14 ms·
You wouldn't download a back end
- seejayseesjays 4y agoI realize postwrite that there must be some exploits to some client-side frontends that enables fully-featured capabilities, and that in a lot of cases it would probably take significant effort to lock such features down from the server. But really, where would that be in the world?
- superb-owl 4y agoThere's actually a really interesting question here - could it be possible to "pirate" a backend with sufficiently clever AI? At the end of the day, you're just trying to model a black-box function, mapping inputs to outputs. And most of that is CRUD with some basic access control on top. There are definitely complications (e.g. 3rd party integrations, a properly designed/named database schema), but you might be able to get 80% of the way there in an automated way...
- kmeisthax 4y ago"Sufficiently clever AI" would, in this case, be the person writing a reverse-engineered work alike app. In some of the cases mentioned (e.g. Spotify, Chegg, etc) you can't really do this, because the actual value in the app is just the copyrighted material being purchased. Reverse-engineering is protected under US law for a variety of reasons, mostly that you can't copyright basic functionality (that's for patent law) and that copyright shouldn't extend to interfaces[0]. AI trying to reverse-engineer all of music or art or writing already exists. They're called MuseNet, DALL-E, and GPT-3 respectively. While you can sort of trick them into regurgitating training data in a way that would make their use to create novel works legally perilous, it's still kind of difficult to get them to generate exact copies in a way that would be useful for "pirating" all of Spotify. [0] SCOTUS tried very very hard in the Google v. Oracle decision not to actually say this. However, the actual ruling has a similar effect.
- derangedHorse 4y agoThat would be considered a remake though and would essentially be a competing product with the same api (since it’s highly unlikely the remake would be written the same as the original). Whether copying the api is infringing on anything seems to be uncertain as the outcome of the Google v Oracle case seemed to only set a light precedent
- laumars 4y agoPeople reverse engineer back end servers for online games all the time. You don't need AI. Just a really dedicated following and a lot of free time. It's not piracy doing this though. Technically you might still be in breach of some intellectual property but since it's usually discontinued services a lot of games publishers turn a blind eye.
- tmp_anon_22 4y ago> You don't need AI I grew up in the private server scene for a popular MMO and you're absolutely right. It was a whole lot of teenagers with energy drinks grinding through reverse-engineering minutia that adults would gawk at and make excuses to avoid doing. That said there was a lot of automation, scripts, and other tooling, to make it easier. The best were able to i.e. update a private server automatically when the base game updated. We were doing automation at a higher level then F500 companies were at the time (mid 2000s) and we were just kids.
- kelnos 4y ago> It was a whole lot of teenagers with energy drinks grinding through reverse-engineering minutia that adults would gawk at and make excuses to avoid doing. Right. I don't think the question is if you need AI (obviously you don't), but if AI could do all the annoying, tedious bits for us, and speed up the process.
- laumars 4y agoI doubt it. You'd probably end up spending more time training the AI than you would using it. To be clear, people do this stuff as a passion project so nothing stopping someone from investing the time in training a ML model to assist here if that’s something that sounds like fun to them. they wanted to take on. So from a technical standpoint one “could” use AI. But I’d expect you’d first have to train the AI to play game before you can even think about training it to read the network packets. And the former is a far more daunting problem than the latter. Sometimes problems are better solved with human intelligence, a lot of automation, and patience.
- hlandau 4y agoIf there's sufficient determination, people will just write replacement backends. This is a real phenomenon. As I recall some years ago Ubisoft tried to come out with a (single-player) video game which couldn't be played offline, and which was dependent on an online server as an anti-piracy tactic. I believe this game was still pirated using some kind of fake server. It's also interesting how common it is for people to create replacement servers for popular MMOs, given the extent of the reverse engineering that this requires, using custom non-HTTP protocols which are much harder to reverse. MMOs should be "unpirateable" yet unofficial open source server reimplementations are a real thing.
- deaddodo 4y agoThis has become SOP for Ubisoft and EA; but I believe you’re referring to Simcity by EA. That was the most egregious example with the most press and was zero-day cracked with a stub server interface.
