Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Do you consider being banned in a video game because of hacking to be an example of something killing computing freedom?

The user still maintains all the freedom of doing whatever computing they want on their own machine, but if they want to play with others who don't want to play with cheaters then they have to use the official client.

For people who want a high degree of freedom and be able to access as many digital services as possible I foresee such people using a hypervisor that runs both a provable secure OS and another OS that is as free as they want.



How about being banned from online banking, government services and all social networking / communication platforms? Because that's the road we're already heading down.

What makes you think they will give us this magical hypervisor capability? It's more effort, increases the chances someone finds a bypass and takes power away from the incumbent online platforms. It's so much easier to just prevent it all. The only reason it hasn't happened yet is the amount of devices without this ability in circulation. But that number is shrinking rapidly.


>How about being banned from online banking, government services and all social networking / communication platforms?

You aren't banned. You just have to use a secure device. It's like saying that a store banned you because they stopped taking checks and started requiring a credit card since they are more secure and harder to commit fraud with. As a person you didn't lose any freedom. Freedom does not mean someone has to be able to force their will on another person. That sounds like the opposite of freedom to me.

>What makes you think they will give us this magical hypervisor capability?

It's not magical. Look at Windows WSL2 which already works like that.


It's not about being secure. Google allows devices with up to 10 years without any patches to pass their integrity API. Meanwhile Graphene OS, which is very secure and up-to-date, doesn't pass.


This. Plus if I want to access my bank account on a device I trust, the bank shouldn’t say “hey we don’t trust it so buzz off”. It’s my money in that account.

I understand there’s some stupid compliance thing that makes banks do this, but it clearly isn’t a hard requirement, as there’s still plenty of banks that don’t participate in this security theatre.


To be fair to your bank, it has to cover you if your money gets stolen through a hack through their app, no matter what your operating system is.


I’d very much love to have an option to waive that cover though! Just give me a scary warning “hey, we’ve determined your device is unsafe; so if you get hacked through that device, you agree not to hold us liable for that. proceed? [y/N]”

For more specific mitigations, they could issue shorter-living tokens to such devices, in case it gets stolen and it didn’t store the token properly (say, the user did something stupid like “hey I’ll substitute secure enclave with a shim that writes secrets to an SD card”). And they could limit certain critical functions that do require attestation for some reason (e.g. Host Card Emulation, aka “tap your phone to pay”, which they usually delegate to Google Wallet/Pay/Wallet anyway).

Wise seems to do it correctly. It works on rooted phones, even, just gives a scary warning and blocks some app functions. They also have a fully functional webapp, so you mostly don’t need the app anyway. Revolut, on the other hand, has outright blocked me from my account – so I’m not using it anymore.


You may waive that cover, but when (not if) you get hacked and your money gets stolen, someone still has to pay it back or you will die. Neither of those options are okay with the government and only one is okay with your bank.


I am talking about attestation in general. I already left a comment in the thread agreeing with you.


They allow old devices to report to Play Integrity. That doesn't mean the service provider requesting attestation has to allow such devices. These things usually give just a risk grade to the service provider and it's up to them to make the decision.

Graphene OS says they are secure, but the definition of secure they're using isn't the same one the service providers are using, so that doesn't help much.

The best route forward here is to push for a separation of certification types. Ideally it would be possible to pass the security related aspects of Google's CTS test suite and get approved by Play Integrity without triggering the other parts of Android certification.


> You just have to use a secure device.

No, you have to use government backdoored device. I.e. the most secure android rom (at least the only rom we know is not penetrable by state-sponsored celebrite based malware) is not covered by google's play protect, while bunch of outdated CVEd phones are.

Same will go with many hardened Linux machines, QubesOS, Whonix stations, you name it. I'd argue they are far more secure than any average windows/macos installation.

Hardware attestation has nothing to do with security, it's censorship.


>QubesOS, Whonix stations, you name it. I'd argue they are far more secure than any average windows/macos installation.

OK, then let's see you argue it.

Most of the people who claim Linux is more secure have simplistic one-sentence arguments (e.g., "Linux is open-source, and many eyeballs make bugs shallow including bugs that are security holes") whereas those who say that MacOS and ChromeOS are more secure go into great technical detail as to why they think that.


> You just have to use a secure device.

Secure as defined by a duo of monopolists. It's a contractual concept and doesn't have a firm relation to security-related characteristics. I'd trust GrapheneOS to be as secure as anything Google is capable of releasing, but that doesn't help them if Google refuses to vouch for a device running their OS. Which is also why your check/credit card analogy falls flat.


Graphene supports attestation and any backend service can add support for handling it. No one is forcing people to only use two.


I think you got it reverse.

Gaming and such are dedicated services. Fine if people agree to pay premium to have the required platform / console / etc.

General services such as communications / banking must be free, and must not require trusted hardware on the end point. The services must be designed to be secure even in the case of compromised end points. But that's against the current trend where all banks are trying to push all the responsibility on the end user because they want to reduce their costs. There are plenty of solutions but they don't go for it because it's not in their interest and they want to squeeze out any little penny of infrastructure cost.


