Update Aug. 27 12:32pm CT – Activision’s response:
“The author is entitled to question whether firmware-based security requirements create too much friction for players. We recognize that updating motherboard firmware can be a more involved process for some users. Our concern is that the story builds its argument by conflating several separate technologies and presenting inaccurate claims as fact.Kernel-level anti-cheat is not a new development. The technology has existed across PC games for roughly two decades, and Call of Duty introduced its kernel-level driver in 2021. A kernel driver is also not synonymous with a rootkit. RICOCHET Anti-Cheat’s driver only operates while a protected Call of Duty title is running and shuts down when the game closes. The story instead presents its privileged access as proof that it continuously surveys everything a player does, which is not accurate.
The descriptions of TPM and Secure Boot are also fundamentally wrong. TPM does not allow Microsoft to “peer into” a user’s machine. It provides hardware-backed security functions and evidence about the integrity of the system’s boot state. Secure Boot verifies authorized software in the boot chain. Neither technology monitors a player’s files, applications or general activity. Read Microsoft’s documentation on how they use TPM here: https://learn.microsoft.com/en-us/windows/security/hardware-security/tpm/how-windows-uses-the-tpm and more about Secure Boot here https://learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-secure-boot.
The story also characterizes the firmware requirement as Activision arbitrarily “disagreeing” with AMD’s TPM implementation. We are asking affected players to update TPM firmware that AMD itself has identified as vulnerable and untrustworthy. AMD’s security bulletin is available here: https://www.amd.com/en/resources/support-articles/faqs/pa-420.html.The update comes from the motherboard manufacturer. Activision does not install software into the firmware, modify the TPM or “run the motherboard,” as the story claims.
Most importantly, the article collapses the RICOCHET driver, TPM, Secure Boot, platform attestation and motherboard firmware into one supposed surveillance system. These are separate components with different roles. Presenting them as interchangeable leaves readers with a false understanding of both the requirement and the technology behind it.
No anti-cheat system eliminates all cheating, and we have never claimed otherwise. The continued existence of cheating clips does not establish that these protections have no value. These measures establish greater trust in the system at launch, make certain forms of tampering harder and raise the cost of developing and using cheats.”
Anti-cheat measures in modern video games have always been controversial. I mean, in times of old, folks could just run any given anti-cheat on their machine, and it’d work in the same layer as the game itself, compromising no one’s safety and privacy whatsoever.
But nowadays, it seems big publishers are hellbent on forcing their player base to run rootkits, enable all the TPM bells and whistles to allow Microsoft to peer into our whole machines, and even run Secure Boot to make sure everything checks out at the lowest possible level—the BIOS.
Activision Blizzard is even more aggressive and invasive when it comes to its Modern Warfare 4 anti-cheat and asked me to go and update my entire BIOS, which I had already flashed to a 2025 version, because it did not agree with the version of AMD’s TPM running on it.
And I think that’s the final straw for me.

Kernel-level anti-cheats run at level zero, your machine’s most intimate part, allowing them to survey your entire PC’s activity, including memory, applications, and everything in between. This is apparently done because so many cheats and hacks nowadays are also kernel-level, meaning that if you had an anti-cheat running under normal circumstances, it would simply have no way to detect them.
However, it also raises serious privacy concerns for users. Since this software is running at a kernel level, that means it can basically see everything you’re doing on your machine, forcing you to sacrifice your conscience and safety just to get a semi-functional anti-cheat in a video game.
And then a publisher like Activision comes in and asks you to perform tech-savvy things like flashing your BIOS, which always carries the risk of completely bricking your motherboard if failsafes fail to trigger. This company wants you to get into the lowest level of your machine and install updates it agrees with so you would be able to run a game you paid $80 for.
While flashing the BIOS isn’t particularly radical or challenging, asking the average end-user to do it is ridiculous, especially when we’re dealing with hardware that is merely one year old. Activision simply gives itself the right to not only run a rootkit on your PC, but also your whole entire motherboard, and its software has to adhere to it.
What is it that Ricochet Anti-Cheat does better or differently to warrant such activities and the endangerment of privacy? There are numerous clips on X and other platforms of rampant cheating in MW4 despite all of these invasive measures. Why does the average user have to get their hands dirty—or even pay for servicing—to be able to run a game that has an obviously imperfect anti-cheat system?
Sure, it might be better than Valve Anti-Cheat, which that company is trying desperately not to turn into a kernel-level solution, but it also comes at such a cost that I don’t see why anyone would want to deal with it.
I certainly won’t. I’ll learn to live without Ricochet.