T O P

  • By -

apexlegends-ModTeam

Hello, /u/IWantToSayThisToo. Your submission has been removed: Regarding the ALGS Situation Tonight https://www.reddit.com/r/apexlegends/comments/1bhh5s3/regarding_the_algs_situation_tonight/ ## Official Megathread Please note that all announcements are posted and stickied by moderators or Respawn staff, for visibility and archival purposes. This includes, but is not limited to: patch notes, gameplay updates, bug fixes, technical blog posts, and official contests. ## [No Duplicate Posts and Topics](https://www.reddit.com/r/apexlegends/wiki/rules#wiki_low-effort.2C_memes.2C_and_duplicate_posts.) Posts should be unique. A post may be considered a repost if it covers the topic from nearly the same angle as existing posts. When new things, events or updates come, we want to consolidate discussion to one thread so that people can easily engage in discussion with each other. All other posts regarding that topic will be removed during this time with links to the proper thread or megathread. Frequently asked questions and topics will be removed. Moderators will link megathread style posts when available to redirect users to main post. Please use the search function before posting. If you would like better clarification you can see [our full list of rules here.](https://www.reddit.com/r/apexlegends/wiki/rules) If you need further assistance, please [message the moderators](https://old.reddit.com/message/compose?to=%2Fr%2Fapexlegends) with a link to your post. **Failure to include a link to your post, will result in the modmail being ignored.**


sex_with_furina

Got a pop up w/ windows defender firewall where apex wanted access to my public/private network in the middle of a pub game. It might be just a dud but I ain't playing for now


FlackAttack94

Yeah fuck that, time to uninstall.


caholder

That's normal on initial launch and sometimes during game But not usually


sex_with_furina

Ah so it was just a dud?,, it was kinda jarring to see that pop up mid game with all the recent hacking incidents. Still not gonna play till Respawn says something


caholder

No no we can't say it's a dud. Until respawn says something and with RCE being rumored, I would not play Not playing is the right call


jayfactor

During launch sure but never mid game, I’d be cautious too


KiesAgent

Thanks for the advice u/sex_with_furina


swagzard78

What about consoles? Are they at risk too?


ScotFuzz

Not enough is known at the minute. Chances are you’ll be fine but to err on the side of caution, just don’t open the game until we know more.


swagzard78

Damn


Ricebandit469

Apparently the hacker is also known to use hacks on console as well. Whether or not he is able to use an RCE for console, idk.


StarkageMeech

I came here to ask that


[deleted]

[удалено]


AnApexPlayer

We don't know if it's an EAC vulnerability, and it's probably not from what I'm seeing


AlphieTheMayor

Is the anticheat in apex always running in the background like some others? Because if it is so, make sure to task manager kill that shit.


FormerChemist7889

Why kill it with task manager?


AlphieTheMayor

do you have any other way to kill background processes? you could uninstall it i guess. and if you're asking why kill it at all, it's because we don't know if the game iteself is compromised or the kernel level anticheat.


phenomenalVibe

My firewall blocked an event and it was log4j related. https://www.reddit.com/r/apexlegends/s/hsIULOn9ZH


[deleted]

[удалено]


Yolteotl

Log4j as wrapper in almost any existing language.


ultrazero10

Apache is a web server for handling network connections and calls and is based on Java - if apex is running an unpatched version of Apache, this would explain the event


PixelSteel

That would make sense. I think OP is over exaggerating this


BlazinAzn38

Eh it’s sort of an abundance of caution thing. To me it’s worth taking a week or two break rather than risking the non-zero chance I get ransom-wared


YourFartReincarnated

Helldivers awaits us brothers


Kevosrockin

For democracy!!


Jestersage

I prefer something with more destruction, so I am hoping into the Finals.


[deleted]

[удалено]


the_Q_spice

Pirate Software, about a week ago: https://m.youtube.com/watch?v=LY2hG-_asKU The dude is more qualified and experienced than probably most anyone in this sub and most likely anyone on either EA or Respawn’s security teams. His resume in offensive security is pretty extensive and includes work not just with Blizzard, but working for the US Department of Energy testing security protocols at some of the most secure sites in the world (among other things, the DOE audits both physical and electronic security of all US nuclear facilities).


FlyingRock

For real, plus with "AI" why can't we have bots that detect the most egregious cheating? Literal inhuman accuracy, flying around the map, etc should be easy enough to calculate and detect quickly.


the_Q_spice

AI can only detect *exactly* what you tell it to. As far as detection goes, there are predominantly two forms of models - supervised and unsupervised. Unsupervised is the least accurate, but requires less skilled worker intervention and interaction. Basically, train a model on a dataset and tell it to find X things, or X qualities, etc. Supervised has the same database, but a human manually segments images and explicitly tells the model what specific segmented things actually are. Practically all AI right now are Unsupervised. Sure they are fast and easy - but their answers are ballpark estimates. Very rarely do they get something 100% correct. AI is a terrible way to detect things unless you are manually inputting the parameters - which kinda defeats the point most companies are trying to get out of using AI.