>How about being banned from online banking, government services and all social networking / communication platforms?

Defense is depth actually works. It's better security to require a dedicated device to make it harder to commit fraud. This is why credit cards became a secure device instead of just being a magnetic strip.


> Do you consider being banned in a video game because of hacking to be an example of something killing computing freedom?

No. It's the constant attempts to invade our computers and "prevent" the unwanted behavior that are problematic. See kernel level anticheat nonsense. They want to own our computers.

> if they want to play with others who don't want to play with cheaters then they have to use the official client

They should be able to play with whatever client they want. It's their computer, it should run whatever software they want.


>See kernel level anticheat nonsense.

This nonsense mainly exists only because the operating system is unable to attest that it the app is secure and the right app is what is running.

>It's their computer, it should run whatever software they want.

I agree, but companies shouldn't be forced to match cheaters with legitimate players. Cheaters just can't secretly be cheating.


To defend my own freedom, I'm forced to defend scoundrels as well in a totally unhinged manner. So be it.

> the operating system is unable to attest

And it should remain unable. There should be no "attestation" of anything. The corporations who want such things should remain unsure of the device's "security". They should just accept it. Let them write it off as a cost of doing business or something. The optimal amount of fraud is non-zero, as they say.

> the app is secure and the right app is what is running

These machines are our personal computers. They are extensions of our minds. They are general purpose tools with limitless potential, just waiting to be shaped in accordance to our wills.

There is no such thing as being "secure" from us. Not inside our own computers. The mere idea of it is offensive. It is an affront to us all. We are the gods of these machines. To attempt to "secure" a video game of all things against us is an attempt to usurp our power.

> Cheaters just can't secretly be cheating.

Now that remote attestation is in play, the ability to do that -- forge attestations to pretend to be a corporate owned machine while remaining free and subversive -- has become key. So I'm forced to say that cheaters absolutely should be able to secretly cheat. If the cheater wants to edit his computer's memory or whatever, it's his divine right as the owner of the machine. An inability to do that means our freedom is lost.

Cheating in video games is literally nothing compared to the loss of our computer freedom. Let the entire industry go bankrupt if it must. We cannot sacrifice it no matter what, and certainly not over something as mundane such as video games. There is so much more at stake here. Ubiquitous access to cryptography. Adversarial interoperability. Our very self-determination in the digital world. Video games are nothing -- and that's coming from a fellow gamer.


I don't see any consumer nor developer demand to make cheating in multiplayer games an inherent tenant of a computing ecosystem. Attestation is just an optional feature that expands what is possible. Services have no obligation to check attestation or use it as a hard signal to block people. All previously existing freedom is still possible on your computer.


> Attestation is just an optional feature that expands what is possible.

So optional that everything that can require it will require it. Games want it because cheating. Streaming services want it because piracy. Banks want it because fraud. Web sites want it because advertising. Governments want it because encryption and anonymity.

> Services have no obligation to check attestation or use it as a hard signal to block people.

They will do so of their own free will.

> All previously existing freedom is still possible on your computer.

You're "free" on your paperweight of a computer that can't do anything useful because it can't interface with the rest of society. Maybe one day even ISPs will reject clients that can't pass attestation. Can't even join the internet if you "tampered" with your machine. Such is life in the land of the free.


If there is market demand to not require it then there still will be services that don't require it. If there is such little demand for it, is such a thing actually valuable to society?


The problem is not that the OS can’t attest the app is secure. The problem with cheating is that the game servers cannot attest the client is genuine in all aspects that matter: non-modified client, running in an environment where there is no inspection of its memory for map hacks, aim bots, and more. The only way to do that is a remote attestation of the entire chain: hardware, locked down OS, app. (If the OS isn’t locked down it can’t prevent the player from running cheating software.)

The choice is simple: tolerate some level of online cheating, or require remote attestation to run the game. If you ask me, I’d rather take the first option. Locked down game console already make me a bit queasy. A locked down desktop, laptop, or palmtop? That’s not acceptable. People should be able to run any program they want on their computers. If that means the end of online gaming, so be it.


The solution to cheating is what we used to have: moderated, privately owned servers, and invite-only servers.

Let the cheaters join the cheat-friendly servers or the foolishly unmoderated servers.


I agree, but then you lose the convenience of centralised match making, and I’m guessing, a number of predatory monetisation schemes. Allowing third party servers however would be a very good way to stop killing games.

I don’t believe intrusive anti-cheating is required for online gaming to flourish. But even if it was, I would give up Elite Dangerous, for which I have bough a VR setup and build my cockpit, before I give up full control over my PC.


This is typically handled by the game offering a modding API for people to make mods with. This API limits mods to do things which will not be cheating.


