‪@PirateSoftware‬

Поділитися
Вставка
  • Опубліковано 5 вер 2024
  • Riot Vanguard and kernal level anticheat
    If you have more question go ask ‪@PirateSoftware‬ on his stream
    / piratesoftware
    Thor if you read this and you want this to be taken down plzz say so in the comments or send me a message on discord.

КОМЕНТАРІ • 129

  • @meropticon_1651
    @meropticon_1651 Місяць тому +114

    The recent crowdstrike disaster is a perfect example of what happens when you let 3d party programs into your kernel. Riot deserves to go bankrupt.

    • @iris.87
      @iris.87 Місяць тому

      are you stupid on purpose? or does it just come naturally to you?

    • @iris.87
      @iris.87 Місяць тому +1

      not really true at all, its simply because cloudstrike doesnt like waiting for microsoft on proper signing

    • @meropticon_1651
      @meropticon_1651 Місяць тому +15

      ​@@iris.87 You are seriously STILL defending this shit. What makes you think that a company that thinks it's ok to charge 200 dollars for a skin cares about proper signing? Vanguard has bricked PC's, that's all the proof one should need to not trust that crap.

    • @iris.87
      @iris.87 Місяць тому

      ​@@meropticon_1651 i could care less about defending riot, i just hate when people yap about things that aren't true (e.g. vanguard bricking pcs)

    • @vasatruhl
      @vasatruhl Місяць тому

      Crowdstrike just had a corrupted file lol it has nothing to do with kernel anti cheats

  • @gs7326
    @gs7326 Місяць тому +25

    1:20 in.. ASSEMBLY?

    • @MatVeiQaaa
      @MatVeiQaaa 13 днів тому +8

      Assembly is not that scary, for hacks smeared across the code caves it would be good enough, there likely won’t be too complicated high level code. Likely the hacks themselves would originally be written in assembly, as it’s what you do with codecaves. Human written assembly instead of that generated by a compiler is even easier to comprehend.

  • @nzeu725
    @nzeu725 Місяць тому +82

    Kernel level is basically do whatever the fuck you want

    • @iris.87
      @iris.87 Місяць тому +1

      nope

    • @MessiahFromR6
      @MessiahFromR6 Місяць тому

      And i am totally fine with it

    • @nzeu725
      @nzeu725 Місяць тому +2

      ​@@iris.87 well yes, it's at the level of the kernel

    • @iris.87
      @iris.87 Місяць тому

      @@nzeu725 please explain how usermode access differs from kernel mode access in terms of a security concern, and please dont say legality as said in the video (hes wrong)

    • @nzeu725
      @nzeu725 Місяць тому +3

      @@iris.87 User mode is in the most outer ring of the operating system, meaning that it has the least permissions. The kernel mode access however is in the most inner ring, the same as the kernel. That way it dosen't need permission to do things so whereas a normal anticheat would need to get permission to do something a kernel mode access anticheat can do it without asking and without anyone knowing. It can also tweak with the system like the kernel can.

  • @azim2714
    @azim2714 25 днів тому +19

    The only good thing out of this is that I can laugh at every new exploit someone finds against Vanguard and laugh at the people who were defending this garbage back then.

  • @TheFlyingSailorYT
    @TheFlyingSailorYT 6 днів тому +3

    And note, Tencent owns Riot, and Tencent's products routinely report back to the CCP. That is why they're so anxious to get into your kernel, because maybe someone has something useful on their rig.

    • @helix8462
      @helix8462 3 години тому

      Very true, also every other product we use like youtube Instagram Facebook reports back to the cia
      Why don't people focus on this more? It bothers me a lot.

  • @zoladkow
    @zoladkow Місяць тому +14

    Carnal anticheat would be even better 🙃

    • @lipca
      @lipca Місяць тому

  • @azazel-oss
    @azazel-oss 2 дні тому

    going to jail just because I had no clothes on is kinda harsh but I understand the sentiments

  • @namegoeshere197
    @namegoeshere197 Місяць тому +2

    3:04 what about DMA? can none kernal anticheats detect that?

    • @iris.87
      @iris.87 Місяць тому +1

      easily detectable in its current state, dma is awful on eac (not eos), vgk, faecit, esea etc

    • @AruthaRBXL
      @AruthaRBXL Місяць тому +2

      from what I know of, DMA can be detected usually in very simple ways. EAC and faceit tend to check the serial numbers of pci-e cards to determine if its a legitimate card or a DMA device. EAC or faceit (cant remember which) will take the extra step and try to call certain functions on the PCI-E card to see what data it returns, so if it calls for the same function the most common DMA device uses and returns data from memory then it is a definite DMA device and will know you're cheating. This is a good way to get around people who spoof the serial of the device to make it seem if it is a nvidia gpu etc.

    • @fortender97x
      @fortender97x Місяць тому

      A DMA card is basically a PCIe expansion card that you plug into your PC. So it's recognized by the system as an additional piece of hardware that can be observed as such. To remain undetected you need to spoof several info such as the hardware id and "look like some legit hardware" such as a network card. Obviously, if a lot of those DMA cheaters flashed the same config onto their DMA card, chances are high that anti-cheat devs find a pattern in the data they captured. If i recall correctly, that's what riot did when they banned a lot of them. They found out that they all spoofed a specific network card.

