• w3dd1e@lemmy.zip
    link
    fedilink
    English
    arrow-up
    9
    ·
    9 hours ago

    The article says because he installed the chip and launched Valorant, his other PC components such as his motherboard are not also blocked.

    He can’t play a Riot game unless he buys an entirely new computer.

  • UnLocoPoco@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    1
    ·
    10 hours ago

    This is why kernel level anti cheat and every variant of it include the tpm ones should be discouraged. Performance Hits are huge too in case of denuvo

  • carrylex@lemmy.world
    link
    fedilink
    English
    arrow-up
    42
    arrow-down
    1
    ·
    23 hours ago

    Ah classic Riot games, investing all the money in anti-cheat while their launcher lacks basic functions like “download throttling”.

    No idea how Steam keeps winning…

    • Smoogs@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      arrow-down
      1
      ·
      12 hours ago

      valorant is the facebook of games. only boomers blithly ok with human right violations linked to the socials they use would think it is a good idea to stick with it

  • mavu@discuss.tchncs.de
    link
    fedilink
    English
    arrow-up
    59
    ·
    1 day ago

    This is so dumb. as if there was no reasonable way to detect cheating without these super invasive anti-cheat monstrocities.

  • palordrolap@fedia.io
    link
    fedilink
    arrow-up
    91
    arrow-down
    1
    ·
    1 day ago

    I would be very interested to know how they are able to identify a specific CPU. The article speculates but does not answer this question.

    The fact that this is even possible is a security nightmare.


    OK, I’ve done a bit more digging and pieced it together. Acknowledgement to @dual_sport_dork@lemmy.world for prompting me to try (again) to find a command that might do it among other things.

    IMO, this sort of information shouldn’t be in processors in the first place, but apparently it is there and needs admin/root access to, well, access it.

    … and the game in question requires kernel-level anti-cheat, so of course, it has the necessary access.

    The command for Linux is sudo dmidecode -t processor, which dumps a lot of info including an ID field, which is supposedly the CPU’s specific identifier. It can be grepped for or otherwise filtered out.

    My own Ryzen gives 8 hexadecimal pairs, so it’s a 64-bit value.

    I would not know that that was unique to my specific individual processor if I had not been told, but I’ll assume that at least part of it is not unique between Ryzens of the same calibre. (I won’t be posting any of it for comparison, for obvious reasons.)

    So the upshot is, if you don’t want to be identified right down to your CPU, don’t run programs as root if there’s any chance of them phoning home.

    • nyan@lemmy.cafe
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      9 hours ago

      Question is, what happens if you don’t have dmidecode installed? Even more interesting, what happens if you’ve replaced it with a fake that spews back values of your choosing? If they’re bundling it, given that it appears to be GPL2, they’re opening themselves to a lawsuit unless they provide source upon request.

      (Somehow, I don’t think they’re actually using dmidecode.)

      • ferret@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        6
        ·
        7 hours ago

        dmidecode is a tool for reading loads of platform registers, it is obviously not the only way to do it, or even the intended way really. Riot has almost certainly implemented the functionality from scratch in their anticheat, it’s a relatively trivial thing to do.

      • palordrolap@fedia.io
        link
        fedilink
        arrow-up
        1
        ·
        6 hours ago

        What I’ve read just now is what I’d deliberately not gone looking for up to this point in case I found this out.

        Linux and Windows happen to require that the executables that access that information be run with root privileges, but it looks like that’s merely an affectation.

        It seems that any old piece of software, without root or other privileges, can independently run the CPUID instruction that obtains a processor’s serial number.

        I do not like this one bit.

        • frongt@lemmy.zip
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 hour ago

          Why not? Is that information considered sensitive? Personally I tend to avoid running untrustworthy programs outside of a sandbox or VM.

          • palordrolap@fedia.io
            link
            fedilink
            arrow-up
            2
            arrow-down
            1
            ·
            1 hour ago

            Are you a believer in the idea “They who have nothing to hide have nothing to fear”? Hint: You shouldn’t be.

