Live data from Hacker News

FlightSimLabs Alleged Malware Analysis

medium.com

31–40 of 62 posts

Re: FlightSimLabs Alleged Malware Analysis

#31

I thought I’d share this here to spread more attention to the practices of FlightSimLabs, a flight simulator software shop. The short version is that they included an executable in their installer that when run would extract passwords saved in Chrome and presumably phone them home. Their reasoning was that this was purely for DRM reasons. They claim that this password stealing tool would not run for legit/valid seria…

So basically "you broke the law, so we'll break the law"?

Actually, it’s “we suspect you may have broken the law, so we’ll break the law.” A distinction no one seems to be hammering on, but that I think makes what they did much, much worse.

Re: FlightSimLabs Alleged Malware Analysis

#32
post #16

Earlier quoted context omitted.

LinkedIn only has 3 people who are listed at working at this company [0], so I'd assume it's a small indie shop without a legal department. [0] https://www.linkedin.com/search/results/index/?keywords=Flig... .

It still baffles me. You can't stay even moderately up to date on technology news, without knowing that initiating a security breach, even on someone who has stolen your product, will still be criminal.

Just have the user agreement state that if you pirate it, you allow them to exfiltrate all data on your system.

Re: FlightSimLabs Alleged Malware Analysis

#35
post #4

Earlier quoted context omitted.

So basically "you broke the law, so we'll break the law"?

Unfortunately, this sort of attitude is not unheard of among proprietary software vendors - see for example FTDI bricking your hardware if they think it's counterfeit: https://news.ycombinator.com/item?id=8493849

And as a side effect to that story - I recently needed to purchase a USB to RS232 adapter to program a router and I went explicitly out of my way to make sure the adapter I purchased didn't use an FTDI chip.

FTDI is a name I won't be forgetting anytime soon.

Re: FlightSimLabs Alleged Malware Analysis

#36

Unfortunately, the moment a company has distributed malware intentionally, they are totally written off. They will never be trustworthy to distribute software again. Never touch any program this company has released, there is a high risk of malware.

Lefteris Kalamaras is not to be trusted. His organisation knowingly distributed malware in a legitimate software installer provided by his company.

Re: FlightSimLabs Alleged Malware Analysis

#38
post #10

I never understood the point of DRM. "10 extremely determined people want to steal my intellectual property! I'll go miles out of my way to design this in such a way that 1,000 people have a crappy experience to slow down the 10 people who want to be pirates!" Vendor makes a shitty product Pirates find a workaround, pirate shitty product anyway Vendor makes shitty product even shittier for all 1,000 people to agin tr…

I'm not a big fan of DRM and don't want to defend it, but your description is a bit incomplete.

Those 10 determined people/pirates go off and put the cracked software (or the serials) up for download for the "not so determined" pirates who just want to download a cracked version (or serial) that works. Those don't have the skills (and willpower) to do the work needed to crack software.

Those, however, aren't 10 people: the ratio of cracker to "not so determined pirate" is an important part of the puzzle. Perhaps 1000 people will get the cracked version. I don't know, but the 1-to-many relationship is quite obvious from a distribution system such as BT or Mega.

I'm not trying to justify DRM (and certainly not what these guys have been up to), but your presentation makes it look like measures such as these are trying to fight a super-minority of folks (ie 10 out of 1000, or about 1%), when reality is most likely very different.

I have an app on the Mac App Store (I won't spam you with the download link since it's irrelevant to the discussion and I'm not here to fish for downloads) with analytics that report that many "purchase attempts" fail with a strange error (ie not a cancellation by the user, not a problem reaching servers, etc), and I have no other choice but to imagine that these are from people who are trying to pirate my app. And it's nowhere near a 1% fraction.

In my previous company, we'd have server side verification of receipts (per Apple rules), and about an hour after we'd release our software, we'd see a torrent of verification failures in our logs.

Software piracy is quite widespread and is an issue that we shouldn't gloss over. Still, I wouldn't condone what these guys seem to have been doing.

As a side comment on style, you could have made your point without saying "Vendor makes a shitty product" as there is no need to denigrate products that vendors make in such a generalized manner. You'll be taken more seriously if you can adopt a more balanced stance.

Re: FlightSimLabs Alleged Malware Analysis

#39

I thought I’d share this here to spread more attention to the practices of FlightSimLabs, a flight simulator software shop. The short version is that they included an executable in their installer that when run would extract passwords saved in Chrome and presumably phone them home. Their reasoning was that this was purely for DRM reasons. They claim that this password stealing tool would not run for legit/valid seria…

> They have again made statements saying that this tool was only used against pirated copies of their software.

That's quite a claim. But it wouldn't matter if they did apologize. No apology would take away the malware or cause this publisher to have not used the secrecy of proprietary software (and the implicit trust all of their users had in the publisher) to not do what they did.

Too bad for the users who obtained copies (regardless of how) that this claim is utterly unverifiable and ultimately up to the dictates of an organization that already misrepresented its aim to its users -- I'll bet that people who got a copy thought they were getting a flight simulator, not a credentials copier. There's no reason to trust that they're not lying now. And what if FlightSimLabs (or some organization they trust to hold data) inadvertently leaked sensitive information? That's the trouble with trusting organizations to hold sensitive data; they can end up contributing to harm even if they don't intend to do so, or do so accidentally purely by way of making bad decisions about whether to hold the data in the first place and also by bad design of where and how to store the sensitive data.

Proprietary software hides malware (see https://www.gnu.org/proprietary/proprietary.html for lots of examples), users deserve software freedom (the freedom to run, inspect, modify, and share published software), and users deserve to control their own computers. And this DRM was indiscriminate (as most DRM is): it was installed on all users of the affected program, including on the copies distributed in the manner FlightSimLabs wanted.

Re: FlightSimLabs Alleged Malware Analysis

#40
post #10

I never understood the point of DRM. "10 extremely determined people want to steal my intellectual property! I'll go miles out of my way to design this in such a way that 1,000 people have a crappy experience to slow down the 10 people who want to be pirates!" Vendor makes a shitty product Pirates find a workaround, pirate shitty product anyway Vendor makes shitty product even shittier for all 1,000 people to agin tr…

Not only that: they end up enabling the pirates because the pirates are then able to provide the potential users of the product with a major reason for breaking the social contract (and the law): a much better user experience than the original.

Back when I was buying DRM-infested games on disc (lately I don't do AAA crap because it's boring, so the only DRM i have to deal with is Steam), the first thing before even unpacking the discs was to download the nocd crack.

Those pirates provide a good service to the legitimate owners as well ;)

Post reply on HN