9 ms·
Wouldn't you expect the default action of SecuROM to ENABLE all installations if the contract goes bad? I would urge all companies to stop using them if this i
by coding123 7y ago
Wouldn't you expect the default action of SecuROM to ENABLE all installations if the contract goes bad?
I would urge all companies to stop using them if this is their stance.
- ThrowawayR2 7y ago> "Wouldn't you expect the default action of SecuROM to ENABLE all installations if the contract goes bad?" No, because it would probably take all of 5 minutes for pirates to figure out a way to leverage that to bypass the protection.
- grrowl 7y agoIf the server is contactable, and the server goes from returning a signed KEY_IS_VALID response to a signed KEY_IS_ALWAYS_VALID_BECAUSE_DISNEY, it has the same level of security as the existing solution. It does give SecuROM less subscription revenue security, though.
- devrand 7y agoMy hunch is that they turned down the endpoints that the clients are trying to connect to.
- jchw 7y agoNo, I think that this makes sense. Failing open would make the DRM useless if you could trick the client into thinking the contract was expired. OTOH, SecuROM is also “securing” their software from modifications, so if it were to fail open, it would still at least be working to keep binary integrity and obfuscation working; obviously SecuROM does not want to offer this for free. In my mind the correct action would be for the developers to release a patch that removes SecuROM. Similar was often done for other games that had CD based authentication; it was often removed years after original release, which makes sense to do after the pirates have long compromised the security. I think it makes just as much sense for online authentication for a game this old. Aside: I am trying to avoid injecting my personal opinions about DRM here since they aren’t relevant, but just to be clear I am not trying to express sympathy or support for either party. This is amazingly dumb in my opinion.
- munk-a 7y agoI think personal opinions are quite relevant here, legally speaking the law is clear and we've all got a problem with that - concurrently, legally speaking any game you've got through steam is a leased copy so if steam revoked your ability to play it tonight you wouldn't have a clear legal way to challenge them (unless the game is a subscription and they continue to collect that fee)
- jchw 7y agoWell, from SecuROM’s perspective I think everything makes sense. Personally I think the responsibility should fall on the developers to ensure that people who paid for something can access it. Consumer protection really hasn’t caught up here. Desperately need it to, imo.
- andrecarini 7y agoRegardless of the EULA, there are legal arguments [1] to be made that Steam's games are goods, not services, and buyers whose games are remotely disabled due to auth servers being shut off should be entitled to either a refund, a reasonable patch to keep the game working locally or have a clear expiration date stamped on the storefront since day one. This recent French court's ruling [2] indirectly supports this interpretation. [1]: https://m.youtube.com/watch?v=tUAX0gnZ3Nw https://m.youtube.com/watch?v=tUAX0gnZ3Nw [2]: https://www.rockpapershotgun.com/2019/09/19/steam-should-let-users-resell-games-french-court-rules/ https://www.rockpapershotgun.com/2019/09/19/steam-should-let...
- BlueTemplar 7y agoOk, so it seems to be that : 2012 EU ruling : "software is a good that can be resold" 2014 German ruling : "games are not just software, but also "art"(?), they can NOT be resold" https://www.rockpapershotgun.com/2014/02/10/german-court-rules-against-rights-to-resell-steam-games/ https://www.rockpapershotgun.com/2014/02/10/german-court-rul... 2019 French court ruling : "Steam accounts are just software(?), they can be resold" https://www.nextinpact.com/news/108209-ufc-que-choisir-vs-valve-justice-consacre-vente-doccasion-jeux-dematerialises.htm https://www.nextinpact.com/news/108209-ufc-que-choisir-vs-va...
- AdmiralAsshat 7y ago> Wouldn't you expect the default action of SecuROM to ENABLE all installations if the contract goes bad? Wouldn't this mean that you could theoretically bypass the DRM simply by temporarily turning off internet on your laptop?
- mlyle 7y agoNo, because you have the client treat the inability to reach SecuROM's servers as failure, but on the server treat non-renewed license as success.
- takeda 7y agoFor a publisher, DRM really helps with securing the game for the first few months when it gets most sales, the protection will be broken anyway. So protection doesn't matter that much later. For SecuROM blocking after expiration is a better strategy, because blocking games that were purchased will encourage publisher to renew the subscription. I think for the Disney it would be best to simply release patch that removes the copy protection, that is assuming they still have the source code.
- arcticbull 7y agoSeems like a case could be made for treating DRM like cell phone carrier locking. Legislation could be passed to permit DRM only for the first 12-24 months of a games life post release and require developers to provide patches that remove said protections thereafter.
- als0 7y agoWe live in a world where patents can be extended almost endlessly. Intellectual property is also treated in the same way, and I think unless there's a big cultural shift in company incentives this will remain for a long time to come.
- jefftk 7y ago> We live in a world where patents can be extended almost endlessly. Why do you say that? Twenty years from filing and everything in your patent is now available for anyone to use. Various parts of our IP system are pretty broken, but "patents last forever" isn't a thing.
- roywiggins 7y agoIn that case you'd be able to dodge the DRM just by yanking your ethernet cord.
- deleted 7y ago[deleted]
- lopmotr 7y agoA lot of people saying this, but the games could still have to connect to SecuROM who would then approve them all. Of course, it won't protect customers against SecuROM itself shutting down, but that's not the problem here.
- shawnz 7y agoIf we're talking about a scenario where the server must be online and working, then why have an expiry mechanism at all?
- saxonww 7y agoI can't think of a reason other than encouraging customers to continue to pay. In a 'fail closed' scenario like this one, customers not only lose the DRM protection, but SecuROM gets a customer's end users to harass the customer, which punishes the customer for not paying. In a 'fail open' scenario, the customer can choose to end their relationship with SecuROM with basically no side effects; they lose the DRM protection, but end users don't notice and can still play the game. Another point is that in both scenarios, SecuROM has to spend cycles handling auth requests for people playing the game while not receiving any money to do so. From their perspective it's better to make customers remove SecuROM vs. 'fail open' and authorize games 'for free'.
- BlueTemplar 7y agoRemember how the same company basically made a (copyright-violating!) rootkit installed on 22M CDs, and now makes Denuvo, a DRM that Steam doesn't list as DRM ?