{"id":19017,"date":"2026-10-08T14:41:47","date_gmt":"2026-10-08T21:41:47","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=19017"},"modified":"2026-10-08T14:41:47","modified_gmt":"2026-10-08T21:41:47","slug":"big-brother-inside-revisited","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/10\/08\/big-brother-inside-revisited\/","title":{"rendered":"Big Brother Inside, Revisited"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A long but very good article with an interesting bit of history. They&#8217;ve been working towards computers having IDs for tracking, and humorously being exposed by game cheat bans. And notice if you use Windows or macOS, you have a unique identifier for tracking you. And Google is looking to do the same with Android devices, and locking out degoogled phones from their ReCAPTCHA&#8230; Throw in age verification, and we&#8217;re moving towards a world where you&#8217;ll have to be identified to use the internet, and their coming digital ID system with agentic AI will link everything together making it easy for them to lock you out of the internet, your money&#8230; your life.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/reclaimthenet.org\/big-brother-inside-revisited\" target=\"_blank\" rel=\"noopener\">https:\/\/reclaimthenet.org\/big-brother-inside-revisited<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_b6d0b508-5441-4baf-a35a-734d8527d2a8\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<h5 class=\"wp-block-heading\">A used CPU becomes a paper trail, a punishment, and a preview of computing\u2019s next privacy fight.<\/h5>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/media.reclaimthenet.org\/images\/2026\/10\/IJd1mBSf3adc.jpg\" alt=\"Pixel art illustration featuring an eye window, a retro computer, a globe, and text reading big brother inside.\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">By Ken Macon<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s start with the German buyer who, on September 21, <a href=\"https:\/\/www.pcworld.com\/article\/3250222\/your-used-cpu-might-come-with-someone-elses-valorant-ban.html\"><u>picked up a used AMD Ryzen 7 5800X3D processor<\/u><\/a> and tried to play Valorant on it. The game wouldn\u2019t start. It had run just fine on the old chip.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The buyer said that the game\u2019s developer, Riot Games, told them through its support that the processor had been blacklisted by its anti-cheat system, Vanguard, as of August 12 \u2013 more than a month before the purchase.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Riot\u2019s support allegedly said the ban was the result of the previous owner cheating, and that the ban would not be lifted. The motherboard and the drive were now flagged as well, the player was told.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Riot has not responded to a request for comment sent by PCWorld.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.pcgamer.com\/games\/fps\/valorant-player-claims-to-have-inherited-hardware-ban-through-secondhand-cpu-riot-anticheat-boss-disputes-parts-of-story\/\"><u>Riot\u2019s head of anti-cheat, Phillip Koskinas, responded on X<\/u><\/a> to the story, which was first posted on the German-language PCBaumeister subreddit on September 26 and then picked up by a user called CR1337.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Koskinas called the account \u201cpretty unlikely\u201d and said he could not find a support ticket matching the one described by the German player.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Koskinas said that a hardware ban lasts a maximum of four months, applies only to the game where the cheating happened, and that the support should have told the player how long the ban had left.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.xda-developers.com\/used-cpu-allegedly-got-entire-pc-banned-valorant-riot-says-not-how-its-anti-cheat-works\/\"><u>Koskinas also denied<\/u><\/a> that Vanguard blacklists other parts of a PC if it finds one that is banned.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even if we take Koskinas\u2019 explanation as true, the fact remains that even according to him, an innocent buyer of a used processor is left unable to play the game until the ban on that chip expires \u2013 and there is no way for the buyer to know this before making the purchase.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When a company like Riot bans a game account, the punishment is directed at a person found to have violated the rules, and they are unable to play the game using that account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When the company bans hardware, the punishment is directed at an object, and whoever holds the object at a given time is the one who is punished.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While it may seem like a good idea to buy second-hand in order to save money and reduce electronic waste, some gamers are learning the hard way that it can also mean buying a used component that is banned from playing a game, with no way to find out before making the purchase.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/support.riotgames.com\/en-us\/riot\/penalties\/understanding-hardware-id-hwid-bans\"><u>Riot Games&#8217; own support page<\/u><\/a>, &#8220;Understanding Hardware ID (HWID) Bans,&#8221; calls a hardware ban &#8220;a drastic step.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;When a computer has a hardware ID ban, it means that we&#8217;ve banned the physical components of that computer rather than just banning an account,&#8221; the page explains.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It continues that a ban is &#8220;effectively a statement that we don&#8217;t want that particular person to create, access, or use any account on a Riot platform or game for the duration of the ban.