Company promises countermeasures against new DRM bypasses — zero-day game releases become norm as security concerns mount over hypervisor-based bypass

all 43 comments

sorted by: hot top controversial new old
[–] [S] 127 points 5 months ago* (15 children)

Good luck

Using the hypervisor bypass, even in its latest incarnation, requires users to disable:

  1. Virtualization-Based Security (VBS): a layer that separates the Windows operating system from the its security enforcement features that run at a higher privilege level.
  2. Credential Guard: a sub-feature of VBS that keeps login credentials in an container isolated from the rest of the operating system.
  3. Driver Signature Enforcement: verification that any drivers installed in the system must have a digital signature issued by Microsoft to an identifiable company or developer, in order to prevent installing random drivers at the system level.
  4. Core Isolation / Memory Integrity (HVCI): similar to the above, but prevents any kernel-level unsigned code entirely, as well as modifications to existing signed code so programs can't attempt to mess with existing drivers.
  5. Installing a community-made hypervisor (HV) with Windows running on top of it. This HV fakes responses to the checks that Denuvo makes, and runs with higher permissions (ring level -1) than the operating system itself and has full, nearly untraceable access to hardware and software.
  • source
  • hideshow 30 child comments
  • [–] 73 points 5 months ago (2 children)

    First 4 are disabled on unsupported systems anyway (4 is also sometimes disabled to squeeze out gaming performance), but 5 is scary as hell.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 30 points 5 months ago (1 child)

    Windows forcing users to have to pay extra for what should be default security features has always been an awful practice.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 10 points 5 months ago* (last edited 5 months ago) (2 children)

    The only one of those that is locked behind a specific Windows edition is Credential Guard, which only works on Enterprise and Education because it has to do with auth tokens of the domain, not local windows login AFAIK

    The rest are locked behind hardware features like TPM and UEFI settings like secure boot.

    I hate Microslop as much as the next person, but they do actually try to push their security features on everyone because of the reputation they've had as the most insecure OS.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 36 points 5 months ago (1 child)

    I don’t see how this is much worse than running Denuvo malware to begin with. I treat my windows gaming partition as a disposable DMZ anyway.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 21 points 5 months ago (6 children)

    This seems like a bad faith argument, the crack is basically installing a rootkit in your system. Its fair to assume a lot of casual users will be as ignorant as you are about the security issues and not re-enable the features.

    If you truly can't see why that might be worse then DRM installed in a game your a fool.

  • source
  • parent
  • hideshow 12 child comments
  • [–] 39 points 5 months ago (2 children)

    If it's a question of installing a rootkit belonging to either the evil pirates who are closer to my kind of evil, or evil corporations who are literally destroying the internet, civilization, and the world in order to masturbate in their AI training gulags with my personal data? I'd choose to trust the pirates every time.

    That said, if I have to install a rootkit from anyone to play a fucking game, I'm probably just not playing that fucking game.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 7 points 5 months ago*

    That's assuming they're just pirates, not state actors or hackers taking advantage of it. Still though, Denuvo is possibly assisting state actors too, so 🤷. The ideal solutions is just don't play games with Denuvo. It's not that difficult.

  • source
  • parent
  • [–] 1 point 5 months ago*

    Lol that's not the question at all. People are making this into a false dichotomy. This is not a question of install denuvo or use the HV crack. Don't do either. Period.

    These are both terrible for security. HV is worse as it goes deeper into your system and requires you to turn off a bunch of critical security features for it to work.

  • source
  • parent
  • [–] 14 points 5 months ago* (1 child)
  • [–] 0 points 5 months ago* (1 child)

    Could a kind soul repipe all that garbage JavaScript escape code for:
    <discourse-assets-json> <div class="hidden" id="data-preloaded" data-preloaded="{&quot;topic_7768&quot;:&quot;{\&quot;post_stream
    to markdown, Creole, or Org?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 9 points 5 months ago

    the crack is basically installing a rootkit

    So is denuvo.