- lmkg 4y agoEA claimed that it needed a server connection because a desktop computer couldn't run the simulation. This claim was absurd on the face of it; EA couldn't possibly turn a profit if each copy of the game required dedicated beefy-ass server hardware to support it. But of course, on launch it was quickly discovered the game ran just fine without an internet connection. After 30 minutes, the game would complain the server would time out and shut down voluntarily. But all it took was patching the "30 minutes" magic number. Poof, problem solved. Long story short, it is an ongoing problem that pirates receive a superior product. (A problem for publishers anyways, not one for pirates.)
- mrits 4y agoI spent years playing WoW on a pirated backend.
- the_af 4y agoI read a lot of times about this, and I find it fascinating. Are pirated WoW backends "pirated" in the sense of "someone downloaded leaked code and maybe tweaked it", or are they completely reverse-engineered, in which case it's original code and not piracy?
- hgazx 4y agoThe latter.
- bytehowl 4y agoTo my knowledge they are fully reverse-engineered, which makes Blizzard occasionally going after servers for piracy even more infuriating.
- hgazx 4y agoEven if the code is completely new, you need a lot of copyrighted material to run a wow server.
- KptMarchewa 4y agoIsn't the copyrighted material in game client itself? Did WOW stream content back then?
- hgazx 4y agoPositions and names of NPCs, quest texts, encounter mechanics, texts said by NPCs, I think item names (not completely sure), etc are all stored in the server and are sent over the wire to the player from the server. That’s quite clearly a copyright violation.
- 4y ago
- dusted 4y ago> There will never be a true way to "pirate a backend" Get access to one of the machines hosting the backend and download it.. I guess, an even more true way would be to don the wooden leg, cannons and drive up to a data center fueled primarily by rum and old-time maritime jargon xD
- moffkalast 4y ago"Your instances, hand them over."
- api 4y agoI think this is the most fundamental driver of everything going to cloud. The cloud is DRM, and it's the only kind of DRM that really works. It also lets companies play both sides by releasing clients open source but keeping the real value back in the cloud. They can be considered "FOSS" while at the same time being even more closed than closed-source software. You could say the industry has found a way to comply with the letter of FOSS licenses while avoiding the spirit, namely the idea of empowering the user.
- benjaminjosephw 4y agoThis is exactly why I think FOSS has become irrelevant for end-users. An open source client for a proprietary API only gives superficial freedoms and doesn't guarantee those freedoms will not be taken away. The software landscape has changed so much since the conception of GPL and all it stood for. Back then, freedom was about expert users having autonomy over their own systems. These days, I think the real fight for freedom is about user communities and general end-users. I think there is potential in the emerging field of community authored software. Community's coming together to build their own platforms is an ethos that I think has gained some traction and, if it builds more momentum, could become the next free software movement.
- api 4y agoThe fundamental error is confusing free "as in beer" with free "as in freedom." The two are unrelated or in some cases even at odds with one another, such as when "free" stuff is used as a barbed hook to bait people into closed SaaS or surveillance based ecosystems. The reality is that software is extremely expensive, especially polished software with a good user experience that's usable by non-experts. Good UX can take many times more effort than just getting something working. Without an economic model, FOSS will always lose in the general market. I've been ranting about this for years on this site and elsewhere. Doctrinaire FOSS people seem to largely not get it or not care. If you try to introduce any alternative license or distribution model it'll be rejected by the OSI, which is largely captured by the big surveillance capitalist companies like Facebook and Google. These have no incentive to change anything about the landscape. They're perfectly happy with open source as free labor for them and with competitors being unable to grow revenue.
- creshal 4y agoReverse engineering APIs tends to be surprisingly trivial, even for binary or otherwise non-standard protocols. The content served by them is the only real challenge.
- iforgotpassword 4y agoIf asymmetric encryption gets thrown into the mix it becomes much more annoying to get to the point where you can even begin to see the traffic.
- solarkraft 4y agoThere are many things you can do to make reverse engineering more annoying, but the content ultimately reaches the user and somehow you can always mess with that.
- quickthrower2 4y agoHmmm… Can I get free BMW seat warming this way?
- sgtnoodle 4y agoA seat warmer is just a resistor. Find the connector and wire up 12V to it through a switch.
