Easy Anti-Cheat: We have investigated recent reports of a potential RCE issue within EAC. At this time - we are confident that there is no RCE vulnerability within EAC being exploited. - eviltoast

    • BruceTwarzen@kbin.social
      link
      fedilink
      arrow-up
      11
      arrow-down
      1
      ·
      8 months ago

      That’s exactly how i read that. It’s so bizzare that they get kernel access to so many computers, and don’t even do the thing that they are supposed to do.

  • TootSweet@lemmy.world
    link
    fedilink
    English
    arrow-up
    69
    arrow-down
    2
    ·
    8 months ago

    It’s really disturbing how popular the notion that rootkit-based anti-cheat is a good thing is on the internet at large.

    I love it when a thread like this comes up on Lemmy every single comment condemns EAC’s whole anti-cheat model.

    Y’all are all right.

    • Live Your Lives@lemmy.world
      link
      fedilink
      English
      arrow-up
      18
      arrow-down
      2
      ·
      8 months ago

      While I am sceptical of rootkit based anti-cheat as well, I am also not a fan of how quickly everyone has jumped to assuming this is EAC’s problem and not a problem with Apex Legends, is there some solid evidence for that that I’m just unaware of?

    • Aux@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      6
      ·
      8 months ago

      Kernel level and root kit are two different things. Please don’t confuse them.

  • Davel23@fedia.io
    link
    fedilink
    arrow-up
    21
    arrow-down
    1
    ·
    8 months ago

    Says the company that took three years to implement a shopping cart for their shitty store.

  • MyNamesNotRobert@lemmynsfw.com
    link
    fedilink
    English
    arrow-up
    19
    arrow-down
    1
    ·
    edit-2
    8 months ago

    If I was a hacker, I would be spending most of my effort attacking anticheats. Installing spyware on people’s computer to prevent cheating is wrong. They should be doing what devs did before anticheat was invented - server side moderation.

      • khannie@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        8 months ago

        Sony-BMG.

        Jeez that’s a blast from the past. I remember the absolute shock and horror going around the internet when that story broke then it instantly being exploited by some clever dickhead for malware which I’m sure caused someone in Sony to have a cardiac arrest.

    • RightHandOfIkaros@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      8 months ago

      Honestly, most people who make cheats were also previously developers for anti-cheat software.

      While I agree that anti-cheat software is spyware, server side moderation by humans would be incredibly costly on the company.

      My vote is to just not have official servers for games anymore. Package the dedicated server files with every client and let the people playing the game host their own servers. Problem is solved twofold: server-sude moderation is now much more viable, and server hosting costs for the developers is eliminated.

      • MomoTimeToDie@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        7
        ·
        8 months ago

        While I agree that anti-cheat software is spyware, server side moderation by humans would be incredibly costly on the company.

        It would also do a poor job at quickly responding to cheaters. Which is fine in some games, but in more competitive titles, the difference between a cheater getting caught in a round or two and a dozen or so is a big deal, with how many people had games effected.

        My vote is to just not have official servers for games anymore

        Nah, official servers are great for anything competitive, since they provide a single definitive competitive ladder and player base. Nobody gives a fuck about challenger rank 1 on Joe schmoe’s home server where it’s him and his buddies from school. Not to mention how difficult 8t would be to balance a game with next to no data to use.

        • Sethayy@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          2
          ·
          8 months ago

          Imagine being this balls deep in propaganda, like yeah and you’re not cool unless you have an iPhone 15 and Gucci belt type vibes

    • xor@infosec.pub
      link
      fedilink
      English
      arrow-up
      6
      ·
      8 months ago

      gamers aren’t usually a prime target, except for cryptominers…

      an anticheat based cryptominer worm would be pretty terrible, now that i think about it…

      • Draconic NEO@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        8 months ago

        gamers aren’t usually a prime target, except for cryptominers…

        Don’t many gamers often have a lot of money, considering those huge libraries of games as well as those very expensive PCs, I feel like it would make sense to target them, at the very least for the possibility of commandeering and selling their accounts, plus the ones who download this malware by opting to play games with Anti-cheats and bullying their friends who are unwilling or on the fence into using it, it seems like they would be easy targets.

