Originally Posted by
TehCheat
I'm honestly not convinced their signature scanning is what is getting people flagged at this point (though I thought it was at first). Maybe they're working around our really crappy hash changing, but I think it's far more likely people are leaving "poehud" in their path, or modifying memory/ggpk files, or something along those lines. The reasoning for this is because far more people should have been flagged if it was simply a signature getting matched. Unless I grossly underestimate how many users would take extra precautions to prevent hud from getting scanned.
I'd love to know if someone has gotten flagged while running hud without a path that contains "poehud" and without anything that would modify memory (map hacks, hooks of any kind, etc.) and without any modifications to the ggpk file. It's just hard to track things down when people are doing more than just running hud. And we don't have the luxury of being told "yeah, that program that was accessing poe matched a signature".
If it's just signatures, then running poe as a lower level user and hud as another user should prevent signature detection (the turbohud method). But if you do that and have poehud in the path, you might still get detected.
There are also some other things that would make detection very simple (perhaps not with the turbohud method) that would be low hanging fruit for the next batch of anti-cheat tactics.