Big Brother Inside, Revisited

A long but very good article with an interesting bit of history. They’ve been working towards computers having IDs for tracking, and humorously being exposed by game cheat bans. And notice if you use Windows or macOS, you have a unique identifier for tracking you. And Google is looking to do the same with Android devices, and locking out degoogled phones from their ReCAPTCHA… Throw in age verification, and we’re moving towards a world where you’ll have to be identified to use the internet, and their coming digital ID system with agentic AI will link everything together making it easy for them to lock you out of the internet, your money… your life.

https://reclaimthenet.org/big-brother-inside-revisited

A used CPU becomes a paper trail, a punishment, and a preview of computing’s next privacy fight.
Pixel art illustration featuring an eye window, a retro computer, a globe, and text reading big brother inside.

By Ken Macon

Let’s start with the German buyer who, on September 21, picked up a used AMD Ryzen 7 5800X3D processor and tried to play Valorant on it. The game wouldn’t start. It had run just fine on the old chip.

The buyer said that the game’s developer, Riot Games, told them through its support that the processor had been blacklisted by its anti-cheat system, Vanguard, as of August 12 – more than a month before the purchase.

Riot’s support allegedly said the ban was the result of the previous owner cheating, and that the ban would not be lifted. The motherboard and the drive were now flagged as well, the player was told.

Riot has not responded to a request for comment sent by PCWorld.

Riot’s head of anti-cheat, Phillip Koskinas, responded on X to the story, which was first posted on the German-language PCBaumeister subreddit on September 26 and then picked up by a user called CR1337.

Koskinas called the account “pretty unlikely” and said he could not find a support ticket matching the one described by the German player.

Koskinas said that a hardware ban lasts a maximum of four months, applies only to the game where the cheating happened, and that the support should have told the player how long the ban had left.

Koskinas also denied that Vanguard blacklists other parts of a PC if it finds one that is banned.

Even if we take Koskinas’ explanation as true, the fact remains that even according to him, an innocent buyer of a used processor is left unable to play the game until the ban on that chip expires – and there is no way for the buyer to know this before making the purchase.

When a company like Riot bans a game account, the punishment is directed at a person found to have violated the rules, and they are unable to play the game using that account.

When the company bans hardware, the punishment is directed at an object, and whoever holds the object at a given time is the one who is punished.

While it may seem like a good idea to buy second-hand in order to save money and reduce electronic waste, some gamers are learning the hard way that it can also mean buying a used component that is banned from playing a game, with no way to find out before making the purchase.

Riot Games’ own support page, “Understanding Hardware ID (HWID) Bans,” calls a hardware ban “a drastic step.”

“When a computer has a hardware ID ban, it means that we’ve banned the physical components of that computer rather than just banning an account,” the page explains.

It continues that a ban is “effectively a statement that we don’t want that particular person to create, access, or use any account on a Riot platform or game for the duration of the ban.”

It’s not that particular person who is punished if they are not the one currently using the hardware. The page spells it out: if a friend or family member logs in on a banned computer, that account is restricted there and banned for a set period, “as the system assumes that the account is attempting to circumvent the original ban.”

Riot advises, “If you suspect a computer has an HWID ban, it’s best not to try to log in with any account.”

“Reinstalling a game or deleting the responsible account won’t remove an HWID ban.”

Activision, another game maker, puts it like this: be careful buying a secondhand device, because you could end up with a banned product, and there is no appeal.

These are not new issues – back in 2007, a person who bought a refurbished Xbox 360 found it had arrived banned for life from Xbox Live. In 2009, banned consoles were resold on eBay. In 2025, some Switch 2 owners reported being banned by Nintendo after using secondhand Switch 1 game cards that they had bought online.

So how exactly does a game know one processor from another of the same model? The chips themselves only report their model to the operating system, so the identity has to be dug out from somewhere the owner never looks, such as the Trusted Platform Module (TPM) inside the processor, or the way it handles clock and voltage (since each processor “behaves slightly differently and can thus be identified”) – or even the firmware serial number.

The only thing that is clear is that it is not the operating system that can identify a processor uniquely. “A Ryzen 7 5800X3D, for example, is not distinguishable from another Ryzen 7 5800X3D without further ado,” German tech site Heise said. The site suggested that the TPM is a good candidate to carry a unique identifier, a “hardware ID,” that can be used by software.