        • Maalus@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          8 months ago

          And then their account gets instantly blocked since they report that it was stolen immediately if they have a huge library and game all the time. Also, not many people buy full accounts, at best they buy an account with a game they want activated in Bumfuck Indiana because it’s cheaper to buy there and can be sold for profit and still be cheaper than in some places in the world.

    • Aux@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      8 months ago

      If you were an actual hacker you’d be targeting web sites and Linux servers. Because that allows you to spread your payloads across huge populations easily.

    • khannie@lemmy.world
      link
      fedilink
      English
      arrow-up
      17
      ·
      8 months ago

      Their wording is actually quite deliberate. They say there isn’t one being exploited, but they do not explicitly say that there isn’t a RCE vulnerability.

      It kinda stinks of ass coverage.

      “I did not have sexual relations with that woman”

      • Maalus@lemmy.world
        link
        fedilink
        English
        arrow-up
        7
        ·
        8 months ago

        It stinks of lawyers checking the press release. They can’t say “there is none” in the offchance that someone, sometime finds one. Then clients could point to this press release saying “SEE, YOU TOLD US THERE WAS NONE AND 25 YEARS LATER WE FOUND ONE”. I bet they are telling the truth, just ran through a lawyer and PR team.

      • CrypticCoffee@lemmy.ml
        link
        fedilink
        English
        arrow-up
        4
        ·
        8 months ago

        Yeah, it stood out to me.

        It’s always in what they don’t say.

        If they say it’s not a RCE vulnerability, it could still be a privilege escalation vulnerability etc. They avoided saying their software isn’t being exploited or “we have seen no evidence our software has been compromised”, or “there is no clear signs…”.

        Which gives a little wriggle room.

  • ShaunaTheDead@fedia.io
    link
    fedilink
    arrow-up
    8
    arrow-down
    1
    ·
    8 months ago

    I don’t know much about anti-cheat development, but it can’t possibly be that hard to at least implement something that checks whether a player even could have done something in a certain amount of time which would eliminate a lot of speed related cheats, and for the rest, why not look at data averages to try to weed out cheaters?

    I know combing through the data is probably complicated, but so is installing kernel level anti cheat software that has to monitor every single process running on a person’s computer.

    • Maalus@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      8 months ago

      Not how it works, and it is a huge science behind it all. First of all, you don’t want false positives. People would ruin your game for it. The reviews would be awful and it would breed more cheaters (angry at a game that banned you for no reason? Make it ban you for a reason, ruining people’s fun in the process and costing them money). Second, most of what you are talking about is already done on server side. Third, the concept of banwaves is a thing. You want to catch as many cheaters at once with a single detected cheat. If you ban someone at first sight, the cheatmaker will refund that first person and think up something worse immediately. If you ban 30k people, all of them flock to the cheatmaker asking for refunds. Which he can’t obviously provide, since they already spent that money over the course of the time the cheat was active, etc. Fourth, lots of cheats are subtle enough to be “invisible” to any sort of detection. Guy has an overlay that shows people through walls. You can’t ban overlays and the client needs to know where people are on the server, it just hides them. All you can see is what a human would see - a guy looking at people through walls, but trying to hide it. A guy with “incredible gamesense” basing their tactics on info he couldn’t have gotten. A moderator that knows what to look for would see it. An admin that abuses power and bans everyone that’s too highly skilled would also ban the cheater. But try writing anything that checks for the “averages” and you ban actually good players that use sound, etc. Same thing with aimbot - it’s very obvious to someone looking at gameplay. But going off of statistics you ban everyone who “has a good day”.

      The way to do it, was how Valve handled it in CSGO. No idea if the system is still in. They basically tasked their community with being the judge and executioner. They would send you a replay in client, showing you 10 mins of the match. Sometimes they would send you a replay that they already know has a blatant cheater in it, to test if you actually say “ban” if you see one. They scored the judges, valuing better ones more and providing feedback saying “your case has banned a cheater”. It was a slow process, but effective, or at least it would be if the game wasn’t so incredibly popular and free. Obviously a live moderator would help a lot, but it’s the next best thing.