with being the judge and executioner. They would send you a replay in client, showing you 10 mins of the match. Sometimes they would send you a replay that they already know has a blatant cheater in it, to test if you actually say "ban" if you see one. They scored the judges, valuing better ones more and providing feedback saying "your case has banned a cheater". It was a slow process, but effective, or at least it would be if the game wasn't so incredibly popular and free. Obviously a live moderator would help a lot, but it's the next best thing.

[–] [email protected] 6 points 8 months ago

It's cheaper to install malware.

That's all there is to it: cost.

[–] [email protected] 20 points 8 months ago

Says the company that took three years to implement a shopping cart for their shitty store.

[–] [email protected] 18 points 8 months ago* (last edited 8 months ago) (4 children)

If I was a hacker, I would be spending most of my effort attacking anticheats. Installing spyware on people's computer to prevent cheating is wrong. They should be doing what devs did before anticheat was invented - server side moderation.

[–] [email protected] 0 points 8 months ago

If you were an actual hacker you'd be targeting web sites and Linux servers. Because that allows you to spread your payloads across huge populations easily.

[–] [email protected] 6 points 8 months ago (1 children)

gamers aren't usually a prime target, except for cryptominers...

an anticheat based cryptominer worm would be pretty terrible, now that i think about it...

[–] [email protected] 2 points 8 months ago* (last edited 8 months ago) (1 children)

gamers aren’t usually a prime target, except for cryptominers…

Don't many gamers often have a lot of money, considering those huge libraries of games as well as those very expensive PCs, I feel like it would make sense to target them, at the very least for the possibility of commandeering and selling their accounts, plus the ones who download this malware by opting to play games with Anti-cheats and bullying their friends who are unwilling or on the fence into using it, it seems like they would be easy targets.

[–] [email protected] 2 points 8 months ago (1 children)

And then their account gets instantly blocked since they report that it was stolen immediately if they have a huge library and game all the time. Also, not many people buy full accounts, at best they buy an account with a game they want activated in Bumfuck Indiana because it's cheaper to buy there and can be sold for profit and still be cheaper than in some places in the world.

[–] [email protected] 0 points 8 months ago

all i know is that i know nothing

[–] [email protected] 8 points 8 months ago (1 children)

Honestly, most people who make cheats were also previously developers for anti-cheat software.

While I agree that anti-cheat software is spyware, server side moderation by humans would be incredibly costly on the company.

My vote is to just not have official servers for games anymore. Package the dedicated server files with every client and let the people playing the game host their own servers. Problem is solved twofold: server-sude moderation is now much more viable, and server hosting costs for the developers is eliminated.

[–] [email protected] -4 points 8 months ago (1 children)

While I agree that anti-cheat software is spyware, server side moderation by humans would be incredibly costly on the company.

It would also do a poor job at quickly responding to cheaters. Which is fine in some games, but in more competitive titles, the difference between a cheater getting caught in a round or two and a dozen or so is a big deal, with how many people had games effected.

My vote is to just not have official servers for games anymore

Nah, official servers are great for anything competitive, since they provide a single definitive competitive ladder and player base. Nobody gives a fuck about challenger rank 1 on Joe schmoe's home server where it's him and his buddies from school. Not to mention how difficult 8t would be to balance a game with next to no data to use.

[–] [email protected] -1 points 8 months ago (1 children)

Imagine being this balls deep in propaganda, like yeah and you're not cool unless you have an iPhone 15 and Gucci belt type vibes

[–] [email protected] -2 points 8 months ago

What the fuck are you smoking that enjoying a consistent competetivie environment is propaganda?

[–] [email protected] 19 points 8 months ago (1 children)

I dunno about non-driver anti-cheats like EAC but Genshin Impact's kernel-level anti-cheat has been used to aid ransomware. Driver-level anti-cheat is certainly malware, that has been settled since Sony-BMG.

[–] [email protected] 2 points 8 months ago

Sony-BMG.

Jeez that's a blast from the past. I remember the absolute shock and horror going around the internet when that story broke then it instantly being exploited by some clever dickhead for malware which I'm sure caused someone in Sony to have a cardiac arrest.

[–] [email protected] 69 points 8 months ago (1 children)

"We have investigated ourselves and have found we have done nothing wrong."

[–] [email protected] 10 points 8 months ago

That's exactly how i read that. It's so bizzare that they get kernel access to so many computers, and don't even do the thing that they are supposed to do.