Live data from Hacker News

FlightSimLabs Alleged Malware Analysis

medium.com

51–60 of 62 posts

Re: FlightSimLabs Alleged Malware Analysis

#51
In my younger days of making sharewares, my way to find pirates was a lot easier... If the serial had been stolen, I would crash the app after a few hours of use, randomly, with a generic message but a very, very specific error code.

Then I'd wait for the support emails to come in with people complaining about that crash/error...

Typical how the pirate support requests were always the most rude and impolite :-)

Re: FlightSimLabs Alleged Malware Analysis

#52

In my younger days of making sharewares, my way to find pirates was a lot easier... If the serial had been stolen, I would crash the app after a few hours of use, randomly, with a generic message but a very, very specific error code. Then I'd wait for the support emails to come in with people complaining about that crash/error... Typical how the pirate support requests were always the most rude and impolite :-)

Ea did something similar with the sims. Screen would slowly blur. You can’t beat pirates but you sure can have fun with them.

Re: FlightSimLabs Alleged Malware Analysis

#53
post #4

Earlier quoted context omitted.

So basically "you broke the law, so we'll break the law"?

Unfortunately, this sort of attitude is not unheard of among proprietary software vendors - see for example FTDI bricking your hardware if they think it's counterfeit: https://news.ycombinator.com/item?id=8493849

> FTDI bricking your hardware if they think it's counterfeit

It's not quite the same thing. Their driver does things that work with the original hardware.

If a different chip uses the same USB ID, they're asking for trouble.

(of course good faith is unlikely in this case)

Re: FlightSimLabs Alleged Malware Analysis

#54

Earlier quoted context omitted.

The silliest part of this is pirates usually get to enjoy a better product because of their actions.

For example, the unskippable piracy warnings on DVDs.

And more recently with uhd. Those disks were supposed to be “uncrackable”. Well thanks to some older uhd drives pirates now have full disk rips and as far as I know they’re not even breaking encryption.

Re: FlightSimLabs Alleged Malware Analysis

#55
post #10

I never understood the point of DRM. "10 extremely determined people want to steal my intellectual property! I'll go miles out of my way to design this in such a way that 1,000 people have a crappy experience to slow down the 10 people who want to be pirates!" Vendor makes a shitty product Pirates find a workaround, pirate shitty product anyway Vendor makes shitty product even shittier for all 1,000 people to agin tr…

I'm not a big fan of DRM and don't want to defend it, but your description is a bit incomplete. Those 10 determined people/pirates go off and put the cracked software (or the serials) up for download for the "not so determined" pirates who just want to download a cracked version (or serial) that works. Those don't have the skills (and willpower) to do the work needed to crack software. Those, however, aren't 10 peopl…

I’ve pirated apps before buying to make sure I’d like them and they work. It’s surprising how many apps don’t have trials or trials that are not so limited you don’t get an idea how it works. This is really true for Mac AppStore apps.

Re: FlightSimLabs Alleged Malware Analysis

#56

I thought I’d share this here to spread more attention to the practices of FlightSimLabs, a flight simulator software shop. The short version is that they included an executable in their installer that when run would extract passwords saved in Chrome and presumably phone them home. Their reasoning was that this was purely for DRM reasons. They claim that this password stealing tool would not run for legit/valid seria…

So basically "you broke the law, so we'll break the law"?

Not even sure if users broke the law. Just using a 3rd party cracked software doesn't necessarily violate laws (at least no criminal offence). The distributors and crackers clearly violated laws but any user with a cracked serial number was targeted. That also included people who might've received the number against payment from someone else and thought they had a genuine copy.

Re: FlightSimLabs Alleged Malware Analysis

#57
post #24
post #10

I never understood the point of DRM. "10 extremely determined people want to steal my intellectual property! I'll go miles out of my way to design this in such a way that 1,000 people have a crappy experience to slow down the 10 people who want to be pirates!" Vendor makes a shitty product Pirates find a workaround, pirate shitty product anyway Vendor makes shitty product even shittier for all 1,000 people to agin tr…

I think there are a few main kinds of reasoning behind DRM (non-exclusive, more then one could be involved in any specific case). One is psychological, one is pure greed and generally not explicitly acknowledged, but the last is potentially reasonable in specific situations. The first essentially boils down to the well studied psychological phenomena of Loss Aversion, which is what you refer to and purely emotional,…

Regarding the end of your post, you apparently make the point that, for a game, if a DRM is not cracked just after the release (let's say 1 to 2 months), the sales of those would be higher than the sales of games which are available at release?