    I trust the random cracker's rootkit more than denuvo's.

    Potential evil is less risky than proven, official, completely intentional evil.

    Still, I have no interest in playing games infected with this shit. Their developers have evidently no interest in making good or even playable games, or they wouldn't infect them with this performance and usability killing malware, so to the blacklist they and their whole publisher go, cracked or not.

  • source
  • parent
  • [–] 4 points 5 months ago (1 child)

    Ok, I'll play the fool. Why is it worse? Is there some reason I should trust irdeto more than a guy in a hoodie?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 5 months ago

    There is a reason, if it's just some guy in a hoodie. If it's a known cracker with a reputation for good cracks, it's probably fine. Some random person? I'd avoid it. I'd probably avoid it either way, but I agree there's no reason to trust the company either. Just don't trust either.

  • source
  • parent
  • [–] 27 points 5 months ago (1 child)

    DRM, game launchers and generally 3/4 of modern software overall are a security threat anyway.

    That said, the best solution for all this problems is to never buy, pirate or play any DRMed crap. Let them choke on their greedy tech.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 22 points 5 months ago

    I can't help but wonder, shouldn't this all be possible on Linux without needing to install a hacked hypervisor? At most you would need a kernel patch, but since Denuvo operates through Wine, maybe an entirely userland solution would be possible too.

  • source
  • parent
  • [–] 15 points 5 months ago

    There will inevitably be some YouTube video that explains how to do all of this, and it will be followed without question by thousands of 12 year olds who don’t understand the security implications. They just want to play the new shiny game, and their parents told them they’d only buy the game if they got all A’s on their report card. So now their computer is orders of magnitude less secure (and likely running some mining/botnet in the background) because they wanted the game for free. This is just going to be the current generation’s version of “accidentally nuked the family computer with LimeWire downloads.”

  • source
  • parent
  • [–] 10 points 5 months ago* (last edited 5 months ago)

    It's gonna be really funny if the meta becomes Windows users booting into Linux just to boot a Single-GPU passthru Windows VM to play triple A's without getting pwned lol

  • source
  • parent
  • [–] 9 points 5 months ago

    Thanks for reminding me about why I have been exclusively playing older games or games from my backlog. Seriously with the prices of video games it's not worth it to buy them anymore let alone have the hardware to even play them. PC gaming sounds like a nightmare where you have to do all this crazy nonsense just to play some games at slightly better performance or if you are poor like me. I have long since stopped at pirating normal PC games though personally and have been pirating ROMs instead for emulators or buying from GOG. Much easier and you have like 4 decades worth of content just to play through. I say just let the modern gaming industry rot and toil. Play some Indie games instead like Deltarune or Silksong or I am your beast. Do anything but not support this dumb market of triple A games where they cost almost a hundred dollars now and require super computers hooked up to your actual computer to run.

  • source
  • parent
  • [–] 7 points 5 months ago

    Never tried, but what about nested vm's ? It should be possible to have a normal secure vm, with a 'compromised' hp/vm running microslop running. In theory I guess..

  • source
  • parent
  • [–] 4 points 5 months ago (1 child)

    If someone just has System for gaming only, is there really a risk? Shunning they only sign into game clients.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 5 months ago

    I you are considering the random hypervisor as a potential threat (which you should):

    • your auth tokens for things like Steam could be stolen, and possibly be used to make purchases with linked cards, or empty your inventory of things like CS skins, gift copies of games, etc.
    • if not fully isolated, it could be an attack vector to other machines on your LAN
    • peripherals like mic, camera, keyboard could be accessed to spy on you
    • and more...
  • source
  • parent
  • [–] 34 points 5 months ago (1 child)

    the sad part is most of these aaa slop games aren't worth the time or risk

  • source
  • hideshow 2 child comments
  • [–] 18 points 5 months ago

    hard hitting journalist Thomas Shardware

  • source
  • [–] 12 points 5 months ago

    It doesn't work on linux from what I've heard so... Meh, unfortunately.

  • source