• Dalaryous@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 day ago

    Even if I’d ever switched back to Windows, no kernel anti-cheat would ever be allowed without some kind of isolation. It is just another data theft tool that happens to also include half-broken anti-cheat. I’m sure gaming companies have already started selling data for profit.

  • AnimalsDream@slrpnk.net
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 days ago

    Oh, something about a game that doesn’t work on Linux. What are the most direct competitors to Valorant that work on Linux? I’m gonna go play those out of spite.

      • AnimalsDream@slrpnk.net
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        To be honest I’ve never found the mechanics in Counter-Strike games enjoyable. Not trying to hate, I’m sure it’s great for those who like it, I just don’t think it’s for me.

        I think the two pvp fps games I’ve found to have the closest to ideal mechanics is Doom 2016, and Red Eclipse 2. In Doom I liked that it had some of the more Call of Duty-esque features like loadouts, and a multiplayer progression system. And I especially liked how the actual combat preserved that classic arena shooter feel in kind of an brilliant way. They made it so right click had that iron sights feature, but which also applied a secondary fire ability - but crucially it was entirely optional for basically every weapon. Like in classic arena shooters you could be in constant motion and shoot from the hip without any penalties to your aiming.

        Red Eclipse does this too (plus has crazy parkour features), but last I checked lacks any kind of progression system for better and worse.

        Titanfall 2 is pretty fun as well, but I am really bad at that game in multiplayer.

  • youmaynotknow@lemmy.zip
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 days ago

    Phillip Koskinas, Riot’s Head of Anti-Cheat, writes on X that hardware bans last for a maximum of four months and apply exclusively to the game in which a cheater was caught.

    Now we have a name. He probably thinks he is doing the Lord’s work with kernel-level anticheat, and we should all be grateful for his awesome contributions to gaming 🤣

      • Zron@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 days ago

        I would think that pulling hardware ID values would be an administration level task, requiring root or kernel level access. So yes they are related or at least should be.

    • Smoogs@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 days ago

      valorant is the facebook of games. only boomers blithly ok with human right violations linked to the socials they use would think it is a good idea to stick with it

  • carrylex@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 days ago

    Ah classic Riot games, investing all the money in anti-cheat while their launcher lacks basic functions like “download throttling”.

    No idea how Steam keeps winning…

  • palordrolap@fedia.io
    link
    fedilink
    arrow-up
    1
    ·
    4 days ago

    I would be very interested to know how they are able to identify a specific CPU. The article speculates but does not answer this question.

    The fact that this is even possible is a security nightmare.


    OK, I’ve done a bit more digging and pieced it together. Acknowledgement to @[email protected] for prompting me to try (again) to find a command that might do it among other things.

    IMO, this sort of information shouldn’t be in processors in the first place, but apparently it is there and needs admin/root access to, well, access it.

    … and the game in question requires kernel-level anti-cheat, so of course, it has the necessary access.

    The command for Linux is sudo dmidecode -t processor, which dumps a lot of info including an ID field, which is supposedly the CPU’s specific identifier. It can be grepped for or otherwise filtered out.

    My own Ryzen gives 8 hexadecimal pairs, so it’s a 64-bit value.

    I would not know that that was unique to my specific individual processor if I had not been told, but I’ll assume that at least part of it is not unique between Ryzens of the same calibre. (I won’t be posting any of it for comparison, for obvious reasons.)

    So the upshot is, if you don’t want to be identified right down to your CPU, don’t run programs as root if there’s any chance of them phoning home.

    • inari@piefed.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 days ago

      Running proprietary programs as root is my definition of hell, especially when it’s something frivolous like a game

      • A1kmm@lemmy.amxl.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 days ago

        This is not running it as root (i.e. privileged userland, still ring 3), this is running it as ring 0 (i.e. the level that the kernel runs at, with no restrictions on access to memory and hardware at all). A tiny bug in ring 0 code can take down the system or open security vulnerabilities, where the kernel can provide more hardening to protect applications to an extent.

        You could say this is the inner circle of hell.

    • nyan@lemmy.cafe
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 days ago

      Question is, what happens if you don’t have dmidecode installed? Even more interesting, what happens if you’ve replaced it with a fake that spews back values of your choosing? If they’re bundling it, given that it appears to be GPL2, they’re opening themselves to a lawsuit unless they provide source upon request.

      (Somehow, I don’t think they’re actually using dmidecode.)

      • palordrolap@fedia.io
        link
        fedilink
        arrow-up
        1
        ·
        3 days ago

        What I’ve read just now is what I’d deliberately not gone looking for up to this point in case I found this out.

        Linux and Windows happen to require that the executables that access that information be run with root privileges, but it looks like that’s merely an affectation.

        It seems that any old piece of software, without root or other privileges, can independently run the CPUID instruction that obtains a processor’s serial number.

        I do not like this one bit.

        • frongt@lemmy.zip
          link
          fedilink
          English
          arrow-up
          0
          ·
          3 days ago

          Why not? Is that information considered sensitive? Personally I tend to avoid running untrustworthy programs outside of a sandbox or VM.

          • WhyJiffie@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 days ago

            Personally I tend to avoid running untrustworthy programs outside of a sandbox or VM.

            what does that mean? are you not running any programs at all? you cannot know just by looking at the name if a program reads such sensitive info. and its not unlikely that some developer figured it would be a good idea to include it in automatic crash reports

            yes, this is sensitive information. its like your fingerprint, you cannot change it. I think its quite obvious. web browsers firefox is fighting to hide more and more that even indirectly could lead to identification. websites can’t read this ID, this is just a comparison.

              • WhyJiffie@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                1
                ·
                23 hours ago

                have you ever used Gentoo? if you do, you know how long it takes to build updated software from source code.

                vetting all that, even just the changes would take a lot more time. and it’s a constant effort.

                • Axolotl.cpp@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  12 hours ago

                  Never used gentoo but i do build the software i use often

                  vetting all that, even just the changes would take a lot more time. and it’s a constant effort.

                  First of all, I am, like you and everyone else not alone in this, and for changes it’s sooo easy thanks to Git

      • ferret@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        3 days ago

        dmidecode is a tool for reading loads of platform registers, it is obviously not the only way to do it, or even the intended way really. Riot has almost certainly implemented the functionality from scratch in their anticheat, it’s a relatively trivial thing to do.

    • FireWire400@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      4 days ago

      I wonder if Riot would provide any info on the ban status of a certain component when given its ID…

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 days ago

        They would not.

        Anyone doing anti-cheat stuff tries to keep it as secret as possible, so that the cheaters have a more difficult time working around it.

        • JcbAzPx@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          4 days ago

          It sounds like at least one cheater already figured it out. Just swap the chips. Then sell the old one used and pass the problem onto someone else.

  • w3dd1e@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 days ago

    The article says because he installed the chip and launched Valorant, his other PC components such as his motherboard are not also blocked.

    He can’t play a Riot game unless he buys an entirely new computer.

  • lil_baka@ani.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    4 days ago

    What’s wrong with this website. I don’t see the button “reject”. I’m not gonna accept whatever that is just to read this.