    • @iris.87
      @iris.87 Місяць тому

      @@fortender97x ye that was prlly the ekknod fw, but atp most of the fw is invalid anyway

    • @crashniels
      @crashniels Місяць тому +1

      ​@@AruthaRBXL so it's detecting the dma device and not the dma itself?

  • @scattermc
    @scattermc Місяць тому +21

    Gaming aint that serious, human anti-cheat better than any anti-cheat. Prove me wrong.

    • @livvydoodlez
      @livvydoodlez Місяць тому

      it would be but the "solution" (im against it honestly), is that kernel level anti-cheats make it so much easier to stop the script kiddies who don't know really how to make scripts, but just simply know how to run them from being able to just do that. It'd be so much easier to have an anti-cheat that stops that from happening than it would to manually review the case, so that's often why it's being done.
      Still horrible, still not a solution, but it does put a huge dent in the cheater population

    • @breeban3388
      @breeban3388 Місяць тому +2

      Tell that to players who are playing at the highest level, for money. It might not matter to us normies, but having a reliable way to detect cheaters is definitely a necessity

    • @egoalter1276
      @egoalter1276 20 днів тому

      It is not a relyable way to detect cheaters.
      And in settings where there is money at stake the compuiters in use are heavily monitored, so the whole issue of not having control over clientside data becomes irrelevant.

    • @TheManOfTheHourEveryHour
      @TheManOfTheHourEveryHour 15 днів тому

      You need both. You need machine learning based algorithmic anti-cheat to flag things in real time, with edge cases and appeals then being handled by people. It's not cost effective to have swarms of people watching live gameplay, unfortunately, companies go the opposite direction and gut their entire anti cheat teams after setting up an alpha state anti cheat tech stack, make sure it has kernal level access to they can accumulate more granular data than they need, and flip that data on the back end to advertisers for an additional stream of income, on top of the cut wages.

    • @Mark-vr7pt
      @Mark-vr7pt 13 днів тому

      ​@breeban3388 actually the opposite, paid matched done on private servers not in public lobbies, so they are not affected. And if someone decided to cheat they can easily be caught because they being monitored very closely by organizers (apex situation is a shitshow and outlier).
      Rampant cheating in public lobbies on the other hands kill games. Because no matter how good top 100 players are, if there no people playing the game it's dead.

  • @ender7966
    @ender7966 5 днів тому

    kernel*

  • @RengarLover123
    @RengarLover123 12 днів тому

    the amount of bs is crazy league is a competitive game where most of the scripter where in master+ (crazy right?) wow has had botters, cheaters and duppers in a way bigger amount and blizzard did nothing about one company cares the other one doesnt

    • @iris.87
      @iris.87 6 днів тому

      ye fr its crazy how much people cry about rampant cheaters in cs2 and other usermode anticheat games then bitch when big scary kernel driver is present

  • @cxa24
    @cxa24 2 дні тому

    I am kernel level anticheat =/

    • @djsuperpanda1
      @djsuperpanda1  2 дні тому +1

      I don't think you want to be kernel level anticheat alot of people will hate you then.

  • @anthrosaurian
    @anthrosaurian 25 днів тому +4

    2:14
    ...except that isn't true in an awful lot of places now...
    They demand entry, you say no, they call for backup, cause a massive scene, gain entry other than the front door, ransack your house, find no evidence of a crime, leave, and suddenly your phone, laptop, and various other personal belongings are gone, and since you had no way of recording them doing it, there is no evidence the police took anything.

  • @gus2603
    @gus2603 Місяць тому +3

    My sides 🤣🤣 *kernal*

    • @XeZrunner
      @XeZrunner Місяць тому +2

      I see it being mistyped like this so often, it leads me to believe many think that's what the actual word is.

  • @MacVerick
    @MacVerick 13 днів тому

    I don’t like it but I don’t like cheaters more so I don’t even know what to think

    • @brianviktor8212
      @brianviktor8212 11 днів тому

      Well, are you willing to sell your soul and shake the devil's hand, just to reduce the chance of cheaters? It's not even 100% efficient btw, cheaters can get around that. It just increases the barrier of entry, and once it is breached (which they frequently do), they distribute new programs (or whatever) to cheat.
      The alternative is a simple cheating-reporting system and server-side detection of cheating. This is what I am going to do as well for my game. The server will check every ~10th data package incoming (otherwise it would be too much) (for example the player's position) and when it detects something weird (too much distance in too short of time), it will increase the suspicion level of that player and check more frequently (or all packages). After all it could have been some mistake, but to be sure it needs to detect that behavior multiple times. Someone who cheats once will cheat multiple times.
      And it doesn't require any invasive client-side programs, and I don't need to play arms race with cheaters on a highly complex kernel level. All it takes are some smart algorithms.

    • @fltfathin
      @fltfathin 9 днів тому +1

      My solution is play the game where you don't need to fight with cheaters.

