Anti-cheat trials

The new anti-cheat trials are… to put it mildly, concerning to me. I understand that the Denuvo being used here is not the Denuvo being used for DRM, and that they are not the same type of software, however I'm concerned about compatibility. The steam deck compatibility is somewhat reassuring, but there's no mention of general Linux support and for someone that hates Windows and has escaped to Fedora… that's a little discouraging.

Client side anti-cheat is also in my opinion, terrible. It relies on invasive technology that tries to essentially guarantee a client is trustworthy. To do this, it has to be able to scan the software that is running on your computer, as one example. The more dangerous part though is, if this is kernel level anti-cheat it opens up a huge security vulnerability because anyone who gets control of the software can do real damage to a system. There are documented cases of this happening in the past.

Why are we, in 2026, still relying on client side anti-cheat? There's so many easy things you can do on the server to make it harder for cheaters. So many simple checks that don't have much overhead, such as checking that a survivor actually has the item they're trying to use, or that they're near the survivor they're healing, or that they're not instahealing them. You have dedicated authoritative servers, why do they blindly trust the client? Heck, I'd be more ok with client side anti-cheat if there was also an attempt to make the server do its job better.

It's also not effective. Cheaters easily bypass anti-cheat for one fundamental reason: It's client side. You cannot control the client. Look at any game that relies wholeheartedly on client side anti-cheat, none of them have meaningfully solved the cheater problem. And why is that? Because you can't guarantee that the client is trustworthy, this is one of the first things you learn in infosec.

Please reconsider this.

Comments

  • Agreed, all the game needs better code, as in more server sided checks.

  • We moved from P2P to dedicated servers with one of the promises being better cheater detection. Clearly that hasn't been the case. Instead of wasting time on another ring 0 anti-cheat that gets bypassed, why not look into validating what the player is doing from the server's perspective? The server should be the source of truth to all players. If a player does something impossible it should be immediately flagged and investigated.

  • @Mr_K said:

    We moved from P2P to dedicated servers with one of the promises being better cheater detection. Clearly that hasn't been the case. Instead of wasting time on another ring 0 anti-cheat that gets bypassed, why not look into validating what the player is doing from the server's perspective? The server should be the source of truth to all players. If a player does something impossible it should be immediately flagged and investigated.

    It is baffling BHVR hasn't decided to do this yet. Maybe its because their game is so buggy many innocent players would be incorrectly banned due to bugs if it was not lenient.

    I can only hope with the games rebuild that BHVR will implement some sort of system for this though, assuming the game will not have horrible code. The server should be able to recognize that a killer using their attack instantly over and over, downing all survivors within the first minute is cheating. The server should be able to tell that a survivor is running faster than they should be able to based on perks etc. The server should be able to detect when a survivor escapes the trial before the hatch or gates are powered.

    Rather than forcing players to install another intrusive anti-cheat software like Denuvo, it would be much better if BHVR just made it so the game itself could detect and tell when things are out of place based on what is and isn't possible. Wouldn't solve all the problems but would certainly be better than just switching to another anti-cheat software.

  • The common argument I see against this is "oh, it's too computationally expensive and would make servers slow!" but I really don't think this is the case, and nobody has been able to argue that without excluding games that have already solved most of these problems.

    Let me go through each type of cheat and explain what it is and why it's solvable. Let's start with the hardest one, just to prove my point right away.

    Wallhacks
    A wallhack shows players through walls and is only useful if the server continuously exposes the entire state of the match to a client. If the server doesn't send the position of everyone without any safeguards every tick, that makes a wallhack effectively useless. You'd only be able to see the last sent position.

    And this isn't as expensive as people think it is. Is it trivial to implement? No, but it's possible. And the proof is Valorant, which has a fog-of-war system that uses voxels to compute visibility for each player. Dead by Daylight's servers could compute this at the start of each match to account for procedural generation, and it would solve this problem completely. And we're talking a 2% slowdown, if even that.

