Soooo, you’re telling me, that if I want to use a NVIDIA graphics card in Linux, I am not allowed to load its official driver's kernel modules unless I either deactivate secure boot or generate my own signing key and load it into the UEFI, as otherwise this would make the kernel untrusted. But on windows every $random_game_publisher is allowed to run at kernel level without it being considered untrusted?
post
Games dont belong in the kernel. Shit should have stayed in userspace. No, I dont care how many billions are on the line, games are not that important.
Isn't Microsoft about to block kernel modules like this entirely? I thought I read that somewhere
Yeah, to stop another CrowdStrike, but it's not a sure thing, yet there's talk of api's etc and wouldn't surprise me if certain companies got a pass. An article covering your point: https://www.theverge.com/news/692637/microsoft-windows-kernel-antivirus-changes
Nope. They’re developing an alternative set of APIs for userspace in conjunction with security vendors for their products to use but it’s all still a long way off and will be optional to start with.
Given the volume of mission-critical devices security products are installed on (which the CrowdStrike fuckup highlighted), getting them out of kernel space would be a huge risk reduction for the world. And security vendors would love to get away from that risk as pulling a CrowdStrike costs a lot of money setting things right with customers.
But an anticheat used by consumers on their personal devices for a game, not such a big deal.
While I’m sure MS will eventually deprecate and then kill off third party kernel drivers, it could take a decade since MS has so much business (both internal and within their customer base) that relies on legacy crap.
Yep, they're planning to create a new way to do it, not disable the old way.
And I think that a decade for disabling the old way is optimistic
I have a feeling you’re right about this. I do wish Microsoft would take the Apple approach as Apple steamed ahead with deprecating kernel-mode access.
Love them or hate them, Apple take security a lot more seriously than Microsoft these days and it’s a real shame MS see security architecture as a nuisance rather than a core responsibility of their business.
it’s a real shame MS see security architecture as a nuisance rather than a core responsibility of their business.
I'm pretty sure the reason behind this is that they treat backwards compatibility as a higher priority in a lot of cases. There are so many odd choices I see in my day to day that I can only explain away by backwards compatibility. It's part of the reason you see them take forever to depreciate old and insecure protocols until they get an encouragement from a vuln hitting the news.
Ahahahaha. 😂 That is just brilliant. The kernel anti-cheat deadlock.
These anti-cheats don't even work. Anyone can go out and buy a hardware DMA card with an FPGA on it, which is basically a modern day Action Replay. It has full access to RAM without touching the OS and cheaters like to use them to get around anti-cheat.
furiously scribbles notes
Very interesting…
I feel I would rather just opt out of playing these games. It ain't worth it.
I feel like they should just host the entire game and stream it to players if they want to eliminate cheating, but that's probably the most anti-SKG way to publish a game possible. Oh well.
Does anti-cheat even work?
kernel or no
Proof is in cheaters existing on day one of battlefield 6 open beta. Client side anti-cheat will never work. It's good to have some basic preventative measures client-side, but server-side anti cheat is the only way to properly prevent cheaters.
Unfortunately companies keep investing in garbage client side anticheat that just pokes security holes into our machines.
Only Valve to my knowledge is investing money into their server side anti cheat, no other big player is to my knowledge.
It needs to be a mix. Have your clientside anti-cheat look for obvious attack vectors, have your serverside anti-cheat look for suspicious play, and let users report others. Then have humans review suspected cheaters and make the final call.
But that's expensive, and off-the-shelf anti-cheat gives them someone else to blame.
Client side anti-cheat (the one installed on your PC) will never work, it's just fundamentally impossible. They can restrict user freedom as much as they want, but the hardware still isn't under their control.
The only reason they push for those kinds of anti-cheats is because they don't have to pay for the extra processing of server side anti-cheat, and they also get the benefit of a backdoor into your computer that you may never fully uninstall without buying a new computer.
It boggles my mind so many people give a shit about these awful franchises. Surely there is something else to play
Sure. And when your entire friend group starts playing one of them, you can either join in, or see if you can wait out their interest.
Or did you think everyone games in a bubble?
Arasaka vs Militech humble beginnings
Its*. This word is an exception to the rule of using an apostrophe to indicate possession. It's is always a contraction for "it is".
My son wanted to play the Battlefield open beta over the weekend. It legitimately took me 4 hours to get their shitty kernel anti-cheat shit working. I can't imagine the average non-technical person being able to do that just to play a game.
You could also just not play games that think they are allowed to access the kernel at all. Seems safer, more affordable, and basically without downside. They aren't even that good of games.
As someone who will likely need to move to Linux after windows 10 goes dark can anybody ELI5 or maybe a little older, TIA
This is windows, So Valorant is running its anticheat stopping Battlefields anti-cheat from starting up. Meaning you will have to pick one game as they all seem to start from boot though other sources have said the games have to be running.
In Linux you could prob just run a pass-through in a couple of VMs. But Linux itself doesn't work with most of these anti-cheats so by default no one running Linux is exposed to this sort of thing.
This is pretty crazy it has gotten to this point.
top 50 comments