  • @iris.87
    @iris.87 Місяць тому +7

    tough watch

    • @hd-bild1513
      @hd-bild1513 Місяць тому +3

      why? Did you not like his explanation or do you like Kernel level anticheat? /gen

    • @iris.87
      @iris.87 Місяць тому

      ​@@hd-bild1513 explanation is garbage and 0 logical thought. he argues that usermode is safer because its "against the law" to access user files, and that kernel mode access allows anticheats to just randomly upload files to their servers for analysis legally. dumbest thing ive heard in a while, this is NOT how vanguard works nor ANY km anticheat outside of China (ive heard ACE can just randomly upload files to their servers for analysis). idc about kernel mode anticheat, and i dont think its the perfect, ideal solution, but this is just fear mongering for no reason

    • @hd-bild1513
      @hd-bild1513 Місяць тому

      ​@@iris.87 @iris.87 its not super illogical to not not trust a list of corporations to not peek at your data, especially when you explicitly allow them to (aka its not illegal to take a screenshot of your PC if you explicitly install a kernel level program, Right?). I mean look at google. Also the uploading screenshots thing seems like it's real to me. And riot is owned by a Chinese company and, not to hate on China, but they do have a rep for peaking where they shouldn't.

    • @meropticon_1651
      @meropticon_1651 Місяць тому

      @@iris.87 Look up crowdstrike and be proven wrong by reality.

    • @KingMuttley
      @KingMuttley Місяць тому +11

      @@iris.87 riot bot

  • @ritzcar6567
    @ritzcar6567 Місяць тому +3

    ngl cod need this type of anti cheat

    • @TracerBH
      @TracerBH Місяць тому +31

      nothing needs this type of anti cheat

    • @iris.87
      @iris.87 Місяць тому

      already has it, ricochet is just a terrible anticheat that was recentishly developed

    • @raviexthegod
      @raviexthegod Місяць тому

      in truth, NOTHING needs Kernel Level Access to your computer other than the Operating System and the Antivirus measure shipped with it (Meaning like Windows Defender, not any pre-built OEM contract programs). Any other program that wants Kernel Level access is something that isn't needed, and is a huge privacy concern especially in our capitalist society that loves to get your information in any way possible and sell it to the highest bidder. A kernel level anticheat may be more efficient at its job in some scenarios due to it's capability to access all memory on the machine, but at least in my opinion, that added efficiency is nowhere near worth the privacy violations that can legally occur since you're willingly giving them kernel level access to do whatever they please on your machine. This also means that if, somehow, that kernel level software, which has been given permissions, gets highjacked by malware, it can now do whatever the hell it wants, and your antivirus will most likely never detect that it's there.
      Edit: Fixed a wording oversight when referring to installed antivirus programs, I originally said any installed antivirus, which is definitely not the right call, especially with Pre-Builts being shipped with bloat like Norton or McAfee. Thanks to @iris.87 for pointing that out.

    • @iris.87
      @iris.87 Місяць тому

      ​@@raviexthegod quick reminder that usermode antiviruses have literally sold ur data in the past, not really sure why you think antiviruses are safe, or that you need kernel mode access to find & sell said data..

    • @raviexthegod
      @raviexthegod Місяць тому +1

      @@iris.87 not saying that you need kernel level access to find data, what I'm, saying is that, similar to Thor's analogy in the video, would you rather the cop have to get a warrant to come in, i.e. find a way to scrape data, or just give the cop verbal consent to rummage around as they please, i.e. kernel level access. And with the antivirus I was referring to Windows Defender, which, while part of the OS and it does ship with it, it's a separate program in and of itself that integrates deeply with the OS. I simply worded it wrong, re-reading my original comment.

  • @wolverine8238
    @wolverine8238 День тому

    Give a solution or don’t complain

  • @monadoboy9639
    @monadoboy9639 2 місяці тому +3

    i think this is interesting kernel level access does suck but if it results in better league games and less cheaters its probably a good thing overall

    • @hanz.b_
      @hanz.b_ 2 місяці тому +36

      not for me. no more league on linux:(

    • @monadoboy9639
      @monadoboy9639 2 місяці тому +3

      @@hanz.b_ lmao well I guess it's time to switch to Windows then like every other normal person

    • @le1senmaybe
      @le1senmaybe 2 місяці тому +1

      @@hanz.b_ Hi, i really suggest trying dual boot, i really like TFT (i don't play much league) and so after vanguard happened i couldn't play for a long time. Then i switched from NixOS to dual booting ubuntu and windows 10! It's really easy if you have the memory for it, around 300-200GB for windows will be more than enough. You can make the partitions yourself, and more importantly you can play most games on ubuntu now with drivers actually being updated and patched to linux kernel 😂.

    • @chuck948
      @chuck948 Місяць тому +38

      @@monadoboy9639 you are not a person

    • @Murukku47
      @Murukku47 Місяць тому +23

      it can also lead to massive data breaches if a vulnerability from a kernel level anticheat is ever discovered by malicious actors (who will try to because it'd be a giant prize to black hat hackers) so you better hope that any kernel level anticheat you put on your machine is coded with absolute iron security AND that no novel ways to exploit it are ever discovered.