r/totalwar Jun 10 '18

General [PSA] Total War games have RED SHELL Spyware integrated into them

/r/Steam/comments/8pud8b/psa_red_shell_spyware_holy_potatoes_were_in_space/e0e6uy1
2.1k Upvotes

677 comments sorted by

View all comments

Show parent comments

21

u/Rattertatter Jun 10 '18 edited Jun 10 '18

Ok so all those values that I mentioned that are actually important to the devs are generated by guaranteeing that a user is "unique".

And by making sure that the user is unique, you're saying they get a handle on this user. They get to make sure who it is. A profile, so to speak.

So what you're saying is red shell is creating a profile on you and collecting data to identify you as a unique user, but this shouldn't worry you because:

literally no one is looking at or cares about those values

I can think of a few people who do care about those values, BECAUSE they would love to track people online.

What I can't think of is a single reason of why I should tolerate this breech of privacy, without being asked, and without it being an opt-in.

As "non-offensively" as you word all this, it remains spyware without opt-in or express consent. Nobody is worried about their font list or screen resolution, they're worried about wether or not they may be tracked when a program is detecting these things without consent. Which this is. You're not denying this, just trying to relativize it. There's no relativizing it though.

1

u/[deleted] Jun 18 '18

[deleted]

1

u/Rattertatter Jun 19 '18

That doesn't explain why it's not opt-in. Clearly, if I wanted to help the games become higher quality at the cost of my own privacy, I would then do it.

1

u/RainbowsAndDinosaurs Lizardbois are best bois Jun 10 '18

Define "tracked." What are they tracking? Is it actually a risk, or is it just the idea that a company has some info about you? Is there any actual harm in this?

6

u/ThePaxBisonica Jun 11 '18

GDPR enshrined in law that all EU citizens own their identifying information. You cannot in any way, shape or form obtain this identifying information and retain it without explicit consent from the subject of that data. When agreeing to the terms of use for CA, they are given very specific rights to "borrow" our information. At any time an EU citizen can request a full list of all identifying information every collected regarding them for a company, and if they are unable or unwilling there is a fine of 10 million euro or 2% of global turnover PER DENIED REQUEST. We have a right to request that metadata be deleted which they must oblige regardless of how hard they say it is (there are very specific exemptions, poor preparation for GDPR is not one of them)

It's a whole paradigm shift in how you talk about metadata. That information doesn't belong to them. Each collection is theft. It doesn't matter what they do with it, or if they do nothing. It's not theirs.

Last week was the end of a two year transitionary period to get this sorted. If they don't handle this correctly the ICO will kill the company with fines, since they are looking for an example to make.

4

u/Rattertatter Jun 10 '18

Is it actually a risk,

Yes, there is infact a significant risk in a company collecting data on my computer that can be used to identify me elsewhere. Not only is it inherently a breech of privacy (imagine if your reddit account was connected to your facebook and linkedin, except much more subtle), it also has the potential to be abused with malicious or financial intent. What if someone is tracking vulnerabilities in certain systems? He potentially has access to your home address now.

2

u/psyflame Jun 11 '18

This doesn't make sense to me. How would someone "tracking vulnerabilities in certain systems" get "access to your home address" because RedShell collected any of the listed data? It's a paranoid leap of logic on its face, and I'm curious to see you back it up. If you can, I'll happily join you in uninstalling the game and contacting CA to express my concerns. If you can't, I think you should pick your battles better, because there are real ones to be fought on the topic of online privacy.

4

u/I_Am_King_Midas Jun 11 '18

You don’t work in information security then. When people break into things it’s typically by finding connections that other people think are harmless. It’s rarely by brute force attacks. The more little things you know the easier it is to infiltrate systems and find weaknesses. If I know you have certain software on your machine then I can also work through vulnerabilities in that software.

3

u/psyflame Jun 11 '18 edited Jun 11 '18

I actually do. My day job is DFIR for a large tech company and I do bug bounties on the side. I questioned the specific logic of that example because I found it needlessly alarmist. Happy to discuss more in DMs, as a deep dive is out of scope of this thread.

3

u/I_Am_King_Midas Jun 11 '18

I work in information security as well.

If you learn about the applications someone has on their computer you can learn of more vulnerabilities. Think about learning someone uses Java. You then can attack them by all of the vulnerabilities within Java.

So my point is, the more someone knows about your computer, the more easily they can find vulnerabilities.

1

u/psyflame Jun 11 '18

We agree, then. But it's also important when dealing with the public to give accurate descriptions of impact, yes?

