How Hackers Bypass Kernel Anti Cheat

แชร์
ฝัง
  • เผยแพร่เมื่อ 17 ก.ค. 2024
  • Check out 365Games! win.365games.net/Ryscu
    How Hackers Bypass Kernel Level Anti Cheat
    Support the channel: / ryscu
    For as long as video games have existed, people trying to break those video games for their own benefit have come along with them.
    Running at the deepest level of your system, kernel-level anti-cheat has been hailed as the most effective way of stopping cheaters.
    So how are they still breaking through?
    Chapters:
    0:00 External cheating
    3:40 Injection
    4:10 Into The Kernel
    5:05 The danger begins
    9:01 Vanguard and friends
    10:01 Vulnerable drivers
    14:03 Direct memory access
  • บันเทิง

ความคิดเห็น • 2.3K

  • @Ryscu
    @Ryscu  10 วันที่ผ่านมา +166

    Check out 365Games here! ✅
    win.365games.net/Ryscu

    • @zengd8017
      @zengd8017 10 วันที่ผ่านมา +2

      You should talk about DMA's next

    • @OiIMan
      @OiIMan 9 วันที่ผ่านมา +16

      Erm, don't wanna

    • @teknixstuff
      @teknixstuff 9 วันที่ผ่านมา +7

      Stop with the sponsorblock bypasses!

    • @MacGuffin1
      @MacGuffin1 9 วันที่ผ่านมา

      Kernel AC is a complete waste of time (almost)PCs can never be fixed or patched(HW/FW Ppl wake the fuck up), if ur not playing on Xbox with crossplay off every SINGLE game you play will be 30-80% cheaters, it's just facts, has been this way for a long time and the whole NVIDIA #PCMASTERACE has sold everyone a lie and ruined the actual fun of gaming. Now there will be no safe-space, if you want an awesome video idea (no one is talking about.. idk why) but Microsoft/Activision are forcing people to play crossplay-on because they make more money from the higher account/microtransaction turn-over from the very occasional ban waves... The Xbox console is a work of art and purpose built around this exact problem: Locked Bootloader/Signed Code with actual real Kernel and Memory isolation.. For the first time in 12 or so years a kernel sploit was 'found' exactly the same time I started making a lot of noise about this (this exploit can never lead to cheating online, as the xbox engineers are the best in the world and everything has overlapping security) Playstation isn't too bad either, but they tend to do their patching by HW/SKU, one of the reasons they employ planned obsolescence...

    • @malzaharbeasttheone
      @malzaharbeasttheone 9 วันที่ผ่านมา +2

      Loved this

  • @alterranlongbow5067
    @alterranlongbow5067 10 วันที่ผ่านมา +4519

    "do you trust the developer of the game you're playing?"
    the entire league community: no but its not gonna stop us

    • @maciejmalewicz9123
      @maciejmalewicz9123 10 วันที่ผ่านมา +139

      the genral consensus is that people have your data anyways + your data is not important and not worth the risk for them

    • @Willow1w
      @Willow1w 10 วันที่ผ่านมา +213

      video game addiction is very sad

    • @supershid464
      @supershid464 10 วันที่ผ่านมา

      @@maciejmalewicz9123 it's not the data though, it's an anticheat that runs 24/7 through which anyone malicious can get literally everything. One vulnerability and it's over

    • @magicalnoodles
      @magicalnoodles 10 วันที่ผ่านมา +305

      Idk about others, but I did stop playing. People really undervalue how much data they generate, and how much can be gained from it. A better solution for Riot would have been to only require the anti-cheat in platnum+ lobbies. Cuz realistically, ppl below this LP score aren't gonna be able to get far with cheating anyway. Even if they climb to plat and above, the cheat gets detected, and that's that.
      By forcing all LoL players to intall kernel level chinese spyware, it's really hard to earn the trust of the playerbase.

    • @meerpirat3418
      @meerpirat3418 10 วันที่ผ่านมา +224

      it stopped me. I will not install Chinese Kernel Level spyware.
      And tbh League is not worth it.
      the fun thing is on mac you don't have to deal with that Vanguard BS.

  • @Rivalrvn
    @Rivalrvn 10 วันที่ผ่านมา +3801

    Bros videos are an artform now

    • @oussemabentaher2983
      @oussemabentaher2983 10 วันที่ผ่านมา +33

      Learn from bro

    • @tudorique24
      @tudorique24 10 วันที่ผ่านมา +8

      your videos are high quality aswell

    • @Yobamos
      @Yobamos 10 วันที่ผ่านมา +29

      You two aren’t fooling anyone we know you’re the same person

    • @dashyz3293
      @dashyz3293 10 วันที่ผ่านมา +3

      you 2 are different people?

    • @egg-mv7ef
      @egg-mv7ef 9 วันที่ผ่านมา +6

      glazing someone for divulging basic ass information with 1337 super hacker videoclips in the background is crazy

  • @morosov4595
    @morosov4595 9 วันที่ผ่านมา +557

    DMA users have been caught only because they all used the same driver for their DMA cards. In order to hide the DMA card, it pretends to be a network card, but Vanguard just banned every user that used that one network card. Those who used different drivers (not many) for their DMA didn't get banned.
    Edit: Yes that means legit users of that network card did get banned. But when was the last time Riot cared.

    • @meneldal
      @meneldal 8 วันที่ผ่านมา +76

      Yeah as long as you do the spoofing right there's no way they can ban you. And there are still so many ways to spoof stuff.
      Also I can't believe they can't just not send all the info that DMA exploits use in the first place, you'd remove so much cheating with that. Why send the enemy position data in the first place?
      Also, I'm surprised there aren't some fun tricks where you MITM your own connection to get the packets on another computer and analyse that.

    • @morosov4595
      @morosov4595 8 วันที่ผ่านมา +54

      ​@@meneldal They already do not send the data they don't need.
      League only sends the data about champions that are close to the edge fog of war. They can't do the same with Valorant, as there is no fog of war in that game. And if they tried to calculate what does a player see for 10 players per match, the servers would explode.

    • @nerd_nato564
      @nerd_nato564 8 วันที่ผ่านมา

      ​@@morosov4595Why not just use a system similar to Source's rooms? Draw a line between two players, and if they're not in view just don't send the data. It can't be that expensive in terms of performance.

    • @KeinNiemand
      @KeinNiemand 8 วันที่ผ่านมา +20

      what if somone used that network card legitamtley as a network card

    • @Resetium
      @Resetium 8 วันที่ผ่านมา +30

      ​@@meneldalHonestly if you can MITM yourself with a second computer in order to cheat, you really should get yourself some six figure job working network security at that point. Your skills will be put to better use.

  • @Alcaline-hu2vu
    @Alcaline-hu2vu 9 วันที่ผ่านมา +96

    Allat just for most games to still be full of hackers
    Vanguard classifies people trying to play on Linux as hackers more often than it does actual hackers, basically because Linux doesn't just let people start writing shit to the kernel because that's stupid
    Also, having Vanguard boot up on startup, you know that kinda sounds like a virus

    • @Coconut-219
      @Coconut-219 7 วันที่ผ่านมา +17

      It's like the same hell-worthy development sin as every single phone application which magically decides to not work if you don't allow it to access microphone and GPS at all times for no reason.

    • @jfbeam
      @jfbeam 5 วันที่ผ่านมา

      Actually, it's pretty trivial to mess with kernel memory in linux. There are ways to be 100% invisible, too.

    • @user-hw8wr7bg2i
      @user-hw8wr7bg2i 4 วันที่ผ่านมา +6

      I mean League really barely has any scripters left and Valorant also has barely any cheaters
      Vanguard classifies 'Linux players' as cheaters because they are actively bypassing the anti-cheat requirements to play the game, they don't allow for League or Valorant to be played on Linux because they can't attest to the sanity of the OS it's on
      This video is full of misinformation but at *least* the part where he explains how Vanguard needs to be an UEFI RT Driver to sanitize the entire OS and it's APIs is correct

    • @SteveSunny
      @SteveSunny 4 วันที่ผ่านมา

      @@user-hw8wr7bg2i You're probably one of the few people who actually knows what they're talking about int his entire comments section lol. Do you think the vanguard outrage over overdrawn?

