7 ms·
FlightSimLabs Alleged Malware Analysis
- taylorexpander 9y agoI thought I’d share this here to spread more attention to the practices of FlightSimLabs, a flight simulator software shop. The short version is that they included an executable in their installer that when run would extract passwords saved in Chrome and presumably phone them home. Their reasoning was that this was purely for DRM reasons. They claim that this password stealing tool would not run for legit/valid serial keys. This was only discovered by someone on reddit recently, and since this has been public the developers have claimed they’ve removed the password stealing malware from their installer. They have again made statements saying that this tool was only used against pirated copies of their software. Not once have they apologized and their users for the most part don’t seem to care.
- toomanybeersies 9y agoSo basically "you broke the law, so we'll break the law"?
- kees99 9y agoUnfortunately, this sort of attitude is not unheard of among proprietary software vendors - see for example FTDI bricking your hardware if they think it's counterfeit: https://news.ycombinator.com/item?id=8493849 https://news.ycombinator.com/item?id=8493849
- IntronExon 9y agoWouldn’t that be downright illegal? Moreover, someone bricking my hardware would inspire me to forcefully return said “brick” to them, through their nearest window.
- draugadrotten 9y agoWouldn’t that be downright illegal? Moreover, someone breaking my windows would inspire me to forcefully discuss said behaviour with them, with their nearest brick.
- IntronExon 9y agoTotally illegal, but while I would feel like tossing something through their window, I would never do it. If only this company had as much of a moral compass!
- alyandon 9y agoAnd as a side effect to that story - I recently needed to purchase a USB to RS232 adapter to program a router and I went explicitly out of my way to make sure the adapter I purchased didn't use an FTDI chip. FTDI is a name I won't be forgetting anytime soon.
- mariuolo 9y ago> FTDI bricking your hardware if they think it's counterfeit It's not quite the same thing. Their driver does things that work with the original hardware. If a different chip uses the same USB ID, they're asking for trouble. (of course good faith is unlikely in this case)
- arkades 9y agoActually, it’s “we suspect you may have broken the law, so we’ll break the law.” A distinction no one seems to be hammering on, but that I think makes what they did much, much worse.
- dx034 9y agoNot even sure if users broke the law. Just using a 3rd party cracked software doesn't necessarily violate laws (at least no criminal offence). The distributors and crackers clearly violated laws but any user with a cracked serial number was targeted. That also included people who might've received the number against payment from someone else and thought they had a genuine copy.
- Digital-Citizen 9y ago> They have again made statements saying that this tool was only used against pirated copies of their software. That's quite a claim. But it wouldn't matter if they did apologize. No apology would take away the malware or cause this publisher to have not used the secrecy of proprietary software (and the implicit trust all of their users had in the publisher) to not do what they did. Too bad for the users who obtained copies (regardless of how) that this claim is utterly unverifiable and ultimately up to the dictates of an organization that already misrepresented its aim to its users -- I'll bet that people who got a copy thought they were getting a flight simulator, not a credentials copier. There's no reason to trust that they're not lying now. And what if FlightSimLabs (or some organization they trust to hold data) inadvertently leaked sensitive information? That's the trouble with trusting organizations to hold sensitive data; they can end up contributing to harm even if they don't intend to do so, or do so accidentally purely by way of making bad decisions about whether to hold the data in the first place and also by bad design of where and how to store the sensitive data. Proprietary software hides malware (see https://www.gnu.org/proprietary/proprietary.html https://www.gnu.org/proprietary/proprietary.html for lots of examples), users deserve software freedom (the freedom to run, inspect, modify, and share published software), and users deserve to control their own computers. And this DRM was indiscriminate (as most DRM is): it was installed on all users of the affected program, including on the copies distributed in the manner FlightSimLabs wanted.
- GCU-Empiricist 9y agoI wonder what their legal department told them about this idea. I can't imagine any well briefed copyright lawyer concurring with this.
- filesystem 9y agoMy thoughts exactly. This is so unbelievably bone-headed. I want to believe that this was slipped in by a small rogue group within FSL, and that its not something everyone approved of...
- fyfy18 9y agoLinkedIn only has 3 people who are listed at working at this company [0], so I'd assume it's a small indie shop without a legal department. [0] https://www.linkedin.com/search/results/index/?keywords=Flight%20Sim%20Labs%2C%20Ltd https://www.linkedin.com/search/results/index/?keywords=Flig....
- GCU-Empiricist 9y agoIt still baffles me. You can't stay even moderately up to date on technology news, without knowing that initiating a security breach, even on someone who has stolen your product, will still be criminal.
- ikeboy 9y agoJust have the user agreement state that if you pirate it, you allow them to exfiltrate all data on your system.
- jnbiche 9y agoYeah, not sure if you're being sarcastic, but if not: the law doesn't work like that. You can't annul a criminal statute simply by including a clause in your EULA.
- milesdyson_phd 9y agoOh shit, I literally just bought one of their products for P3D... Edit: FSLabs_A320X_P3D_v2.0.1.215.exe also has it present
- maze-le 9y agoHey, thanks for the info. I was just thinking about buying the A320 for FSX the other day. I will refrain from installing any software from "Flight Sim Labs" in the future, its kind of troubling to see this development. I mean it is clear that you do not run just any old software you found on some shady corners on the internet, but this is a big vendor, with a lots of sales, a certain name and a community. How the hell can this happen?
