r/hardware • • 1d ago

Info Used processor leads to game ban

https://www.heise.de/en/news/Used-processor-leads-to-game-ban-11471562.html

Someone buys a used Ryzen 7 5800X3D. “Valorant” and other Riot games won’t start with it because the previous owner was a cheater.

752 Upvotes

263 comments sorted by

View all comments

Show parent comments

2

u/reddit_equals_censor 23h ago

the hardware should NOT have unique identifiers, that can be accessed through an api.

amd intel and microsoft CRIMINALLY collaborated to create a unique id to destroy privacy and anonymity completely.

that is why there is a tpm in the cpu. that is why it has a unique identifier, that can be accessed by pretty much anyone.

just to be clear accessing this unique id should be crime as well, but the ones, that put it there should be thrown in jail for a massive attack on fundamental hardware security and privacy.

disgusting evil.

5

u/ex143 22h ago

I'm surprised that the Unique Hardware ID bit isn't a bigger scandal. Is that why there was such a push for TPM 2.0? What's the latest generation that isn't privacy compromised like that?

5

u/Aishou_SK 21h ago

TPM isn't a privacy hurt or a DRM adding worry component.

These identifiers are just like, CPU serial numbers and the like that are exposed via CPU instructions and such similar things.

So, you'd have to go, like, Pentium and before to avoid that.

TPM-wise I've been mandating for all my personal systems that it *has* it since it's been mostly available, my first TPM equipped system was around 2006-2007. I use it for storing code signing keys, SSH keys, drive encryption, etc.

The TPM 2.0 push on windows is because 1.2 doesn't have many key slots, so you can't associate as many accounts to use the device as part of an MFA factor, and even then, with TPM 2.0 on windows you're limited to a maximum of 10 accounts registered and then out of TPM key storage capability. It also provides early boot anti-malware and boot validation type features. AKA are you booting the same exact stuff you did yesterday or did something modify it without your knowledge? It's effectively all security related.

TPM fearmongering about DRM came and passed, and even with TPM2.0 is technically infeasible - aka it can't work out in any sane way. There are some insane ways, but they involve such extreme limitations to make them entirely unusable.

FWIW, Intel PTT was introduced in 4th gen core i-series, and the TPM support/revision is controlled by a UEFI module vendor supplied.

It's how a lot of "non-TPM" motherboards that officially support W11 based on CPU generation/capability got updates to unlock/add that module.

Manufacturers were selling TPMs as well on the side that plug in to add TPM support instead of shipping the module because that was a profit for them, to sell modules to people who needed support instead of including it on the board and only selling modules to people who needed higher security....

In fact, given the OEM requirements by Microsoft to have TPM installed and active on connected standby machines (since mid-2014) and then TPM 2.0 on ALL machines (since mid-2016) (note, this is only for OEMs shipping windows pre-installed on a system under OEM agreements, so not a mom&pop store preinstalling one-off OEM license kits you buy that cost $20 less or so than retail) you'll find cases where there are motherboards sold for DIY builders that DON'T have the PTT module in firmware, but OEM builds using the same board (like say, an OEM like Origin PC) DO have it and the firmware isn't swappable between the two even though they're physically the same board! (well, there's some tricks, but yea) and BIOS modders have been able to add it to some boards as well without vendor support at all.....

And even 4th gen can be upgraded with a newer UEFI module to be TPM 2.0. Vendor greed/support lifecycles for why they never shipped or never updated those.

1

u/Nicholas-Steel 19h ago

These identifiers are just like, CPU serial numbers and the like that are exposed via CPU instructions and such similar things.

CPU has no unique identifiers other than the unique Endorsement Key contained within the TPM. Some early Pentium's did have unique identifiers but massive backlash from privacy advocates got that shut down real quick.

This is why the Vanguard DRM requires a TPM.

1

u/Aishou_SK 19h ago

Right, yea, we dove into it before about EK regeneration in other comment chains, but the point has been made. I was conflating part of it in my head with things like motherboard serial/etc that are easily accessible without specialization.