Live data from Hacker News

Ubisoft "Uplay" DRM exposed as rootkit

news.ycombinator.com

31–40 of 148 posts

Re: Ubisoft "Uplay" DRM exposed as rootkit

#32
post #12

Oh hell no. I can't believe this shit... and Tom Clancy's Ghost Recon: Future Soldier was such a good game too. T_T Next time I want to play an Ubisoft game I'm just going to pirate it. EDIT: I buy 99% of my video games through Steam, and when the games I get through Steam want to use their own launcher (play, windows live games, or EA's Origin, for example) I always get peeved.. to find out it allows arbitrary remot…

I hate the hoop jumping in modern games. I was playing Street Fighter 4 recently and it comes up with "oh, you want to save your single player game? You have to create a MicrosoftWindowsBingGamesPhone8ForXboxLive.Net account" .

Then of course you have to wait for the damn thing to sign in every time you want to play the game "Connection failed, do you want to retry?"

Re: Ubisoft "Uplay" DRM exposed as rootkit

#34
post #12

Oh hell no. I can't believe this shit... and Tom Clancy's Ghost Recon: Future Soldier was such a good game too. T_T Next time I want to play an Ubisoft game I'm just going to pirate it. EDIT: I buy 99% of my video games through Steam, and when the games I get through Steam want to use their own launcher (play, windows live games, or EA's Origin, for example) I always get peeved.. to find out it allows arbitrary remot…

I hate the hoop jumping in modern games. I was playing Street Fighter 4 recently and it comes up with "oh, you want to save your single player game? You have to create a MicrosoftWindowsBingGamesPhone8ForXboxLive.Net account" . Then of course you have to wait for the damn thing to sign in every time you want to play the game "Connection failed, do you want to retry?"

Short of doing extensive background research on a title, Steam has no indication of a game's dependence on some third party launcher or cloud service, so every time I run a new game for the first time I have to clench and pray the Windows Live overlay doesn't drop down.

Meaning: I feel your pain, brother.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#35

Why does Tavis Ormandy ( http://seclists.org/fulldisclosure/2012/Jul/375 ) keep putting fully usable proof of concept exploits out for widely deployed software without giving a vendor time to prepare a patch, or in this case, even notifying them? Off the top of my head, I remember he did this for the windows help center exploit and the java web start exploit. I can't understand why you would do this. You could at lea…

Giving a browser plugin the ability to run any program on the user machine without any kind of validation or prompting is so stupid/evil that they deserve the worst PR backlash they can get.

Also, that's probably the quickest way to get them to release a fix.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#36
post #13
post #9

Earlier quoted context omitted.

Because the company wasn't acting in good faith? IMHO they put that there on purpose and they deserve to be exposed as evil bastards that they are.

Do you have any evidence they put that here on purpose or are you just spreading rumors? It could as well be shoddy programming.

If they are going to install low level software on my computer they better be very sure it's properly coded.

Instead, they ask for their interns to build the "solution" that makes my computer part of the Borg.

I really don't feel compassion in this case towards the company (towards the users is a different story, no doubt)

Re: Ubisoft "Uplay" DRM exposed as rootkit

#37

Why does Tavis Ormandy ( http://seclists.org/fulldisclosure/2012/Jul/375 ) keep putting fully usable proof of concept exploits out for widely deployed software without giving a vendor time to prepare a patch, or in this case, even notifying them? Off the top of my head, I remember he did this for the windows help center exploit and the java web start exploit. I can't understand why you would do this. You could at lea…

Very few comapnies will pay for this type of exploit, even fewer will offer a thanks. It's easier to get them fixed this way.

The question is whether it's easier for the security researcher or the users. I don't think it's easier for the users if they end up being exploited for weeks while the vendor rushes to fix it.

If the vendor tries to delay you for months or ignores you, sure. But it doesn't even seem like he tested the exploit here to understand whether it was a serious threat.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#39

Why does Tavis Ormandy ( http://seclists.org/fulldisclosure/2012/Jul/375 ) keep putting fully usable proof of concept exploits out for widely deployed software without giving a vendor time to prepare a patch, or in this case, even notifying them? Off the top of my head, I remember he did this for the windows help center exploit and the java web start exploit. I can't understand why you would do this. You could at lea…

I asked a question. If you're going to downvote me for having a wrong opinion, you should at least respond and tell me me the answer to my question, like 'this is proper behavior for a security researcher because X'.

You asked a very laden question. You have no doubt encountered discussions about full-disclosure to know the arguments against it; giving a one-sided rehash of that topic is a provocative way to invoke an old and tired discussion.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#40
post #10

I'm not sure if that's what the OP implied, but I'm not sure this was done on purpose. "Never attribute to malice that which is adequately explained by stupidity". Ubisoft is well know for their aggressive anti-pirating practices (cloud saves for instance), but that's just too idiotic. Here's taviso's mail on seclists: http://seclists.org/fulldisclosure/2012/Jul/375 I hope ubisoft reacts quickly.

If they can't do a crippling DRM properly, then maybe they have no business building one at all.
Post reply on HN