5 ms·
Fair context: I make cheats/utilities this exact game being talked about in this article, so perhaps my opinion on the subject is biased or even invalid. I par
by johnmg 8y ago
Fair context: I make cheats/utilities this exact game being talked about in this article, so perhaps my opinion on the subject is biased or even invalid.
I partially disagree about the transparency of this article, while they do explain most of their approach to anti-cheat (and that is pretty cool for them to do), they seem to leave out any mention of anything that could be controversial.
It suppose that it does make sense to not mention the implementation details of their anti-cheat, but I wish that they would be a little more transparent about how/when/what they snoop around and send to their servers. The current Mac game client for League Of Legends contains full debug symbols and it doesn't have Packman (the packer described in this article), which makes it quite easy to look through the symbols. Inside you can find all of the anti-cheat-related network packets, in specific:
PKT_C2S_EnumDrivers
PKT_C2S_EnumProcesses
PKT_C2S_EnumDrives
PKT_C2S_EnumHandles
PKT_C2S_EnumRecentFiles
PKT_C2S_EnumModules
PKT_C2S_ProcessorData
PKT_C2S_SystemState
PKT_C2S_ModuleLoadNotification
PKT_S2C_SendModule
PKT_C2S_ModuleResponse
Now, I personally expect anti-cheat to snoop around my system when I'm doing something shady like scanning its memory. However, if I was a normal user of the game, I would be a bit concerned to know that it might be sending my recently used file names, drive names, system driver names, currently running processes, processor information, system state, and even entire binary files that it automatically deems as "suspicious", to their servers.
- mehrdadn 8y agoDo you know if process information contains command-line information? Because that could totally contain someone's credentials...
- ipython 8y agoWouldn't that run afoul of GDPR?
- ryanlol 8y agoThe anticheat team at a videogame company might not know/care about this. This has definitely been the case with past European data privacy regulations.
- lucb1e 8y agoOr it might be deemed reasonable. E.g. you may not film public road in the Netherlands because of privacy, but you may film the patch that your car stands on it if there have been car fires in your neighbourhood in the past month and you are concerned about your car.
- munchbunny 8y agoNot necessarily. GDPR isn't a blanket ban on collecting/using this info without consent, it's a policy that consent is required for non-essential collection/usage. You could argue that anti-cheat is essential for an online multiplayer game like this. I think it's sketchy to collect this much info, but I don't think it's explicitly illegal.
- mikekchar 8y agoIt's a bit more complicated than that. You have to do a few things. First you have to tell the customer that you are collecting their data. Then you have to tell them under what lawful basis you are collecting their data. The user then has various rights (depending on the lawful basis you choose) to object, etc. If you must collect and use the data in order to fulfil the contract (i.e., there is no other way to do it -- for example you need to get their address in order to ship them a package), then you can just do it (as long as you tell them that you are doing it). For most other lawful bases, you have to allow them to object, in which case you have to stop using the data. I think the real question is whether or not the information in question is personally identifiable information. If it's not, then GDPR doesn't apply. I think you could make a pretty strong argument that it doesn't apply, as long as you take pains to ensure that you can't identify the person from the information.
- saagarjha 8y ago> The current Mac game client for League Of Legends contains full debug symbols and it doesn't have Packman Probably because the person writing these anti-cheating facilities isn't as aware of how to implement these on macOS.
- IntelMiner 8y agoUnlikely. More likely there's simply not a very large Mac player base for the game, as compared to Windows
- VectorLock 8y ago>even entire binary files that it automatically deems as "suspicious", to their servers If "deems as suspicious" means "whatever the server tells it to send" I would be very concerned.
- Thaxll 8y agoHow do they know you're not doing something shady if they don't actively scan...
- matheusmoreira 8y agoWhy do you think they have the right to know whether I'm doing something shady? Are they some kind of police? Did they get a warrant?
- matheusmoreira 8y agoI don't expect software I use to scan my hard drives and exfiltrate data ("send samples") to their developers. That's exactly what malware does. Companies just say it's for "security reasons" as if that somehow justified everything. When I read an anti-cheat software's privacy policy, I discovered it could scan my RAM, my files, take screenshots... They're basically trojans. It's not just game companies either. Banks here trick users into installing "security modules" that are actually kernel mode network monitors. I refuse to accept that. These shady anti-cheating practices makes cheaters look good in comparison; similar to how copy protection measures make a genuine product inferior to the cracked version. If a hacker figures out the game's network protocol and writes his own client, he won't have to install a bunch of malware on his machine just to play the game. In my opinion, these developers are the real heroes.
- hycaria 8y agoSo are you living out of that?