this post was submitted on 02 Oct 2026
231 points (97.5% liked)

Technology

88390 readers
3838 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] nyan@lemmy.cafe 2 points 8 hours ago (2 children)

Question is, what happens if you don't have dmidecode installed? Even more interesting, what happens if you've replaced it with a fake that spews back values of your choosing? If they're bundling it, given that it appears to be GPL2, they're opening themselves to a lawsuit unless they provide source upon request.

(Somehow, I don't think they're actually using dmidecode.)

dmidecode is a tool for reading loads of platform registers, it is obviously not the only way to do it, or even the intended way really. Riot has almost certainly implemented the functionality from scratch in their anticheat, it’s a relatively trivial thing to do.

[–] palordrolap@fedia.io 1 points 5 hours ago (1 children)

What I've read just now is what I'd deliberately not gone looking for up to this point in case I found this out.

Linux and Windows happen to require that the executables that access that information be run with root privileges, but it looks like that's merely an affectation.

It seems that any old piece of software, without root or other privileges, can independently run the CPUID instruction that obtains a processor's serial number.

I do not like this one bit.

[–] frongt@lemmy.zip 1 points 58 minutes ago (1 children)

Why not? Is that information considered sensitive? Personally I tend to avoid running untrustworthy programs outside of a sandbox or VM.

[–] palordrolap@fedia.io 0 points 40 minutes ago

Are you a believer in the idea "They who have nothing to hide have nothing to fear"? Hint: You shouldn't be.

And do you know for certain that your sandboxes and VMs don't simply pass through the CPUID instruction? And if they don't, do they rotate their fake CPUIDs? And how often does that happen?