- shmde 4y agoYou can see how well this goes. https://www.youtube.com/watch?v=MrnCDKB1hE0 https://www.youtube.com/watch?v=MrnCDKB1hE0
- CRConrad 4y agoExcept in your heated seat in the car, a heating element that's correctly designed not to fry bacon or heat huge volumes of air is already integrated into your seat. This video is just this guy intentionally being a a moron. (Well, at lest for the first few minutes of it which I could bear to watch. Maybe he smartened up later.)
- jwilk 4y agohttps://news.ycombinator.com/item?id=32065026 https://news.ycombinator.com/item?id=32065026 ("BMW heated seats subscription costs $18 per month in South Korea") for people out of the loop.
- seejayseesjays 4y agoQuite possible, I think. I've heard quite a bit of buzz around jailbreaking Teslas for unpaid for features. https://www.vice.com/en/article/y3mb3w/people-are-jailbreaking-used-teslas-to-get-the-features-they-expect https://www.vice.com/en/article/y3mb3w/people-are-jailbreaki...
- martinhm 4y agoI guess unofficial APIs through reverse engineering are the closest you can get to what the article proposes. But, as other comments point to, data is still data and access to it is highly restricted, or is vast enough to not making it worthwile (imagine downloading Google's backend).
- mumphster 4y agoPeople have pirated MMO backends since.. well a long time, mainly KMMO servers. Lineage 2 and Ragnarok Online had big servers running on leaked / hacked official server code for a really long time before emulators became more practical to update with more recent game content.
- ircop420 4y agoI can thank Rangarok Online and Lineage 2 for teaching me Unix administration and scripting at a young age. While the eAthena project has rested, there is a fork rAthena that is still surprisingly running. The truth though is that Aegis (the official software) was stolen by an RDP hack on Gravity's servers back in the day. That was a boon to the jAthena and later eAthena projects.
- MonkeyMalarky 4y agoPlaying on unofficial Ragnarok Online servers was fun as hell back in the early 2000s. Modded economies so you didn't have to spend months grinding, modded spawn and drop rates, custom monsters and items. Crazy unstable servers that could crash at any time. 4chan level of discourse. Admins who were barely older than the players themselves. Great times!
- Havoc 4y agoAnd then players like Ubisoft go “we’ve decided to shut down the servers”
- hypertele-Xii 4y agoCalling a publisher and developer a "player" in the context of video games makes your sentence confusing to parse.
- solarkraft 4y agoWhich is exactly why backends need to be pirated!
- rektide 4y agoPut another way, the mainframeization of computing is nearly inescapable. We no longer have personal computing, even when we run our apps & game clients locally.
- shlurpy 4y agoIt turns out individualized software freedom, like all individualized freedom, results in deep systemic problems.
- blablablerg 4y agoslighty OT, but it is a travesty that Quizlet (previously Slader) has gone behind a paywall. Slader had a lot of community generated solutions to textbook problems. Users gave them the content for free, and they monetized it, kept only verified answered and dumped the (unverified) solutions and feedback.
- randomdata 4y agoI would. In fact, I learned to program because a misconfigured web server once spit out its source code and I was able to learn from it.
- seejayseesjays 4y agoI hear about instances like this a lot. Did a broken request just resolve to the contents of the file that created it, or did it just spit itself out in your browser console?
- KptMarchewa 4y agoPHP was infamous for just dumping whole stacktrace when some site ran into 500.
- jrockway 4y agoI ran into a site like this recently. Honestly, I think it's great because you can tell what action you need to take to resolve the error. Clear cookies? Come back later? They're actually out of business? The stack trace reveals all. I enjoy how transparent client-side apps are these days. I remember trying to order something from an online store, and the "submit" button wouldn't work because some third-party license key wouldn't validate (I think it was to load a map to show your own address?), and that error stopped the actual sending of the HTTP request to submit an order. I patched that out and submitted my order. Easier than finding their email address and waiting a week for their contractors to fix it.
- randomdata 4y agoThe former. This was back in the days when CGI was popular and it was common for the URL path to point to the file that served the application, with the web server recognizing that it should execute the file rather than serve it. In this case the misconfigured web server didn't execute the file but rather served it up as if it were a regular file.
- bambax 4y ago> adblockers will exist for as long as Google deems them unproblematic (...) the existence of such piracy is heavily dependent on the providing body, and as such, are existant by benevolence Mmm, what? Adblockers aren't piracy.