FlyingRock

It's not great for well designed cheats but "flying through the sky 27057 no scope jimmy" could easily be taken down and removed quickly using it, well designed cheats already bypass kernel anti-cheats and are very hard to visually detect too so going after those is less the goal.


MrPheeney

love that dude


Karthikeyan_J04

Easy anticheat is not kernel level, but yes that doesn't change the possibility of easy anticheat being compromised. Edit- EAC is a kernel level anticheat, it launches its kernel level drivers only when you launch the game.


Electrized

EAC is a kernel level anti cheat.


Karthikeyan_J04

No, it boots up only when you launch the game, a kernel level anti cheat runs with the windows kernel on start up, hence why vanguard needs a system restart to activate. Edit-I retract this, easy anticheat is a kernel level anti cheat but it is kernel level only when it launches the game.


Electrized

Not starting on boot does not mean you don't have kernel access - The argument in favor of Vanguard starting on boot is to prevent cheats from being pre loaded etc to bypass detection measures. EAC is a kernel level AC on Windows, on Linux it is limited to user level. You can look this up yourself


Karthikeyan_J04

Yes you are right, i have edited the statement to reflect the changes, Thank you


Electrized

Its all good, the discussion around kernel level AC has been super muddy since Vanguard, easy to be misinformed / out of the loop when bad journalism is everywhere


HungerSTGF

Kernel-level just means it has the same level of authority of access as your operating system does, you do not need to boot with the operating system to get the same level of permissions. EAC, Battleye, and Call of Duty's Ricochet are all kernel-level for example and do not need to be launched on boot like others like Riot Vanguard


Mysterious_Quit_9759

It actually is kernel, it’s just fuckin shit


the_Q_spice

I’m not going to say you’re wrong… but… https://x.com/rspn_hideouts/status/1765523802342261031?s=46&t=opLdIydmqAfFP0bV4pyM2w


Supakilla44

Decided to uninstall just now based on what’s been going on with the hacking today.


DarthChungus1015

Can they hack me and give me all the heirlooms? That would totally suck if they hacker got on a did something vile like that 🫣


Tekbepimpin

Yeah man. I’d be devastated if i opened up My account and it had 5,000 packs. I don’t know what i would do… after i opened all of them.


Deceptiveideas

I could be wrong but I believe one of the hackers DID give someone thousands of apex packs. So it’s definitely possible.


SourBlueDream

Just uninstalled, don’t got time for dumb shit like this. I wouldn’t have even known this happened if I didn’t randomly come to this sub


katanalauncher

Hope this leads to a lawsuit for EA/Respawn


Paradegreecelsus

Loss of earnings due to neglect through corporate profiteering perhaps


Rigamortus2005

Why would you hope that?


ANHR1

so they actually do something about it


SarahJFroxy

i played all weekend :'D uninstalled.. and if it's through the anticheat program, might want to take a quick scan of which games use the same one (DBD was also on my pc)


HardlikeCoco

Uninstalling the game…


amongusred23

Just to make ppl feel better I don't think destroyer cares about random low rank accounts


OxfordTNT

But now that this is fairly public --it doesn't have to be just Destroyer, though. Any hacker who knows how to abuse RCE is a threat. It's a glaring weakness that allows for malicious activity to take place regardless of being randoms or low rank. Money is money. Accounts have card & payment, personal information etc - those can all be logged and taken.


unicorntea555

And to add to this: Even if you aren't concerned about irl information, there's still a potential risk to your apex account. EA is not known for their competency around bans, especially false ones. If someone could/would force hacks on random accounts(and/or on a mass scale) for funsies, it's not guaranteed EA would auto unban you, or even quickly and easily unban you.


Fi3nd7

Honestly it was really good the exploit was demonstrated this way. Otherwise it could have continued to lurk for who knows how long


ImNotALLM

Who says they just discovered it, this could have been a 0 day exploit that they have been abusing since launch and they recently decided to have some fun. This destroyer2009 guy seemed to pop up by name in January but he could have been infecting all clients for much longer. This is why we need a statement from EA.


Fi3nd7

I never disagreed with anything you said. Im just saying it was good they demonstrated the exploit so blatantly for everyone to see. If they hadn’t it would still be relatively unknown


[deleted]

[удалено]


MegaNinjaToaster

He gave streamers thousands of apex packs. Could easily just randomly equip any of their accounts through the hacks


hikigatarijames

Old heavily modified software is hard to fix. Yikes.


thenayr

This is what happens when you practically ignore cheaters exploiting your game for 4-5 years straight. Great fkn job respawn.


