7 ms·
A320-X DRM: What happened
- cptskippy 9y agoI am curious what the piracy rates are for this game vs actual sales, because I am having a hard time justifying investing that much effort into what they did.
- tomalpha 9y agoI wonder if the publisher even knew, or could ever know. It's presumably hard* to work out the counterfactual - how many more sales would have been made in the absence of the crack/keygen being available. They do mention that they kept seeing repeated personal information being used on registration, but also that the cracked version was changed to use a different activation server. Confusing. *or even impossible
- eps 9y agoWhat's the background exactly? As I read it, they had a function to grab various bits of data from a specific machine that was linked to a specific cracker. Did it misfire and started to pilfer data from other unrelated machines? Edit - for the record, the original post title was somehing like "Flightsimlabs attempts to explain their password-stealing DRM malware".
- Twirrim 9y agohttps://www.rockpapershotgun.com/2018/02/19/flight-sim-group-put-malware-in-a-jet-and-called-it-drm/ https://www.rockpapershotgun.com/2018/02/19/flight-sim-group...
- gervase 9y agoAs I understand it, it decompressed the offending code onto legitimate users' systems, where it was detected by antivirus software. The presence of this software at all, rather than whether or not it was executed, is the core of the issue, I believe.
- christoph 9y agoCan anyone chime in on the legality of this? I understand the thought process behind doing this, however, I'm struggling to see how what they've done can possibly be legal?
- IntronExon 9y agoI don’t know about the US, but in Germany it would be very illegal.
- coldacid 9y agoIt'd be very illegal in the US as well.
- ineedasername 9y agoThey infected all of their users with malware. Users they believed were pirates had usernames and passwords stolen, while legitimate users have been exposed to the risk of the malware. For the pirates, while they broke the law, this company has broken the law by unlawfully obtaining their credentials and using those credentials to impersonate them in various services. Many steps in this process are illegal in the countries in which this dev operates.
- Macha 9y agoVarious bits of data = Chrome password database.
- marklyon 9y agoHere's a Reddit thread discussing the malware: https://www.reddit.com/r/flightsim/comments/7yh4zu/fslabs_a320_installer_seems_to_include_a_chrome/ https://www.reddit.com/r/flightsim/comments/7yh4zu/fslabs_a3... I'm shocked that the company admitted to doing this.
- originalsimba 9y agoAdmitting to the crime is a form of damage control. Someone with a clue figured out what was going on, spoke to the lawyers, and determined that the penalties, if any, would be harsher if they wait for a trial before admitting guilt. That's all it was. They are in a lot of trouble, potentially, and it will be interesting to see how this plays out. I am hoping that charges will be pressed, because this is not the first time developers have "booby trapped" pirated software, but it could be the last if justice is served.
- SlowRobotAhead 9y agoAll for their DRM scheme. I still find it interesting how many people don’t realize that generosity could be a valuable part of your product. That growing the industry as a whole may be more important than getting back at people who weren’t going to buy your product anyhow.
- cm2187 9y agoI can see generosity working for a single developer but you are not going to build Electronic Arts with donations alone.
- originalsimba 9y agoWhats wrong with that? Electronic Arts is a cancer on the gaming industry.
- cm2187 9y agoWouldn’t it require one of the users of the pirated version to fill a complaint? If the software wasn’t doing anything nefarious to regular users, just had potentially dangerous code sitting in a dll in a directory, it is hard to justify any damage. Kind of like if I had a function to format the C drive in one of my binaries. It never gets executed but would I be liable for having that function in a binary I distributed.
- mastazi 9y agoThe Chrome password database is a bit more than "various bits of data", more like "important personal data"
- Twirrim 9y agoI wonder if they realise just how illegal their actions are, and that they've fully confessed to breaking the law? They should have at least sought legal advice before trying to do what they did, but failing that at least sought it before posting this message.
- BillinghamJ 9y agoTo be honest, it doesn't really sound illegal to me. Detecting fraud and collecting additional data when it is detected doesn't sound unreasonable or unusual - as long as it is specified in the privacy policy anyway. That being said, I'd be very interested to learn more about why it would be illegal. Could you elaborate/source?
- manicdee 9y agoApart from stealing passwords which is definitely misuse of computing resources?
- BillinghamJ 9y agoThe link doesn't mention extraction of passwords
- manicdee 9y agoThe story is that the bundle contains a piece of software that uses elevated privileges gained through the installer to extract passwords from Google Chrome, and then ships that data back to mothership. I am not sure how that’s not stealing passwords but I am open to interesting arguments supporting the negative. The publisher pinky-swears that they only steal passwords from bad people. That is not an interesting argument to me.
