- cross-posted to:
- technology@lemmy.world
- cross-posted to:
- technology@lemmy.world
Company promises countermeasures against new DRM bypasses — zero-day game releases become norm as security concerns mount over hypervisor-based bypass
Good luck
Using the hypervisor bypass, even in its latest incarnation, requires users to disable:
- Virtualization-Based Security (VBS): a layer that separates the Windows operating system from the its security enforcement features that run at a higher privilege level.
- Credential Guard: a sub-feature of VBS that keeps login credentials in an container isolated from the rest of the operating system.
- Driver Signature Enforcement: verification that any drivers installed in the system must have a digital signature issued by Microsoft to an identifiable company or developer, in order to prevent installing random drivers at the system level.
- Core Isolation / Memory Integrity (HVCI): similar to the above, but prevents any kernel-level unsigned code entirely, as well as modifications to existing signed code so programs can’t attempt to mess with existing drivers.
- Installing a community-made hypervisor (HV) with Windows running on top of it. This HV fakes responses to the checks that Denuvo makes, and runs with higher permissions (ring level -1) than the operating system itself and has full, nearly untraceable access to hardware and software.
First 4 are disabled on unsupported systems anyway (4 is also sometimes disabled to squeeze out gaming performance), but 5 is scary as hell.
Windows forcing users to have to pay extra for what should be default security features has always been an awful practice.
The only one of those that is locked behind a specific Windows edition is Credential Guard, which only works on Enterprise and Education because it has to do with auth tokens of the domain, not local windows login AFAIK
The rest are locked behind hardware features like TPM and UEFI settings like secure boot.
I hate Microslop as much as the next person, but they do actually try to push their security features on everyone because of the reputation they’ve had as the most insecure OS.
If Microsoft were honest they’d change the name from Windows to Backdoors.
No backdoors here!
But the windows are all wide open and on the ground floor.
I don’t see how this is much worse than running Denuvo malware to begin with. I treat my windows gaming partition as a disposable DMZ anyway.
This seems like a bad faith argument, the crack is basically installing a rootkit in your system. Its fair to assume a lot of casual users will be as ignorant as you are about the security issues and not re-enable the features.
If you truly can’t see why that might be worse then DRM installed in a game your a fool.
If it’s a question of installing a rootkit belonging to either the evil pirates who are closer to my kind of evil, or evil corporations who are literally destroying the internet, civilization, and the world in order to masturbate in their AI training gulags with my personal data? I’d choose to trust the pirates every time.
That said, if I have to install a rootkit from anyone to play a fucking game, I’m probably just not playing that fucking game.
That’s assuming they’re just pirates, not state actors or hackers taking advantage of it. Still though, Denuvo is possibly assisting state actors too, so 🤷. The ideal solutions is just don’t play games with Denuvo. It’s not that difficult.
the sad part is most of these aaa slop games aren’t worth the time or risk
Exactly. Don’t know when I last got a new game… I think it was that Hogwarts game




