Cracking a commercial anticheat's packet encryption

Obfuscation does not make your product strong. If it can be deobfuscated and is shown to be insecure and unstable, then that's what it was regardless. You can put lipstick on a pig but at the end of the day, it's still a pig. There is no disingenuity here, it's sincerely* believed that BattlEye should not be trusted as an anti-cheat solution. Documenting poor design practices, rushed development, and unstable behavior in an anti-cheat that, while may do its job, does a damn mediocre job and is constantly overpromising and underdelivering is not throwing shade. If you're claiming you're the gold standard and conning publishers into buying a license to use your anti-cheat you sure as hell should hold up better against tests and research performed on it.

There are other articles documenting the other problematic and potentially privacy-invading things they've done. Everyone gets riled up about Vanguard but doesn't read real research on a much more prevalent anti-cheat.

/r/ReverseEngineering Thread Parent Link - secret.club