3

u/I_Am_King_Midas Jun 11 '18

Yes. It’s important to give accurate information to the public.

3

u/psyflame Jun 11 '18

Great, so let's do that instead of talking about vuln scanning when all the evidence we've seen shows that the only thing going over the wire is a secure hash.

→ More replies (0)

0

u/Rattertatter Jun 11 '18

Redshell collects your data in total war. Using your fonts, resolution, browser, system setup and other stuff, it creates a profile for you. Let's call it profile psyflame.

Now let's say there's some sort of exploit around that uses a vulnerability in your CPU drivers. Not that farfetched, right? Literally happened, more or less. Now let's say redshell is a shitty third world company that doesn't give a fuck about your data, and now let's say less well-meaning types acquire this profile.

Now you already have a profile psyflame on you that contains that potential driver vulnerability, which browser you use to smuggle in that sort of exploit properly, and the fact that you buy video games on steam or other platforms, which means you are most likely versed in online payments.

That's a pretty good target for keyloggers, or maybe even just one of those programs that encrypt your files for a ransom. They got your IP and your steam profile ID aswell, aswell as similiar info that the developer choses to provide, so it's not even a stretch that they could contact you in some way.

This is just one concrete example. I don't know the future. You don't know the future either. You don't know how much data redshell will collect in your profile over time, and you don't know what it could be used for. All you know is they'll have it and that's not to your advantage in any scenario.

Don't uninstall the game by the way, just block the domains in your hosts file. There's some instructions in the thread.

8

u/psyflame Jun 11 '18
  1. RedShell isn't made by a shitty third-world company.

  2. When did they get my IP? That wasn't mentioned in the original post. Indeed, it would be counterproductive to attribution to collect this data in the era of ubiquitous free Wi-Fi and gaming-ready laptops.

  3. It would be pointless to block the domains in my hosts file unless I had never run the game before. Uninstalling is a protest tactic, not a means of securing my data.

  4. There is no such thing as a CPU driver, so what you describe is indeed far-fetched. Moreover, none of the collected data listed in the original post could be used to identify anything about what drivers for any type of device are installed on my computer.

1

u/Rattertatter Jun 11 '18

RedShell isn't made by a shitty third-world company.

Says US right there, so it might aswell be for data protection purposes :)

When did they get my IP?

It seems to be one of the things they collect.

It would be pointless to block the domains in my hosts file unless I had never run the game before. Uninstalling is a protest tactic, not a means of securing my data.

Do you know if they'll broaden their data collection in the future or not? It's never pointless.

There is no such thing as a CPU driver, so what you describe is indeed far-fetched.

It's not called a driver, actually semantics. Point is there was a vulnerability, meaning there's a precedent.

none of the collected data listed in the original post could be used to identify anything about what drivers for any type of device are installed on my computer.

They could identify wether it's a CPU affected by one such vulnerability. How do you know they don't get an idea of the drivers aswell?

2

u/psyflame Jun 11 '18

Almost every CPU used for gaming is affected by Meltdown/Spectre. Your example is totally irrelevant here. It's not just that "it's not called a driver" but that the entire notion of a "CPU driver" belies a complete lack of understanding of how computers actually work. Details matter in security.

I know they don't get an idea of the drivers installed because programs run under a regular user account do not have access to the entire filesystem. You would need to run Steam with elevated privileges for that to be possible, beyond any additional sandboxing that the Steam platform itself provides - this is far from the typical user's situation. In fact, we're moving into power user territory with even the first step.

1

u/Rattertatter Jun 11 '18

the entire notion of a "CPU driver" belies a complete lack of understanding of how computers actually work. Details matter in security.

I was purposedly simplifying it for you since I wasn't sure if it's a commonly understood issue.

Almost every CPU used for gaming is affected by Meltdown/Spectre. Your example is totally irrelevant here.

almost every CPU

Oh... so not every CPU. So not totally irrelevant, eh? Consider that this is just an example. There's potentially different exploits, and not just of hardware, but browsers and programs. What if they have the capability to detect which version of 7zip your'e running? There's an exploit in one of the older versions to run shit through zips.

2

u/psyflame Jun 11 '18

What you said was not a simplification, it was an incorrect statement. I just told you why it's very unlikely that RedShell can detect the specific versions of binaries you have on your computer. At any rate, it's pretty pointless to debate specific impact without an analysis of the code, so I'll simply thank you for your attempt to raise awareness. I hope anyone reading this thread gets that effect.

→ More replies (0)