Riot Games has not revealed exactly how its Vanguard anti-cheat software identifies a processor, but Heise said it would be “much easier to write identification hashes into the Trusted Platform Module. Because this TPM sits as a coprocessor directly in the CPU in most PCs, the hash remains when switching to a new PC.” In 2024 Riot said it was using Vanguard to enforce TPM and Secure Boot, even on Windows 10, “to eliminate bootkits as a vector and to give ourselves a better form of hardware ID.”

On AMD machines, the TPM usually runs as firmware inside the processor itself, the fTPM. A 2023 paper by TU Berlin researchers, who reverse-engineered the fTPM, found that its storage and integrity keys “are derived from a 128 bit secret unique to each CPU.” AMD itself warns on its support page that when its fTPM fails attestation, “Gamers may be unable to compete in online cash tournaments.”

Microsoft says that the TPM’s Endorsement Key (EK) is unique to every TPM and cannot be changed or removed. This key can identify the module.

In Windows 11, Microsoft says, the TPM’s unique RSA key, which is “burned into the chip,” can be used for device authentication.

Some AMD and Intel processors also have a Protected Processor Identification Number (PPIN).

We have had this fight before. In 1999, Intel announced the Pentium III would carry a processor serial number, a unique ID readable by software. Privacy groups immediately launched a boycott, and the campaign against what they called Big Brother Inside was on. In January 1999, Intel’s Pat Gelsinger explained the purpose of the number at the RSA conference, using an example that today seems almost quaint, given the way the same idea has evolved.

Gelsinger said the number would be needed to enter a chat room. “You think about this maybe as a chat room, where unless you’re able to deliver the processor serial number, you’re not able to enter that protected chat room,” he said.

Junkbusters, EPIC, and Privacy International quickly realized that the number would be like a permanent cookie, but one that cannot be deleted or changed. The groups warned that it would enable a massive profile to be collected and sold, and called for a boycott of Intel products.

At the time, Congressman Edward Markey wrote to Intel CEO Craig Barrett, “I hope that Intel will seek to design its products to improve the security of electronic commerce transactions without putting consumer privacy at risk.”

In April 2000, Wired reported that Intel was dropping the serial number from future chips, and quoted an Intel source as saying that the company had decided that the benefits were not worth “the bad rep it would give us.”

That was not the end of it. In 2026, the example of a chat room that you could not enter without your chip’s number, given by Intel’s Pat Gelsinger in 1999, has turned into a game you cannot play because of the same issue.

What came after that was Trusted Computing – and we have to give it this: the Trusted Platform Module (TPM) does do real security work.

The idea of a unique chip ID has not gone away since then. In 2003, the Cambridge security researcher Ross Anderson explained the purpose of the Trusted Platform Module (TPM) that was being introduced at the time: “The TCG specification will transfer the ultimate control of your PC from you to whoever wrote the software it happens to be running.”

Anderson also noted that the idea was not new, and compared it to the way the Soviet Union used to control its citizens by registering and tracking their typewriters and fax machines. “TC similarly attempts to register and control all computers,” he wrote.

The same year, the EFF’s Seth Schoen noted at the time that remote attestation, a key feature of TPMs, treats the computer owner as an adversary, and proposed an “Owner Override” that would allow people to control what their machine reports to remote parties. Schoen conceded that this would prevent “trusted computing” from being used for the purpose of stopping cheating in online games.

The industry came up with Direct Anonymous Attestation (DAA) in 2004, a way to prevent the linking of different transactions by the same TPM.

The authors of the DAA paper – Brickell, Camenisch, and Chen – said that the goal was to ensure that a verifier “only learns that she uses a TPM but not which particular one,” and that without this, “all her transactions would become linkable to each other.”

One of the authors, Camenisch, would later say that DAA was introduced “to make privacy groups happy.”

In 2022, Richard Stallman updated his essay “Can You Trust Your Computer?” to say that “the threat I warned about in 2002 has become terrifyingly real.”

The identity chip has now become mandatory hardware, included in almost every new PC, with Windows 11 requiring TPM 2.0 to even install.

If you think of your PC as your property (and you should, since you paid for it) then the price of entry of many popular online games these days is the kernel, the deepest level of your operating system.

You hand that over to a game company, and the code stays there even when you are not playing the game.

The kernel is where an operating system’s most sensitive components live, and where a malicious actor can do the most damage.

In exchange, you get to play the game.

Companies whose games install kernel-level software say they do this to detect and prevent cheating.

EA, for one, has said it doesn’t want deeper access to users’ PCs than necessary, but that anti-cheat software requires it.

The problem is not so much the intent of the game company, it’s the fact that once you give a third party the keys to the kingdom, you can never be sure what will happen next.