            And do you know for certain that your sandboxes and VMs don’t simply pass through the CPUID instruction? And if they don’t, do they rotate their fake CPUIDs? And how often does that happen?

    • inari@piefed.zip
      link
      fedilink
      English
      arrow-up
      29
      ·
      1 day ago

      Running proprietary programs as root is my definition of hell, especially when it’s something frivolous like a game

    • dual_sport_dork 🐧🗡️@lemmy.world
      link
      fedilink
      English
      arrow-up
      34
      ·
      1 day ago

      You can extract the chip’s serial number in software trivially. In Windows, from a commandline:

      wmic cpu get pricessorid

      I’m positive you can do the same with some Linux command, and failing that certainly with basically every vaguely modern benchmarking tool. Same deal with hard drives and probably also video cards. My BIOS/UEFI even enumerates all my connected hard drive serial numbers on screen if I interrupt its graphical boot screen.

      Given that the anti-cheat schemes these competitive games are literal rootkits, I don’t think gathering the user’s hardware serial numbers in order to attempt identify them is much of a stretch.

      • Kristell@herbicide.fallcounty.omg.lol
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 day ago

        You at least could in the past, I haven’t had to do it in a while. Seems like the command would just be “dmidecode”, with grep if you’re looking to automate it

    • FireWire400@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      I wonder if Riot would provide any info on the ban status of a certain component when given its ID…

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        5
        ·
        1 day ago

        They would not.

        Anyone doing anti-cheat stuff tries to keep it as secret as possible, so that the cheaters have a more difficult time working around it.

        • JcbAzPx@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          23 hours ago

          It sounds like at least one cheater already figured it out. Just swap the chips. Then sell the old one used and pass the problem onto someone else.

          • AwesomeLowlander@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            3
            ·
            18 hours ago

            From the article, it tracks and blacklists other major system components too, so you would essentially have to replace most of your system. Probably the entire thing, since a single leftover bad component would lead to your entire new system being added to the blacklist.

      • palordrolap@fedia.io
        link
        fedilink
        arrow-up
        6
        ·
        1 day ago

        Either I knew and forgot, or misunderstood it as CPU family identification whenever I’ve come across it. Denial is also a possibility. We’ll see if I remember this in a month or two.

  • Carmakazi@piefed.social
    link
    fedilink
    English
    arrow-up
    26
    ·
    1 day ago

    Happened to a coworker with CoD 2019+ with a Facebook marketplace rig. Was also not being smart, and after he got his account banned and not realizing what was going on, he got his brother to log into his account as a sort of test, and also got that account banned.

  • FireWire400@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    1 day ago

    Wow, that sucks. I don’t even know if you could get your money back for the CPU in that case, as the seller could just claim it wasn’t him. Doesn’t sound like Riot is being that cooperative in such cases either.

    • nyan@lemmy.cafe
      link
      fedilink
      English
      arrow-up
      1
      ·
      9 hours ago

      Claim that it isn’t fully functional (which it isn’t, for the buyer’s use case), and therefore not as described?

    • Dr. Wesker@lemmy.sdf.org
      link
      fedilink
      English
      arrow-up
      12
      ·
      1 day ago

      HWID bans usually involve a much larger fingerprint of the system hardware. Riot would have to be really big assholes not to revert the ban, if they were to snapshot the rest of his system and see that only the CPU was part of the original ban.

      • JcbAzPx@lemmy.world
        link
        fedilink
        English
        arrow-up
        14
        ·
        23 hours ago

        Riot would have to be really big assholes not to revert the ban,

        So, yeah, that’s not getting reverted.

  • lil_baka@ani.social
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    2
    ·
    1 day ago

    What’s wrong with this website. I don’t see the button “reject”. I’m not gonna accept whatever that is just to read this.

  • Yggstyle@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    ·
    1 day ago

    Meanwhile I play(ed) on a VM and would frequently have to fight with support over: no, fuck you - unban me. Virtual hardware isn’t a valid reason to ban every few months. It worked. It was bothersome - so I quit playing. Ample free time for games that weren’t user hostile.

