Chinese-owned Riot installs rootkit on every League of Legends players' computer
osnews.com
osnews.com
for those not in the loop, Vanguard is the anti-cheat Riot Games created for Valorant, their competitive first person shooter. The issue with Vanguard is that it's quite an aggressive anti-cheat, it runs on Ring 0 as a windows kernel driver. Hence, why some people call it a "rootkit".
Don't game on a computer with any other sensitive information on it.
Typically, yes, egregiously. We need either computing platforms that sandbox things fully, or else full control over our software. And an end to these Eula’s Eula’s that, let’s be honest, could ask for anything and we couldn’t say no. Even governments get stuck here and can’t refuse
They’re doing what seems to be literally the standard for windows anti cheat. That they’re Chinese owned is moot as worrying about evil Chinese government hackers is to me a secondary concern to the long and illustrious history of terrible security vulnerabilities in all kernel mode “anti-cheat” drivers.
It seems much more likely that this anti cheat driver is just as buggy as every other anti cheat driver, and will end up being exploited by the same groups that every prior driver has been.
My view is that the correct fix for anti cheating is simply pitting all suspected cheaters against each other rather than trying to ban/block them.
I feel that security minded folks are apt to avoid installing software from notably untrusted vendors on important machines. If Riot ends up malicious then I'm not sure that kernel level access is capable of _that_ much more damage than what's required for a 'regular' anticheat to function. My bank account is unsafe either way. Obviously less access is better, but it feels like discussion around Vanguard always distills into an argument that would also suggest Riot's software to be untrustworthy even without a ring-0 anticheat.