We had fun in online games without kernel level nonsense. Why do I need to compromise my hardware when the problem is an outlier in the social graph? Anticheat is part an arms race and part just raising the bar so people cant cheat too easily. That said you can feed a video feed into a Kria K26 or even a pi or jetson and make automatic targeting completely transparant to the kernel. Then what? Hardware attestation in peripherals?

How do old boomershooter communities tackle cheaters? When and why do methods that work on a social graph fail or necessitate anticheat? I agree on the hypervisor part. Putting different applications in microvms would be good for isolation.


>We had fun in online games without kernel level nonsense.

You might of. But there was a percentage of players turned away by cheaters or even just had a bad experience one day because of one. At scale this can cause a bad experience for a ton of players so trying to stop as many cheaters as possible does matter.

>Why do I need to compromise my hardware

You don't have to compromise anything. In fact it is optimal to have the system be as secure as possible that way cheats can't mess with the game.

>How do old boomershooter communities tackle cheaters?

By limiting the rate of new players. This goes against the wishes of games who want to achieve massive growth.

>When and why do methods that work on a social graph fail or necessitate anticheat?

If people provided IDs that could work too instead of anticheat, but usually people do not want to do that just to play a game. It adds friction to the onboarding process.


> You don't have to compromise anything.

So… I don’t have to compromise the ability to run any program I want on my machine, and I don’t have to compromise the ability to be root on my machine. Right? And of course, when I say "me", I’m talking about everyone, including cheaters. Meaning, we don’t have to compromise the cheater’s ability to run any program they want (that would include cheats), nor their ability to be root on their machine.

> In fact it is optimal to have the system be as secure as possible that way cheats can't mess with the game.

Secure for the game company you mean. I want a computer that’s secure for me, that responds to my commands. And again, "me" includes everyone and cheaters too.

---

The online gaming industry is not worth sacrificing individual ownership of computers.


>So… I don’t have to compromise the ability to run any program I want on my machine, and I don’t have to compromise the ability to be root on my machine. Right?

Yes. You are free to do whatever you want on your machine.

>Meaning, we don’t have to compromise the cheater’s ability to run any program they want (that would include cheats), nor their ability to be root on their machine.

Yep. The only thing the cheater is unable to do is prove to the server that they aren't using cheats.

>Secure for the game company you mean.

No I mean that the operating system protects applications from messing with each other. The operating system should isolate each app for security purposes.


> No I mean that the operating system protects applications from messing with each other. The operating system should isolate each app for security purposes.

Oh but that is far incomplete a specification. What security purposes? Who are we protecting, from whom? On whose behalf does the OS isolates applications from each other? If it’s on mine, then you bet I absolutely want the ability to lift that isolation in specific cases. It’s my computer, I decide when and how the rules are broken.

But the moment I have that (a computer and OS that really work for me), I lose the ability to prove that I don’t. If I play an online game, being in control means the game company is not, and I can’t prove to them I’m not cheating.

I’m not aware of any third alternative.


In short the integrity of the application must be secured. This integrity must be protected from everyone. Nothing should be able to violate the integrity of the app.

>I absolutely want the ability to lift that isolation in specific cases.

There is no need for this. Allowing end users to turn off security features is not a good idea. Users should not have to think about such things.

>I decide when and how the rules are broken.

Most users do not want this ability. They just want a computer that works and is safe to use. They don't want to dictate how exactly it was written. That is the manufacturers job.


> In short the integrity of the application must be secured. This integrity must be protected from everyone. Nothing should be able to violate the integrity of the app.

I’m getting a strong sense that you don’t know what you’re talking about. "Everyone" for instance doesn’t include the app vendor. You want to allow updates, right?

> Most users do not want this ability

Again with the ambiguous wording. What do you mean exactly? That >50% of users don’t care about having this ability, or that >50% of users explicitly reject this ability?

In my experience, most users think they don’t care, until they need to run an app that’s not on the main app store. Easy example: skip YouTube ads. On Android, you jumps a few hoops, install Newpipe or Tubular, and voilà, no more ads. But I’ve met several iPhone users who wanted the same, and were quite dejected when they realised they couldn’t have it.

Of course, the idea that most users explicitly reject the ability to bypass security measures is utterly ridiculous.

> Allowing end users to turn off security features is not a good idea.

Not that I’m not talking about flipping a switch that would end all process isolation. I’m talking giving permission to one app to mess with one other app. Secure by default with fine grained permissions, not "please revert to Windows 98 with zero memory protection".

> Users should not have to think about such things.

They have to anyway. Where their credentials are, what if they break their computer, lose their phone, their data gets leaked…


PC gaming has always been rife with statistical inferencing of cheating, accusations of cheating both true and false and resultant low levels of trust that do destroy gaming communities. That's with aggressive software solutions that implement an ad hoc not entirely robust form of remote attestation.

A lot of gaming migrated to consoles for this reason. They have secure remote attestation implemented properly. Accusing winners of cheating doesn't work there, and it's obvious why that results in happier and healthier gaming communities.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: