Company promises countermeasures against new DRM bypasses — zero-day game releases become norm as security concerns mount over hypervisor-based bypass

  • Encephalotrocity@feddit.onlineOP
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 months ago

    Good luck

    Using the hypervisor bypass, even in its latest incarnation, requires users to disable:

    1. Virtualization-Based Security (VBS): a layer that separates the Windows operating system from the its security enforcement features that run at a higher privilege level.
    2. Credential Guard: a sub-feature of VBS that keeps login credentials in an container isolated from the rest of the operating system.
    3. Driver Signature Enforcement: verification that any drivers installed in the system must have a digital signature issued by Microsoft to an identifiable company or developer, in order to prevent installing random drivers at the system level.
    4. Core Isolation / Memory Integrity (HVCI): similar to the above, but prevents any kernel-level unsigned code entirely, as well as modifications to existing signed code so programs can’t attempt to mess with existing drivers.
    5. Installing a community-made hypervisor (HV) with Windows running on top of it. This HV fakes responses to the checks that Denuvo makes, and runs with higher permissions (ring level -1) than the operating system itself and has full, nearly untraceable access to hardware and software.
    • alakey@piefed.social
      link
      fedilink
      English
      arrow-up
      1
      ·
      5 months ago

      First 4 are disabled on unsupported systems anyway (4 is also sometimes disabled to squeeze out gaming performance), but 5 is scary as hell.

      • upstroke4448@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        0
        ·
        5 months ago

        Windows forcing users to have to pay extra for what should be default security features has always been an awful practice.

        • boonhet@sopuli.xyz
          link
          fedilink
          English
          arrow-up
          0
          ·
          edit-2
          5 months ago

          The only one of those that is locked behind a specific Windows edition is Credential Guard, which only works on Enterprise and Education because it has to do with auth tokens of the domain, not local windows login AFAIK

          The rest are locked behind hardware features like TPM and UEFI settings like secure boot.

          I hate Microslop as much as the next person, but they do actually try to push their security features on everyone because of the reputation they’ve had as the most insecure OS.

          • D06M4@lemmy.zip
            link
            fedilink
            English
            arrow-up
            0
            ·
            5 months ago

            If Microsoft were honest they’d change the name from Windows to Backdoors.

            • boonhet@sopuli.xyz
              link
              fedilink
              English
              arrow-up
              1
              ·
              5 months ago

              No backdoors here!

              But the windows are all wide open and on the ground floor.

    • ayyy@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      5 months ago

      I don’t see how this is much worse than running Denuvo malware to begin with. I treat my windows gaming partition as a disposable DMZ anyway.

      • upstroke4448@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        5 months ago

        This seems like a bad faith argument, the crack is basically installing a rootkit in your system. Its fair to assume a lot of casual users will be as ignorant as you are about the security issues and not re-enable the features.

        If you truly can’t see why that might be worse then DRM installed in a game your a fool.

        • cecilkorik@piefed.ca
          link
          fedilink
          English
          arrow-up
          1
          ·
          5 months ago

          If it’s a question of installing a rootkit belonging to either the evil pirates who are closer to my kind of evil, or evil corporations who are literally destroying the internet, civilization, and the world in order to masturbate in their AI training gulags with my personal data? I’d choose to trust the pirates every time.

          That said, if I have to install a rootkit from anyone to play a fucking game, I’m probably just not playing that fucking game.

          • Cethin@lemmy.zip
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 months ago

            That’s assuming they’re just pirates, not state actors or hackers taking advantage of it. Still though, Denuvo is possibly assisting state actors too, so 🤷. The ideal solutions is just don’t play games with Denuvo. It’s not that difficult.