Discussion summary

Discussions around kernel anti-cheat highlight concerns about overreach, effectiveness, and privacy risks. Some argue kernel anti-cheats are unnecessary or risky, while others see them as effective for reducing cheating.

What the discussion says

  • Kernel anti-cheats may be overreach and can be replaced by user-mode solutions.
  • Effectiveness of kernel anti-cheats in stopping cheating is debated.
  • Concerns about privacy and malware risks with kernel-level access.
  • Some believe legal consequences are better than kernel anti-cheats.
  • Detection of subtle cheating behaviors remains difficult.
“Kernel anti-cheats can be done from user mode too.”
— charcircuit
“It has largely reduced cheating in competitive play.”
— AuthAuth

Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • I play a lot. Competitive shooters mostly. Most of them are unplayable for one or two reasons. Cross play (controllers with aim assist) and cheaters. As a PC player I would like to see no aim assist and actual consequences for cheating. I’ll gladly verify my real world identity, if it meant cheaters where banned once and forever. I’ve heard this is how it works in Korea (claim not verified) and could see it work here too as most of Europe has access to very UX friendly state sponsored digital ID.

    If there were actual stakes to cheating, it would be less prevalent. Now you can create another account and keep playing. Often for free!

    On a side note. How come replay analysis doesn’t catch more cheaters?

  • > During setup, I did a clean Windows 11 install

    > Unfortunately the install was legacy MBR

    > I was forced to convert the disk with mbr2gpt and spent about an hour manually rebuilding the boot drive to work under UEFI.

    I'm surprised Windows 11 even booted on MBR, I was under the impression that after 7 all Windows installs had to be GPT/EFI, regardless of whether secure boot was on or not.

  • I’m actually surprised how a lot of commenters here are defending kernel-level anticheat.
  • This article reminds me of Chesterton Fence - the author is complaining about something, without ever experiencing why it exists.
  • > Riot went as far as pushing a UEFI firmware update to Valorant players to close a hardware attack — the first time an anti-cheat has reached below the operating system to change your firmware

    I don't believe Vanguard did this at all? It told users they need to update their firmware to play, it didn't touch the firmware itself.

    > Cheats started in user space, so anti-cheat moved into the kernel to see them. Cheats followed into the kernel, and then below it into hypervisors

    I think cheats moved into kernel space before anti-cheats did.

  • Uninstalled riot years ago, not playing games that dont run on linux with proton, problem solved and you should do the same.

    Avoiding to play games that take over my system on a low-level is a no go, I can live without LoL or BF6 and I live even better :)

    ignoring this problems means you don't care about your identity, data, privacy and you prefer to keep ignoring this and play the games that hype abd you like, but inside you know that long term your are profiled and such profiling will be used against you!

  • > I want to preface this with the fact that I’m not a gamer.

    So you're prefacing it as someone who has never really dealt with the games you like to play getting totally infested with and nearly unplayable with so many cheaters in practically every lobby.

    Its easy to think its something that's not needed if one never spends any time in the space.

    Do they stop all cheats? No. Do they make the bar extensively higher to cheat? Absolutely. Even they point this out: "A DMA cheat is a separate FPGA card that sits in a PCIe slot and reads the game’s memory directly over the bus, while a second computer processes what it sees and feeds back aim and wallhacks..." Any random person can go run some executable they found on a forum, what percentage of the playerbase has these FPGA cards and a second computer to properly run these cheats? And even then, more modern systems can even detect these kinds of things.

    Are there lots of problems with these anti-cheat platforms? Sure. Are they now often developed with ties to countries many wouldn't want have that deep of access to their computers? Sure. Is kernel-level anti-cheat overall as a concept overreach? Probably not for what a lot of players actively want. Players want systems to ensure everyone is playing on a somewhat equal playing field. Other than the games being rendered in the cloud I don't know any other real way to begin to enforce it.

    > I would rather share a match with the occasional cheater

    What if it wasn't "the occasional cheater" and instead was "nearly every match of every game you like to play"?

  • > So I would rather share a match with the occasional cheater than run un-auditable ring-0 software on the same machine I use for anything private.

    The article makes an argument that anti-cheat is not worth the trade-off, yet the author admits they are a non-gamer. Then they go on to present one example of anti-cheat that tells us all we need to know about actual gamers' preferences—FACEIT. For those who don't know, FACEIT is a third-party matchmaking service, primarily for CS2. People choose to go through the hoops of using third-party service that installs kernel-level anti-cheat on their computer because it helps to keep cheaters out of their games. This seems like pretty strong evidence that the author's argument is not a good representation of gamers' thoughts on this. I don't know what the actual solution is. I suspect if Valve made their own kernel-level anti-cheat people might trust it more, but it's still the same problem.

Explore Birbla archives