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It&#8217;s not that particular person who is punished if they are not the one currently using the hardware. The page spells it out: if a friend or family member logs in on a banned computer, that account is restricted there and banned for a set period, &#8220;as the system assumes that the account is attempting to circumvent the original ban.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Riot advises, &#8220;If you suspect a computer has an HWID ban, it&#8217;s best not to try to log in with any account.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Reinstalling a game or deleting the responsible account won&#8217;t remove an HWID ban.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/support.activision.com\/articles\/call-of-duty-security-and-enforcement-policy\"><u>Activision, another game maker, puts it like this<\/u><\/a>: be careful buying a secondhand device, because you could end up with a banned product, and there is no appeal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These are not new issues &#8211; back in 2007, a person who bought a refurbished Xbox 360 found it had arrived banned for life from Xbox Live. In 2009, banned consoles were resold on eBay. In 2025, some <a href=\"https:\/\/www.engadget.com\/gaming\/nintendo\/nintendo-reportedly-bans-switch-2-user-playing-preowned-game-cards-192452163.html\"><u>Switch 2 owners reported being banned<\/u><\/a> by Nintendo after using secondhand Switch 1 game cards that they had bought online.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So how exactly does a game know one processor from another of the same model? The chips themselves only report their model to the operating system, so the identity has to be dug out from somewhere the owner never looks, such as the Trusted Platform Module (TPM) inside the processor, or the way it handles clock and voltage (since each processor &#8220;behaves slightly differently and can thus be identified&#8221;) &#8211; or even the firmware serial number.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The only thing that is clear is that it is not the operating system that can identify a processor uniquely. &#8220;A Ryzen 7 5800X3D, for example, is not distinguishable from another Ryzen 7 5800X3D without further ado,&#8221; <a href=\"https:\/\/www.heise.de\/en\/news\/Used-processor-leads-to-game-ban-11471562.html\"><u>German tech site Heise said<\/u><\/a>. The site suggested that the TPM is a good candidate to carry a unique identifier, a &#8220;hardware ID,&#8221; that can be used by software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Riot Games has not revealed exactly how its Vanguard anti-cheat software identifies a processor, but Heise said it would be &#8220;much easier to write identification hashes into the Trusted Platform Module. Because this TPM sits as a coprocessor directly in the CPU in most PCs, the hash remains when switching to a new PC.&#8221; <a href=\"https:\/\/playvalorant.com\/en-us\/news\/game-updates\/vanguard-x-valorant\/\"><u>In 2024 Riot said it was using Vanguard<\/u><\/a> to enforce TPM and Secure Boot, even on Windows 10, &#8220;to eliminate bootkits as a vector and to give ourselves a better form of hardware ID.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On AMD machines, the TPM usually runs as firmware inside the processor itself, the fTPM. <a href=\"https:\/\/arxiv.org\/pdf\/2304.14717\"><u>A 2023 paper by TU Berlin researchers<\/u><\/a>, who reverse-engineered the fTPM, found that its storage and integrity keys &#8220;are derived from a 128 bit secret unique to each CPU.&#8221; <a href=\"https:\/\/www.amd.com\/en\/resources\/support-articles\/faqs\/pa-420.html\"><u>AMD itself warns on its support page<\/u><\/a> that when its fTPM fails attestation, &#8220;Gamers may be unable to compete in online cash tournaments.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/identity\/ad-ds\/manage\/component-updates\/tpm-key-attestation\"><u>Microsoft says that the TPM&#8217;s Endorsement Key<\/u><\/a> (EK) is unique to every TPM and cannot be changed or removed. This key can identify the module.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.microsoft.com\/en-us\/windows\/windows-11-specifications\"><u>In Windows 11, Microsoft says<\/u><\/a>, the TPM&#8217;s unique RSA key, which is &#8220;burned into the chip,&#8221; can be used for device authentication.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some AMD and Intel processors also have a Protected Processor Identification Number (PPIN).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We have had this fight before. In 1999, Intel announced the Pentium III would carry a processor serial number, a unique ID readable by software. Privacy groups immediately launched a boycott, and the campaign against what they called <a href=\"http:\/\/web.archive.org\/web\/20000815054206\/http:\/\/www.bigbrotherinside.org\/\"><u>Big Brother Inside<\/u><\/a> was on. In January 1999, Intel\u2019s Pat Gelsinger explained the purpose of the number <a href=\"http:\/\/web.archive.org\/web\/19991007221227\/http:\/\/intel.com\/pressroom\/archive\/speeches\/pg012099.htm\"><u>at the RSA conference<\/u><\/a>, using an example that today seems almost quaint, given the way the same idea has evolved.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Gelsinger said the number would be needed to enter a chat room. \u201cYou think about this maybe as a chat room, where unless you\u2019re able to deliver the processor serial number, you\u2019re not able to enter that protected chat room,\u201d he said.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Junkbusters, EPIC, and Privacy International quickly realized that the number would be like a permanent cookie, but one that cannot be deleted or changed. The groups warned that it would enable a massive profile to be collected and sold, and called for a boycott of Intel products.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At the time, Congressman Edward Markey wrote to Intel CEO Craig Barrett, \u201cI hope that Intel will seek to design its products to improve the security of electronic commerce transactions without putting consumer privacy at risk.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.wired.com\/2000\/04\/intel-nixes-chip-tracking-id\/\"><u>In April 2000, Wired reported<\/u><\/a> that Intel was dropping the serial number from future chips, and quoted an Intel source as saying that the company had decided that the benefits were not worth \u201cthe bad rep it would give us.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That was not the end of it. In 2026, the example of a chat room that you could not enter without your chip&#8217;s number, given by Intel&#8217;s Pat Gelsinger in 1999, has turned into a game you cannot play because of the same issue.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What came after that was Trusted Computing \u2013 and we have to give it this: the Trusted Platform Module (TPM) does do real security work.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The idea of a unique chip ID has not gone away since then. In 2003, the Cambridge security researcher <a href=\"https:\/\/www.cl.cam.ac.uk\/~rja14\/tcpa-faq.html\"><u>Ross Anderson explained<\/u><\/a> the purpose of the Trusted Platform Module (TPM) that was being introduced at the time: \u201cThe TCG specification will transfer the ultimate control of your PC from you to whoever wrote the software it happens to be running.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Anderson also noted that the idea was not new, and compared it to the way the Soviet Union used to control its citizens by registering and tracking their typewriters and fax machines. &#8220;TC similarly attempts to register and control all computers,&#8221; he wrote.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The same year, the EFF\u2019s <a href=\"http:\/\/web.archive.org\/web\/20070102095154\/http:\/\/www.eff.org\/Infrastructure\/trusted_computing\/20031001_tc.php\"><u>Seth Schoen noted<\/u><\/a> at the time that remote attestation, a key feature of TPMs, treats the computer owner as an adversary, and proposed an \u201cOwner Override\u201d that would allow people to control what their machine reports to remote parties. Schoen conceded that this would prevent \u201ctrusted computing\u201d from being used for the purpose of stopping cheating in online games.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The industry came up with Direct Anonymous Attestation (DAA) in 2004, a way to prevent the linking of different transactions by the same TPM.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"http:\/\/web.archive.org\/web\/20110520023857\/http:\/\/www.zurich.ibm.com\/~jca\/papers\/brcach04.pdf\"><u>The authors of the DAA paper<\/u><\/a> &#8211; Brickell, Camenisch, and Chen &#8211; said that the goal was to ensure that a verifier &#8220;only learns that she uses a TPM but not which particular one,&#8221; and that without this, &#8220;all her transactions would become linkable to each other.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One of the authors, Camenisch, would later say that DAA was introduced &#8220;to make privacy groups happy.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In 2022, <a href=\"https:\/\/www.gnu.org\/philosophy\/can-you-trust.en.html\"><u>Richard Stallman updated his essay<\/u><\/a> &#8220;Can You Trust Your Computer?&#8221; to say that &#8220;the threat I warned about in 2002 has become terrifyingly real.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The identity chip has now become mandatory hardware, included in almost every new PC, with Windows 11 requiring TPM 2.0 to even install.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you think of your PC as your property (and you should, since you paid for it) then the price of entry of many popular online games these days is the kernel, the deepest level of your operating system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You hand that over to a game company, and the code stays there even when you are not playing the game.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The kernel is where an operating system\u2019s most sensitive components live, and where a malicious actor can do the most damage.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In exchange, you get to play the game.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Companies whose games install kernel-level software say they do this to detect and prevent cheating.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">EA, for one, has said it doesn\u2019t want deeper access to users\u2019 PCs than necessary, but that anti-cheat software requires it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The problem is not so much the intent of the game company, it\u2019s the fact that once you give a third party the keys to the kingdom, you can never be sure what will happen next.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What about when this software is abused for other purposes? In 2022, <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/22\/h\/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html\"><u>Trend Micro found<\/u><\/a> that the Genshin Impact anti-cheat driver was used by ransomware to kill antivirus products installed on a system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The driver, mhyprot2.sys, was found to be used by ransomware to uninstall and disable security software. Trend Micro said that the game did not have to be installed on a victim\u2019s PC in order for the attack to work.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Trend Micro noted that even when a fix is issued, \u201cthe module cannot be erased once distributed.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In 2013, the New Jersey Attorney General <a href=\"https:\/\/nj.gov\/oag\/newsreleases13\/pr20131119a.html\"><u>settled for $1 million with E-Sports Entertainment<\/u><\/a>, whose anti-cheat client was found to be mining Bitcoin on users\u2019 computers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The state\u2019s Division of Law Director Christopher Porrino said at the time that subscribers to the service \u201cpaid for protection from cheaters \u2013 not to be cheated by the very services they\u2019d purchased.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In July 2024, a CrowdStrike update <a href=\"https:\/\/blogs.microsoft.com\/blog\/2024\/07\/20\/helping-our-customers-through-the-crowdstrike-outage\/\"><u>crashed an estimated 8.5 million Windows devices<\/u><\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That same year, Microsoft announced that it was moving security tools out of the kernel, and into user space, where the rest of the applications run.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The reason given was to improve overall system security. In 2025, <a href=\"https:\/\/blogs.windows.com\/windowsexperience\/2025\/06\/26\/the-windows-resiliency-initiative-building-resilience-for-a-future-ready-enterprise\/\"><u>Microsoft explained<\/u><\/a> that this means that \u201csecurity products like anti-virus and endpoint protection solutions can run in user mode just as apps do.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Riot itself has written that Microsoft is trying to move all third-party applications out of the kernel.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Yet gamers continue to allow this type of software to run on their PCs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The fact remains that the kernel is no place for third-party software, and that includes anti-cheat tools.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the world of PC gaming, the anti-cheat arms race is reaching for lower and lower levels of the software stack, all the way to the hardware. And each round of this race is making gaming more expensive and more difficult for honest users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Riot Games, makers of League of Legends, and of Vanguard, the anti-cheat software that has been under some fire lately, are particularly proud of the latest iteration of their product. In May, they announced that they had managed to block DMA (direct memory access) cheat devices, that work by having one computer read the memory of another. The cost of these devices can be as high as $6,000.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.tomshardware.com\/software\/valorant-dev-bans-players-who-spent-usd6-000-on-cheats-then-trolls-them-on-social-media-studio-tweets-congrats-to-the-owners-of-a-brand-new-usd6k-paperweight\"><u>Riot\u2019s statement at the time<\/u><\/a> was that owners of these devices had now been left with a \u201cbrand new $6k paperweight.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The update that blocked these cheats relies on a Windows 11 25H2 feature that monitors driver activity. And it only works with a number of other security features turned on: Secure Boot, TPM 2.0, VBS, HVCI, and IOMMU. Riot calls this checklist Pre-Check, and says that 34.33% of machines are fully compliant.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Other major game publishers have similar, if less stringent requirements: Activision\u2019s Ricochet anti-cheat uses Remote Attestation to check PC security settings directly with Microsoft. <a href=\"https:\/\/www.ea.com\/security\/news\/anticheat-progress-report\"><u>EA said that over 4.8 million players<\/u><\/a> enabled Secure Boot after the company made it a requirement, and the game Battlefield 6 requires TPM 2.0. <a href=\"https:\/\/support.faceit.com\/hc\/en-us\/articles\/23117181142556-Windows-Security-Requirements-FAQ\"><u>FACEIT, a platform<\/u><\/a> for competitive multiplayer games, also requires TPM 2.0 and Secure Boot, and says that the former \u201crecords a unique fingerprint of every component in the boot chain.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then there are the games that have decided to block Linux players, and Linux users who happen to own a Steam Deck. In 2024, Apex Legends blocked both, explaining that there was \u201cno reliable way\u201d to differentiate between a legitimate Steam Deck and a \u201cmalicious cheat\u201d claiming to be one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While this may look like a cat-and-mouse game between cheaters and anti-cheat developers, the reality is that each round of this fight moves the verification and control of the system deeper: from the game itself to the kernel, from the kernel to the boot chain, and from software to hardware.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">And at each step of the way, it is the honest user who pays the price.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/reclaimthenet.org\/microsoft-stamped-a-secret-number-in-your-windows-pc-a-vpn-cant-hide-it\/\"><u>The case of Peter Stokes<\/u><\/a>, who was identified and caught by the FBI thanks to the unique identifier of his Windows installation, is not an isolated example of how this technology is used.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft\u2019s Global Device Identifier is defined as \u201ca persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Stokes used a VPN, but the VPN only hid his IP address, it could not change the identity of the machine. Microsoft\u2019s records then tied the device to Stokes\u2019 accounts and his travels. Microsoft proactively went to the authorities with this information in October 2024, more than a year before Stokes was charged.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That\u2019s a pretty strong case, and Stokes has a lot to answer for, if the accusations against him are true.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our reporting at the time noted that nothing about this is aimed only at criminals. The identifier is there on every Windows machine, and there is no settings toggle to switch it off. Reinstalling Windows will give you a new number, but if you log in to your Microsoft account, the company will know it is the same machine and will join the two identifiers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/reclaimthenet.org\/can-you-escape-the-device-identifiers\/\"><u>Apple machines have a hardware UUID<\/u><\/a> that survives a software reinstall because it describes the logic board.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/reclaimthenet.org\/silicon-with-a-side-of-surveillance\/\"><u>In 2025 we reported<\/u><\/a> that a senior US official, Michael Kratsios, confirmed talk of giving AI chips \u201cbetter location-tracking.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nvidia said it does not and will not put &#8220;backdoors&#8221; in its chips.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, features introduced for &#8220;specialized&#8221; hardware have a way of eventually trickling down to regular users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What the Stokes case shows is that the game ban is merely the most visible part of a much broader trend of machines identifying themselves, whether their owners wish it or not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Google has been trying for a long time to turn the web into a place where hardware ID can be used to decide who can access what content, and how \u2013 and this effort has been persistent, despite the giant abandoning one such initiative, <a href=\"https:\/\/github.com\/RupertBenWiser\/Web-Environment-Integrity\/blob\/main\/explainer.md\"><u>Web Environment Integrity, in 2023<\/u><\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That plan was to let websites check if a browser was running on approved hardware and software. This was met with criticism from the likes of Mozilla, Brave, and Vivaldi, while <a href=\"https:\/\/www.eff.org\/deeplinks\/2023\/08\/your-computer-should-say-what-you-tell-it-say-1\"><u>the EFF said at the time<\/u><\/a> that \u201cremote attestations have no place on open platforms.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The plan didn\u2019t go away, it only <a href=\"https:\/\/reclaimthenet.org\/google-fraud-defense-web-attestation\/\"><u>changed its name to Fraud Defense<\/u><\/a> and instead of a standards process, Google simply went ahead and started rolling it out in May 2026. This reCAPTCHA successor uses the Play Integrity API and Google-certified hardware, and is already resulting in de-Googled phones being blocked from using parts of the web.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Those phones, running GrapheneOS, LineageOS, and CalyxOS, <a href=\"https:\/\/developer.android.com\/google\/play\/integrity\/overview\"><u>fail the Play Integrity check<\/u><\/a>, and that means their users are unable to access some apps, including those provided by governments, such as Australia\u2019s myGov and Brazil\u2019s gov.br. GrapheneOS reacted by saying that these apps are in reality enforcing Google\u2019s business interests, rather than improving security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In 2022, free software pioneer Richard Stallman warned about remote attestation already being used in Google&#8217;s Play Integrity API.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What this means is that once hardware ID becomes the deciding factor in who can access what on the web \u2013 the question is no longer what you do or who you are \u2013 but rather, whether your machine is approved.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A very strong argument can be made that the whole thing is illegal in the EU, specifically in Germany where the player lives.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Device identifiers are personal data, as is clear from <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32016R0679\"><u>Recital 30 of the GDPR<\/u><\/a>, which states that &#8220;natural persons may be associated with online identifiers provided by their devices, applications, tools and protocols&#8221; and that these identifiers &#8220;may be used to create profiles of the natural persons and identify them.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The CJEU has ruled in <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:62014CJ0582\"><u>Breyer (2016)<\/u><\/a> that information can be personal data even if &#8220;it is not necessary that that information alone allows the data subject to be identified.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The ePrivacy Directive, meanwhile, <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:32002L0058\"><u>in Recital 24<\/u><\/a>, states that &#8220;terminal equipment of users of electronic communications networks and any information stored on such equipment are part of the private sphere of the users.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, the EU has defined a device as part of the private sphere, and its identifiers as personal data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to the ePrivacy Directive, accessing and storing information on a device is only allowed if the user has given consent, unless this is \u201cstrictly necessary\u201d for a service the user has asked for.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The European Data Protection Board (EDPB) <a href=\"https:\/\/www.edpb.europa.eu\/system\/files\/2024-10\/edpb_guidelines_202302_technical_scope_art_53_eprivacydirective_v2_en_0.pdf\"><u>guidelines from 2024<\/u><\/a> cover information stored by a hardware manufacturer, such as the MAC addresses of network interface controllers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The EDPB\u2019s predecessor, <a href=\"https:\/\/ec.europa.eu\/justice\/article-29\/documentation\/opinion-recommendation\/files\/2014\/wp224_en.pdf\"><u>the Article 29 Working Party<\/u><\/a>, made this point in 2014, when it said that device fingerprinting can read \u201cthe CPU type\u201d and warned that \u201cthere are limited opportunities available to reset or modify any information elements being used to generate the fingerprint.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The principle of accuracy of personal data, as per GDPR Article 5(1)(d), is also at stake here, because the ban record refers to a chip, but the information it contains is now no longer accurate, as the processor has a new owner who is being punished for nothing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">GDPR Article 22(3) gives people the right to \u201cobtain human intervention\u201d and \u201cto contest the decision\u201d when they are subject to automated decision-making.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When you buy a used phone, you can check if it was reported stolen and blacklisted, and there\u2019s even a way to remove it from that list. But there is no such list for processors, so a buyer has no way of knowing if the chip they are purchasing has been banned by a game maker.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Meanwhile, Activision warns buyers of used devices to \u201cexercise caution\u201d \u2013 but what are they supposed to do, and check what? <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/HTML\/?uri=CELEX:62011CJ0128\"><u>The EU Court of Justice ruled in 2012 (UsedSoft)<\/u><\/a> that a seller\u2019s contract cannot stop the resale of a copy of software \u2013 but a hardware ban can stop it, and without any contract at all. The court said, \u201cnotwithstanding the existence of contractual terms prohibiting a further transfer, the rightholder in question can no longer oppose the resale of that copy.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A hardware ban does just that. The difference is that while a seller can inform a buyer of contractual restrictions, there is nothing a seller can do to lift a hardware ban, or inform a buyer of its existence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A hardware ban is a statement made about a previous owner, but enforced against a new one.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In the past, privacy advocates and regular users have been able to successfully push back against some of these efforts, such as when Intel in 1999 announced it would be introducing a processor serial number, a unique ID that could be read by software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">After a campaign by groups like Junkbusters, EPIC and Privacy International, Intel backed down, and in April 2000 dropped the serial number from its Pentium III chips.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Now this is back, and in many more devices and components, including phones, and not only as a way to identify and control a device, but also as a way to track people.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is not just about games, or even just about desktop computers. The same system that can blacklist a CPU can do the same to a phone, and in that case, the app that is &#8220;banned&#8221; could be a crucial one, such as a mobile banking app.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While the German player may or may not have been the victim of a false positive, and may or may not have been eventually able to play their game, the incident shows that the system is there, it is being implemented, and it is here to stay &#8211; unless there is enough pushback from users to make it unpalatable for the industry to continue to use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For now, if you buy a used processor, there is no way to check if it has been blacklisted by any game or app makers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A computer should forget the people who owned it before you.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A long but very good article with an interesting bit of history. They&#8217;ve been working towards computers having IDs for tracking, and humorously being exposed by game cheat bans. And notice if you use Windows or macOS, you have a unique identifier for tracking you. And Google is looking to do the same with Android [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,7],"tags":[],"class_list":["post-19017","post","type-post","status-publish","format-standard","hentry","category-tech","category-world"],"blocksy_meta":{"styles_descriptor":{"styles":{"desktop":"","tablet":"","mobile":""},"google_fonts":[],"version":8}},"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/19017","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=19017"}],"version-history":[{"count":1,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/19017\/revisions"}],"predecessor-version":[{"id":19018,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/19017\/revisions\/19018"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=19017"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=19017"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=19017"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}