    • @user-hw8wr7bg2i
      @user-hw8wr7bg2i 4 วันที่ผ่านมา +3

      @@SteveSunny Eh I think a tiny portion of the outrage is warranted, Riot isn't known to ship the best software out there and I completely understand the stability concerns
      Privacy wise though, they have to abide by US/EU laws, while it doesn't completely prevent them from breaking them there's a risk/benefit ratio here so bad for them that's it's not even close to being worth it
      Also all the 'omg but it's a security risk!!!' stuff is blatantly wrong, if anything vgk.sys is the most heavily protected driver on your machine, and you probably have anywhere between 80 to like 300 WDF/KMDF running on your system at all time so like...
      On the other hand, people have been complaining so much about scripts/botted accounts, and realistically going kernel is the only long-term solution to these problems

  • @PopeMical
    @PopeMical 10 วันที่ผ่านมา +2527

    You know normally I hate kernal level anti-cheat, but maybe I should thank Vanguard for making me quit my 8 year league addiction...

    • @BoredCoat
      @BoredCoat 10 วันที่ผ่านมา +162

      This right there. Literally me

    • @asdfbeau
      @asdfbeau 10 วันที่ผ่านมา +62

      kernel-level ac is everywhere now- you're going to have a hard time playing anything.

    • @popopapi
      @popopapi 10 วันที่ผ่านมา +54

      so true lmao vanguard coming to league finally pushed me to quit

    • @PopeMical
      @PopeMical 9 วันที่ผ่านมา +159

      @@asdfbeau While partially true, it actually has been relatively easy for me to completely avoid it with the type of games I specifically enjoy.
      Also it's a minor difference but I do dislike Vanguard a lot more for requiring boot on startup and not just game launch. That small annoyance will likely keep me away from League specifically even if I do end up installing a game with say current EasyAntiCheat.

    • @CrunkNuts
      @CrunkNuts 9 วันที่ผ่านมา

      ​@@PopeMicalit has to be run at start up to load before user level stuff. You can't have a kernel level anticheat that starts when you open the game.

  • @rekscoper
    @rekscoper 10 วันที่ผ่านมา +1203

    Honestly with how many more people make cheats vs employees making anticheat, i dont think it will ever be possible to make an uninvasive anticheat that has no workaround, one of my favourite bits of real life lore was when ubisoft (i think it was them at least) put new anti piracy measures in and the guy who cracked it left a note file in his pirated version of the game saying something like "good job with all those months of development, it made my team take about 7 minutes longer to pirate"
    Cheaters will always find a way, no matter what

    • @TKDMwastaken
      @TKDMwastaken 10 วันที่ผ่านมา +150

      only way is hardware lockdown. Standardised hardware like consoles. But then consoles will be a target. beacuse with freedom of PC comes freedom of executing whatever code we want. if they start detecting DMA there will be DMA boards mascarding as GPUs or other normal PCI-E devices. nothing you can do about short of total hardware lockdown (with 100% patched devices so if something is exploited then EVERYONE needs to update). But ppl will start soldering wires and running linux on it as soon as they can like ppl do with everything.
      Only thing that can prevent that would be Streaming like Stadia.

    • @rekscoper
      @rekscoper 10 วันที่ผ่านมา +99

      @@TKDMwastaken like i said, there can never be an unbeatable anticheat that is unintrusive. People will always inevitably find a weakness or exploit, unless you can somehow stop them from even starting up a cheat or having basic freedoms on their system and its hardware

    • @mityab20
      @mityab20 10 วันที่ผ่านมา +35

      @@rekscoper honestly anti cheats aren’t meant to be uninvasive not like they could. Cybersecurity is an eternal cat and mouse game where one side always try’s to outsmart the other if that makes sense. In my opinion (while I hate kernel level anti cheats) vanguard is essentially the perfect anticheat, it has made cheating such a massive pain the ass that 99.99% wouldn’t bother. Yes there are 100% ways to get around it but I think cheats that use pci-e cards were like the last frontier where it wasn’t insanely difficult to setup. While I never messed around with vanguard so I’m not super sure what exactly it does I would assume now that they can detect hardware level cheats you probably need highly specialized hardware to get around it. While spoofing something like a pci-e card is definitely possible to hide what it’s truly doing or what it really is to do it on the hardware level is no easy task. Anyway I rambled on for too long I just wanna say that while it’s not uninvasive the cheats that could bypass it would either require you to have a deep understanding of how computers function to do it yourself or require you to pay a whole lotta money to somebody who does because I doubt it can be as easily mass spread as normal pci-e hacks.

    • @laersonverissimo1715
      @laersonverissimo1715 10 วันที่ผ่านมา +11

      There’s an easy solution: Confidential computing.
      Using stuff like SGX from Intel CPUs to make data impossible to read from unauthorized applications.

    • @LegioXXI
      @LegioXXI 10 วันที่ผ่านมา +60

      @@TKDMwastaken "only way is hardware lockdown. "
      This already exists, it's called "Mac".
      Hardware cheating is also a thing where a camera or HDMI-grabber gets the visual information and moves the mouse (or controller) mechanically. While it's not as effective as software cheats and limited to specific game genres where reflexes matter, it's basically undetectable and completely independent from the gaming hardware and software. PC, Mac, console - nothing matters. Even game-streaming can't prevent that since all this cheat system needs is the visual information, which is what you also need as a legitimate player.
      If a cheater has enough money to buy stuff like that, he will always get the upper hand.
      No matter how much spyware the game devs force onto their clients.

  • @MrAntiKnowledge
    @MrAntiKnowledge 9 วันที่ผ่านมา +288

    Honestly I repect the bravery of people who played League for more than a couple games and decided
    that's the company they trust to not (intentionally or unintentionally) fuck up their system with Kernel level software.

    • @FunctionallyLiteratePerson
      @FunctionallyLiteratePerson 8 วันที่ผ่านมา +25

      Most dont know/understand, and the rest are more apathetic than brave

    • @venkaramon
      @venkaramon 8 วันที่ผ่านมา +4

      Vanguard has been on Valorant for years. How many systems has it fucked up there?

    • @ivan19119
      @ivan19119 8 วันที่ผ่านมา +21

      @@venkaramon quite a few some stopped working and others had massive preformance issues after installing it

    • @w花b
      @w花b 8 วันที่ผ่านมา +7

      ​@@FunctionallyLiteratePerson you're right. I've met a lot of league players and they're either insane (like constantly on caffeine) or apathetic.

    • @yGKeKe
      @yGKeKe 7 วันที่ผ่านมา +10

      Brother, people have been playing games with kernel level software for over two decades. No one bitched about VAC or EAC. Most people don't complain about nGuard or any of the other plethora of kernel level anti-cheats from various Chinese companies. It's cringe AF that people suddenly care about kernel anti-cheats more than 20 years later.

  • @shanematthews1985
    @shanematthews1985 9 วันที่ผ่านมา +531

    Do i trust riot games with a kernel level driver?
    Having seen the shitshow that is the league client for 13 seasons, the shitshow that is the league API and the general decline in QA quality since they laid off a bunch of staff, the answer is
    Fuck No
    This was the straw that broke the camels back and what drove me away from league, been league free since vanguard was added and i don't regret that decision for even a second

    • @JordaanM
      @JordaanM 9 วันที่ผ่านมา +18

      I'm in the same boat. I ended up installing and Android App player for Windows so I could play TFT with friends again, but I'm gonna be miffed if Vanguard is required for 2XKO as well.

    • @rainchopper898
      @rainchopper898 9 วันที่ผ่านมา +7

      dota 2 is good if u want a replacement
      and ur data is safe w/ volvo

    • @shanematthews1985
      @shanematthews1985 9 วันที่ผ่านมา +7

      @@JordaanM Oh its almost a guarantee that it will use it, its safe to assume that any of their online games going forward will probably use it

    • @tommyfanzfloppydisk
      @tommyfanzfloppydisk 9 วันที่ผ่านมา

      same here, maybe i'll come back to league once i got enough money to buy a pc merely for that and other games. they'll get their own special house.

    • @JordaanM
      @JordaanM 9 วันที่ผ่านมา +1

      @@tommyfanzfloppydisk I've considered doing that as well, just having my 8 year old PC as a dedicated Rito box.
      Good thing league runs on a toaster.

  • @vert2048
    @vert2048 10 วันที่ผ่านมา +1477

    Dude I didn't expect a whole documentary, this is sick

    • @shedblood1645
      @shedblood1645 10 วันที่ผ่านมา +3

      He has alot of them, why wouldn’t it be?