- nullymcnull 9y agoThe post kind of dances around exactly what 'information' was exfiltrated from the targeted user, but it's pretty clear from a close reading that it has to have included his Chrome passwords. unfortunately we could not be able to enter the registration-only web sites he was using to provide this information to other pirates. We found ... that the particular cracker had used Chrome to contact our servers so we decided to capture his information directly .. to dump that cracker's information needed for us to gain access to those illicit web sites this method worked, in fact, and we were able to receive this information This all followed by screenshots from the "registration-only web sites" they could not previously reach. Also, at least one of the initial reddit reports which set off this whole thing was due to A/V software detecting an executable file included in the installer (which was dropped but not executed on all user installs) as "Chrome Password Dump" malware. Edit: The earliest responses about this from FSLabs seem to confirm that they were running the password dumps on anyone who was using known pirated serials; it looks safe to say that the linked post is overstating how targeted their actions actually were. This method has already successfully provided information that we're going to use in our ongoing legal battles against such criminals. If they truly believe that they have any hope of using any information thus gathered to aid them in their 'legal battles' against crackers and pirates, this is one deeply confused company.
- kevinday 9y agoPreviously: https://news.ycombinator.com/item?id=16412541 https://news.ycombinator.com/item?id=16412541 It sounds like they distributed a tool that goes through your Chrome saved passwords database and if the installer thinks you're a pirate, it sends credentials from that database back to the author. The author is now saying they used credentials they learned from this to break into a private website to learn more about how their DRM was being bypassed. This seems so incredibly illegal, I can't believe they admitted that this is what they're doing.
- abtinf 9y agoIANAL. While the entire scheme looks to be clearly unethical, the only part that strikes me as illegal was the use of credentials to log into the online forums/services.
- mastazi 9y agoIANAL but AFAIK stealing data, even without using it, is illegal per se in the EU, where this company is based: http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:31995L0046 http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE...
- abtinf 9y agoIANAL but, assuming taking the data happens after the user agrees to the license, there is no stealing of data.
- slrz 9y agoSo if I put some small text into a 100 page EULA that says I may break into your house and take whatever I can carry, then I only have to make you click-through and I'm all set? Awesome. Unfortunately for me, things don't work that way. For most of Europe at least, you'd be perfectly justified in treating my 100 page EULA like the garbage it is and basically ignore everything in it that isn't already prescribed by law anyway.
- ocdtrekkie 9y agoI sort of appreciate the creativity here, though it's blatantly creepy and uncomfortable for a software vendor to be pushing updates with single-user-targeting functionality, in particular, to say nothing of the spyware issue itself.
- anilakar 9y agoHam Radio Deluxe blacklisted one user for writing a critical review, then blackmailed him to remove the review in exchange for lifting the ban: https://www.theregister.co.uk/2016/12/21/amateur_radio_fans_drop_hammer_on_hrds_blacklist/ https://www.theregister.co.uk/2016/12/21/amateur_radio_fans_...
- k_sze 9y agoI wonder if they are in fact shooting themselves in the foot in their fight against this cracker. Aren’t there laws that basically invalidate evidence gathered by illegal means?
- mastazi 9y agoand even if there weren't, is it worth it to face legal consequences of your actions, just to stop some hacker? I mean they are a small shop - albeit highly respected in the flight sim community - if this ends up in court, it could be game over for them.
- cjensen 9y agoIn the US, there are laws that invalidate evidence gathered by the government through illegal means. This simply does not apply to private entities.
- shmerl 9y agoReleasing DRM-free is a thing if you want to respect your users, instead of insulting them.
- Johnny555 9y agoWhat I don't understand from their explanation is why they had to do this at all -- if they could identify the bogus serial numbers, then why not just block those serial numbers from registering?
- jandrese 9y agoMight have been a whack a mole situation where the crackers have figured out how to make key and they know how to switch them easily whenever you invalidate one.
- fourthark 9y agoYes the article says that pirates were not only generating keys but patching the software to validate against their own servers.
- TylerE 9y agoSo maybe stop wasting effort of a clearly lost battle and instead spend it on making your product so brilliant people will be begging you to take their money?
- TylerE 9y agoBecause simulator addon developers - especially flight sim addon developers - are barking mad and have views on piracy that would make Jack Valenti blush.
- paraxisi 9y agoSent base64'd to a non-secure endpoint with open RDP... ouch. https://www.fidusinfosec.com/fslabs-flight-simulation-labs-dropping-malware-to-combat-piracy/ https://www.fidusinfosec.com/fslabs-flight-simulation-labs-d...
