Anti-Cheat Kernel Driver
eune.leagueoflegends.com
eune.leagueoflegends.com
They don't go into detail here about how far this goes, but I wouldn't be at all surprised to hear that it is directly sending and receiving data from the internet. That is such a bad idea for obvious reasons.
Also, what gives you panic here? What more damage can they do than running in user mode? They can already access all your files, steal all your cookies etc.
So yeah audit does not fill me with confidence.
Any sane security-minded person should slightly panic IMHO.
Alternatively, you could stream a game from a remote server like on Stadia. These anti-cheat systems are only for online games anyway, and you can let Google deal with their kernel driver.
If you mean dual-boot, sure, that's a very reasonable solution as well. I just don't like to reboot often and would personally have a 2nd computer as it probably takes me an hour or more to go from "booted" to "productive"
The "I think I'm going to panic" section is super condescending. It obviously does give surveillance capabilities it didn't previously have: I could previously disallowed the user that was running a game from viewing a file, and Windows would respect that. The game might crash, but it would not have accessed the file.
They are being directly misleading in the article and trying to use technical terms to confuse people. Ick.
That said, they're writing for multiple gun-jumpy audiences so I don't think they lose all of the benefit of the doubt here. Just that this isn't good enough at the moment/yet.
Here was Valve’s elevator pitch of the situation. If you click the link inside OP, you can crawl down the rabbit hole and literally see the code in question.
Again, not Chinese. Fuck China.
How does that compare to American or five eyes countries, given what we know about those situations?
What makes, to you, one a higher threat than the other?
Edit: to be clear I'm trying to work out, as someone who is clearly OK contributing and participating in the Chinese economy (gotta get dat new iphone), why is my concern for the morality of the Chinese government in this exact instance higher than, say, the government I actually live under (UK) or their allies (US and the rest of 5 eyes)
Edit: The implication is that, if the government of China, was exceptionally interested placing a backdoor in the software of a Tencent system, they may not be able to reasonably object. Where if the FBI came to Apple, (and we know they have) they can say no. [1]
[1] https://en.wikipedia.org/wiki/FBI%E2%80%93Apple_encryption_d...
I thought the point was they couldn't say no? Hence the warrant canaries and things like that. And the NSA hooking directly into Google's internal fibre etc etc.
To be clear I think your points are interesting from the perspective of "the chinese government is morally worse and I'm worried about those implications", I'm just trying to work out as someone who doesn't live there (but is clearly OK participating in their economy, I buy endless chinese goods) how that affects me concretely.
My point is, I think it is harder to de-tangle a Chinese corporation's objectives from China (the governments) objectives than say a corporation in the US or EU. There are stronger laws and separation of controls (on the books and in practice) in those regions.
Do I trust the US government? Not terribly. Do I trust the US government more than China as a US Citizen? Yes. Should you? I don't know.
Defending against nation state targeting as an individual may be an impossible task unless you follow in Richard Stallman's footsteps, in which case, the conversation about LoL installing a kernel driver in Windows is very much outside your concerns :)
If the Chinese government came to Apple, could they say no any easier than Tencent?
But that could just be a matter of publicity goals; of it benefiting China's goals for their citizens to know they are watching, and it not benefiting Western governments the same way.
I think it's natural (not necessarily rational) for people to be more skeptical of the goals of outside nations than of their own. Certainly, other nations with a very different and disliked form of government would engender more suspicion, however irrelevant that aspect may actually be.
So we know (right?) that the US government put backdoors in lots of parts of the backbone of the US internet they had access to that wasn't public knowledge, and that they have data sharing agreements with 5 eyes countries so that, for example, they can use their backdoors to send information about canadian citizens to canadian spy authorities without triggering various laws that would otherwise make that information illegal to obtain, and get the reverse in return.
Distrusting Google for their cooperation with government spying in no way precludes avoiding or criticizing Riot's software choices due to the risk and known behaviors of China's government.
> Distrusting Google for their cooperation with government spying in no way precludes avoiding or criticizing Riot's software choices due to the risk and known behaviors of China's government.
Right, so you're saying here that Five Eyes' ability to hack infra isn't comparable to CPC's ability to put backdoors in software? I.e. that while you acknowledge that infra might be compromised, in terms of a collection of bits executing on your computer you trust that software generated by a US company isn't compromised (or is less likely or whatever) compared to software generated by a Chinese company?
Canadians are suspected by more Chinese people than Chinese are suspected by all of North America.
And USA is suspected by, well, everyone, right?
There is obviously more transparency when companies must comply with American or British courts vs the Chinese government. At the same time, all three show very little regard for the privacy of their citizens, and seem to have no problem paying off or breaking into domestic industry to gain information or exert control.