  • mynameisbob@lemmy.ml
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    21
    ·
    19 hours ago

    I just quit gaming. I refuse to be a beta. I don’t give a fuck no more. After Holocaust 2.0 these types of things bring me no joy. Grow up

    • stoy@lemmy.zip
      link
      fedilink
      English
      arrow-up
      4
      ·
      16 hours ago

      Holocaust 2.0?


      Also, I use one criteria for defining an adult:

      “An adult is a person who understands when it is apropriate to be childish”

      Just telling others to “Grow up” means that you have a lot of growing up to do yourself.

  • echo@lemmy.today
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    9
    ·
    1 day ago

    Sounds like FUD… I want to see it confirmed by someone reputable with an explanation before believing it.

      • echo@lemmy.today
        link
        fedilink
        English
        arrow-up
        4
        ·
        24 hours ago

        If they are banning on a single piece of hardware such as a single CPU, then they are morons.

      • Nora (She/Her)@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 day ago

        not op but surely Riot isn’t only looking at CPUs for hardware bans? That leads to all kinda of funky stuff like… well, this. Usually fingerprinting via hardware is a more complete package no?

      • cantstopthesignal@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        1 day ago

        They’ve been hardware finger printing for years now. They one hundred percent know if you’re a piss drinking titty fucker just from your chipset.

      • echo@lemmy.today
        link
        fedilink
        English
        arrow-up
        1
        ·
        24 hours ago

        Their fingerprinting is flawed if this story is true. If I take someone else’s CPU and drop it into what is otherwise different hardware then the fingerprint should absolutely change. If it doesn’t then their fingerprinting is broken and this is going to happen whether any particular CPU has been banned or not.

        It seems far more plausible that someone got themselves banned and they’re lying to try to get out of it.

        • schipelblorp@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          4
          ·
          24 hours ago

          Fingerprinting that is that hyperspecific is the one that’s actually flawed. If you could circumvent a hardware ban by rearranging your RAM sticks, it wouldn’t be much good.

          As it is, the CPU is the one most stable, expensive, and difficult piece to replace, so it makes sense to ban on that alone.

          But, I do agree that cheaters are really slimy fuckers, so what you’re saying is certainly possible. I remember a kid that had his grandmother bring his computer into the shop to see we could evade his hw ban, talked his grandmother into agrreing to buy him a new GPU right in front of us before we turned him down flat.

          • echo@lemmy.today
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            23 hours ago

            In this case they even had a completely different install of Windows. There is simply no way at all that the fingerprint should match. If it did match, then their implementation sucks. Fuck them if they made it that bad intentionally. Better to have to catch and ban the same person 10 times than ban an innocent person even once.

            • schipelblorp@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              1
              ·
              23 hours ago

              I can’t verify that each CPU has a unique id, the way a network card does (MAC address), but it might be a trade secret, who knows.

              As far as banning innocent people, if the math is that one cheater drives away 100 honest players, it’s better to ban up to 99 honest players to get to that 1 cheater.

              • frongt@lemmy.zip
                link
                fedilink
                English
                arrow-up
                3
                ·
                20 hours ago

                A CPU serial number or other ID is more unique than a MAC address, as those can be spoofed, and are not guaranteed to be unique, either. I heard one case of someone tearing their hair out over a mystery network issue, eventually discovering two NICs with the same MAC. And also the case of someone buying a whole pallet of NICs, which turned out to all have the same MAC address.

                But I don’t think that math checks out. A player driven away might return, but a banned player can’t.

                • schipelblorp@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  10 hours ago

                  That pallet of NIC’s: oof! I thought there were complicated methods in place to assure that didn’t happen.

                  As for the math, cheating is a problem because it drives players away. Whatever the math is, there is a number of innocent players that could get swept up in a ban that would be acceptable if enough cheaters were also kicked out. I’m not talking morally, just the viability of an online game.