Dozens of PC games drop tracking software after surveillance fears
wired.co.uk
wired.co.uk
If the software is so benign, offer it to users as totally optional install or a separate download, and see how many agree to that offer.
EDIT: For example, see the official response from the Quake Champions team [1]. Summary: This data vacuum is actually for your own good. That said, we’re busted! So we will remove it for now, and we will tell you about it when we add it later, when everyone chills out.
EDIT2: Wow, so much garbage the further you get through the article:
> [Adam Lieb] expressed his frustration with the response online, which he says painted a false picture of Red Shell as a spyware programme trying to sell data for malicious purposes.
spy·ware
noun
software that enables a user to obtain covert information about another's computer activities by transmitting data covertly from their hard drive.
While they may not be selling the data for malicious purposes, it is, by definition, spyware.
1: https://steamcommunity.com/games/611500/announcements/detail...
Companies could then signal whether they agree to adhere to that code of conduct or not, and use it as a selling point for consumers to tell, at a glance, whether they want to support said company or not.
I have no problem with it being an optional label, but I see no reason it should be enforced legally.
I envision the agreement would be non-binding--it would simply be a list of things we the Consumers want our companies to agree to. The companies can then say yes, we agree to follow your guidelines (perhaps introduce some third party to "certify" that the guidelines have been followed if companies start lying about it).
So it would be very hard for the OS to tell the game, "You can send packets about the player's current position in the gameserver, but you can't send packets back to the software developer that contain fingerprint information." The developer would just encrypt the info and send it all to the same destination to make all packets look the same.
If its free I'm the product: fine. I can live with that. But if I pay for something I don't want spyware and targeted ads.
In nothing changes then tomorrow companies might be copying your whole disk content to their servers. This way they would earn more profit than without disk image analysis.
All you need is a Linux host, some capable entry-level hardware, and two hours in the morning before the house is awake for the initial setup.
Stupid question (since there is no Wikipedia lemma for that term): is that the same as IOMMU? http://enwp.org/IOMMU_hardware_list
Of practical concern is finding out which devices are in which IOMMU groups, because devices within the same group can't be split. For instance, if you had an ethernet controller with two ports, they'd both likely be in the same group, so you couldn't give one to the host and one to a VM.
IOMMU info: https://heiko-sieger.info/iommu-groups-what-you-need-to-cons...
VFIO explanation: https://www.kernel.org/doc/Documentation/vfio.txt
VFIO community: https://www.reddit.com/r/VFIO/
Archwiki: https://wiki.archlinux.org/index.php/PCI_passthrough_via_OVM...
Just SSH in, then after you've done the other configurations and added the GPU's PCI ids to vfio-pci, create the VM with virsh, attaching the GPU. Run "virsh autostart [vmname]", and it'll spawn automatically at each boot.
If you need a host with graphics, you can always unbind the GPU from the host and allow it to be re-attached to VMs if you don't need a headless hypervisor. I know I've seen a few small bash scripts on github for reference.
Err..isn't the point of this exercise to have enough data to identify who bought the game and why? I feel the exact kind of computer I use and the various customizations that lead to it being a unique machine are very personal and identifiable.
> ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
https://gdpr-info.eu/art-4-gdpr/
> ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
[...]
> ‘profiling’ means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
> ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
To layer on some interpretation: * Red Shell is collecting information * which relates to "an identifiable natural person" * who "can be identified [...] by reference to [...] one or more factors specific to the physical [...] identity of that natural person" * where these factors are the information Red Shell is collecting about the software and hardware of their physical devices * and thus are "personal data", as regulated by the GDPR.
Given that their primary purpose is identifying users, they're going to have a hard time arguing that they don't fall under the GDPR's jurisdiction.
The information collected in this program is more than enough to identify me personally, and probably enough to start making some kind of psychological profile to help them predict how to convince me to vote for Donald Trump (or in my case, a Liberal Party member).
You only need good lawyers if you are trying to game it.
It wouldn't be a problem to collect that. If I am informed as well as have the (easy) ability to opt out.
Did they collect after 25. of May? Wouldn't they be liable regarding GDPR?
The problem Red Shell is trying to solve is the "download divide" -- You can track clicks/users on the web before they download, and you can track them after they launch your product, but you can't easily connect the two.
As for why devs want this, if you know ad campaign 1 cost $1 and had 2000 clicks, and ad campaign 2 cost #1 had 1000 clicks, that is helpul but what you really want to know is "what is the lifetime value (LTV) vs cost of acquisition of users from campaign 1 vs 2" because if LTV is significantly different then despite higher cost it may clearly be worth it. But if you can't connect a user from before the download to after you can't do this sort of calculation.
Devs really don't care who the users are, we just want to know how effective a campaign is compared to one another.
Source: Was planning on integrating Red Shell ourselves before this (false) outrage made us cancel our plans.
> "These are generally data points about the user’s device, such as its operating system, installed fonts, browsers (and versions) used, timezone, language, the user’s in-game ID, and screen resolution. This is what Red Shell calls a ‘fingerprint’, which can also be made on games consoles as well as PCs."
Such a fingerprint is very unique and can easily be connected to a person with very little effort down the line, even if now nobody does that (yeah, right).
Personally, I do not trust any company that collects such detailed information without my informed consent and without a clear (i.e. verifiable and legally enforceable) pledge to delete that information when the original purpose has been served. This is exactly the overshooting behaviour that was rightfully targeted by the Europeans with their recent data protection law.
edit: formatting
All of these factors are available to web browsers (which is why they were chosen, so they can be matched up to web clicks). These are tracked in most web analytics suites today by default.
