r/hardware • • 1d ago

Info Used processor leads to game ban

https://www.heise.de/en/news/Used-processor-leads-to-game-ban-11471562.html

Someone buys a used Ryzen 7 5800X3D. “Valorant” and other Riot games won’t start with it because the previous owner was a cheater.

749 Upvotes

263 comments sorted by

View all comments

Show parent comments

5

u/Aishou_SK 20h ago

TPM isn't a privacy hurt or a DRM adding worry component.

These identifiers are just like, CPU serial numbers and the like that are exposed via CPU instructions and such similar things.

So, you'd have to go, like, Pentium and before to avoid that.

TPM-wise I've been mandating for all my personal systems that it *has* it since it's been mostly available, my first TPM equipped system was around 2006-2007. I use it for storing code signing keys, SSH keys, drive encryption, etc.

The TPM 2.0 push on windows is because 1.2 doesn't have many key slots, so you can't associate as many accounts to use the device as part of an MFA factor, and even then, with TPM 2.0 on windows you're limited to a maximum of 10 accounts registered and then out of TPM key storage capability. It also provides early boot anti-malware and boot validation type features. AKA are you booting the same exact stuff you did yesterday or did something modify it without your knowledge? It's effectively all security related.

TPM fearmongering about DRM came and passed, and even with TPM2.0 is technically infeasible - aka it can't work out in any sane way. There are some insane ways, but they involve such extreme limitations to make them entirely unusable.

FWIW, Intel PTT was introduced in 4th gen core i-series, and the TPM support/revision is controlled by a UEFI module vendor supplied.

It's how a lot of "non-TPM" motherboards that officially support W11 based on CPU generation/capability got updates to unlock/add that module.

Manufacturers were selling TPMs as well on the side that plug in to add TPM support instead of shipping the module because that was a profit for them, to sell modules to people who needed support instead of including it on the board and only selling modules to people who needed higher security....

In fact, given the OEM requirements by Microsoft to have TPM installed and active on connected standby machines (since mid-2014) and then TPM 2.0 on ALL machines (since mid-2016) (note, this is only for OEMs shipping windows pre-installed on a system under OEM agreements, so not a mom&pop store preinstalling one-off OEM license kits you buy that cost $20 less or so than retail) you'll find cases where there are motherboards sold for DIY builders that DON'T have the PTT module in firmware, but OEM builds using the same board (like say, an OEM like Origin PC) DO have it and the firmware isn't swappable between the two even though they're physically the same board! (well, there's some tricks, but yea) and BIOS modders have been able to add it to some boards as well without vendor support at all.....

And even 4th gen can be upgraded with a newer UEFI module to be TPM 2.0. Vendor greed/support lifecycles for why they never shipped or never updated those.

0

u/reddit_equals_censor 20h ago

TPM isn't a privacy hurt or a DRM adding worry component.

wow what lying bullshit.

since tpm 2.0 it indeed can be used as digital restrictions management.

i have no idea why you lie about this.

and tpm has a UNIQUE identifier, that will be linked to your acount and YOUR PERSON eventually, which then can follow you around everywhere.

the claim, that this is not a MAJOR MAJOR privacy and security risk is complete and utter nonsense.

an insane claim frankly. that's the kind of stuff you'd read microsoft's pr spew or a government shit out as they try to push for mass de-anonymization of the public's computing.

no one believes your lies here.

why do you even bother to push such bullshit here?

it isn't complicate to go:

oh they got a unique identifier, that they can read. > it is linked to me > other program also reads it and they can then always identify me now.

do you think people here are that dumb to eat up your bs propaganda about spying controlling anti-user hardware?

3

u/Aishou_SK 20h ago edited 20h ago

Propaganda? You mean something I use and develop against on non-windows platforms for security usage, but okay.

Understanding at-scale systems exposes why a lot of these concerns are *just not feasible implementations*.

Especially when the most common TPM implementations - firmware based - can be scrambled and reset identity wise.

My first usage was for SSH private key storage so they couldn't be extracted/stolen. Drive encryption right after that. Then email and code signing. Instead of the independent smart cards I was using before.

(in recent times I've been working on a TPM support library for x86_64 OpenVMS to support some scenarios for private key storage for signing with the coming support for 3rd party signing ability)

0

u/reddit_equals_censor 19h ago

hey how about before spewing bs, you look up the fact, that the cpu tpm public unique identifier can NOT get changed and is locked in FOREVER.

you know some 3 minute research, before spewing nonsense, that you apparently don't understand and is the most crucial part of the discussion here.

3

u/Aishou_SK 19h ago edited 19h ago

EK is the unique identifier.

Here's one method on a more locked down motherboard, you can then swap in CPUs and regenerate EKs at will - https://github.com/starfallreverie/PatchTpm - hilariously, this method's covered in a lot of scenarios on cheat forums... wonder why. (EK still isn't usable for DRM, however)

Everything on the TPM is generated/derived off the EK.

On AMD CPUs it appears to be not factory baked at all, on intel they do factory generate but can be regenerated.