Announcement

Collapse
No announcement yet.

Latest ESEA Client Poses a Huge Security Risk

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Latest ESEA Client Poses a Huge Security Risk

    If you frequently make use of the ESEA client to play on their Counter-Strike servers, you may want to hold off on updating to the latest version. Hell, I'd go so far as to suggest that you uninstall the ESEA client right now and take your business elsewhere.

    Why?

    It seems as though the latest client gives the ESEA full administrative access to your computer. The client makes use of a kernal driver that now runs 24/7 on your machine. It has the capability to look at any file on your computer and send that information to the ESEA servers. It can be viewed by any admin of the ESEA. This "service" runs even when you are not playing Counter-Strike and runs from the moment you boot up your machine to the moment you shut down. It also has the ability to take a screenshot whenever it wishes. It has even caused a repeated blue screen (BSOD) for users.

    Ipkane and the rest of the ESEA team claim that this was all done to better detect cheats. Ipkane's feelings on the matter are simply "if you don't like it, go elsewhere."
    tonight's Client update requires a windows restart in order to play on ESEA servers, this is due to the fact that, like an anti-virus, the ESEA Client is now always running (unless you uninstall and restart)

    please note that running the ESEA Client and playing on ESEA servers is entirely optional, there are other places to play, and if you're uncomfortable with the Client always running then you should uninstall and cancel your subscription

    ESEA is already the industry leading anti-cheat, it's been that way for more than a decade, and tonight's update further represents our commitment to doing whatever it takes to maintain the competitive integrity of our community

    That is precisely what you should do. Don't put up with this kind of shady shit from the ESEA. Take your business elsewhere. As one Reddit user, skittay, put it:
    Their anti-cheat is very effective but I have no idea what their backend looks like or what their internal security is. I don't even know what kind of tooling they use to pull data from me. In order for me to be OK with this they'd need to have extremely reliable cyber security and on-premise security; like Goldman Sachs level - and be very public facing about it. They don't and aren't.

    By using their client you're not just trusting them with your data but you're trusting that they can protect it and access to it. Before it didn't matter because I only had the client running when playing and don't store any important data - and my profile contains 0 sensitive information. Now its a bit different because it can audit everything I do all the time (maybe it doesn't, who knows?). I work as a software dev at a large company and often from home and I do access sensitive internal information from my desktop - I can no longer do that with any measure of confidence with this client.

    This is the same company that also hid a bitcoin mining program in one of their previous client updates. It's the same company that has been found to store passwords as plain text. And now they have admin level access to your computer? Get out while the getting is good.

    More information can be found at this Reddit megathread in the Global Offensive section, which includes more first hand accounts of what this client does, the lack of proper public relations from the ESEA, and concerns raised by this community.
Working...
X