- userbinator 9y agoIf anything this is just going to want to make the crackers keep cracking their releases even more, because one thing they certainly love is a good challenge, and these "bomb-like" features would appeal to them greatly. (Long-retired cracker, no longer active in the scene but still fights from time to time. ;-)
- supergirl 9y agowould be funny if the pirate sues these guys for hacking and puts them in jail
- duncan_bayne 9y agoThat is a very possible outcome, especially as several of the actors involved are based in the EU.
- dmitrygr 9y agoIf they are in the US, anybody on whose PC this ran, including the Cracker, can probably get them all thrown in jail for CFAA violations.
- mdip 9y agoGotta say, on reading this I went "They did what?!". This raised my eyebrows so much, I'm fairly certain they're now lost somewhere in my hairline. In the US, at least, I'm fairly certain they've broken more than a few laws. Kudos to them for admitting it, entirely; I guess that would be the only hope they'd have of ever re-gaining any sort of trust with their install base, but they'd be equally smart to find a lawyer[0]. I get that a lot of time and effort goes into developing a product and it's really frustrating when you find out that your product is being pirated. I can't imagine if I'd happened upon a whole community sprung up around pirating my product; they had to be incredibly angry and this likely led to this terrible idea. And no matter how often you repeat to yourself that "piracy does not represent lost sales", when you've poured your time into something -- time that you hope will make you a nice living, time that you took away from your family or other enjoyable pursuits -- you tend to get really angry when you find out there are people that think it's perfectly OK for you to work for free. I like to repeat the mantra that "piracy does not equate to lost sales" and tell myself that those wouldn't be paying customers anyway, or they're not my real target audience, or that it speaks to the popularity of the product if someone went to the trouble to crack it. And I'm a believer that effort spent on DRM is wasted (especially efforts like this). It's not entirely, true, of course. I always think back to the story I read a few years ago about the TCP/IP stack that nearly every DOS PC used -- a piece of shareware that, at the time, was probably the most popular piece of shareware in existence. I'm sure I, like many, didn't even think to pay for it and operated under the assumption that large corporations were probably using it and the developer was probably using $20 as kindling by now when in reality I think he netted somewhere in the thousands of dollars for his efforts. At the same time,... well... this. This is exactly what happens when you focus on piracy so hard. Developer time is a finite resource and this company wasted that time developing a piece of DRM that is indistinguishable from malware. It succeeded in not stopping the pirates, not catching the pirates, angering their paying customers, easily exposing them to civil legal issues and possibly exposing them to criminal legal issues. That little bit of wasted developer effort could very well end the company that made this product in a way that piracy probably never would have. Assuming their customers like the product and would like it to continue to exist, this company basically did everything in their power to not serve their customers. To be clear, I'm not completely against purchase verification in software products. If it's light-weight, and doesn't get in my way as a customer, it's fine (i.e. provide the ID/password used when it was purchased with a fallback to an offline serial number ... asked one time and never again). I get it. A small road block is enough to keep my mom or dad from grabbing a copy that a friend attached to their e-mail. Heck, in the case of my mom or dad, they may not even realize that it's not a free product if it doesn't ask for some form of verification. I don't mind how Steam works or how the variety of stores handle these sorts of things. If your DRM effort goes any beyond this, it's wasted effort. You're not going to stop a determined pirate even (especially?) if the product your selling is an anti-piracy product. Just don't. Don't waste the effort. It's never worth it. Even as I write this I'm still amazed. I get frustrated when I upgrade my CPU/memory/GPU and Office won't run without some extra steps. I can't imagine if step #2, after falsely identifying me as a pirate, was "send a bunch of personal data to the authors"[1] so they can turn me in to the authorities. Pro-DRM folks like to equate piracy with theft, so I'll make an equally poor analogy and say that'd be like if I purchased bed sheets at Wal-Mart, and the processor in those sheets[2] decided I stole them, so they started sending the GPS location of my house along with pictures of my bedroom to corporate so that they could turn that information over to the police. [0] Sure wouldn't be difficult to compare this with any other piece of malware in its behavior, but IANAL. [1] And yes, I realize that they've stated that they're looking for specific information from a specific pirate that they consider to be the source of the problem, but including that payload in the installer makes me question the truth of this statement. I don't have any reason to dis-believe them, especially considering they've basically written up a post admitting to a bunch of activity that may very well be illegal in nature, but having no way to verify that they are telling the truth, or that there isn't a circumstance that could false-positive flag someone who isn't that very specific case, I will err on the side of assuming the worst in this case. [2] I laughed when I wrote that, then I thought ... there's probably already sheets with processors in them. If there isn't, there will be. Shortly followed by the first case of DDoS by IoT bed-sheets.
- singularity2001 9y agofrom the headline I thought it was about the Iranian airplane that crashed
- kseifried 9y agoThis now has the identifier: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7259 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7259