The problem is that the recent examples of games not being cracked on release (like the latest Tomb Raider) does not fit with your reasoning, since they did not have sales number above the norm.

Re: FlightSimLabs Alleged Malware Analysis

#58
post #46
post #45

Earlier quoted context omitted.

Yeah, not sure if you're being sarcastic, but if not: the law doesn't work like that. You can't annul a criminal statute simply by including a clause in your EULA.

If someone signs a contract allowing you to do something you're generally allowed to do the thing, with exceptions. Dropbox uploads data from your computer on to their servers, which would be illegal had you not agreed to that as part of signing up and installing the software.

So you're suggesting that the FlightSim EULA laid out exactly what the installer was doing, and asked permission to exfiltrate your passwords if the registration key didn't match? I very much doubt that, and I'm skeptical it would be legal even if so.

It's unquestionably illegal to do it on the down-low, like FlightSim has done. It's malware, nothing less, nothing more.

Re: FlightSimLabs Alleged Malware Analysis

#59
post #58
post #46

Earlier quoted context omitted.

If someone signs a contract allowing you to do something you're generally allowed to do the thing, with exceptions. Dropbox uploads data from your computer on to their servers, which would be illegal had you not agreed to that as part of signing up and installing the software.

So you're suggesting that the FlightSim EULA laid out exactly what the installer was doing, and asked permission to exfiltrate your passwords if the registration key didn't match? I very much doubt that, and I'm skeptical it would be legal even if so. It's unquestionably illegal to do it on the down-low, like FlightSim has done. It's malware, nothing less, nothing more.

>So you're suggesting that the FlightSim EULA laid out exactly what the installer was doing, and asked permission to exfiltrate your passwords if the registration key didn't match?

No, I'm suggesting they should add a clause saying that they have the right to access and upload anything on your computer if it's being pirated.

I never said anything about the current EULA and haven't looked at it.

Re: FlightSimLabs Alleged Malware Analysis

#60
post #55

Earlier quoted context omitted.

I'm not a big fan of DRM and don't want to defend it, but your description is a bit incomplete. Those 10 determined people/pirates go off and put the cracked software (or the serials) up for download for the "not so determined" pirates who just want to download a cracked version (or serial) that works. Those don't have the skills (and willpower) to do the work needed to crack software. Those, however, aren't 10 peopl…

I’ve pirated apps before buying to make sure I’d like them and they work. It’s surprising how many apps don’t have trials or trials that are not so limited you don’t get an idea how it works. This is really true for Mac AppStore apps.

I've heard this rationalization before, but I doubt it's a widespread practice in the pirates' world. Look, people are selling their soul to get "free products" (think about all the use cases where you are the product when using all the nice "free services"). Free is awesome. We're used to free. We demand free. We get offended when some app asks for $1.99 (I exaggerate for style of course, but as someone who has an app on the Mac AppStore, this comment has a reason rooted in reality - and for the record my app is Free while you try it and you pay to unlock it so you can customize it).

It's an interesting rationalization for an illegal activity, but you are not forced to go down the path of illegality by pirating a software you want to try. You can ask the author for a trial version, and if that leads nowhere, you can just skip this software. Not happy with the terms of the deal? Don't take the deal! The author would be wise to have a trial option, but doesn't owe it to anyone.

Personal anecdote time: when I was much younger I wanted to buy an exotic car and the dealer didn't offer test drives (understandably). I'm not sure it would feel acceptable to anyone if I had snuck into the dealership at night and took the car out for a spin around the block and put it back after an hour just to "test it out". I realize many flaws can be pointed out in my analogy easily, but the point is that one can get away with "illegal software test drive" because it's software and one would never think of doing it with hardware, because the risks of getting caught (and their consequences) are too high when we deal with tangible assets vs sitting home downloading cracks or serialz.

Post reply on HN