For your case in this exact instance, the Chinese government has no disincentives I can think of from pwning your computer through this kernel driver, besides that it is obviously way more effort than you are probably worth, so you probably don't have to worry about it. Alternatively, were your own government to pwn your computer through this kernel driver, it is possible you could seek legal recourse. Was legal recourse not possible, you could go to the press, who would (I think? I'm not from the UK) be free to print your story.
So yeah, I think its pretty obvious installing a kernel driver from a company under Chinese jurisdiction is less safe than one from a company under American or UK jurisdiction.
But noones targeting you anyways ¯\_(ツ)_/¯
You seem to object to two separate things: 1) the majority owner is scummy; 2) the majority owner is Chinese.
For many people these equate to the same thing. But you have broken them out. So perhaps you don't think all Chinese are scummy. What then is your objection to non-scummy Chinese? Also, would you be ok if it was majority-owned scummy Swedish company?
I think your statement as it stands builds prejudice (unintentionally, I hope) against Chinese simply for being Chinese. I can think of a number of characteristics that bother me about some "Chinese" companies. But they aren't really about the geography. They would apply equally to non-Chinese and could be remedied by any company that exhibited those characteristcs. Thus, I think it would be helpful to list specific objections rather than blanket with "Chinese".
For instance, I'm generally reluctant to online order from a "Chinese" webfront because it takes so long to ship. But for some time now, that critism applies equally to Amazon because they have tried to compete with AliExpress, Banggood, etc. by flooding me with direct-from-China merchandise. It takes just as long to reach me whether I order through Amazon or from Banggood. And Banggood is cheaper. For the exact same product from the exact same source.
By listing my exact complaint, I can warn any Chinese or non-Chinese companies exactly which behaviors I find objectionable. They may not be willing to change being Canadian or French or Texan, but they might be willing to work on my true objection.
You might argue that Chinese companies often don't have a choice on some objectionable matter. But it is a lot easier to push back on their government with, "Such-and-such is a specific business-killer. Don't force this" instead of "Being Chinese is a specific business-killer. Don't force this." And it also sends the message you want to USA, Iran, Venezuela, Poland, etc. companies at the same time.
Wait, really? What surveillance capabilities does LoL already have without a kernel driver?
It is still odd that in all their gaming pushes on windows with things like the Windows 10 Game Mode ( https://support.microsoft.com/en-us/help/4028293/windows-usi... ) that they haven't just made this a "thing" yet. Have a flag or some way for an application to signal that they want their memory actually restricted. You'd at least stop all user-mode cheats overnight, and can also attempt to impose restrictions on kernel-mode drivers. Or let a game know if there's unsigned drivers installed, and let the game segment off that user population.
But I guess they won't do anything about this until someone's kernel-level driver anti-cheat becomes a PR disaster for Microsoft. The same way they didn't do anything about anti-virus protection out of the box until McAfee & Norton went off the deep end and contributed to the constant perception of Window's horrible slowness.
Doubtful. Apple has generally been ratcheting up restrictions on kernel extensions [1] -- currently, kernel extensions must be signed with a developer certificate that has explicit entitlements for kernel extensions, and must be explicitly approved by the user in security settings. [2] A normal Apple developer certificate is not sufficient to sign a kernel extension, and Apple has signalled that they intend to end all support for loadable kernel extensions in the future.
[1]: https://developer.apple.com/support/kernel-extensions/
[2]: https://developer.apple.com/library/archive/technotes/tn2459...
I guess you could look at it as another level of metagame, though.
You win a lot, you get grouped on a server with other winners, you lose a lot, you get grouped on a server with others that lose a lot.
This keeps skill levels (and challenge) consistent.
Or, is that too much of an algorithmic challenge for the game designers?
If they can write the game in the first place, it shouldn't be...
Their most popular game (League of Legends) used to be somewhat playable on Linux through WINE, but that was never officially supported. They've banned Linux users on multiple occasions due to false positives in bot/cheat detection (e.g. [1], [2]), and rolling out this anti-cheat driver is likely to make Linux play completely impossible.
[1]: https://dotesports.com/league-of-legends/news/riot-games-ant...
[2]: https://www.reddit.com/r/leagueoflinux/comments/8pag4y/banne...
It's already been defeated, and it's not like LoL didn't have a crypto miner before.
As annoying as MacOS is, I find myself reassured every now and then that Windows is worse.
> This isn’t even news. Several third party anti-cheat systems— [install kernel drivers]
Is there is a different in a rootkit and kernel driver? I think so.