Question is, what happens if you don’t have dmidecode installed? Even more interesting, what happens if you’ve replaced it with a fake that spews back values of your choosing? If they’re bundling it, given that it appears to be GPL2, they’re opening themselves to a lawsuit unless they provide source upon request.
(Somehow, I don’t think they’re actually using dmidecode.)
What I’ve read just now is what I’d deliberately not gone looking for up to this point in case I found this out.
Linux and Windows happen to require that the executables that access that information be run with root privileges, but it looks like that’s merely an affectation.
It seems that any old piece of software, without root or other privileges, can independently run the CPUID instruction that obtains a processor’s serial number.
Personally I tend to avoid running untrustworthy programs outside of a sandbox or VM.
what does that mean? are you not running any programs at all? you cannot know just by looking at the name if a program reads such sensitive info. and its not unlikely that some developer figured it would be a good idea to include it in automatic crash reports
yes, this is sensitive information. its like your fingerprint, you cannot change it. I think its quite obvious. web browsers firefox is fighting to hide more and more that even indirectly could lead to identification. websites can’t read this ID, this is just a comparison.
Are you a believer in the idea “They who have nothing to hide have nothing to fear”? Hint: You shouldn’t be.
And do you know for certain that your sandboxes and VMs don’t simply pass through the CPUID instruction? And if they don’t, do they rotate their fake CPUIDs? And how often does that happen?
dmidecode is a tool for reading loads of platform registers, it is obviously not the only way to do it, or even the intended way really. Riot has almost certainly implemented the functionality from scratch in their anticheat, it’s a relatively trivial thing to do.
This is not running it as root (i.e. privileged userland, still ring 3), this is running it as ring 0 (i.e. the level that the kernel runs at, with no restrictions on access to memory and hardware at all). A tiny bug in ring 0 code can take down the system or open security vulnerabilities, where the kernel can provide more hardening to protect applications to an extent.
Either I knew and forgot, or misunderstood it as CPU family identification whenever I’ve come across it. Denial is also a possibility. We’ll see if I remember this in a month or two.
From the article, it tracks and blacklists other major system components too, so you would essentially have to replace most of your system. Probably the entire thing, since a single leftover bad component would lead to your entire new system being added to the blacklist.
You can extract the chip’s serial number in software trivially. In Windows, from a commandline:
wmic cpu get pricessorid
I’m positive you can do the same with some Linux command, and failing that certainly with basically every vaguely modern benchmarking tool. Same deal with hard drives and probably also video cards. My BIOS/UEFI even enumerates all my connected hard drive serial numbers on screen if I interrupt its graphical boot screen.
Given that the anti-cheat schemes these competitive games are literal rootkits, I don’t think gathering the user’s hardware serial numbers in order to attempt identify them is much of a stretch.
You at least could in the past, I haven’t had to do it in a while. Seems like the command would just be “dmidecode”, with grep if you’re looking to automate it
I would be very interested to know how they are able to identify a specific CPU. The article speculates but does not answer this question.
The fact that this is even possible is a security nightmare.
Question is, what happens if you don’t have dmidecode installed? Even more interesting, what happens if you’ve replaced it with a fake that spews back values of your choosing? If they’re bundling it, given that it appears to be GPL2, they’re opening themselves to a lawsuit unless they provide source upon request.
(Somehow, I don’t think they’re actually using dmidecode.)
What I’ve read just now is what I’d deliberately not gone looking for up to this point in case I found this out.
Linux and Windows happen to require that the executables that access that information be run with root privileges, but it looks like that’s merely an affectation.
It seems that any old piece of software, without root or other privileges, can independently run the CPUID instruction that obtains a processor’s serial number.
I do not like this one bit.
Supposedly only the pentium III returns serial info with CPUID though, and even then it can be disabled in the bios.
Why not? Is that information considered sensitive? Personally I tend to avoid running untrustworthy programs outside of a sandbox or VM.
what does that mean? are you not running any programs at all? you cannot know just by looking at the name if a program reads such sensitive info. and its not unlikely that some developer figured it would be a good idea to include it in automatic crash reports
yes, this is sensitive information. its like your fingerprint, you cannot change it. I think its quite obvious.
web browsersfirefox is fighting to hide more and more that even indirectly could lead to identification. websites can’t read this ID, this is just a comparison.Are you a believer in the idea “They who have nothing to hide have nothing to fear”? Hint: You shouldn’t be.
And do you know for certain that your sandboxes and VMs don’t simply pass through the CPUID instruction? And if they don’t, do they rotate their fake CPUIDs? And how often does that happen?
dmidecode is a tool for reading loads of platform registers, it is obviously not the only way to do it, or even the intended way really. Riot has almost certainly implemented the functionality from scratch in their anticheat, it’s a relatively trivial thing to do.
Running proprietary programs as root is my definition of hell, especially when it’s something frivolous like a game
This is not running it as root (i.e. privileged userland, still ring 3), this is running it as ring 0 (i.e. the level that the kernel runs at, with no restrictions on access to memory and hardware at all). A tiny bug in ring 0 code can take down the system or open security vulnerabilities, where the kernel can provide more hardening to protect applications to an extent.
You could say this is the inner circle of hell.
This has been a thing for decades
Either I knew and forgot, or misunderstood it as CPU family identification whenever I’ve come across it. Denial is also a possibility. We’ll see if I remember this in a month or two.
I wonder if Riot would provide any info on the ban status of a certain component when given its ID…
They would not.
Anyone doing anti-cheat stuff tries to keep it as secret as possible, so that the cheaters have a more difficult time working around it.
It sounds like at least one cheater already figured it out. Just swap the chips. Then sell the old one used and pass the problem onto someone else.
From the article, it tracks and blacklists other major system components too, so you would essentially have to replace most of your system. Probably the entire thing, since a single leftover bad component would lead to your entire new system being added to the blacklist.
You can extract the chip’s serial number in software trivially. In Windows, from a commandline:
wmic cpu get pricessoridI’m positive you can do the same with some Linux command, and failing that certainly with basically every vaguely modern benchmarking tool. Same deal with hard drives and probably also video cards. My BIOS/UEFI even enumerates all my connected hard drive serial numbers on screen if I interrupt its graphical boot screen.
Given that the anti-cheat schemes these competitive games are literal rootkits, I don’t think gathering the user’s hardware serial numbers in order to attempt identify them is much of a stretch.
You at least could in the past, I haven’t had to do it in a while. Seems like the command would just be “dmidecode”, with grep if you’re looking to automate it