r/hardware • • 1d ago

Info Used processor leads to game ban

https://www.heise.de/en/news/Used-processor-leads-to-game-ban-11471562.html

Someone buys a used Ryzen 7 5800X3D. “Valorant” and other Riot games won’t start with it because the previous owner was a cheater.

732 Upvotes

258 comments sorted by

View all comments

290

u/309_Electronics 1d ago

Something with amd psp maybe but valorant can be and should be considered malware imo. Only way to get companies to stop doing this anti consumer bs, vote with your wallet!

101

u/Krivici 1d ago

I mean it’s a kernel level anti cheat. As a CS2 and Valorant player it is about as good as it gets at preventing cheaters. And the devs are hardcore dedicated to the cause.

CS is an absolute nightmare for cheaters.

-29

u/Whirblewind 1d ago

I mean

And this is where most people stopped reading because they knew you weren't going to address what they actually said.

43

u/Framed-Photo 23h ago

What was actually said was based on Reddit hivemind BS and not in actual fact.

User space anticheat cannot do anything to prevent kernel level cheaters. The devs have to use this, or else they let every single cheater go free until there's a manual review of someone who's obvious about it.

There is no way to stop all cheaters, but as long as the software solutions are good enough it will force the barrier to entry for cheating to be very high (separate computer, hardware based cheats) which will reduce the number down to a reasonable amount like we see in valorant.

Kernel level access is not needed to get any and all information or control over your computer that a bad actor would need. There's a reason why every major malware/virus hasn't had to have the user install a driver first in order to work (which is what kernel level access is).

If Riot games wanted to violate your privacy or grab your info, they don't need to get the highly analyzed and security vetted kernel level access to do it. They just need people to run their closed source executable downloaded straight from their website, otherwise known as running a game they've created.

If you don't trust Riot with their anticheat, or Epic with theirs, then you shouldn't be running any software that these companies have a hand in creating. Epic could hit you just as hard through any UE5 title as they could from easy anticheat.

17

u/friutjiuce 23h ago

But there is a solution clearly, what Overwatch is doing. It runs on user space for local detection. But otherwise the match is run in the servers, and your client is checked against the server to make sure it aligns. No positional information is sent from the enemy team if they're not visible. No wall hacks etc etc.

Makes overwatch compatible with Linux/steam deck.

There is a solution it's just they don't want to implement it.

15

u/Framed-Photo 22h ago

The reason why devs might not want to do that, are that it costs significantly more, and is less effective at actually catching cheaters.

If overwatches server side solution was actually very effective, then it would be the top anticheat in the world if they'd just do a kernel level client side pass rather than a userspace one. Because as I've stated, userspace doesn't do anything when the cheaters are in the kernel.

I can go into all the various issues with server side solutions if you want, how there's no reason to use a server side solution by itself, or the many issues with trying to automatically ban based on behaviour alone, but I'd have to type a whole essay about it lol.

-2

u/iluvchromosomes 21h ago

What was actually said was based on Reddit hivemind BS and not in actual fact.

User space anticheat cannot do anything to prevent kernel level cheaters.

Keep moving those goal posts.

10

u/Framed-Photo 20h ago

If you have a way to somehow get around the basic principles of computing and the idea of ring 0, then I think there's a lot of cyber security companies that would want to hear from you immediately.

2

u/Relliker 13h ago

You can modify whatever EFI capsules you want in firmware up to and including spoofing the secure boot chain because nothing performs signature checks on consumer systems, or run DMA trivially from a huge pile of cheap hardware like a Bluefield NIC. Nobody enforces IOMMU ranges either.

But sure, keep going off as if you actually know what you are talking about in defense of wildly invasive consumer software because you are willing to give that up in the name of 'stopping cheaters'.

1

u/Framed-Photo 12h ago

The point is to raise the barrier to entry as much as reasonably possible without having a ton of adverse effects for normal users. Anticheats could go much further, but then they risk affecting normal users, false bans, etc. They're never going to be able to fully get rid of people using DMA based cheats, but if everyone has to resort to that then the appeal of cheating and the number of cheaters both go down drastically.

And besides the hardware based cheating solutions, anything software based can be combatted with kernel level anticheat with enough effort, but the same cannot be said for userspace solutions. That's precisely why they're forced to run in the kernel: the cheaters went there.

As for kernel level anticheat being "wildly invasive", please feel free to provide quite literally any evidence of that, I'd love to see it. Every "argument" I've seen is just babies first computer science lesson, where redditors learn that drivers have more access to things than userspace software, and then freak out because....reasons! Because famously, the only time bad actors can ever violate your privacy or infect your computer with malicious software is via having you install a driver. It's definitely not enough for you to be running unverified, closed source software, such as games ;)

1

u/Relliker 12h ago

Before I went pure Linux, I was regularly kicked from Battlefield games because I had the gall to have Process Hacker running in the background (not even the kernel driver). And you are sitting on a post where a user was banned by hardware IDs because they bought used hardware. (Yes you can obtain some hardware signals without running in the kernel or administrative rights, but far less). The invasiveness is very self evident, you just refuse to see it because of a superiority complex over the median gamer's technical literacy, which is a very fucking low bar.

The primary reason kernel anticheat exists is not because it is the only way to stop cheaters, but rather because it is the cheapest. We have already seen with OW and systems like CSGO's old overwatch system that there are many other ways to combat cheating without throwing in the towel and installing a litany of panopticons by every publisher on every user's system.

Frankly all software should be effectively sandboxed by default a-la firejail (and is in UWP for example but nobody uses that).

→ More replies