What about when this software is abused for other purposes? In 2022, Trend Micro found that the Genshin Impact anti-cheat driver was used by ransomware to kill antivirus products installed on a system.

The driver, mhyprot2.sys, was found to be used by ransomware to uninstall and disable security software. Trend Micro said that the game did not have to be installed on a victim’s PC in order for the attack to work.

Trend Micro noted that even when a fix is issued, “the module cannot be erased once distributed.”

In 2013, the New Jersey Attorney General settled for $1 million with E-Sports Entertainment, whose anti-cheat client was found to be mining Bitcoin on users’ computers.

The state’s Division of Law Director Christopher Porrino said at the time that subscribers to the service “paid for protection from cheaters – not to be cheated by the very services they’d purchased.”

In July 2024, a CrowdStrike update crashed an estimated 8.5 million Windows devices.

That same year, Microsoft announced that it was moving security tools out of the kernel, and into user space, where the rest of the applications run.

The reason given was to improve overall system security. In 2025, Microsoft explained that this means that “security products like anti-virus and endpoint protection solutions can run in user mode just as apps do.”

Riot itself has written that Microsoft is trying to move all third-party applications out of the kernel.

Yet gamers continue to allow this type of software to run on their PCs.

The fact remains that the kernel is no place for third-party software, and that includes anti-cheat tools.

In the world of PC gaming, the anti-cheat arms race is reaching for lower and lower levels of the software stack, all the way to the hardware. And each round of this race is making gaming more expensive and more difficult for honest users.

Riot Games, makers of League of Legends, and of Vanguard, the anti-cheat software that has been under some fire lately, are particularly proud of the latest iteration of their product. In May, they announced that they had managed to block DMA (direct memory access) cheat devices, that work by having one computer read the memory of another. The cost of these devices can be as high as $6,000.

Riot’s statement at the time was that owners of these devices had now been left with a “brand new $6k paperweight.”

The update that blocked these cheats relies on a Windows 11 25H2 feature that monitors driver activity. And it only works with a number of other security features turned on: Secure Boot, TPM 2.0, VBS, HVCI, and IOMMU. Riot calls this checklist Pre-Check, and says that 34.33% of machines are fully compliant.

Other major game publishers have similar, if less stringent requirements: Activision’s Ricochet anti-cheat uses Remote Attestation to check PC security settings directly with Microsoft. EA said that over 4.8 million players enabled Secure Boot after the company made it a requirement, and the game Battlefield 6 requires TPM 2.0. FACEIT, a platform for competitive multiplayer games, also requires TPM 2.0 and Secure Boot, and says that the former “records a unique fingerprint of every component in the boot chain.”

Then there are the games that have decided to block Linux players, and Linux users who happen to own a Steam Deck. In 2024, Apex Legends blocked both, explaining that there was “no reliable way” to differentiate between a legitimate Steam Deck and a “malicious cheat” claiming to be one.

While this may look like a cat-and-mouse game between cheaters and anti-cheat developers, the reality is that each round of this fight moves the verification and control of the system deeper: from the game itself to the kernel, from the kernel to the boot chain, and from software to hardware. 

And at each step of the way, it is the honest user who pays the price.

The case of Peter Stokes, who was identified and caught by the FBI thanks to the unique identifier of his Windows installation, is not an isolated example of how this technology is used.

Microsoft’s Global Device Identifier is defined as “a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine.”

Stokes used a VPN, but the VPN only hid his IP address, it could not change the identity of the machine. Microsoft’s records then tied the device to Stokes’ accounts and his travels. Microsoft proactively went to the authorities with this information in October 2024, more than a year before Stokes was charged.

That’s a pretty strong case, and Stokes has a lot to answer for, if the accusations against him are true.

Our reporting at the time noted that nothing about this is aimed only at criminals. The identifier is there on every Windows machine, and there is no settings toggle to switch it off. Reinstalling Windows will give you a new number, but if you log in to your Microsoft account, the company will know it is the same machine and will join the two identifiers.

Apple machines have a hardware UUID that survives a software reinstall because it describes the logic board.

In 2025 we reported that a senior US official, Michael Kratsios, confirmed talk of giving AI chips “better location-tracking.”

Nvidia said it does not and will not put “backdoors” in its chips.

However, features introduced for “specialized” hardware have a way of eventually trickling down to regular users.

What the Stokes case shows is that the game ban is merely the most visible part of a much broader trend of machines identifying themselves, whether their owners wish it or not.