- seejayseesjays 4y agoEntirely true, though Linus Sebastian would probably disagree. In terms of receiving content without paying the tithe of attention/money/time, though, one could consider it a form of """piracy"""
- iforgotpassword 4y agoYeah like, I would have disagreed at first too, but he has a point there.
- lelandbatey 4y agoLinus is totally off his rocker though. His argument is that "he deserves to get paid for what he does, if you AdBlock he doesn't get paid, hence you are taking money from him if you AdBlock." This idea though is totally wrong, and is some serious post-hoc BS after over a decade of this internet advertising business model becoming comfortable. Linus's business is GIVING AWAY content and hoping that advertisers (his real customers) will want to agree to pay him according to his terms. You can say things about TOS and EULA and how that is totally a legally and morally binding or whatever but that's moving the goalposts now that folks have found a way to exploit audiences for money after years of GIVING AWAY content for free. I don't have to read each advertising flyer that comes with my pizza, even if the pizza store decides to give me 100 advertising flyers in exchange for making the pizza free, and no amount of EULAs will make it so. It's my computer, I can throw out the garbage you give me if I want.
- BLKNSLVR 4y agoThat's an interesting point. He's paid by the advertisers therefore they're his direct customers whilst the viewing public are secondary, and therefore have far less responsibility to maintain the viability of his business plan.
- madrox 4y agoI'm weirdly cheerful about being able to report that this isn't true. Backends do get pirated with sufficient motivation...mostly in games. MMOs spring to mind, but lots of games with online multiplayer get this treatment. Some of it is piracy, but some of it is because the developer is no longer supporting it, so the community stepped in with emulation.
- Teknoman117 4y agoIt's not piracy per se, but the practice of reverse engineering a backend to a paid service, whether that's real logic or just a licensing server, has existed for a long time. I remember friends running World of Warcraft private servers back in '08 and '09. Heck, we even hosted one as a class project in high school. World of Warcraft Classic exists partially due to the number of fans who ran private servers as a way to properly experience previous versions of the game as current expansions have you steamroll through older content.
- kragen 4y agoI wrote an essay about this problem in the 01990s: https://www.gnu.org/philosophy/kragen-software.html https://www.gnu.org/philosophy/kragen-software.html
- Kiro 4y agoI've always wondered how for example private WoW servers work. Do they replicate the whole backend based on observations of how the actual game works and the network requests being made? How is that even possible without knowing all the quirks and other indirect behaviors you have no visibility of? E.g. when the server game loop ticks a thousand things happen that are not transmitted to the clients.
- Macha 4y agoYes, they reimplement the backend. Yes, this does require a lot of experimentation. Yes, they sometimes get details wrong. Or sometimes they just change it, because they feel like it (e.g. accelerated xp, or just for paying customers)
- remram 4y agoA lot of games, particularly the "massively multiplayer" ones, don't actually do much on the server. The clients are authoritative for their characters, running the simulation, and the server just relays the serialized state to other clients. They rely on anti-piracy software (kernel DRM modules) to avoid cheating. In that situation replacing the server is easy. For games where the server is doing the work and clients are just thin frontends which don't even know all the rules, it is basically impossible.
- antifa 4y agoI'd argue writing a headless server is easier than writing a video game client app, but maybe that's only because I'm traditionally a backend server dev.
- remram 4y agoIf your headless server does complex physics and AI processing and needs to be optimized to handle many clients in real-time, possibly taking full advantage of multiple cores or distributing segments of the world between machines, it is hundreds of time more difficult than a Unity client that moves some animated models around. Some servers are complex, I don't know why you'd paint with such broad strokes as "headless server = easy". Even if your background is completely web development, surely you've been exposed to more than CRUD.
- londons_explore 4y agoI disagree. As web apps and web services get more and more e2e encryption and strong privacy, the backends become dumber and dumber. If the backend can't see the data it's working with, it can't have much business logic in - instead the backend ends up looking much like a dumb storage service or message queue. Some companies will just make their app talk direct to S3/pubsub rather than run their own application servers. At that point, some 'hacker' can download the APK or the javascript bundle of the frontend, and simply put up a replacement backend that does the same storage service. Well done, you now have a 'pirate' web service.
- nmilo 4y agoLet's be realistic, Quizlet is not e2e encrypting their protocol, and most web services are not getting strong privacy. Good old HTTPS is enough for most services.
