Red Shell - spyware ?
Page: 1/2»
  Go to:
razing32 Jun 29, 2018
I recently became aware of Red Shell
https://redshell.io/home

It's an SDK to track info about users for developers of games.
Seems some linux ones are on the list like Total War and Ballistic Overkill , though they seemed to remove it. Civ 6 is STILL using it

List of games in quote:
QuoteGames who used Redshell which removed or pledged to remove it (as of 28.06.2018):

Elder Scrolls Online ( Removed it )
Conan Exiles ( Removed it )
Ylands ( Removed it )
Holy Potatoes! We’re in Space?! ( Removed it )
All Total War games, ( Pledged to remove it )
Warhammer: Vermintide II, ( Removed it )
My Time At Portia, ( Removed it )
Dead by Daylight, ( Removed it )
Battlerite, ( Pledged to remove it )
AER Memories of Old, ( Pledged to remove it )
Magic the Gathering Arena (closed beta & not on Steam), ( Removed it )
Secret World Legends ( Pledged to remove it )
Hunt: Showdown ( Pledged to remove it )
Escapists 2 ( Removed it )
Omensight ( Removed it )
Ballistic Overkill ( Pledged to remove it )
Vaporum ( Removed it )
Tales from Candlekeep: Tomb of Annihilation ( Removed it )
Yoku's Island Express ( Removed it )
Clone Drone in the Danger Zone ( Removed it )
The Wild Eight ( Removed it )
Desolate ( Removed it )
Trailmakers ( Removed it )
Raging Justice ( Removed it )
Dungeon Rushers ( Removed it )
Indygo ( Removed it )
Kerbal Space Program ( Removed it )
Quake Champions (no redshell dll files, seems to be integrated in game ) ( Pledged to remove it )
NosTale ( Pledged to remove it )
SoulWorker ( Pledged to remove it )
RockShot ( Pledged to remove it )
Archangel: Hellfire ( Removed it )
Skyworld ( Removed it )
Eternal Card Game ( Removed it )

.

Games still using Redshell according to community reports (as of 28.06.2018):

Civilization VI,
Guardians of Ember (Publisher removed from Steam),
The Onion Knights (Publisher removed from Steam),
Heroine Anthem Zero,
Warhammer 40k Eternal Crusade,
Krosmaga
Sniper Ghost Warrior 3
Astro Boy: Edge of Time
Cabals: Card Blitz
CityBattle | Virtual Earth
Doodle God
Doodle God Blitz
Doodle God: Genesis Secrets
Labyrinth
My Free Farm 2
Shadowverse
SOS & SOS Classic
Stonies
War Robots
Survived By
Injustice 2
Warriors: Rise to Glory!
League of Pirates
The House of Da Vinci


Source : https://www.reddit.com/r/SidAlpha/comments/8qh9fg/psa_red_shell_spyware_found_in_many_steam_games/


Video where i first found out about it : https://www.youtube.com/watch?v=wF-umETMsSg
Ehvis Jun 29, 2018
I'm not so sure that Feral/Aspyr included redshell in their ports. Unity games seem to be much more worrying because they may actually be able to use it on Linux.
Mountain Man Jun 29, 2018
Host files are your friend.

http://someonewhocares.org/hosts/
s8as8a Jun 30, 2018
I recommend the sandboxing program named firejail (which is easy to use - you just type firejail, followed by the command you would have otherwise typed, such as steam). (I also recommend sandboxing / not trusting any proprietary program, even if you don't hear or read of some controversy like this one.) (Sandboxing Steam also sandboxes all programs started via Steam.) (If you're using Debian, you can find firejail in its repositories.)

Edit:
Actually, did I misunderstand what it's tracking, exactly?
razing32 Jun 30, 2018
Quoting: s8as8aI recommend the sandboxing program named firejail (which is easy to use - you just type firejail, followed by the command you would have otherwise typed, such as steam). (I also recommend sandboxing / not trusting any proprietary program, even if you don't hear or read of some controversy like this one.) (Sandboxing Steam also sandboxes all programs started via Steam.) (If you're using Debian, you can find firejail in its repositories.)

Edit:
Actually, did I misunderstand what it's tracking, exactly?

