NizBotIO
2 months agoRising Rookie
Concerns Regarding EA App and Javalin AC
Hi Guys,
I have some concerns relating to the security of the "EA App" including: EA Desktop, EA LocalHost, EA BackgroundService, EACefSubProcess, and EA AntiCheat.
These are my concerns: Whilst playing any EA game on my desktop for this example lets say BF2042 I notice a large number of IP connections and data transfer to/from various external IP addresses unrelated to the concurrent BF2042 connections. This concerns me for more than one reason:
- My EA app is set to not auto update.
- My EA app is set to not download during gameplay.
- My EA app is bandwidth limited for updates.
- My EA app's Overlay is disabled.
- My EA app seems to ignore these settings and shares many MB/s of data with these external IP's during a gaming session.
- The external IP's do not seem to match that of the game being played, such as BF2042
- I'm concerned that your APP Suite inc EAAC is insecure, as occasionally during game play my Keyboard gets disconnected, and it's only when your app and games are running, Xbox Games do not display this same behaviour and I do not use a controller for these.
- I'm concerned that you are using peoples available hardware resources for some kind of mining/folding/compute servicing, which would raise legitimate criminal concerns, you see if you are doing so, then you are stealing from your customers, using their hardware and costing them money (Energy Bills) for your own gain, could be considered theft in many countries. (I'm hoping this isn't the case.)
- The Disconnection of peripherals comes from the fact your anti-cheat uses a Kernel-Mode driver and has FullTrust access to all machines that could potentially be accessed, abused by an attacker.
- Your Anti-cheat service seems to update, after every Microsoft update to windows and windows security, which seems too coincidental IMO. Like you have patched Microsoft's own measures on their OS so that your Kernel-Mode driver can still have FullTrust.
I could be barking up the wrong tree, but it does seem awfully suspicious that when your software is running these are the problems that I have and the pattern I see when on a gaming session.