- londons_explore 4y agoBut in the future, more and more things will be e2e. Some fields like messaging practically require it today. Any company that wants to use 'privacy' as a selling point pretty much has to do e2e encryption today.
- YuriNiyazov 4y agoScihub is a pretty good counterexample to this theory.
- stack_framer 4y agoPart of the problem is that ordinary users have no clue just how much the app actually costs to develop and maintain. And how could they? I worked on Socrative for several years (similar to Quizlet), and we had backlash when we introduced a "Pro" version with paid features. All existing free features, which had been developed over several years, could still be used for free—it was only new features that would be behind the paywall. Many users lamented all over social media that Socrative was no longer "free." But it had never been free—it had been losing over $1m per year!
- jobs_throwaway 4y ago>My significant win is that I’ve never personally found a need/desire to pirate something Personally, I wouldn't count this as a win, more of a lack of curiosity/failure to be adventurous enough to be in a situation where piracy is advantageous
- seejayseesjays 4y agoMaybe you're right. I'm curious as to what situations would make it advantageous, though.
- pm3003 4y agoMake old games playable again. Use professional software you can’t afford to buy or don’t have affordable access to in order to develop your skills (seems ethical to me, though it’s disputable). Use software for which you have legitimate access to a Windows version but you need it on another OS. The personal satisfaction and skill demonstration of doing reverse engineering (RIP fravia).
- pm3003 4y agoThe author is 18 years old, I believe. To put this into context. He writes rather well btw.
- seejayseesjays 4y agoYou believe correctly, and thanks so much!
- kelnos 4y agoA sibling claims he's 18 years old; it's also just possible that he and his parents are well off enough that he doesn't want for anything, and that paying for everything is reasonable for them to do. Also consider that streaming (music, TV, movies) has been decently plentiful and cheap for the entirety of his teen years. He may not have had a need to pirate anything just because his parents paid for Netflix and Spotify accounts. For games, most have an online component and are more difficult to pirate, as he points out in his article. Certainly it's not impossible (there are many single-player/offline games that just want to do a license check, which can often be hacked, and others where the server components have been reverse-engineered and clones), but it was a lot easier to pirate games when you just had a CD or floppy that you could disassemble and poke at to create a patch. And again, maybe he and his parents have been able to afford to buy whatever games he's wanted to play. But I also see this as a result of the newest generation of computer users being raised in restrictive computing environments. iOS and Android don't encourage you to tinker; their security and product model tries to preclude that. Desktop macOS is more and more locked down with every release. Windows is... well, Windows. Desktop Linux still has yet to develop any kind of traction (and I say this as someone who has been using Linux on the desktop, nearly exclusively, for 20 years). Even many people I know who grew up in the 80s and 90s like I did, who used to have desktop or laptop computers, have shelved them and replaced them with iOS/Android/iPad OS. In many ways, I think this is really a crappy time for computing. Sure, we have all this cheap computing power, but for the most part we're using it just to consume mainstream media. I say this even with the explosion of easy creation tools like digital cameras, and things like Instagram and TikTok. Fortunately there are still a lot of healthy hacker/maker communities, but I think their percentage of the whole of computing has been steadily dropping over the past 15 years.
- datavirtue 4y ago
- dvngnt_ 4y agoI real life example of this for web dev is cypress.io which offers enables parallel testing and access to a dashboard of test runs. then https://sorry-cypress.dev/ https://sorry-cypress.dev/ came which is a self-hosted version for free. Then came a commercial offering that directly competes with cypress' official version
- solarkraft 4y agoI need to pirate a backend, but I don't know the API. A fitness tracker I have (Jawbone Up Move) is coupled with an app, which is coupled with an online service, which has been dead since 2017. Are there any tips, tricks or resources regarding this? Best I can currently do is `mitmdump –set connection_strategy=lazy` (the last part is important so it doesn't try to connect to the original server and throw a weird error), but I don't know what the app wants as a response to its login request. A look at the decompiled code doesn't immediately reveal much. Are there any common patterns for this type of stuff?
