Summary of “Anti Cheat at Embark Studios” prensentation by Embark Studios Senior Software Engineer Tom van Dijck, at devcom in Germany on August 24.

… Linux presents an even worse situation. Because users can custom-build the OS kernel, embedding a cheat directly into the kernel and compiling it makes it nearly impossible for a game to detect its existence. “How do you detect that?” van Dijck asked, adding that while support for SteamOS and Proton will remain, platform requirements will become stricter.

Though he mentions anti-cheat on Linux being more challenging to implement that on Windows, he doesn’t seem to think that it’s impossible. He goes on to talk about “undetectable” cheating hardware becoming cheaper, which sounds like a bigger problem, but he sounds optimistic about being able to detect those as well.

IMO “platform requirements will become stricter” could mean something like only allowing signed kernels with anti-cheat module built in + secure boot.

  • dillekant@slrpnk.net
    link
    fedilink
    English
    arrow-up
    3
    ·
    2 days ago

    Cheats today aren’t like the TF2 cheats some people imagine. The way modern cheats are described is “cannot distinguish from high level play”. To use a hardware cheat as an example, you have a mouse and capture card, and connect that to a raspberry pi, put some software on the pi, then make the pi imitate a USB mouse. Then, whenever aiming near a target, have the pi “lock on” to that target (the pi uses object detection to find targets). You can also make it more or less accurate to make it less detectable. In this example, it’s literally a mouse moving around. Doing something like confirming aim on the server side doesn’t help here.

    To explain a (hardware) wallhack, you can plug in a USB-C device into the PC. Now USB-C devices can also use thunderbolt, which is just PCIe, which means it has DMA access to the PC’s RAM, no OS required (the OS needs to permit the device but after “trusting” the device, the device can do whatever it wants). So, you do a similar trick. Capture card + DMA access to the PC RAM. The Pi finds the place where the game tracks objects, finds targets, and places a box around them (so you see the game from the capture card with the box over all targets, including behind walls). Now you might be saying “well the server shouldn’t send targets behind walls”, but even if the server doesn’t do that, it needs to send them a little bit before they’d be visible, and that’s enough of an edge.

    Kernel hacks are basically the same thing, but without the expense. You can see a target a fraction of a second before they’re visible, and the mouse can be told to move to the target. This is the same as high level play because people can often predict where someone is going to be, and are very, very good with tracking targets, so it just looks like a good player.