Based on my research I don't believe that these (even all of them together) are PII.
The distinction here is that they have been doing it a very long time, and user privacy actually is a core tenet of what they worry about at Google.
That is vastly different from a spyware module installed clandestinely together with a software I paid for that sends data about me to somewhere and somebody then does something with it that I don't know about.
If you really think this is false outrage you need to work on seeing things from other people's viewpoints
> Consumers do not want to pay money for a product and then also have their data harvested to be used to make even more money off of them.
Agreed. And both the game devs and Red Shell as far as I can see aren't selling this data. The devs are spending money to use Red Shell to try to have better / more cost effective advertising campaigns.
Just collecting the data makes it vulnerable to abuse. What if there is a breach?
I am struggling to think of how this affect my life.
They are outraged because the data is being collected at all, not what you are using it for
The nature of marketing hasn't changed at all over the years. Show an impression, ask what the user was influenced by. Surreptitiously stealing data off of someone's computer as a means of answering the question is flat out the wrong way to do it.
If you take my personal data without my consent, I will consider that an intrusion upon my privacy.
This is why I roll my eyes back into my head every time some marketing suit says "well we anonymize the information" and it's just flat out ridiculous if you think about it, if the information was properly anonymized, then IT COULDN'T BE USED FOR AD TARGETING. Full. Stop.
So if the data collection is for ad targeting, then it's identifiable because it can't not be otherwise it would be useless for the thing it's collected for.
*We sell it to others who do that!
One of the ways malicious people circumvent that is to leverage the scripting that many of the games support. I have dug into many games that use LUA scripting and have appalling security practices. The worse offender is Garry's Mod. Trivial to dox players and fairly trivial in some cases to take over the players machines.
That's a service I'd actually pay for.
I bet intercepting some syscalls + running as another user might go a long way without affecting performance that much.
Give apps a secure sandbox by default, and require them to prompt for any external or 'dangerous' permissions. This gives ultimate control to the user.
Another idea would be to make an exception in the copyright law to allow anyone remove spyware or offer such services.
Check redshells API docs. They turn the data the games client sends to them into a hashed ID.
I think it is related to two very important details.
First, Red Shell purpose, as stated by Red Shell themselves, is to create a "fingerprint" of the computer, yes, each tidbit of info separately is not "identifiable" but the purpose of the software is build indentifiable information in first place.
And second... the game where people found Red Shell first, and went nuts about it, Conan Exiles, is a game that lots of people don't want anyone to know they play it, the game has lots of very politically incorrect themes (slavery for example), and is very popular to use for Erotic Roleplay... People of course get paranoid when there tracking software in their porn!
Actually there has been quite a bit of backlash, there's a thread with around 2000 comments about it in the forums: https://steamcommunity.com/app/289070/discussions/0/17095641...
Also, the recent reviews have been negative because of Red Shell.
> Conan Exiles, is a game that lots of people don't want anyone to know they play it [...] and is very popular to use for Erotic Roleplay
Citation required?
Are you saying that it's difficult for you to google those search terms?
> ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
Claims that deleting the related file causes the game to no longer launch. Why is that necessary for marketing tracking or were they just too lazy to skip over that particular file not found error?
That the SteamID can be transmitted. Seems like identifiable information to me despite the claims otherwise.
There is a way to opt out of the tracking. Going to the opt out page I see a request for your gamer ID for the game in question. Which goes back to that being identifiable information. It also states a game could have opt out options in place so I'm wondering why those seem to not be available in the game?
At this point I say I'm surprised that their actually is surprise from developers at this backlash. This sort of things gets attempted every few years that comes to the same result.
Not sure if that is deliberate or not, but I'd like to submit a GDPR subject access request! Coincidence? perhaps.
Edit: privacy@redshell.io Looks like their webpage might be trying to do a "mailto:" link? For me it just opens a blank window and I cant be bothered to try and pick apart their javascript.
Sorry Abid, but that's not true. I avoid Google products and services because I am uncomfortable with how invasive their tracking program is. I've worked in advertising tech, and I have a good idea of what goes on inside these companies. I do not ever want to participate in that ecosystem again. I even browse the web with JavaScript disabled in order to avoid tracking.
That said, I don't blame Abid. I know it can be hard to bootstrap a small games studio. In fact, I played one of his studio's games (the weapon shop one) and it was fun. I wish him and his company luck, but I hope he doesn't go back to tracking customers without consent. I avoid purchasing products that include this kind of tracking.
Red Shell could theoretically do whatever the hell it wants on your machine. And if it uses online updates, then you really never know what it could be tracking at any given time.
This should not be normal. If the company wants to use tracking and analytics then they should at least disclose it in advertising materials, and on the game store page. Or maybe make two versions of the game, with and without tracking, so that anyone would be free to chose whatever they prefer.
And who cares about marketing or ad performance? That is not a consumer's problem.
there is absolutely no game on steam without DRM and anti-cheat rootkits. none. zero. All games there have either or. including steam itself. It's all a matter of how far they go.
Most games, and obviously all single player games, also have no form of anti-cheat.
https://pcgamingwiki.com/wiki/The_Big_List_of_DRM-Free_Games...
This list is pretty incomplete, and in my experience many if not most indie games fall into this category.
Your assertions are entirely incorrect.
i said DRM and/or anti-cheat. 100% of valve games have anti-cheat.
Both of those run as administrator and have a great deal of opaque control of your machine.
https://unity3d.com/legal/gdpr
Despite their claims, I've never seen any opt out options like that. Games simply always collect data and send it "home". And really this should be opt-in.