- stevemk14ebr 9y agoSomeone sue them please
- zelon88 9y agoI never understood the point of DRM. "10 extremely determined people want to steal my intellectual property! I'll go miles out of my way to design this in such a way that 1,000 people have a crappy experience to slow down the 10 people who want to be pirates!" Vendor makes a shitty product Pirates find a workaround, pirate shitty product anyway Vendor makes shitty product even shittier for all 1,000 people to agin try to stop the same 10 determined pirates
- barry0079 9y agoThe silliest part of this is pirates usually get to enjoy a better product because of their actions.
- ceejayoz 9y agoFor example, the unskippable piracy warnings on DVDs.
- applecrazy 9y agoOh, the irony is palpable.
- dawnerd 9y agoAnd more recently with uhd. Those disks were supposed to be “uncrackable”. Well thanks to some older uhd drives pirates now have full disk rips and as far as I know they’re not even breaking encryption.
- jacquesm 9y agoNot only that: they end up enabling the pirates because the pirates are then able to provide the potential users of the product with a major reason for breaking the social contract (and the law): a much better user experience than the original.
- nottorp 9y agoBack when I was buying DRM-infested games on disc (lately I don't do AAA crap because it's boring, so the only DRM i have to deal with is Steam), the first thing before even unpacking the discs was to download the nocd crack. Those pirates provide a good service to the legitimate owners as well ;)
- exabrial 9y agoThe passwords aren't protected somehow from copying?
- deleted 9y ago[deleted]
- yjftsjthsd-h 9y agoNot usually, though perhaps if you've added a master password? It's the same reason why if you install a new browser it generally allows you to import bookmarks, passwords, and probably other stuff from an old browser.
- lima 9y agoNot on Windows, but on Linux it's encrypted with your account password (it uses the Gnome Keyring/KDE Wallet APIs). But none of that is going to help against an attacker with the same permissions.
- Someone1234 9y agoIf that's the case that's a choice Google made. Windows via the CryptProtectData API[0] allows you to protect data via the user's session just like the Gnome Keyring/KDE Wallet. But as you pointed out, another process with the same privileges can decrypt it making it pretty pointless in both cases. Only way to securely do it is to prompt the user for a decryption key each time they open the browser which has usability issues but Firefox offers it via the Master Password functionality. [0] https://msdn.microsoft.com/en-us/library/windows/desktop/aa380261(v=vs.85).aspx https://msdn.microsoft.com/en-us/library/windows/desktop/aa3...
- exabrial 9y agoSo Windows doesn't have an equivalent of OSX Keychain, where an item can have a per-application ACL? [or I have misunderstood the OSX Keychain]
- 9y ago
- tutts 9y ago"How do we know that FSLabs don’t use this, just because they say so?" How do you know the main executable doesn't do the same thing? How is trusting them not to run this .exe different from trusting them not to secretly implement this functionality in the actual program?
- yjftsjthsd-h 9y agoWell yeah. The appropriate reaction here is to assume that the company is shipping malware in the product regardless of what particular format.
- tutts 9y agoSure, but what of significance has changed? Every time you run a program, you're trusting the developer not to do nefarious things like reading your Chrome credentials, because the only assurance you have is the developer's word about what the program does. As far as I can tell, that hasn't changed at all. I'm not saying this is okay - there are reasons why this is a bad thing to do, I just don't see how no longer being able to trust the developer not to be malicious is one of them.
- yjftsjthsd-h 9y agoThere is a difference between "developer could hypothetically do bad stuff" and "developer has been caught doing bad stuff"
- coldacid 9y agoOnce they ship malware in any one form, anything else from a developer is eternally suspect. Even if they don't do something like this in their apps' main executables _now_ doesn't mean they won't in the future. Once a company pulls shit like this, they are dead to me, and they should be dead to everyone else as well.
- sibbl 9y agoPlease don't see Fiddler as a Wireshark replacement. If Fiddler doesn't show a network request, the tool might simply not use the Fiddler proxy...
- 45h34jh53k4j 9y agoUnfortunately, the moment a company has distributed malware intentionally, they are totally written off. They will never be trustworthy to distribute software again. Never touch any program this company has released, there is a high risk of malware.
- 45h34jh53k4j 9y agoLefteris Kalamaras is not to be trusted. His organisation knowingly distributed malware in a legitimate software installer provided by his company.
- originalsimba 9y agoWhat they've done is a crime. Trying to fight piracy by using evil and criminal methods is the wrong approach. There's an old saying "Two wrongs don't make a right".
- buserror 9y agoIn my younger days of making sharewares, my way to find pirates was a lot easier... If the serial had been stolen, I would crash the app after a few hours of use, randomly, with a generic message but a very, very specific error code. Then I'd wait for the support emails to come in with people complaining about that crash/error... Typical how the pirate support requests were always the most rude and impolite :-)
- dawnerd 9y agoEa did something similar with the sims. Screen would slowly blur. You can’t beat pirates but you sure can have fun with them.
- kseifried 9y agoThis now has the identifier: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7259 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7259