• nyan@lemmy.cafe
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    Question is, what happens if you don’t have dmidecode installed? Even more interesting, what happens if you’ve replaced it with a fake that spews back values of your choosing? If they’re bundling it, given that it appears to be GPL2, they’re opening themselves to a lawsuit unless they provide source upon request.

    (Somehow, I don’t think they’re actually using dmidecode.)

    • palordrolap@fedia.io
      link
      fedilink
      arrow-up
      0
      ·
      2 days ago

      What I’ve read just now is what I’d deliberately not gone looking for up to this point in case I found this out.

      Linux and Windows happen to require that the executables that access that information be run with root privileges, but it looks like that’s merely an affectation.

      It seems that any old piece of software, without root or other privileges, can independently run the CPUID instruction that obtains a processor’s serial number.

      I do not like this one bit.

      • phlegmy@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 day ago

        Supposedly only the pentium III returns serial info with CPUID though, and even then it can be disabled in the bios.

      • frongt@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 days ago

        Why not? Is that information considered sensitive? Personally I tend to avoid running untrustworthy programs outside of a sandbox or VM.

        • WhyJiffie@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 days ago

          Personally I tend to avoid running untrustworthy programs outside of a sandbox or VM.

          what does that mean? are you not running any programs at all? you cannot know just by looking at the name if a program reads such sensitive info. and its not unlikely that some developer figured it would be a good idea to include it in automatic crash reports

          yes, this is sensitive information. its like your fingerprint, you cannot change it. I think its quite obvious. web browsers firefox is fighting to hide more and more that even indirectly could lead to identification. websites can’t read this ID, this is just a comparison.

        • palordrolap@fedia.io
          link
          fedilink
          arrow-up
          0
          ·
          2 days ago

          Are you a believer in the idea “They who have nothing to hide have nothing to fear”? Hint: You shouldn’t be.

          And do you know for certain that your sandboxes and VMs don’t simply pass through the CPUID instruction? And if they don’t, do they rotate their fake CPUIDs? And how often does that happen?

    • ferret@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      dmidecode is a tool for reading loads of platform registers, it is obviously not the only way to do it, or even the intended way really. Riot has almost certainly implemented the functionality from scratch in their anticheat, it’s a relatively trivial thing to do.