• RGB Peripherals Are A Red Line For Windows Anti-Cheat Software Now

    From Lawrence =?iso-8859-13?q?D=FFOliveiro?=@ldo@nz.invalid to comp.misc on Sun Aug 23 01:58:31 2026
    From Newsgroup: comp.misc

    Yet again, another monthly update for Microsoft Windows is causing
    machines to crash <https://www.tomshardware.com/software/windows/microsoft-blames-rgb-peripherals-for-crashing-windows-11-rgb-software-is-causing-blue-screens-crashes-and-game-freezes>.

    This time, Microsoft is blaming an interaction between the drivers for
    RGB peripherals (the ones with colourful LEDs that can be made to
    cycle in different patterns) and anti-cheat mechanisms built into some
    of the more expensive games.

    Quote:

    RGB software installed on affected PCs was interfering with core
    system components, causing Windows 11 to become unstable.

    Actually, no it wasnrCOt. The article goes on to make an educated guess:

    Microsoft didn't explain the underlying cause, but it's likely
    tied to anti-cheat not appreciating a kernel-mode driver in user
    space. RGB software, like other apps, should be limited to user
    space, but the driver it uses to interface with peripheral
    controllers runs in kernel space. For anti-cheat software, this is
    essentially an exploit waiting to happen, so it tries to block the
    driver to make sure it doesn't inject malicious code.

    (Of course, by rCLmaliciousrCY they mean rCLhaving the ability to snoop into their gamerCY.)

    So the RGB drivers on their own were fine. But bring in something from
    some paranoid multi-billion-dollar company that thinks it has a right
    to control the way you use your machine, and then the wailing and
    gnashing of teeth will start.
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Theo@theom+news@chiark.greenend.org.uk to comp.misc on Sun Aug 23 23:13:31 2026
    From Newsgroup: comp.misc

    Lawrence DrCOOliveiro <ldo@nz.invalid> wrote:
    Yet again, another monthly update for Microsoft Windows is causing
    machines to crash <https://www.tomshardware.com/software/windows/microsoft-blames-rgb-peripherals-for-crashing-windows-11-rgb-software-is-causing-blue-screens-crashes-and-game-freezes>.

    This time, Microsoft is blaming an interaction between the drivers for
    RGB peripherals (the ones with colourful LEDs that can be made to
    cycle in different patterns) and anti-cheat mechanisms built into some
    of the more expensive games.

    Quote:

    RGB software installed on affected PCs was interfering with core
    system components, causing Windows 11 to become unstable.

    Actually, no it wasnrCOt. The article goes on to make an educated guess:

    Actually it was: https://windowsforum.com/windows-news.4/kb5121003-remove-inpoutx64-to-fix-arc-raiders-crashes-megathread.442938/

    inpoutx64.sys is an _ancient_ driver that allows userspace to poke any hardware. Of course that blows through lots of security barriers. RGB software uses it to poke their hardware registers from userspace, because
    they were too lazy to write a proper kernel driver and get it signed by MS
    so they just reuse this already-signed debugging driver from 2008.

    In fact we've been here before: https://www.theverge.com/report/629259/winring0-windows-defender-fan-control-pc-monitoring-alert-quarantine
    https://gitlab.com/CalcProgrammer1/OpenRGB/-/merge_requests/1036 https://github.com/ixjf/MSIRGB/issues/115

    First they used InpOut32 but it was blocked by anti-cheat, then it was
    WinRing0 and now it's InpOutx64. History keeps repeating.

    Theo
    --- Synchronet 3.22a-Linux NewsLink 1.2
  • From Lawrence =?iso-8859-13?q?D=FFOliveiro?=@ldo@nz.invalid to comp.misc on Mon Aug 24 02:33:58 2026
    From Newsgroup: comp.misc

    On 23 Aug 2026 23:13:31 +0100 (BST), Theo wrote:

    Lawrence DrCOOliveiro <ldo@nz.invalid> wrote:

    Actually, no it wasnrCOt. The article goes on to make an educated guess:

    Actually it was: https://windowsforum.com/windows-news.4/kb5121003-remove-inpoutx64-to-fix-arc-raiders-crashes-megathread.442938/

    inpoutx64.sys is an _ancient_ driver that allows userspace to poke
    any hardware.

    How is this different from, say, libusb on Linux?

    Of course that blows through lots of security barriers.

    Not if the I/O access is itself protected behind suitable privilege protections. Again, there is a mechanism for this under Linux <https://manpages.debian.org/ioperm(2)>.

    First they used InpOut32 but it was blocked by anti-cheat, then it
    was WinRing0 and now it's InpOutx64. History keeps repeating.

    Basically, on Windows, they cannot allow the user to do anything that
    might require privilege on their own machine, because that could be
    considered in some way rCLcheatingrCY.
    --- Synchronet 3.22a-Linux NewsLink 1.2