Google has been trying for a long time to turn the web into a place where hardware ID can be used to decide who can access what content, and how – and this effort has been persistent, despite the giant abandoning one such initiative, Web Environment Integrity, in 2023.

That plan was to let websites check if a browser was running on approved hardware and software. This was met with criticism from the likes of Mozilla, Brave, and Vivaldi, while the EFF said at the time that “remote attestations have no place on open platforms.”

The plan didn’t go away, it only changed its name to Fraud Defense and instead of a standards process, Google simply went ahead and started rolling it out in May 2026. This reCAPTCHA successor uses the Play Integrity API and Google-certified hardware, and is already resulting in de-Googled phones being blocked from using parts of the web.

Those phones, running GrapheneOS, LineageOS, and CalyxOS, fail the Play Integrity check, and that means their users are unable to access some apps, including those provided by governments, such as Australia’s myGov and Brazil’s gov.br. GrapheneOS reacted by saying that these apps are in reality enforcing Google’s business interests, rather than improving security.

In 2022, free software pioneer Richard Stallman warned about remote attestation already being used in Google’s Play Integrity API.

What this means is that once hardware ID becomes the deciding factor in who can access what on the web – the question is no longer what you do or who you are – but rather, whether your machine is approved.

A very strong argument can be made that the whole thing is illegal in the EU, specifically in Germany where the player lives.

Device identifiers are personal data, as is clear from Recital 30 of the GDPR, which states that “natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols” and that these identifiers “may be used to create profiles of the natural persons and identify them.”

The CJEU has ruled in Breyer (2016) that information can be personal data even if “it is not necessary that that information alone allows the data subject to be identified.”

The ePrivacy Directive, meanwhile, in Recital 24, states that “terminal equipment of users of electronic communications networks and any information stored on such equipment are part of the private sphere of the users.”

So, the EU has defined a device as part of the private sphere, and its identifiers as personal data.

According to the ePrivacy Directive, accessing and storing information on a device is only allowed if the user has given consent, unless this is “strictly necessary” for a service the user has asked for.

The European Data Protection Board (EDPB) guidelines from 2024 cover information stored by a hardware manufacturer, such as the MAC addresses of network interface controllers.

The EDPB’s predecessor, the Article 29 Working Party, made this point in 2014, when it said that device fingerprinting can read “the CPU type” and warned that “there are limited opportunities available to reset or modify any information elements being used to generate the fingerprint.”

The principle of accuracy of personal data, as per GDPR Article 5(1)(d), is also at stake here, because the ban record refers to a chip, but the information it contains is now no longer accurate, as the processor has a new owner who is being punished for nothing.

GDPR Article 22(3) gives people the right to “obtain human intervention” and “to contest the decision” when they are subject to automated decision-making.

When you buy a used phone, you can check if it was reported stolen and blacklisted, and there’s even a way to remove it from that list. But there is no such list for processors, so a buyer has no way of knowing if the chip they are purchasing has been banned by a game maker.

Meanwhile, Activision warns buyers of used devices to “exercise caution” – but what are they supposed to do, and check what? The EU Court of Justice ruled in 2012 (UsedSoft) that a seller’s contract cannot stop the resale of a copy of software – but a hardware ban can stop it, and without any contract at all. The court said, “notwithstanding the existence of contractual terms prohibiting a further transfer, the rightholder in question can no longer oppose the resale of that copy.”

A hardware ban does just that. The difference is that while a seller can inform a buyer of contractual restrictions, there is nothing a seller can do to lift a hardware ban, or inform a buyer of its existence.

A hardware ban is a statement made about a previous owner, but enforced against a new one.

In the past, privacy advocates and regular users have been able to successfully push back against some of these efforts, such as when Intel in 1999 announced it would be introducing a processor serial number, a unique ID that could be read by software.

After a campaign by groups like Junkbusters, EPIC and Privacy International, Intel backed down, and in April 2000 dropped the serial number from its Pentium III chips.

Now this is back, and in many more devices and components, including phones, and not only as a way to identify and control a device, but also as a way to track people.

This is not just about games, or even just about desktop computers. The same system that can blacklist a CPU can do the same to a phone, and in that case, the app that is “banned” could be a crucial one, such as a mobile banking app.

While the German player may or may not have been the victim of a false positive, and may or may not have been eventually able to play their game, the incident shows that the system is there, it is being implemented, and it is here to stay – unless there is enough pushback from users to make it unpalatable for the industry to continue to use.

For now, if you buy a used processor, there is no way to check if it has been blacklisted by any game or app makers.

A computer should forget the people who owned it before you.