    • @vert2048
      @vert2048 9 วันที่ผ่านมา +8

      @@shedblood1645 Huh, good point. I hadn't realized but I haven't watched/been recommended a Ryscu video in over 6 months when he did shorter videos.
      Glad to know I have several more high-quality videos like this to go back to :)

    • @Margen67
      @Margen67 8 วันที่ผ่านมา

      birb

    • @Twisted_Code
      @Twisted_Code 7 วันที่ผ่านมา +1

      TBH the fact that all of TH-cam isn't quality Edutainment like this disappoints me. I really like learning things, and doing so in 20 minute intervals is quite convenient. Fortunately, TH-cam algorithm (for all its flaws, including some that make it feel a bit like a miniature Vanguard due to loss of privacy) makes it pretty easy to find more of what I'm genuinely interested in. It's hard to hate the algorithm if it works, even if I hate how it works.

    • @SioxerNikita
      @SioxerNikita 7 วันที่ผ่านมา +1

      This is not a "whole documentary", it is a video essay. A "whole documentary" would be about the whole 1½ hours....
      It is frankly in-depth enough to be called a documentary though, but doesn't have the length... otherwise you could call any few minutes long video talking about a subject a "documentary".

  • @Sin1234Nombre
    @Sin1234Nombre 10 วันที่ผ่านมา +824

    For the last question: no, I don't trust Riot and Tencent with my information

    • @Stabidistabstab_PBP
      @Stabidistabstab_PBP 10 วันที่ผ่านมา +83

      -25, you will be missed

    • @yourunclejoe9500
      @yourunclejoe9500 10 วันที่ผ่านมา +138

      that wasnt very 冰淇淋 of you

    • @tabletennisstars1227
      @tabletennisstars1227 10 วันที่ผ่านมา +8

      tencent is sad rn bye

    • @soupofdoom4542
      @soupofdoom4542 9 วันที่ผ่านมา

      @@yourunclejoe9500 bing chilling

    • @Element_Doom
      @Element_Doom 9 วันที่ผ่านมา +65

      -600.000 social credit 🇨🇳

  • @hiiver436
    @hiiver436 7 วันที่ผ่านมา +12

    I've stopped playing league after implementing vanguard (linux user) and holy shit, my life got better from that point. I will never return to league

  • @atlas_carry
    @atlas_carry 9 วันที่ผ่านมา +63

    Side note on vanguard, riot recently added "in-game detection" where it pops up a message in game that says "CHEATER DETECTED", but they didn't actually implement any server-side detection for cheaters as they would have you think, all they've done is made it so that once your account is banned, if the account is in game at the time of banning it will terminate the match, and these bans are always delay bans from the first game injection being detected, but riot likes to let scripters play 10-20 games per account before ban to "obfuscate" the detection, but they will actively let someone script in your games and then pop up a "CHEATER DETECTED" message as if they've just discovered it to make you feel like theyve done something new

    • @deagle2yadome696
      @deagle2yadome696 9 วันที่ผ่านมา +1

      they’re one of the only games that hwid bans on first offense what more do you legits want?

    • @atlas_carry
      @atlas_carry 9 วันที่ผ่านมา

      @@deagle2yadome696 their hwid bans are shit any spoofer avoids them

    • @dakota9821
      @dakota9821 8 วันที่ผ่านมา

      @@deagle2yadome696 HWID bans are garbage; It's extremely easy to spoof.

    • @Cheato
      @Cheato 8 วันที่ผ่านมา

      @@deagle2yadome696 easily bypassable

    • @nerd_nato564
      @nerd_nato564 8 วันที่ผ่านมา +31

      Letting cheaters play for a while after they've been detected is good. It's why you do banwaves instead of banning immediately, so whenever developers try to figure out why they were caught, they get as few clues as possible.

  • @SleepyFen
    @SleepyFen 10 วันที่ผ่านมา +332

    A correction for 2:40 - the cheat shown with Flash having zero cooldown was possible not because of cheating software, but because runes and masteries used to be saved locally on your PC, allowing people to open those files with a text editor and sink 30 mastery points into summoner spell cooldown reduction. This exploit was fixed by moving runes and masteries to be stored server-side.

    • @MaakaSakuranbo
      @MaakaSakuranbo 9 วันที่ผ่านมา +49

      And this is why the argument of "Devs neeeeeed anticheat!!!" is dumb. Server-side verification and such will catch a lot of things. They just want to save on server costs though, since it owuld be expensive to avoid wallhacks (i.e. you'd have to only send player positions the player can see, so you'd have to check for that on the server)

    • @SleepyFen
      @SleepyFen 9 วันที่ผ่านมา +18

      @@MaakaSakuranbo anticheat is still necessary for a lot of reasons, but I'm just pointing out some misrepresentation.

    • @thechugg4372
      @thechugg4372 8 วันที่ผ่านมา +10

      @@MaakaSakuranbo the more shit you put server side the harder the game to preserve (or modify for the community)

    • @MaakaSakuranbo
      @MaakaSakuranbo 8 วันที่ผ่านมา +4

      ​@@thechugg4372 Okay?
      Strange line of argument really, since it's not like it's "easy" exactly even with games that don't do that.
      If you don't have the server software anyway (for preservation), then you need to write some. So if you don't want client anticheat that doesnt' get updated anymore and is basically useless anyway, you'd need serverside checks or your own anticheat to begin with.
      If you have the software, I don't see the issue.
      And removing anticheat from the client in case you want to go that route instead also has its challenges depending on how the game implements it

    • @illuminoeye_gaming
      @illuminoeye_gaming 8 วันที่ผ่านมา +2

      @@MaakaSakuranbo and aimbot?

  • @Hylofear
    @Hylofear 10 วันที่ผ่านมา +762

    Hearing the compilation of cheater screams was music to my ears

    • @PiFsc2
      @PiFsc2 10 วันที่ผ่านมา +8

      Timestamp? :D

    • @dhimitrinano2276
      @dhimitrinano2276 10 วันที่ผ่านมา +20

      @@PiFsc2 17:20

    • @ascend2046
      @ascend2046 10 วันที่ผ่านมา +24

      bro sounded like shaco

    • @johanestebanramirezbarrios1411
      @johanestebanramirezbarrios1411 10 วันที่ผ่านมา +2

      @@PiFsc2 17:10

    • @asdf0747
      @asdf0747 10 วันที่ผ่านมา +28

      lmao it's just one person who recorded it. The fact is that majority of the population hates privacy violation and probably quit. Those who stayed are helpless addicts who can't get off the game. also, the cheat developers probably adapted quickly, probably figured out vanguard's code from valorant, which makes the release on LOL even more unjustified.

  • @mrgummage
    @mrgummage 9 วันที่ผ่านมา +16

    The cheater crying about his DMA ban was beautiful.

    • @pocuu
      @pocuu 4 วันที่ผ่านมา +1

      that was an arduino colorbot not a dma lol

    • @SigmaMusic007
      @SigmaMusic007 9 ชั่วโมงที่ผ่านมา

      Dma isnt cheating its just a bit of advantage, i dont cheat but i dont mind dma players, because its just radar on other monitor

    • @nin1ten1do
      @nin1ten1do 4 ชั่วโมงที่ผ่านมา

      if i want cheating on screen with OFFLINE TOOL i juist TRite MY ABIULITY range and AA range oon folia overlay on my screenn.. ez and care free.-.- for sure shot i make it 5%smaller.. enjoy.. never get catch XD

  • @LMD100797
    @LMD100797 9 วันที่ผ่านมา +7

    Bro, the animation, the sound effect usage, to the utilization of abrupt breaks and silence is phenomenal.
    Just want to let you know your editing earned you a sub, I will try my best to learn about video planning and editing from your videos from now on, and your content is really cool too!

  • @matthewdavis3421
    @matthewdavis3421 10 วันที่ผ่านมา +386

    The question of balancing user privacy with game integrity is one that developers are simply going to ignore, forever, until large enough percentages of their games' player base collectively boycott the game. As it is, this question won't even appear on their radar of concerns.

    • @jost76x2
      @jost76x2 10 วันที่ผ่านมา +3

      I personally don’t care at all about privacy on my computer as long as the reason I risk it is working but as of right now vanguard cannot efficiently detected dma cards that are sighted I think the only way to lose cheater completely is using a ai anticheat that can scan for unnatural movement and keep a data base of you play style as an alternative to hwid band.