    It would also be an even better fit for this game, because there's less players to compute and this isn't an FPS that requires super low latency 128 tickrate to be playable.

    Speedhacks
    A speedhack is a cheat that allows you to move faster than you should be able to based on the game's conditions. It can be subtle or blatant, but even the subtle version can be validated.

    Instead of the client having authority on where you are, the client lets you move as normal client side (so there's no input lag), but sends the inputs of each player instead of their position. The server can then validate where they should be based on the inputs and perk state, and if it doesn't match up, you get rubber-banded back. You can also compensate for ping. If this happens enough times, the server accumulates data and when it reaches a point where it is statistically improbable to be caused by lag, you get banned.

    This also makes teleportation impossible.

    And if you're concerned about rubber banding for people with bad internet, well that happens regardless of validation on bad connections. And as much as it sucks, I don't think we should sacrifice everyone else's experience for the sake of giving people with a poor internet connection a better experience.

    Item and perk validation
    The server validates what items you have based on your cloud save, and if you try to join a match with an item/perk/addon/offering you don't have, or try to use one you don't have in a match enough times, you get banned.

    Don't ban immediately, accumulate statistics over time - that way you avoid false positives if the client has a bug that causes items not to match up with the cloud. That can also be solved further by making the client query the server for what items and perks you have before the match, then update your inventory - and then simply remove anything you don't have from your loadout.

    As for aura related items and perks, let's use the blood amber as an example. If you're actively using the item, the client tells the server that and the server keeps track of your charges and sends you the killer's position if you're in range until you run out of charges. When you run out, the server stops sending the data based on the fog-of-war system I explained earlier.

    And now if a player tries to use a perk or item they shouldn't have in the match, they can't. The server will refuse the action and other players won't see it, and over time this repeated action gets you banned.

    These checks are super trivial, I'd wager less than a millisecond if even a few nanoseconds. There's no reason not to do them.

    Insta-completions/Remote completions
    This is when a cheater instantly heals a survivor, instantly completes a gen, and so on. This is again super trivial, the server keeps track of progress instead of the client. Just like the movement validation, the client still increases progress client side (so you get a smooth progress bar), but the server validates it based on your position, perks/items, and time passed. If it doesn't match up, the server makes a note of that.

    If you're on the other side of a map, you obviously shouldn't be able to complete that gen or heal that survivor. If only a second has passed, you can't complete a heal, and you have to stay still to heal them. If you're downed and another survivor is not healing you, you can't get up. If you have unbreakable for example, the server validates the progress of your recovery and once you get up, the server knows that you don't have unbreakable anymore and won't let you use it again.

    Bypassing anonymous mode
    Often used to target streamers to hold their game hostage or ruin their experience with other cheats. This one is arguably the easiest. Don't send the player's steam info to the client if anonymous mode is on. That's it.

    And now we've covered the most common cheats used in this game, and proven they can be solved with server side validation, and that the validation won't meaningfully reduce performance. I think given that it almost completely solves the cheater problem, it's more than worth it.

    So what's left? Well, there's still the case of client side cheats such as making trapper's traps more visible by modding the game. That's why we can still have some level of client side anti cheat, but it doesn't need kernel level access and instead just validates the integrity of your game so that if a hash doesn't match up the server doesn't let you join a match. It's still bypassable, but given that we've now solved the most damaging cheats server side, I think people being able to see traps on the ground easier won't ruin your games. Perfection is the enemy of good.

    Considerations
    I understand that this requires time, money, and effort to implement, but I still don't think trying yet another ineffective client side anti-cheat is going to be worth it or improve the experience.

    The expenses of writing the code for all these checks is real, especially considering the thousands of perks this game has. I understand that. But it would solve a problem that has plagued this game for years, and once it's done the cheater problem will be miniscule which will improve the game health tremendously.

  • Excellent comment, I hope if they rebuild the game code it wont be so client based like right now, the real solution as discussed making it impossible with server sided checks. Any kind of anti cheat isnt the right way to go.

    You make it impossible with proper coding to begin with