Posts by 0xNemi

Bloodnoskie

when will there be fps fixes? i get microstutters every time i try retake a site and everyone is shooting and fps is broke in other games :(

Most of these issues should already be fixed by now, however, there'll be more optimizations in the new VALORANT build coming out soon (hopefully this week).

OWPD

Awesome write up hopefully, this shutdown all the AHK meme aimbots that people think will be the end of this game lmfao

/u/riotarkem is conjuring something for that one. SoonTM.

bapplebo

Thanks for this, adds a bit of extra transparency. Unfortunately, I imagine you'd still have those who think that disabling through this way is somehow psyops to trick people into giving information to CCP.

Anyway just wanted to also say your blog had a few articles that were interesting to read through /u/0xNemi.

Can't please everyone! Glad you enjoy the blog 😉. I haven't had a lot of time to work on it recently.

[deleted]

Because HWMonitor loads a driver that can be abused by third party applications to read and write physical memory, read and write MSRs, perform IO operations (privileged); all from usermode. It's unsafe to load anyways and they're blocking it because it can be potentially used by hackers to read and write memory for the game.

This is accurate.

DingusDong

Well you've hit the nail on the head. Not having perfect security on what essentially a backdoor to potentially hundreds of millions of computers around the world is frankly a little terrifying given who's at the top of the Valorant totem poll.

Quoting what was said in another thread:

It depends how brazen they want to be. Small scale they could gather a whole heap of data. Like where do people look for their news and information would be really handy in prioritising propaganda efforts. Between Tik Tok monitoring phones and Riot monitoring PCs they can probably get a solid sample size for young westerners. On the other end of the spectrum, they could use it for distributed attacks (credential stuffing/DDOS) or to try and hide the origin on a more sophisticated attack (i.e. using compromised user credentials to exfiltrate data). They have administrator access to the machine, they can do with it whatever you could do with it.

Going really tinfoil hat here but it could make for a really secure onion router style network for secret coms. Assuming China doesn't trust TOR (which it shouldn't) they can't deny the inherent benefits of that style of routing. It's effectively untraceable and if it's machines and ports that they compromised it reduces their potential exposure even further. The Tl;Dr of onion routing is that messages you send get broken up and sent to multiple machines before reaching its target. Nothing is perfectly secure, but that is as close as we can really get. Let's say your computer is picked to be one of the middle stops for the data. Assuming you were running wireshark, and looking for data traveling through ports assigned to Valorant (or any other CCP program) you would likely only see a packet full of junk data coming from a random IP, going to a random IP. If there is any P2P data exchange in that game then it would be even harder to find.

/u/0xNemi could we get your thoughts? Are we crazy for having these concerns?

There's nothing I can say to help reduce your concerns. You've already made up your mind.

Ultimately, you get to choose what you run on your machine.

We're aware. There's some networking issues that we're sorting out on our backend. They're unrelated to the most recent changes.

Things should be back to normal in the next few minutes. Sorry for the inconvenience!

Theostru

Hi /u/0xNemi and /u/RiotArkem !

Is there a way to check what was blocked beyond the notification? On boot, the notification disappeared before I could click it, and when I then went to notification center and clicked on it, it went away without presenting any popup or additional information on what was blocked.

Reading this thread, I'm 99% sure it was HWMonitor, but the fact that I have to rely on an ephemeral popup rather than an actual application or even just a log file is pretty frustrating.

Run this command in command prompt:

reg query HKLM\System\CurrentControlSet\Services\vgk /v BlockedImage    

The tray icon reads from that location.

[deleted]

Vanguard is blocking System32 .sys drivers on system start up. xtuacpidriver.sys to be exact. Which is Intel tuning software.

Make sure you have the latest update from the vendor: https://downloadcenter.intel.com/download/24075/Intel-Extreme-Tuning-Utility-Intel-XTU

Extremely old versions of this have been known to cause issues.

While we normally don't plan on documenting changes to Vanguard, our Anti-Cheat system for VALORANT, on a frequent basis, this new update to Vanguard adds a new visual component that will give you, the player, more visibility and control over it. This post serves to provide some context.

Starting today, Vanguard will start showing a system tray icon (after a reboot) while it's running. From there, you'll be able to turn off Vanguard at any time. Turning off Vanguard puts your machine in an untrusted mode and will prevent you from playing VALORANT until you reboot. If you want to keep Vanguard off indefinitely until you play VALORANT (e.g. persisting across multiple reboot sessions), you'll be able to do so more easily now by uninstalling it from the handy dandy system tray. Vanguard will automatically be reinstalled when you launch VALORANT. If you dislike the new system tray icon, you'll be able to disable (or re-enable) it at any time by going into your Windows Notification Area....

Read more