    • @johanestebanramirezbarrios1411
      @johanestebanramirezbarrios1411 10 วันที่ผ่านมา +2

      they are not ignoring that, because we have rights that they cant ignore, and they still always fixing problems with vanguard

    • @user-uv6qu3wb5d
      @user-uv6qu3wb5d 9 วันที่ผ่านมา +25

      ​@@jost76x2 it literally does detect dma cards... It's even in this video

    • @jost76x2
      @jost76x2 9 วันที่ผ่านมา

      @@user-uv6qu3wb5d it detects normals dma card I’m a bit more deep in cheating what cheaters nowadays do is sign custom firmware to there dma cards so vanguard thinks it’s a real device and there is nothing really vanguard can do about this accept making a list of the firmwares but that’s hard bc cheaters are just buying 1/1 firmwares and staying fully undetected

    • @soundspark
      @soundspark 9 วันที่ผ่านมา

      @@user-uv6qu3wb5d Doesn't a DMA card have to enumerate itself into the system to even work?

  • @itchylol742
    @itchylol742 10 วันที่ผ่านมา +354

    the endgame for cheaters is having a robot with a camera pointed at the monitor and using mechanical hands to press buttons on the keyboard and move the mouse around, and the endgame for anti cheat is either AI that just bans people for looking sus, or having thousands of human moderators review replays and ban people for looking sus

    • @qlx-i
      @qlx-i 10 วันที่ผ่านมา +90

      The problem being, the best cheat is essentially indistinguishable from a good player. And the error margin is much wider than the cheat accuracy.
      This nicely flows into philosophy. Being optimized is the direct opposite of being random. It is being predictable. It means the lack of character. And we already saw that. We saw a chess GM pre-moving the entire game and auto-mating another GM.
      There are few perfectly good plays. There are few perfectly bad plays. And there are much more random plays that average somewhere in-between. A player that trained a near-perfect aim is not much different from a neural network sitting on a PC doing the same. And a trained neural network is no different to a written algorithm. Being good means to sacrifice personality and the lack of personality makes to entities indistinguishable.

    • @user-qq4dh3rk3u
      @user-qq4dh3rk3u 9 วันที่ผ่านมา +8

      ​@@qlx-i If a neural network always does the best move in each scenarios (or what it thinks is the best move) then it may be possible to detect. For example, it might rush A first all the time on Ascent or buy the same guns. With enough of these events tracked by Riot they could use probability to detect people using neural networks. Of course you could add some variability into the input to make the output more variable, but this would also decrease the strength because it will no longer be doing the "best" move. Maybe a manual algorithm to move from the start and then a neural network takes over in order to mitigate these predictable events?

    • @konstantinsotov6251
      @konstantinsotov6251 9 วันที่ผ่านมา +10

      being able to almost always choose the best move is basically a definition of skill. And AIs are random, they are not like chess bots that have deterministic algorithm to follow, their approximation of "good"ness of a move is dependant on random factor, thus they will be making mistakes to some extent, like humans. Maybe not mistakes, but at least not taking the best move is very possible

    • @lainverse
      @lainverse 9 วันที่ผ่านมา +6

      I heard there's already server-side AI-based anti-cheat in development (no idea is it actively used anywhere) based solely on behavior detection. So, yes, it literally detects sus players. We are at this stage already or will be quite soon. Furthermore, it learns from your previous inputs, so it should be able to detect when you start using a cheat since behavior will change noticeably enough.
      So, next phase are cheats that learn from your inputs and start gradually add on top of them over time, I guess. So, they won't even do anything for a while... and the cheater may legitimately learn to play the game in the process. XD

    • @rico4.700
      @rico4.700 9 วันที่ผ่านมา +6

      "having thousands of human moderators review replays and ban people for looking sus" valve overwatch in a nutshell lol

  • @chohsena627
    @chohsena627 9 วันที่ผ่านมา +3

    This was insanely interesting to watch and well edited as well. I enjoy these docu-series/deep dives.

  • @MistyStarStrike
    @MistyStarStrike 9 วันที่ผ่านมา +3

    Really enjoying these video essay-styled videos, man. They're always such a damn good watch

  • @_Dearex_
    @_Dearex_ 10 วันที่ผ่านมา +29

    Only Addition I have to make: definetly not that good as memory access, but you can feed the Video singal to an external device and do Image recongition to implement aimbot/Auto trigger.
    At this point it is more like statistical analysis if you are cheating

    • @Mano-us7ct
      @Mano-us7ct 10 วันที่ผ่านมา +7

      Yes, that is true, and there is no reason to add any kernel level anti cheat, just monitor what players do in game, and use some ml algorithm to predict.
      But in modern days your main source of profit is usually data gathering.

    • @cewla3348
      @cewla3348 9 วันที่ผ่านมา

      @@Mano-us7ct if a game has demos, then almost everything but ESP can be detected very quickly with ml - if they're making insane, frame perfect flicks every shot, then that's silentaim. if their aim is completely locked onto someone's center of mass, then that's aimbot.

    • @LiEnby
      @LiEnby 9 วันที่ผ่านมา

      @@cewla3348 dropped packets: "lol get banned scrub"

    • @ougonce
      @ougonce 9 วันที่ผ่านมา +4

      @@cewla3348 What makes you think ML can’t be used to mimic human inputs to an undetectable, or at least plausible, degree?

    • @itsTyrion
      @itsTyrion 8 วันที่ผ่านมา

      @@Mano-us7ct ...you could gather all inputs, screen content, browser data, personal files, audio (in/out) with just the game or a user level anticheat service. you do not need Ring 0 for a lot of data grabbing on Windows.

  • @chaficchamchoum1469
    @chaficchamchoum1469 10 วันที่ผ่านมา +276

    You know when a creator cares about his viewers. This is one example.
    Loved it

  • @FOGoticus
    @FOGoticus 9 วันที่ผ่านมา +3

    That kid almost crying when he got banned live in valorant had me smiling ear to ear.

  • @zurubusu
    @zurubusu 9 วันที่ผ่านมา +2

    Ryscu's quality of videos/ the editing is through the roof. That was one big jump in your content mate, awesome job! :)

  • @RocoPwnage
    @RocoPwnage 10 วันที่ผ่านมา +588

    Anticheat was never about making cheating literally impossible, just enough of a pain in the ass that most people won't bother, and those who do can be caught manually.

    • @crashniels
      @crashniels 10 วันที่ผ่านมา +105

      Yeah it just deters the "casual" cheaters. Professionals still have their ways

    • @user-tq3cn9ct2e
      @user-tq3cn9ct2e 10 วันที่ผ่านมา +48

      ​@@crashniels thats why a good game would have anti cheat and moderators i think. Not everything can be automated.

    • @pineappleenjoyer9297
      @pineappleenjoyer9297 10 วันที่ผ่านมา

      Its frightening how naive you non IT people are.
      You‘re literally downloading a rootkit that can spy on you without you ever having the slightest knowledge. Just wait till a RCE is found, gl.

    • @GdBearman
      @GdBearman 10 วันที่ผ่านมา +36

      And in the end, nothing happens to the cheater, they just move a level and the regular consumer suffers the consequences. I'd make this shit illegal.

    • @mikeybayne7985
      @mikeybayne7985 10 วันที่ผ่านมา +42

      @@GdBearman my man... Less cheaters is good last time I checked...

  • @lukapogo
    @lukapogo 7 วันที่ผ่านมา +3

    “Ring 0 is the most privileged level of your system”
    Chris Domas has entered the chat

  • @KEROVSKI_
    @KEROVSKI_ 7 วันที่ผ่านมา +2

    Great video man, editing, story and the video/audio quality.

  • @4bSix86f61
    @4bSix86f61 10 วันที่ผ่านมา +116

    I will not play any game with obligatory spyware.

    • @MaoRatto
      @MaoRatto 8 วันที่ผ่านมา +4

      This is why I don't blame any or much F2P games.

    • @MrAdeelAH
      @MrAdeelAH 7 วันที่ผ่านมา +7

      If valve copies this shit I officially quit cs2... The future of this stuff is probably AI. Anyone else remember that one server side ai anticheat demo that was like it's ai can detect any aimbot? What happened with that

    • @w1z4rd9
      @w1z4rd9 6 วันที่ผ่านมา +6

      You already do. It’s called your computer.

    • @4bSix86f61
      @4bSix86f61 6 วันที่ผ่านมา +1

      @@w1z4rd9 Debloated windows

    • @motiv8462
      @motiv8462 5 วันที่ผ่านมา +1

      So 90% of any new game along with your pc and phonei hope you follow what you say and throw your phone pc delete all your accounts and live in a mountain

  • @eleven5707
    @eleven5707 10 วันที่ผ่านมา +14

    DAMN, this longer video format is awesome, and the editing is amazing, keep it up!

  • @themagicalex
    @themagicalex 9 วันที่ผ่านมา

    Great video man. Graphics were very well put together and the whole arc was well written and planned out.

  • @ArushYadlapati
    @ArushYadlapati 9 วันที่ผ่านมา

    Dude this is actually insane!! Keep up the insane work, I can tell that you put a lot of effort into this!

  • @MyReXaR
    @MyReXaR 10 วันที่ผ่านมา +19

    I never knew you or your Group could do such an Amazing Edit. gotta say, nice editing Touch.

  • @grcatm
    @grcatm 10 วันที่ผ่านมา +15

    I was just yesterday watching many videos like this one (hacking cia, cicada 3307, etc...) which I gained some proper interest in, and I stumbled upon your Vanguard video, and wondered "Wait, what happened to the guy that was in my recommended all the time?". Glad to have this mashup! I really like this video's style, keep it up

  • @Mesazane
    @Mesazane 9 วันที่ผ่านมา +2

    Holy, the video is magnificent!
    Hope your video blows up soon!

  • @lainverse
    @lainverse 9 วันที่ผ่านมา +8

    Another method I heard about is to run cheat completely "offline", solely based on screen data to control the inputs. No special cards attached, no memory access, nothing. Cheats like this are really limited since what it can see on screen is all it has to work with, but still provide some advantage. As I know, the only way to detect such cheats is scanning for presence of inhuman reaction and impossibly smooth motions in input. As in, behavioral detection.

    • @meyers0781
      @meyers0781 6 วันที่ผ่านมา +3

      that would be a trigger for false positive.
      With virtualization and increasingly powerful system, i have an idea...
      game creates virtual machine for the session (like a virtual PC where the only app is the game and the supporting components), what happen in the game stay in the game, no cheating
      this will have another side effect of the game being playable on Linux (theoretically).

    • @fujinshu
      @fujinshu 6 วันที่ผ่านมา

      @@meyers0781 Yes, but much like kernel-level anticheats, there will always be a vulnerability waiting to be exploited, even when in a VM.
      It also reduces game performance, which isn't a big deal until you consider that many esports games are mostly run on lower-end hardware, which contributes to its mass-market appeal and popularity, and making the game run worse or even barring older PCs from playing because of virtualisation requirements may decrease the overall market share of the game. Just look at the number of Windows 11 users compared to Windows 10 due to TPM 2.0 requirements.

    • @sun3k
      @sun3k 6 วันที่ผ่านมา

      ​@@meyers0781if the player can do it legit, they can do it with cheats

    • @vablo-yt
      @vablo-yt 5 วันที่ผ่านมา

      How do they stop the Virtual Machines program memory from being manipulated? Hackers are very crafty and could easily manipulate the VM imo

    • @nirantali
      @nirantali 5 วันที่ผ่านมา

      The Next Level then gonna be additional mandatory Livecams in your Room that livestream (The Gamer, Screen, Keyboard, Mouse, back+front+sides and the inside of your PC and the rest of your room) while you play online. And during competitive sessions, there must always be two notarized observers to the left and right of the player. Anyone who has nothing to hide will certainly allow this, right? And anyone who doesn't allow it is automatically suspicious and probably a cheater.

  • @RamenEnjoyer404
    @RamenEnjoyer404 10 วันที่ผ่านมา +18

    clean editing, tight script, and about an issue that is incredible important. Good job!

  • @FreedomRoseStein
    @FreedomRoseStein 10 วันที่ผ่านมา +97

    You know what's crazy. I clicked the video finished the video and then went, Wait hang on, THIS IS RYSCU? THE LEAGUE GUY? 💥Blown away mate, Excellent video

  • @carllion
    @carllion 9 วันที่ผ่านมา +1

    a little late but love the editing on this! great job Ryscu!

  • @SuperNuketown2025
    @SuperNuketown2025 9 วันที่ผ่านมา +31

    Tbh, a combo of hardware and kernel modules is probably the way to go in terms of cheating in basically 100% of games. DMA, rerouting input through a second PC instead of an arduino, and writing a custom driver to neuter anti-cheats would probably make it practically impossible for any anti-cheat to do literally anything about it. How’s riot gonna scan your PCIe port if it doesn’t know it exists because you hide it from its view during boot up?

    • @dahahaka
      @dahahaka 8 วันที่ผ่านมา +8

      Not only that, you can literally have dual firmware on one of those DMA devices and "act" as a real PCIe device during bootup for all Vanguard knows it's just a network card :D

    • @jhax
      @jhax 7 วันที่ผ่านมา +2

      They can still detect other factors such as this "custom driver", the way you map your driver, injected keyboard/mouse input, even the way the cheating software itself works e.g. attempting to override rotation. For DMA, you will need to emulate legitimate PCIe devices 1:1 as well as have valid drivers for them, otherwise the device will be blocked and no long able to send TLP packets for reading/writing. It's a constant cat & mouse game, and if you get banned, RIP your HWID. Time to fork out more money for a new motherboard, or TPM chip, finding a spoofer that actually works. But then maybe that spoofer eventually gets detected too.

    • @dahahaka
      @dahahaka 7 วันที่ผ่านมา

      @@jhax there is no unspoofable HWID, and "emulating" is relative, what I meant by emulating is you can literally just run the NIC firmware and they can't discern it from a normal NIC

    • @jhax
      @jhax 7 วันที่ผ่านมา

      @@dahahaka 99% of temp spoofers on the market are not working rn for Valorant. Only a couple of perma spoof methods that work reliably. Most people have to buy a new mobo or TPM chip, this is being realistic not pretending like everyone is some 999 IQ user who can bypass VGKs AC on their own. I currently have a ZDMA with firmware emulating as an Intel network card and with valid drivers, doing so is only enough for EAC/BE. It is still blocked on VGK. It requires more work than just copying the config space of another device.

    • @kugelblitz1557
      @kugelblitz1557 7 วันที่ผ่านมา +4

      The security risk of allowing kernel access isn't worth it for a game. There are very few ways to fix a malware attack from the kernel level short of formatting your drive and restoring it from a backup. You can write a program to be injected and be stored on a separate partition that boots first in the bios and essentially sits between the hardware and OS while hiding its partition from the system after the next reboot. That can log any input or output that goes to the OS that it wants, and send it to whoever you want. Without kernel level access, managing drive partitions without permission is hard. The only way you'd ever notice that is if you opened bios and checked your boot order. No antivirus is going to detect that your whole OS is running in a virtual environment with hardware inputs just being duplicated from the bare metal.

  • @CB-ls2xn
    @CB-ls2xn 10 วันที่ผ่านมา +13

    I don’t know if anyone else has this issue but my computer is always crashing to the blue screen of death but simply restarting moments later. After testing my entire computer to find some broken or corrupted parts i found nothing. After seeing other people having different types of issues with vanguard, I Later found out that is was Riots Vanguard Anti cheat that was causing my random crashing and simply uninstall it, I no longer has any more random crashes

    • @johanestebanramirezbarrios1411
      @johanestebanramirezbarrios1411 10 วันที่ผ่านมา +1

      windows 11 right?

    • @ViciousVinnyD
      @ViciousVinnyD 8 วันที่ผ่านมา +5

      Vanguard is likely causing your pc to crash. It's running at kernel-level priority, meaning this program *must* run and if it doesn't, windows shuts down immediately to prevent issues and starts over, aka a bluescreen.
      By installing vanguard you're effectively relying on it to not crash because if it does, so does your pc.
      If any of this sounds absurd it's because it really is. Kernel-level priority is meant exclusively for running critical tasks such as, you know, windows. Running anything else on this level is risky and should only be done if absolutely necessary. Running anti-cheat software for a video game at this level is both unstable and insecure.

    • @Waskomsause
      @Waskomsause 8 วันที่ผ่านมา

      @@johanestebanramirezbarrios1411 The same issue happens to a lot of Win 10 and win 11 PCs with Helldivers 2 and their anticheat, NProtect. The issue isn't the OS, it's legit a fault in the anticheat that detects windows drivers as cheat software. NProtect killed some VERY important sys32 programs for some people, or bricked their SSDs because it stopped the read/write software on the SSD itself. Shit is terrible, and Vanguard, while not as bad, likely STILL screws this up sometimes.

    • @lucasLSD
      @lucasLSD 8 วันที่ผ่านมา

      @@ViciousVinnyD Remember that we are only here, because the cheaters did this with software made by hackers just to win at some game.

  • @wigmanmania259
    @wigmanmania259 10 วันที่ผ่านมา +27

    I mean, that's cool and all, but how do I stop my mid from AFKing after feeding first blood?

    • @tyfyh622
      @tyfyh622 10 วันที่ผ่านมา +1

      lol

    • @tom_from_myspace
      @tom_from_myspace 9 วันที่ผ่านมา

      Just stop playing these games. Riot Games fucking sucks. Fuck this company. See VideogameDunkey about his ban few years ago for example.

    • @thecipher8495
      @thecipher8495 6 วันที่ผ่านมา

      You got to kernel access them so you can play in their PC, simple as that.

  • @kingoscots9535
    @kingoscots9535 8 วันที่ผ่านมา

    I actually really like this form of content from you Ryscu. I think you should do more :)

  • @mx338
    @mx338 7 วันที่ผ่านมา +3

    You can avoid using third party drivers, by using linux, which has a monolithic kernel design. With very few exceptions every driver is part of the linux kernel codebase directly.

  • @Masterpouya
    @Masterpouya 10 วันที่ผ่านมา +5

    Amazing video here Ryscu ! Thanks a lot man!

  • @jetzesmit2111
    @jetzesmit2111 10 วันที่ผ่านมา +4

    I really love this type of content. Really well done!

  • @Tokiage
    @Tokiage 9 วันที่ผ่านมา

    Great work on this! Loving your documentary videos. Keep it up friend.

  • @pedr9vskcray2102
    @pedr9vskcray2102 8 วันที่ผ่านมา

    the sheer quality of this video is f*ing amazing, congrats mate!

  • @DarkinWithin
    @DarkinWithin 10 วันที่ผ่านมา +6

    The editing on these is artful

  • @CJTallon
    @CJTallon 10 วันที่ผ่านมา +18

    watching the evolution of this channel has been great. this in depth reporting + extra focus on video doc feel has just been next level...

  • @ivangarcia3456
    @ivangarcia3456 8 วันที่ผ่านมา +1

    Such an amazing video, great edition and amazing summary of all the things that are involved in an anticheat. Congratulations

  • @sarahstark2953
    @sarahstark2953 5 วันที่ผ่านมา

    can i just say how well this video seems organized, and how the graphics and explanations provided make this really easy for even non-computer people to understand. great video!

  • @thebyzocker
    @thebyzocker 10 วันที่ผ่านมา +5

    i knew pretty much all of this already but it was still entertaining to watch :D

  • @moderniselife
    @moderniselife 10 วันที่ผ่านมา +6

    These videos are amazing but I keep finding myself answering the questions before you give us the story and it breaks my heart because you’re an amazing story teller! I need to tell my brain to shut up haha

    • @hilkmeister1382
      @hilkmeister1382 9 วันที่ผ่านมา +3

      Nothing wrong with being informed about the subject

  • @D0Samp
    @D0Samp 9 วันที่ผ่านมา +4

    Even with (some) PCIe cards out of the picture, there's still so many possible avenues to get memory access, like DMA via Thunderbolt, stealth VMs that obscure their identity and hypothetically SMM if you are able to get in on the hardware OEM's level (which would sit even deeper than UEFI malware). Failing that, your second cheating PC still could act on the video feed to give you super-human reflexes, combined with a modded physical mouse.

  • @riich.586
    @riich.586 7 วันที่ผ่านมา

    Love this new video format!! Keep it up brother ❤️

  • @zwingler
    @zwingler 10 วันที่ผ่านมา +154

    18:35 "do you trust the delevoper" ... Riot ??? xD Suuuuuuuuuuuuuuuuuuuure.

    • @kosmonauta577
      @kosmonauta577 9 วันที่ผ่านมา

      "Sureeeeee" Clueless

    • @baribari1000
      @baribari1000 8 วันที่ผ่านมา +4

      @@kosmonauta577 not "sureeeeee!", "suuuuuure..."

    • @stevejelly2782
      @stevejelly2782 5 วันที่ผ่านมา

      yeah trust me Xi Jinping won't know it xdd

  • @markandreikinkito8253
    @markandreikinkito8253 10 วันที่ผ่านมา +4

    the production is godlike and educational.

  • @yungren.
    @yungren. 8 วันที่ผ่านมา

    You made seemingly complex ideas actually digestible and easy to understand, kudos to you!

  • @Rokusu
    @Rokusu 5 วันที่ผ่านมา

    your editing has become so crazy good, you deserve all the views and likes you can get

  • @aliceintera5131
    @aliceintera5131 10 วันที่ผ่านมา +7

    The video was interesting and well edited but what are the sources for this? Maybe I just missed them but I don't see them anywhere. So far, for those wanting to read more, I've found
    "Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus" By: Ryan Soliven, Hitomi Kimura,
    "The inside story of the biggest hack in history" By: Jose Pagliery,
    "Hunting Vulnerable Kernel Drivers" By: Takahiro Haruyama,
    and some parts _might_ be sourced from "An In-Depth Look at Windows Kernel Threats" By: Sherif Magdy, Mahmoud Zohdy.

  • @darkjackl999
    @darkjackl999 10 วันที่ผ่านมา +21

    I planned to initially uninstall when vanguard came out, but arena was so fun i decided to stick around for the update but after ~2 weeks i uninstalled because not only was i bored of the changes, but also even with me forcing it to not open on startup it was affecting my other games so i straight uninstalled it

  • @LoloisKali
    @LoloisKali 6 วันที่ผ่านมา

    Hey bro awsome video! Love the visuals great editing and very educational. Subscribed

  • @Ganerrr
    @Ganerrr วันที่ผ่านมา

    The logical conclusion to anticheat is either it being completely pointless to bother with or it being so invasive you have to physically go to some establishment to play the game. This is because nothing is going to be able to detect you pointing a camera at your screen and having an AI play the game for you

  • @sherrykda3511
    @sherrykda3511 7 วันที่ผ่านมา +3

    I like how he tries to give examples how you can trick Vanguard, but does so with the worst ones and the ones most easily detectable

    • @battokizu
      @battokizu 5 วันที่ผ่านมา

      remember he has to be nice to riot otherwise he'll lose his ad money and sponsorships.

    • @Bleiser3
      @Bleiser3 5 วันที่ผ่านมา

      As he said, he doesn't want to inspire anyone to cheat.

    • @battokizu
      @battokizu 5 วันที่ผ่านมา

      @@Bleiser3 He doesn't want to lose sponsorships, not that he cares about cheaters.

    • @octav7438
      @octav7438 5 วันที่ผ่านมา +1

      @@battokizu dma isn't detected either. all you need to do is just make your own driver, which skids have already learned how to do. Only issue with dma is the entry cost of buying an actual hardware device.

    • @丷
      @丷 4 วันที่ผ่านมา

      ​@@octav7438 DMA cheats don't use "drivers"...? guessing you're talking about firmware. valorant & faceit have already detected plenty of DMA firmware providers, only chance of staying undetected now is using a proper emulated firmware which is not easy to make, especially for "skids"

  • @Makanoyasha
    @Makanoyasha 10 วันที่ผ่านมา +4

    Very well put together video, also accurate to the T. The video edits were very clean as well, transitions/positions/angles were very smooth. Have a great one.

  • @Zhincore
    @Zhincore 5 วันที่ผ่านมา

    Really cool animations, visuals and the clips from others are included so nicely! Although some of the animations were totally pointless, I assume those were to retain attention xD

  • @feranks3211
    @feranks3211 7 วันที่ผ่านมา

    insane production value, keep up the great work!

  • @ovencake523
    @ovencake523 9 วันที่ผ่านมา +4

    this is an incredible video and i have so many spinoff ideas from it
    like whats stopping a developer company for using that extreme level of invasive access for data collection?

    • @ovencake523
      @ovencake523 9 วันที่ผ่านมา +2

      oh wait he made a video about basically exactly that.

    • @Coconut-219
      @Coconut-219 7 วันที่ผ่านมา

      You're implying that there is a single company NOT doing that. 😂

    • @ovencake523
      @ovencake523 วันที่ผ่านมา

      @@Coconut-219 companies are using kernel lv anticheat for data collection?

  • @zardon_zane1630
    @zardon_zane1630 9 วันที่ผ่านมา +3

    So, it works for most cheaters but now Vanguard worst enemy is itself

    • @albertcheong8497
      @albertcheong8497 9 วันที่ผ่านมา

      why?

    • @zardon_zane1630
      @zardon_zane1630 8 วันที่ผ่านมา

      @@albertcheong8497 Here, a list:
      1. CPU's get higher temps using the same specs, I tested with HwMonitor in my laptop
      2. I used to get 120 fps and now I had less than 20 fps after the Vanguard update with the laptop plugged in.
      3. Blue screens since Vanguard modifies BIOS
      4. Hackers can bypass Vanguard if they use non signed Drivers on the pc, so yea, they just became stronger
      5. Vanguard is banning people that has no scripts at all
      6. It counts as a cheat program in other games (Wanted to play Solo Leveling Arise but it said you can't play with cheats)
      7. If a hacker hacks Vanguard, gz, now your pc control is no longer yours :D

  • @Ganerrr
    @Ganerrr วันที่ผ่านมา

    "It's not like Microsoft can just reach in and remove the drivers"
    True, as Microsoft would never use one of their state actor backdoors for good

  • @e8xd
    @e8xd 9 วันที่ผ่านมา

    Very good video man! Great future ahead i can tell

  • @koneserchleba2137
    @koneserchleba2137 9 วันที่ผ่านมา +3

    im not trusting any developer owned by tencent

  • @imbirb
    @imbirb 10 วันที่ผ่านมา +3

    ay ryscu big fan of yours. Would you make some good ol small content AND some today-like content? i miss your old content aand your new content is awesome

  • @user-yc2ry2uz4h
    @user-yc2ry2uz4h วันที่ผ่านมา

    As a reverse engineer and cheat development savvy, I confirm this video’s content is actually whats happening in cutting edge cheat vs anti cheat scenario.
    There’s NO WAY to prevent cheat software from working without invasive kernel anti cheat. Literally no way.
    Good video. +rep

  • @Carhill
    @Carhill 9 วันที่ผ่านมา +1

    Firstly, amazing video. Informative and insanely good visuals mate.
    Secondly, I had a laugh after my machine bluescreened whilst watching this at 4:10, only to reboot, continue playing and see the bluescreen at 4:47.

  • @Etrical_
    @Etrical_ 9 วันที่ผ่านมา +18

    Ad ends at 1:48

  • @legendtoni1094
    @legendtoni1094 10 วันที่ผ่านมา +102

    We don't deserve this quality. We are just league players

    • @MIOG_MIOG
      @MIOG_MIOG 9 วันที่ผ่านมา +4

      We are not 🤢

    • @hezuikn
      @hezuikn 9 วันที่ผ่านมา

      @@MIOG_MIOG zzzzzz

  • @heetsoneji3694
    @heetsoneji3694 3 วันที่ผ่านมา

    You deserve more viewers for this work. keep it up man.

  • @effleurager
    @effleurager 7 วันที่ผ่านมา

    Thanks for putting the work in to creating high quality captions. TTML would allow captions to be rendered by TH-cam's closed captioning system, making them even better for end users!

  • @koshkamatew
    @koshkamatew 8 วันที่ผ่านมา +30

    4:44 oh so that's why valorant keeps bluescreening my pc like its a daily routine

    • @sfnsansub
      @sfnsansub 7 วันที่ผ่านมา +2

      ITs because of faulty RAM you had, atleast for me, I had upgraded my RAM from 8 to 16 and at first only the valorant seems to get crashed all the time [Getting blue screen even before main menu comes up]. After wondering through internet I went to the workshop and swap the faulty ram and ever since its working like a charm (It was frustrating when I had to restart every 10 min or so and also got a 1 week of ban for being AFK)

    • @h3ll924
      @h3ll924 7 วันที่ผ่านมา

      @@sfnsansub in my case all I did is downclock my ram to the recommanded value supported by cpu , all other apps didn't complain and system was stable but not valorant

    • @octav7438
      @octav7438 5 วันที่ผ่านมา

      @@sfnsansub it can also be because of cpu, gpu, drivers, etc.. Just because you had that problem doesn't mean everyone does

  • @reinhartdrial8060
    @reinhartdrial8060 10 วันที่ผ่านมา +18

    League just isnt worth this

  • @udbhavshrivastava
    @udbhavshrivastava 7 วันที่ผ่านมา

    This was a really informative and amazing dive into game cheats and I appreciate you for it. However ngl the way this video's title and thumbnail were created were kinda misleading considering it kinda suggested there is an open vulnerability that allows people to run cheats despite Vanguard, when as per the last notes of the video it doesn't seem to be the case.

  • @alvemaster
    @alvemaster 8 วันที่ผ่านมา

    Great video. I think its really important to show people what they are dealing with. When Vanguard was coming to league there was such a massive scare about how it would ruin everything and how it would be a massive privacy issue. This video shows how Anti cheats are much better than what people think, but at the same time they are not foolproof. They can give an attacker a ride right into your PC, but most often it will keep them out and only be positive. Really goes to show that only you as the consumer can decide what to trust or not. Great video!

  • @G0LD3NR0D
    @G0LD3NR0D 7 วันที่ผ่านมา +5

    This is why I have been telling my friends for years that serverside anticheat is the future. Kernel level anti cheat is basically an attack vector waiting to be used, because all it takes is an exploit in one and boom, not only can a cheater break the anticheat, but cybercriminals can use it to deploy malware payloads, utilize privilege escalation exploits, etc. Serverside anticheat on the other hand, doesn't run locally and hackers can't even gain black box access to it. Plus, it can be continually refined without cheaters gaining access to it. On top of that, small, specialized AI can be built in order to create and refine heuristics that allow for catching cheaters that otherwise appear to be just skilled at the game when they're really just skilled at toggling their cheats to blend in their cheating with legitimate gameplay. It's probably the best way to win the war against cheaters. Cheaters vs developers will remain a cat and mouse game, but it will give developers a significant advantage in fighting back against cheating.

    • @OCovilDoMarcos
      @OCovilDoMarcos วันที่ผ่านมา

      Server side anticheat has been something that was implemented a lot in the past (Hell VAC has been around since 2002, it's nothing new). The only one that still stands today to my knowledge is Steam's VAC and if you ask anyone about cheaters in valve games you'll see that everyone complains about it, since serverside needs time to compile a databank on a specific player and then analyze it afterwards it has to be sure false positives don't happen (It's also why they implemented the overwatch system on the games, because it couldn't reach high levels on confidence on specific cases, so those cases that were suspicious but not enough to be bopped by VAC got delegated to trusted players with high overwatch scores)
      Given this model takes weeks to months in order to get enough data to guarantee that the ban is not a false positive, cheaters go on to ruin a considerable amount of games before they actually get banned from the system.
      It has very open and specific weaknesses, most people who cheat in CS2 already knows they'll get bopped in two weeks or a month or so, they really don't care about that it's that free time they get that gets them going, they don't want to win and they don't care about losing money on new accounts they just want to ruin games because it's how they get their kicks.

  • @Cootshk
    @Cootshk 10 วันที่ผ่านมา +7

    How about VM detection?
    I run Linux as my daily driver, and am trying to make a VM that can run games like Valorant or Roblox

    • @mollthecoder
      @mollthecoder 9 วันที่ผ่านมา +4

      Some common ways programs detect VMs:
      1. VMs enable some flags in the OS that say "Hey, I'm a VM".
      2. VMs usually have specific drivers or software that aren't usually on real machines.
      3. VMs can have quirks in their hardware emulation that would be extremely unlikely in real hardware.
      4. Even besides all of the above, there are other less common methods software can use.
      Let me warn you: The goal of making a VM that can run these games is unrealistic. It requires extreme expertise in computing, hacking, virtualization, hardware, and more. However, if you want to try it, your best bet would be to reverse engineer the games and see what information they're looking for and what information contributes to VM detection.

    • @ougonce
      @ougonce 9 วันที่ผ่านมา +7

      @@mollthecoder It really doesn’t. It’s quite trivial to run both of these games in a VM by disabling precisely the things you talked about. The only real bottleneck will be performance, as disabling Hyper-V will tank your CPU, and you’ll need a second GPU for passthrough.

    • @itsTyrion
      @itsTyrion 8 วันที่ผ่านมา

      Forget it. There has not been a publicly known way to bypass Vanguard's VM detection for quite a while.
      As for Roblox, idk about VMs but they're actively detecting and blocking Wine/Proton. waydroid works if you really want roblox for some reason

    • @itsTyrion
      @itsTyrion 8 วันที่ผ่านมา +2

      @@ougonce uh-huh, trivial. I hid a VM well enough that pafish fully passed and the malware I threw at it worked, no luck with Vanguard. There hasn't been a known public way for a while now

    • @mousewheeltojump
      @mousewheeltojump 8 วันที่ผ่านมา

      @@ougonceHAHAHAHAHAHAHAHHAHAHAHAHAHAHAHAHAHAHAHHAHAHAHAHAHAHAHAHAHAHAHA no people have been trying for years at this point

  • @staotheduck4853
    @staotheduck4853 9 วันที่ผ่านมา +1

    I called it, I said it won't do anything but people just kept calling me an idiot, now that Ryscu made a video about it I can call them fools

  • @potatoonastick2239
    @potatoonastick2239 6 วันที่ผ่านมา

    Awesome video brother, you got the technical explanations spot on while keeping it simple to understand for the average joe

  • @111michiel
    @111michiel 9 วันที่ผ่านมา +6

    Imagine making literal malware to stop a cheater in your game and they make a malware to defeat your malware.

  • @SkinShowcase-zm3rs
    @SkinShowcase-zm3rs 10 วันที่ผ่านมา +13

    Finally someone make video about it. I see many scripters on PBE every day.

    • @atlas_carry
      @atlas_carry 9 วันที่ผ่านมา

      League of legends refuses to ban scripters as soon as they are detected, so it always has a delay ban for detection (unless its a wave) so you will always have scripters in this game as we can buy 1000 cracked accounts for 1 dollar total and script 10-20 games even on a detected platform

    • @eweer5398
      @eweer5398 7 วันที่ผ่านมา

      @@atlas_carry No game developer bans scripters as soon as they are detected. We love to call game devs dumb, but they aren't THAT dumb.

  • @furryfan1416
    @furryfan1416 8 วันที่ผ่านมา

    editing n sound design is top tier here. bravo to the editor.

  • @ImNotStealth
    @ImNotStealth 9 วันที่ผ่านมา

    The animations for ring 0 were sick!! Also the screams of cheaters getting banned was like hearing a lullaby before going to bed

  • @exahreycon
    @exahreycon 10 วันที่ผ่านมา +80

    This is one of the best arguments for using Linux, sadly a lot of manufacturers fear monger about Linux making cheating more easy. Just remember none of these companies make thier products available natively on Linux so a hacker would need to write software that bypasses these opensource computability layers. Its only about controll, be aware these tools like Vanguard are only "good" as long those in controll dont abuse it, and due to thier privileges its basically impossible for even advanced users to catch potential missuse if its properly hidden.

    • @Caellyan
      @Caellyan 10 วันที่ผ่านมา +9

      These tools also have their own vulnerabilities, so even if their devs are benevolent they can be used as rootkits by some third-party with knowhow. There's no ideal protection from remote cheaters, so only way to avoid cheaters is tournaments that provide their own PCs.
      I'd mention privacy, but unless you've checked your hardware and each ROM on all your boards manually, you can't be certain of it.

    • @Hundetanga
      @Hundetanga 10 วันที่ผ่านมา +10

      I doubt that Linux is more secure than Windows. The difference is that there are way more people to scam on windows because only few use Linux compared to Windows. I think Android is a good example for linux not being more secure.
      However, this doesn't mean that you are wrong in saying that it's one of linux' best arguments for using it.

    • @Hellscaped
      @Hellscaped 10 วันที่ผ่านมา

      @@Hundetanga Linux is massively more secure than windows, as vulnerabilities are more easily spotted and fixed compared to it. Its fully open-source, so millions scrutinize the code on a daily basis. Windows on the other hand, is not. A white box is infinitely more secure than a black one.

    • @mirzu42
      @mirzu42 10 วันที่ผ่านมา +1

      That goes for any driver. In fact it goes for every single app running as admin because they can install drivers.
      Its stupid to say anticheats are a problem when any driver can be just as bad.

    • @laggerlaggerson4375
      @laggerlaggerson4375 10 วันที่ผ่านมา +13

      I dont think you have any idea about how computer science works if you think using Linux is a magical solution for anti cheat lol.
      Most modern operating systems have a concept of user mode and kernel mode, windows, linux, etc. Even processors themselves have special permission bits for protected access.
      Whether or not you use windows or linux the endgame for anticheat software is memory or hardware inspection (i.e, some kernel mode driver). And hackers will soon follow to make some anti-anti cheat software for that. Arguably its even easier if the entire kernel source code is available. You could even compile your own kernel with built in cheats or memory inspection if you wanted to lol.

  • @reflexx5272
    @reflexx5272 8 วันที่ผ่านมา +3

    Hearing cheaters yelping after getting banned is absolute ecstasy

  • @reidmock2165
    @reidmock2165 8 วันที่ผ่านมา +1

    I don't care about League of Legends. So I really liked how your video was a generalized documentary. I'll have to keep an eye out for more of this from your channel. Well done man

  • @MrZombastic
    @MrZombastic 5 วันที่ผ่านมา

    Wow as a dev its actually great seeing a thorough explanation while not going too deep :) Your definitely a dev too, well explained.

  • @kenshi4296
    @kenshi4296 10 วันที่ผ่านมา +54

    i'm uninstalling league man fuck this, i'm not taking a risk for a cancer game like league, they're driving that game into the abyss anyway

    • @itsmenatika
      @itsmenatika 10 วันที่ผ่านมา +8

      They should make every kernel anti cheat open source

    • @jost76x2
      @jost76x2 10 วันที่ผ่านมา +14

      @@itsmenatikano they should not this would just make it easier to find exploits in them and also it’s not really effective making you private signed driver public

    • @itsmenatika
      @itsmenatika 10 วันที่ผ่านมา

      @@jost76x2 why would I trust spyware?

    • @asdfg5721
      @asdfg5721 10 วันที่ผ่านมา +18

      Such an weird thing to say after watching the video? I mean most of the bypass show in the vid are hypothetical and the one that actually happened (Genshin) was cause by Microsoft, he said in the vid clearly that u don’t need genshin install for the hack to work. Of course, if you don’t want to risk it getting hacked just remember to never download anything online, don’t use the internet, don’t buying second hand products, have separate passwords for every new account and don’t have any social media account with your real informations to not get hack socially. That will reduce your chance of not getting hacked by 90% (cuz why hacked a game that 99% players are ftp? most of the good hackers target bank accounts or create fake apps) just like not going outside your chance of dying is reduced by 50%.

    • @hatyyy
      @hatyyy 10 วันที่ผ่านมา

      @@jost76x2 it would make it easier for people to find exploits to patch as well though

  • @user-gk9oj9ni6u
    @user-gk9oj9ni6u 10 วันที่ผ่านมา +14

    No one should trust some random video game company to run software as soon as your system boots up, especially one that is known for having buggy client and game code. Vanguard is a gross violation of system security and user privacy with its "always on" model.
    If it's not open source or hasn't been audited by trusted third parties then something like this shouldn't be installed. Vanguard forced me to quit League a few months back and there's no way I'm returning if this continues. It's much more preferable to have a few advanced cheaters than this.

    • @ArchaicTTV
      @ArchaicTTV 9 วันที่ผ่านมา

      Its mostly cheaters saying this shit everywhere, trying to use fear to also get noncheaters against the level of anticheat needed to be effective these days.
      Gg cheater. Throwaway name using asshole

  • @SahilP2648
    @SahilP2648 8 วันที่ผ่านมา

    Love the production level of this video!

  • @MuzMysyq
    @MuzMysyq 9 วันที่ผ่านมา +1

    Wow what a great video!! I play Valirant, not league, and I usually dismiss videos about vanguard that try fearmongering about "Chinese stwaling all of your data", but this video provides so much insight about how the anti-cheat actually works. Thank you!