Thanks for the program , will check it out.
It tracks how successful ad campaigns are.
It collects OS , monitor resolution , browsers installed , IP address etc.
They say that it is sent in hash and it won't uniquely identify you , but I do not trust it especially since it is opt-in by default.
GustyGhost Jul 1, 2018
More than that, they even explicitly state it tracks what sites you visit and videos you open. The spooks try to deflect criticism by playing with language: "...we are tracking what machines do..." instead of "...we are tracking what users do..."

This only pushes me even further toward simply following a no proprietary anything rule even for games. Are we going to have to start testing every game we buy through wireshark?
Cyril Jul 1, 2018
Quoting: GustyGhostThis only pushes me even further toward simply following a no proprietary anything rule even for games. Are we going to have to start testing every game we buy through wireshark?

You're right... But "when" the games will be ALL DRM-free, we'll have to open source ALL of them...
It will be hard and I don't expect all of Linux users to be agree with that, unfortunately.
razing32 Jul 1, 2018
Quoting: Cyril
Quoting: GustyGhostThis only pushes me even further toward simply following a no proprietary anything rule even for games. Are we going to have to start testing every game we buy through wireshark?

You're right... But "when" the games will be ALL DRM-free, we'll have to open source ALL of them...
It will be hard and I don't expect all of Linux users to be agree with that, unfortunately.

Truth be told I'm not against closed source proprietary software.
I can understand why some companies might want to protect their intellectual property.
But more and more in this age everyone seems to want to have your data , from governments to social media and ad companies.
And when I see this under handed data slurp in games of all things I am starting to understand the people who advocate open source only more and more.
tuubi Jul 1, 2018
Quoting: razing32
Quoting: Cyril
Quoting: GustyGhostThis only pushes me even further toward simply following a no proprietary anything rule even for games. Are we going to have to start testing every game we buy through wireshark?

You're right... But "when" the games will be ALL DRM-free, we'll have to open source ALL of them...
It will be hard and I don't expect all of Linux users to be agree with that, unfortunately.

Truth be told I'm not against closed source proprietary software.
I can understand why some companies might want to protect their intellectual property.
But more and more in this age everyone seems to want to have your data , from governments to social media and ad companies.
And when I see this under handed data slurp in games of all things I am starting to understand the people who advocate open source only more and more.
There's always a middle ground. We need to openly boycott unethical companies who invade our privacy for profit, but there's no reason to punish the rest of them. It's not "open source" vs. "evil".
Mountain Man Jul 1, 2018
Quoting: razing32
Quoting: s8as8aI recommend the sandboxing program named firejail (which is easy to use - you just type firejail, followed by the command you would have otherwise typed, such as steam). (I also recommend sandboxing / not trusting any proprietary program, even if you don't hear or read of some controversy like this one.) (Sandboxing Steam also sandboxes all programs started via Steam.) (If you're using Debian, you can find firejail in its repositories.)

Edit:
Actually, did I misunderstand what it's tracking, exactly?

Thanks for the program , will check it out.
It tracks how successful ad campaigns are.
It collects OS , monitor resolution , browsers installed , IP address etc.
They say that it is sent in hash and it won't uniquely identify you , but I do not trust it especially since it is opt-in by default.

From what I've read, it collects enough data to uniquely "fingerprint" each user and track them across the internet. It supposedly doesn't track personal details, but I'm sure it wouldn't be hard to figure out based on the "fingerprint" and someone's browsing habits.
Guppy Jul 2, 2018
If you class it as spyware then I'm sorry to tell you that 99.9% of websites is infected by the "spyware" known as "google analytics".

As far as I can tell red shell does the exact same thing - provide generalized user/usage statistics, not quite sure why you'd think it sinister that they would like to know how much ram/gpu power/screen resolution/etc the people that actually play their game has. It's useful data that will help the tune the game and prioritize bug fixing; 95% of active players are Nvidia users @1920x1080p ? maybe bugs relating to that needs fixing first.
While you're here, please consider supporting GamingOnLinux on:

Reward Tiers: Patreon. Plain Donations: PayPal.

This ensures all of our main content remains totally free for everyone! Patreon supporters can also remove all adverts and sponsors! Supporting us helps bring good, fresh content. Without your continued support, we simply could not continue!

You can find even more ways to support us on this dedicated page any time. If you already are, thank you!
Login / Register


Or login with...
Sign in with Steam Sign in with Google
Social logins require cookies to stay logged in.