5 ms·
Previously: https://news.ycombinator.com/item?id=16412541 https://news.ycombinator.com/item?id=16412541 It sounds like they distributed a tool that goes throug
by kevinday 9y ago
Previously: https://news.ycombinator.com/item?id=16412541 https://news.ycombinator.com/item?id=16412541
It sounds like they distributed a tool that goes through your Chrome saved passwords database and if the installer thinks you're a pirate, it sends credentials from that database back to the author. The author is now saying they used credentials they learned from this to break into a private website to learn more about how their DRM was being bypassed.
This seems so incredibly illegal, I can't believe they admitted that this is what they're doing.
- abtinf 9y agoIANAL. While the entire scheme looks to be clearly unethical, the only part that strikes me as illegal was the use of credentials to log into the online forums/services.
- mastazi 9y agoIANAL but AFAIK stealing data, even without using it, is illegal per se in the EU, where this company is based: http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:31995L0046 http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELE...
- abtinf 9y agoIANAL but, assuming taking the data happens after the user agrees to the license, there is no stealing of data.
- slrz 9y agoSo if I put some small text into a 100 page EULA that says I may break into your house and take whatever I can carry, then I only have to make you click-through and I'm all set? Awesome. Unfortunately for me, things don't work that way. For most of Europe at least, you'd be perfectly justified in treating my 100 page EULA like the garbage it is and basically ignore everything in it that isn't already prescribed by law anyway.
- abtinf 9y agoYour example is not persuasive. There are perfectly enforceable EULAs that contain terms potentially far in excess of the value of your home and all of its contents. And there are enforceable EULAs that contain rather onerous audit provisions. And in this case, it is hard to see the comparison to physical action. I am not familiar with the flight sim license in question, but there are a number of general terms it might contain that would allow for the collection behavior. Telemetry, anti-piracy, anti-cheat, audit, fitness of purpose, and many other provisions could cover this particular behavior. Further, if their claims are to be believed, they only initiated this action against a someone in already in breach of contract, so the law isn't going to protect the pirate anyway. Again, I think the company's behavior is unethical - they should have contacted law enforcement. But illegal? That is not at all clear.
- madez 9y agoEULAs are not generally enforceable nor legally binding at least in Europe. I personally have acknowledgment in a legal dispute that parts of even a signed contract were void and invalid because they were considered an EULA (AGB).
- grkvlt 9y agoNo, click through EULAs are not always enforceable. But generally, EULAs are certainly a valid and enforceable form of contract throughout Europe - how else would things work, if not through a contract describing an agreement with the end user to license the software, i.e. an EULA?
- madez 9y agoAn individually negotiated agreement that fulfills all the legal requirements of a contract is a valid way to ensure enforceability. But just repeating a part in many contracts is enough to make a court say that it is not individually negotiated and is therefore treated differently (AGB in German). A seemingly endless text wall with non-negotiabile terms that is considered agreed to by a click on "I have read this and agree to it" might only be binding to very limited extent, if at all. In my contract I mentioned a part was considered invalid because it was an issue that cannot be agreed to in an AGB, and the part was considered to be sufficiently AGB-like. To give another scenario, someone offers me a proprietary software. I don't know the terms and condition but I know that I need to pay for it. I then pay and receive the software. Upon starting it, it presents me with terms and conditions I need to agree to. In this scenario, the terms and conditions in the software are entirely void because the contract was established when the software was exchanged for money and the terms were not agreed to at that point. Only what is agreed to when the contract was established counts. If the software doesn't work for the intended purpose, I am free to modify it such that it does.
- mastazi 9y agoIANAL but I don't think a SW license can have the provision where they say that they will take all your Chrome passwords without your consent and transmit them over a non-secured connection [1], and still be considered legal, at least in the EU. Some protections and rights can't be waived in a private contract, even if both parties agree[2]. [1] https://www.fidusinfosec.com/fslabs-flight-simulation-labs-dropping-malware-to-combat-piracy/ https://www.fidusinfosec.com/fslabs-flight-simulation-labs-d... [2] https://en.wikipedia.org/wiki/Data_Protection_Directive#Principles https://en.wikipedia.org/wiki/Data_Protection_Directive#Prin...
- madez 9y agoClicking a checkbox is no legally binding agreement. Parts in a contract can be void even if agreed by both sides.
- PeterisP 9y agoThey're claiming that they're pirates, i.e. that there is no valid licence that they would've accepted. In that scenario, the user has committed copyright infringement (i.e. it can/should result in a civil claim and a fine). If what is claimed has happened (the company used the passwords retrieved from pirates' computers to access private websites of those pirates), then the company employees who took and used their passwords have committed a crime (i.e. it can/should result in arrests and jail time). Many of the things that police can and will do in an investigation are crimes if you do try to do it yourself. The fact that your target seems to have committed a crime doesn't justify crimes against them; and they are innocent until proven guilty. Those acts aren't comparable; what the company seems to have done is on a much higher level of illegality than software copyright infringement.
- taneq 9y agoPut it this way, if Microsoft or Facebook or Google or Apple released an update which squirreled away your stored Chrome passwords and uploaded them, there'd be a torch-and-pitchfork mob out for their blood. It would be totally unacceptable for a big player to act like this and being a smaller player doesn't grant any free passes.
- PeterisP 9y agoOne illegal part is sufficient. I agree that the other parts might be debatable, but the actual use of stolen credentials has clearly crossed every line. If they had passed this information on to a police investigation that then would've used this with a warrant, then this might maybe work (the admissibility of evidence gotten this way is tricky - maybe it is, since it's not the authorities that obtained it illegally), but if they themselves used those credentials, then I hope that the employee who did it understands that "boss told me to do it" isn't a sufficient defense in criminal prosecution. I mean, the apology seems legit and it's not that likely that anyone will press charges, but it still is a quite stupid risk that they've taken. In many cases "hack-back" may seem a practical alternative, but it's not, because it tends to be absolutely illegal (well, perhaps not if you're in NSA or something). Hopefully this case will be sufficient warning for others.
- ams6110 9y agoNever trusted browser saved passwords. One of the first things I disable after I install a browser. Also disable saving form data
- madez 9y agoWhy? I mean, what could ever go wrong with storing highly sensitive credentials, form data, and usage history in the same app that automatically and promiscuously downloads and executes code from the internet?
- Buge 9y agoEven if you don't save passwords in Chrome, malware can still keylog you, or steal your password from whatever other password database you use.
- madez 9y agoThat's what hardware-backed crypto protects against. Passwords on their own is a bad security practice. A tiny dedicated computer like Tomu[0] that fits into your computer, that provides authentication (and similar cryptographic functionality), with inpedentent input (touch) to receive manual ACKs and output (led) to provide feedback, with no other functionality, is a cheap, reasonably safe, and convenient solution. Maybe unlock it on boot (and after timeout) with a password/PIN for good measure. [0] https://www.crowdsupply.com/sutajio-kosagi/tomu https://www.crowdsupply.com/sutajio-kosagi/tomu
- subway 9y agoThis sort of thing is awesome in theory, but in practice it kinda sucks, and will continue sucking until it becomes a first-class feature in the eyes of browser and desktop environment developers. Currently I'm using Chrome backed by KWallet backed by PGP key on a YubiKey 4. Upon launching Chrome I have to authenticate with/touch the Yubikey to unlock my session, which is spiffy, but after that seemingly random pages (even in an incognito window) will prompt Chrome to unlock my keychain. The Yubikey will flash, indicating something wants access to it, but I have no indication of what that something is. If I ignore the flashing, eventually a KWallet window pops up complaining about being unable to use the GPG key.