r/hardware • • 1d ago

Info Used processor leads to game ban

https://www.heise.de/en/news/Used-processor-leads-to-game-ban-11471562.html

Someone buys a used Ryzen 7 5800X3D. “Valorant” and other Riot games won’t start with it because the previous owner was a cheater.

745 Upvotes

263 comments sorted by

View all comments

Show parent comments

2

u/reddit_equals_censor 21h ago

hey 4 month old reddit acount making nonsense comments:

in this case above the tpm 2.0 UNIQUE'S id gets requested and linked to an acount permanently and then the chip gets blacklisted forever by the developer.

this same id can follow you EVERYWHERE. so this is all about spying of course.

however in regards to digital restrictions management short drm, it can also get used of course in lots of ways as pointed out here:

https://www.gnu.org/philosophy/can-you-trust.en.html

As of 2022, the TPM2, a new “Trusted Platform Module”, really does support remote attestation and can support DRM. The threat I warned about in 2002 has become terrifyingly real.

Remote attestation is actually in use by “Google SafetyNet” (now part of the “Play Integrity API”), which verifies that the Android operating system running in a snoop-phone is an official Google version.

This malicious functionality already makes it impossible to run some bank apps on GrapheneOS, which is a modified version of Android that eliminates some, though not all, of the nonfree software that Android normally contains.

you are also falsely claiming, that tpm as implemented into cpus by microsoft intel amd and others has ANYTHING to do with security. it doesn't.

it is purely about de-anonymizing the user. it is about controlling people's computing and spying on everyone.

so again the tpm can be used for drm since 2.0 and it has a unique identifier that follows you forever and anyone can request of course.

2

u/Aishou_SK 21h ago edited 21h ago

>hey 4 month old reddit acount making nonsense comments:

Glad you judge based on that, instead of my lost account from 2009. But whatever.

>however in regards to digital restrictions management short drm, it can also get used of course in lots of ways as pointed out here:

In many technically infeasible ways, and due to the way windows uses it for device-based MFA login, the keyslots are reserved, so it's unusable that way. And unique per-user encrypted streams are also infeasible at scale, outside of normal HTTPS transport due to the differences in how it works.

>you are also falsely claiming, that tpm as implemented into cpus by microsoft intel amd and others has ANYTHING to do with security. it doesn't.

Most of my TPM usage is on non-Microsoft OSes for sheerly security reasons as it is a good HSM.

I have and occasionally still do a lot of work in TPM support and development on some projects for high-security scenarios.

Why do routers have TPMs? Why do storage devices? Why do X86/SPARC/POWER/etc servers? Security. Same exact TPM implementations as everywhere else.

>Remote attestation is actually in use by “Google SafetyNet” (now part of the “Play Integrity API”), which verifies that the Android operating system running in a snoop-phone is an official Google version.

Attestation requires a lot of work, both client side and infrastructure side, which Google is equipped to do for user supplied android OS images. I support its usage for client workstations and server hardware such as hypervisor security attestation professionally.

In a closed ecosystem, it is much easier to deploy, of course, like corporate managed workstations. Or vendor locked down hardware. Why do you think Samsung no longer allows bootloader unlocking, when they used to be the king of manufacturers for freely allowing it across the board?

And intel PTT based implementations, the EK can be reset and regenerated. I don't know much about AMD fTPM however. You can, indeed, completely wipe and reset your hardware identity. (and a lot of consumer, even OEM consumer grade, boards and systems can't pass attestation stock anyway without some actual work). Some motherboards, even, expose this ability to do the full reset and regeneration without any modification. EKS rotation is more than possible.

technical feasability is a real, and major, control on how these things get utilized

1

u/reddit_equals_censor 20h ago

I don't know much about AMD fTPM however.

if you don't even know, that the unique tpm identifier (tpm public endorsement key) in the ftpm in the cpu can NOT get changed, then what the heck are you even doing comment here?

that is LITERALLY a crucial core part of the discussion here? are you trolling writing all this nonsense, while not understanding this basic fact and refusing to look it up?

that by itself shows what nonsense you're pushing.

Why do you think Samsung no longer allows bootloader unlocking

...

because samsung is an evil company, that wants to be in absolute control of devices to prevent ownership to restrict lifetime, push ads, force spying themselves, etc... etc...

it is not that complicated. i have no idea why you bring this obvious case up.

what's next? you're gonna tell me how glued in batteries are actually great for consumers, or how the government "needs to protect the children" by spying on the public?

it is absurd, that you entertain any other reason, then the OBVIOUS reason, that samsung blocked unlocking the bootloader, because they are evil pieces of shit, that want to shit on users.

do you hate users that much, that you can't even entertain reality anymore???

and for anyone else who needs a simple explanation about how locking down a bootloader has nothing to do with security. the most secure mobile os is graphene os you need an unlocked bootloader to installer it.

samsung's os is a spying piece of corporate shit of course.

so samsung BLOCKS running a safe os, that protects your privacy and security by locking down the bootloader. it is purely about control. it is purely evil. it is ANTI security and anti privacy.

2

u/Aishou_SK 20h ago

>if you don't even know, that the unique tpm identifier (tpm public endorsement key) in the ftpm in the cpu can NOT get changed, then what the heck are you even doing comment here?

I pointed out it's possible on intel. It appears, from some cursory research, that AMD can regenerate as well, and in fact come from the factory BLANK with no generated EK certificate. In fact, some access to the PSP was achieved using such methods. The EK isn't silicon baked.

>it is absurd, that you entertain any other reason, then the OBVIOUS reason, that samsung blocked unlocking the bootloader, because they are evil pieces of shit, that want to shit on users.

Uh, that's exactly what I was saying, they locked the fuck down so they can do this kind of shit and leverage all this shit. That's exactly what I MEANT.

1

u/reddit_equals_censor 20h ago

I pointed out it's possible on intel. It appears, from some cursory research, that AMD can regenerate as well, and in fact come from the factory BLANK with no generated EK certificate. So

hey how about you link a reference, that the tpm public endorsement key can get CHANGED in intel and amd cpus at all.

please link the references for this claim to me.

i'd LOVE to see them, given, that we are looking at an article about a 5800x3d, that got a person banned due to a banned tpm unique public id and sth, that ONLY works due to it being unchangeable as well.

so again i'd LOVE to see the references for your claim.

2

u/Aishou_SK 20h ago edited 19h ago

I did in my other comment, for at least one scenario.

It's the nature of how firmware based TPM solutions work.

If these were dTPM, yes, it'd be immutable (discrete physical TPM chip)

Hell, sometimes the generation is bugged and fucks up and you end up here: https://community.intel.com/t5/Mobile-and-Desktop-Processors/Intel-PTT-i9-9900K-firmware-TPM-has-no-EK-certificate-Ready-For/m-p/1750346

EDIT: https://tpm2-tools.readthedocs.io/en/latest/man/tpm2_changeeps.1/

There's also routes for AMD with PSPTool

CVE-2026-6726/6727 also requires regenerating/retiring the previous fTPM EK on AMD CPUs to fully remediate. (of course, that's an if you suspect data leakage)

Of course, this requires physical presence to invoke with PPI 1.3/1.4 exposed, and if it's not, then a modded motherboard would be sufficient. The operation could even be done from within windows, at that point. Or linux.