逃离塔科夫吧 关注:417,212贴子:8,009,617
  • 1回复贴,共1

关于“国外反作弊不能扫盘”的一些科普

取消只看楼主收藏回复

这个言论我不知道算不算神论,但是首先国外大部分的地方是没有完善的隐私法案的
即使是欧盟的GDPR和加州的CDPR,也只严格限制了能关联到个人的隐私信息而不限制匿名的收集,很显然你电脑上运行了什么是不能关联到你个人的(除非你实名制的购买了游戏)。即使你实名购买了游戏,按照大部分游戏厂商的隐私协议他们并不能分享你的个人信息(不包括匿名信息)给反作弊厂商,所以在GDPR方面完全没有问题。
其次我们再来看两个主流的反作弊系统的隐私协议
在Battleye的官网点击Privacy Policy,就可以看到:
Furthermore:
As trust is paramount when it comes to anti-cheat, we feel that it is important for us to clarify to all of our users that your privacy is respected and protected by us at all times. There has been a lot of misinformation posted on the internet about BattlEye in recent years and therefore we want to emphasize what exactly we are doing in an unambiguous way without confusing you with typical legal language.
While BattlEye needs to have full access to your system’s internals to have the capability to detect all hacks, we do not look at, check, transmit or even sell any of your personal information, data, documents, credit card details, passwords or similar. Our mission is to provide effective anti-cheat protection, not to spy on you. Besides, looking at your personal information does not help us reach the goal of providing a cheat-free environment in any way, so there is absolutely zero point in doing it in addition to it being immoral.
Like most other anti-cheat solutions, BattlEye has the theoretical capability to transmit flagged executable code to our servers for further review. This is needed to be able to discover and identify new hacks being used. However, for normal users that do not run suspicious software this should never happen and other than that we do not transmit any of your memory contents to our servers.
Finally, any data relating to you / your game account is always stored on secure servers. We usually only store data if there is some sort of detection and that includes your IP address, account/in-game name and possibly hardware serial information for identification. This is also mentioned in our EULA that usually comes with the games we support.
简单的说人话:他们会扫,但是他们对你的个人信息不感兴趣,他们需要扫描你全部文件的能力但不会滥用这个能力。
再看一眼EpicGames提供的EasyAntiCheat的Privacy Policy(这是有中文的),可以看到
在 Epic 服务上为用户提供的公平、公正和有竞争力的体验对我们来说非常重要。我们严禁在 Epic 服务上进行作弊、黑客入侵、帐户窃取以及任何其它未经授权或欺诈性的活动。我们使用各种反作弊和防欺诈技术帮助我们识别和防止恶意活动。这些服务可能会收集和分析有关您的计算机或您计算机上软件的数据以侦测作弊行为,并且可能由 Epic 或服务提供商(如 BattlEye)提供。
虽然没有BE说的这么明白,但是我觉得结果也是很明显的。
至于为什么拳头的Vanguard反作弊的能力明显强于BE/EAC,其实这不是扫与不扫的问题,这是ring0层面的权限问题。在两个驱动都在相同的权限下时,windows的机制决定了先进入ring0的驱动基本优势无限大,而拳头选择了将反作弊驱动开机自启而不是在启动游戏时才加载,这就导致了绝大多数的情况下反作弊驱动比“其他驱动”更早的加载,也就有更大的概率检测到“其他驱动”的存在。
以上。


IP属地:江苏1楼2023-01-14 17:29回复
    另外,我想借用杀毒软件来说明一下国外的某些厂商对于“上传你的文件到服务器”有多么大的操作空间并且完全合法。
    图上是一个在美国企业内非常流行的杀毒软件叫CrowdStrike,他们这几年占据了美国大型企业和zf的大部分市场。

    他们在配置要求不能满足他们机器学习运行的场景提供了云端的机器学习,很显然用机器学习来分辨一个文件是否安全不可能只提供hash,必定是回传完整的文件让模型去跑。
    并且他们的架构是完全SaaS,没有自己部署服务器的可能。
    这种情况下他们的软件依然合法,就能从另一个角度说明问题了吧。


    IP属地:江苏3楼2023-01-14 17:34
    回复