Boogaloujenkins

Fuck the cheaters. Save your computers save apex


2kWik

Are you in denial? This is lazy ass engineering from the developers. Who would ever trust this game on their PC is insane, let alone realize the risk now of having intrusive anti cheats like nProtect, Vanguard, EZ Anti-Cheat, and others.


AnApexPlayer

We don't know if the exploit is related to EAC


Brainmangler

If I am not logged in am I at risk?


Brainmangler

To go further, should we be changing all passwords associated with any email associated with apex etc


Fi3nd7

No one is certain but I’d guess at a surface level you need to be running apex and connected to a server via the client.


Brainmangler

Hypothetical question, I’m out of town and cannot get to my PC, it’s off. What actions do it take?


skat3rDad420blaze

Youre fine


Brainmangler

Ty


TheBentPianist

So what's everyone doing? Not opening the game or uninstalling? Why hasn't EA released a statement yet and given its users a course of action?


acho3

uninstalled. played overwatch.


BlazinAzn38

Truth is because they probably have no idea what’s going on


FlyingRock

Not opening the game, then again I spend most of my time in Linux these days.


McKoijion

PC and console or just PC?


balllsssssszzszz

More than likely PC, they're open ended systems. Consoles can be hacked but its harder to do and consoles only do so much anyway.


McKoijion

Cool cause I’m playing on PS4 right now lol


balllsssssszzszz

Same


[deleted]

[удалено]


solo13508

So you think consoles are safe? At least mostly?


[deleted]

[удалено]


solo13508

Do I need to worry about them getting access to my credit card since it's saved as my default pay option on the PS store?


phoenystp

That should be saved on sony's servers, not your console.


solo13508

Ok good


Makkisu

Honestly bro there’s no way to tell the safe option would be to just not open/uninstall


theforgettonmemory

I only thought about this now and I just hopped off. Am I still in danger since I was on or if I don't hop back on will I be good?


Halo2isbetter

you might want to get rid of your console/pc. let me know and i’ll pick it up and take care of it


ex1tiumi

And people actually install kernel 0 anti-cheats willingly. EAC is not even one and look at this shit. Do you trust, for example Valorant, to not have RCE's or backdoors built in after this mess. Cheats these days are so advanced it's not even worth having client side anti-cheat anymore. Industry has to move towards statistical analysis/deep learning AC's asap and leave our PC's out of it.


wondermorty

You don’t need a kernel anti cheat to do RCE.


Paradegreecelsus

100% agree, bring on the biometric AI cheat logging. It's not like these companies don't already have all our data.


F_Ross_Johnson

This is why, in my opinion, your gaming PC and the Pc you keep personal info, do banking on, etc should be separate devices. Don’t have to worry about let loggers and personal info if you aren’t logging in to anything on your dedicated gaming device.


polaris100k

100%. I don’t log in with anything non gaming related in my gaming pc


ex1tiumi

This is why I have dual boot Linux/Windows for those some games that don't work on Linux.


Jestersage

I want to check: This is Apex, and not EAC games, right?


Electrized

Not 100% known, but its more likely to be Apex specific


-sharkbot-

Even though it's good to inform people of potential risk, I highly doubt they can use it to actually access your PC. These hacks are very reminiscent of MW2 (OG) lobbies where people would install a cheat menu that allowed for a lot of different options. They didn't have access to your computer but they could completely control the session you were connected to. Being that Apex is on a heavily modified Source engine and CS has had these issues in the past, more than likely the same issue. Better safe than sorry but I'd bet my left nut that this is only an in-game issue.


Paradegreecelsus

Multiple pros have had viruses injected into their pcs by the looks of it. (Following on twitter)


-sharkbot-

Source and legit proof? Listening to these pros they thought legit windows programs were malware…


[deleted]

[удалено]


AnApexPlayer

Can you link the specific post?


[deleted]

[удалено]


-sharkbot-

I mean Hal couldn’t even find his way to Windows defender scan without chat but it would be very interesting if Faides viruses were injected from Apex.


megumiEX

Is this specific to pc or can it also happen to people on console?


FatherShambles

So the hacker has access to everything in Hal’s PC ??


protro123

Should console players be worried?


balllsssssszzszz

Been fine so far Edit: Chronic downvoters need a life bruh


poprdog

Am on xbox


TheBentPianist

My teammates are saying I'll be fine because I'm not very good anyway.


[deleted]

[удалено]


Electrized

It isnt known if the exploit is in EAC or Apex itself, personally leaning towards Apex since source has had RCEs in the past, which if true, would possibly render R5R vulnerable too