Hacker Newsnew | past | comments | ask | show | jobs | submit | not_a9's commentslogin

Anticheat has very different requirements to antimalware.

Some interesting reads on what modern anticheats do:

https://github.com/0avx/0avx.github.io/blob/main/article-3.m...

https://github.com/0avx/0avx.github.io/blob/main/article-5.m...

https://reversing.info/posts/guardedregions/

https://game-research.github.io/ (less in detail and less IDA pseudo)


Idle curiosity, but: does Linux have similar offerings to HVCI?


I don’t think Witcher 3 or Cyberpunk 2077 have Linux builds available for the common folk? Cyberpunk has a ARM64 Mac build, though.


Huh, I could have sworn Witcher 3 did, but maybe I am misremembering it merely releasing without DRM.


Witcher 2 had a Linux native build, but never Witcher 3.


> We all know they are inefficient and weaponized by hackers.

Name an exploit in EAC/BattlEye/Vanguard/FaceIT/whatever other big name anticheat middleware (though Vanguard and FaceIT don’t sell their services I think) that has actually been used for anything.

Genshin Impact’s driver got used as a vulnerable driver that one time, yeah. EAC had an exploit to inject your own code into processes, but that quickly got patched (https://blog.back.engineering/10/08/2021/).


ESEA's anticheat was used to mine Bitcoin on the players' computers. They are/were a major competitor of FaceIt. They supposedly had to pay a $1 million settlement over it.

So not an exploit, but even worse.


Well, I read HN. I did stop counting.

Unless you beleive in the conspiracy of AI generated news on HN.

You are the same type of guys who is going to try to sell 'computer security' as a deliverable, thing which does not exist.

Please, stop that.


> because Epic has chosen not to support Linux

Because Epic doesn’t want payhack configs to be advertised in whatever leaderboards Fortnite has, like CS2 had for a while.


Fortnite is easy to run in a hypervisor and also cheaters are using hardware DMA to cheat these days anyway. The proposition that Linux enables more cheating relative to Windows is unproven.


Fun fact: LuaJIT FFI actually has a similar feature. You can do funky things like detour hooking with this functionality too.

https://luajit.org/ext_ffi_semantics.html


Pretty sure HvH is still alive and well in CS2 and high rank Premier is still basically Valve-hosted HvH.


(I had to make a HN account to reply to this, but…) If only Riot, Epic, BE, whoever else knew about this wondrous approach! That way they wouldn’t have to reverse half the Windows kernel to figure out ways to stop & detect hacks.

Valve (mostly) does serverside analytics for CS2 and the success of their approach can be measured by one of FaceIT’s benefits being “we have a working anticheat”.

On a sidenote, I highly recommend this presentation on anticheat stuff: https://game-research.github.io/presentations/2025-08-06-bhu...


Always fun to read the "why don't they just..." Comments like it's an easily solved problem.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: