• Technus@lemmy.zip
    link
    fedilink
    English
    arrow-up
    3
    ·
    23 hours ago

    In a lot of ways, it’s the lazy way out because they can just shell out to a vendor like BattleEye. Even with in-house solutions like Riot and EA use, they can be developed by separate teams who don’t really need to have any knowledge of how the game actually works.

    It’s largely all the same syscalls and access patterns they’re looking for. Process injections work the same no matter what the game is.

    Kernel-level access is also in some ways the lazier way to implement it because instead of having an arms race with the cheat developers trying new ways to detect and avoid each other respectively, they just force their anti-cheat module as low in the stack as possible. It’s just also, you know, indistinguishable from a Trojan at that point.