- zffr 4y agoI would suggest looking at how the tracker communicates with the app and try to reverse engineer that part. Once you are able to communicate with the tracker, you can build your own app. Trying to reverse engineer the API the app uses seems harder, and is a less direct solution to your problem, IMO
- ivraatiems 4y agoIf you can elaborate on (or show, but I realize that's legally hazy) the decompiled source, I think this should be possible to discern. I'd probably start by looking for anything in the source that looks like it's making any kind of network connection, then narrowing it down from there. Typically, the response to authentication is a yes/no plus a token or other piece of session state for the authenticated app to store. You might poke through the structure of the in-app storage to see where the authentication information lives, and then go backwards from there to where it is set. Edit: On a cursory google search, https://github.com/ryanseys/node-jawbone-up https://github.com/ryanseys/node-jawbone-up looks like it might help you.
- kazinator 4y ago> There will never be a true way to "pirate a backend" The original way to pirate is to bring your vessel in close proximity and then jump aboard the target vessel and have your way with it. Something like that could be done with a back end.
- x3n0ph3n3 4y agolocalstack is the closest thing I could think of to pirating a backend: https://localstack.cloud/ https://localstack.cloud/
- mdaniel 4y agoThat would be true if it _did_ what the API claims, versus just mocking them. I think eucalyptus/Corymbia would be closer to what you had in mind, as their APIs do actually cause things to change in the real world Also, FWIW, both localstack and the moto library that it wraps are Apache 2
- woojoo666 4y agoIt seems like the popular sentiment here is that not only will client-side programs continue to be crackable, but even server backends too. I posit the opposite. In the future, it will be impossible (in many cases) to crack even client-side applications. Reverse engineering and de-obfuscation are a cat and mouse game. However it's been proven that it's possible to obfuscate a program such that it's effectively impossible to deobfuscate. This is called indistinguishable obfuscation [1]. Basically like encrypting a program. And even though current implementations are impractical, I'm sure it will get better. [1]: https://en.m.wikipedia.org/wiki/Indistinguishability_obfuscation https://en.m.wikipedia.org/wiki/Indistinguishability_obfusca...
- sterlind 4y agoas a full example of how to do this, consider the following proof of concept setup: - FHE-based implementation of whatever function you want to hide, say, a DRM circuit that sends your TV the symmetric key to a movie if you give it the TV's chained certificate along with a token proving you rented it. - shortened zk-SNARK proof that you evaluated the FHE circuit correctly. - simple (iO) obfuscated gadget that decrypts and returns the output of the FHE circuit only if 1) the FHE message says evaluation completed and 2) the zk-SNARK proof checks out; otherwise, return random garbage. in order for this to work, the gadget must have enough entropy in its class of alternative obfuscations, that you can't distinguish it. but what I'm not sure about is, you still can distinguish the gadget from one that simply always outputs garbage. I don't know how you can prove that reverse-engineering a given iO circuit is infeasible. I just don't have the first clue. Help?
- slackfan 4y ago1. Hell yes I would. (Still waiting for my downloadble car.) 2. There is an easy way to pirate backends, you just do some network capture and figure out what the SYN ACK messages between your client and API are. 3. There's plenty of instances of pirated web-based games. (KanKolle comes to mind).
- mrkramer 4y agoThat's why Microsoft moved Office to the cloud. Edit: Didn't know that Adobe didn't move its portfolio to the cloud yet. I thought Adobe Creative Cloud is all about that plus subscription model. My bad.
- nekitamo 4y agoJust as a backend is not a desktop application, so to will "backend piracy" differ from desktop app piracy. You can't think of them in the same terms. Whereas a crack of a desktop app will allow users to "misuse" the app (by circumventing the license protection or other limitations), a backend can be "cracked" through scraping, botting, or creating alternative clients. If a backend somehow limits your access to content, a skilled user can scrape that content and make it available through their own alternative backend. If a backend somehow limits functionality, you can reverse engineer their API and build an alternative client which interacts with the API in a way not intended by its creators, and misuses it. If a backend rate limits access to it, you can write bots to interact with the backend through multiple proxies and alt-accounts, thereby circumventing the rate limits. I'm not advocating for any of the above techniques, any more than I advocate for cracking and software piracy. I just want to offer them as examples of how backends are not magically immune to tampering and misuse.
- sexy_panda 4y agoI mean you could still intercept and index API requests and generate backend code. While this has nothing to do with pirating directly, it would still allow to replicate the backend (without business logic).