Live data from Hacker News

Ubisoft "Uplay" DRM exposed as rootkit

news.ycombinator.com

61–70 of 148 posts

Re: Ubisoft "Uplay" DRM exposed as rootkit

#61

Earlier quoted context omitted.

You sure about that? Section 8: Prejudice [1] (the only GFWL game I own) lists Games for Windows Live under 3rd party DRM. On the other hand, the Batman: Arkham Noun games [2,3] list SecuROM in 3rd party DRM but not GFWL. I'm told that these games are both GFWL titles. I don't know what's going on there, but it looks inconsistent. [1] http://store.steampowered.com/app/97100/ [2] http://store.steampowered.com/app/3514…

Batman: Arkham Asylum requires a Windows Live account, not sure about the new one. Perhaps it is not listed if it is only used to enable "social gaming" but DRM is done by some other software.

Just spotted it, the Batman games hide it in the System requirements:

> Online play requires log-in to Games For Windows – Live

So I guess it's in the DRM list if you need it to play singleplayer, and in system reqs if you don't. Seems fair, but I'd still rather have it be consistent. No reason S8 couldn't list it in both spots.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#62
post #34

Earlier quoted context omitted.

Short of doing extensive background research on a title, Steam has no indication of a game's dependence on some third party launcher or cloud service, so every time I run a new game for the first time I have to clench and pray the Windows Live overlay doesn't drop down. Meaning: I feel your pain, brother.

You sure about that? Section 8: Prejudice [1] (the only GFWL game I own) lists Games for Windows Live under 3rd party DRM. On the other hand, the Batman: Arkham Noun games [2,3] list SecuROM in 3rd party DRM but not GFWL. I'm told that these games are both GFWL titles. I don't know what's going on there, but it looks inconsistent. [1] http://store.steampowered.com/app/97100/ [2] http://store.steampowered.com/app/3514…

Fable 3 doesn't mention GFWL anywhere, except that it's published by "Microsoft Games Studios" which would be a big hint... if you look at publisher info.

Which is why I say it's usually a crap shoot. :(

EDIT: In terms of Tom Clancy's Ghost Recon Future Soldier specifically, it doesn't mention Uplay anywhere on the Steam store page at all. It's like "surprise! This 3rd party launcher / DRM / rootkit comes with it, absolutely free!"

Re: Ubisoft "Uplay" DRM exposed as rootkit

#63

This does not 'install a backdoor that allows any website to take over your computer', right? It just makes it possible to launch any previously installed executable if you know the path.

If someone can launch any executables on your machine, you can consider it to be fairly dangerous.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#64
post #49
post #45

I wouldn't say that this is a rootkit (there's no kernel-based magic or even just privilege elevation going on), nor that this was done with bad intentions. This is just inexperienced developers («it's "encrypted" using base64 - we're fine!!») that had a "great idea" (= launch games from an embedded IE control) that has, kinda, backfired. The sad thing is that it would be trivial (I'm using the word "trivial" here ar…

Just for your information; rootkits can exist in any of the rings[1]. However, kernel-mode rootkits are most often harder to detect and get rid off. There are several definitions of a rootkit, a common definition is "software designed to hide the existence of certain processes or programs from normal methods of detection and enable continued privileged access to a computer."[2] [1] http://en.wikipedia.org/wiki/Ring_(…

It doesn't seem like they went to any particular lengths to hide it, just nobody bothered to look very hard, and you wouldn't expect them to be installing browser plugins. Sony's DRM system, on the other hand, was an actual rootkit and went to a lot of effort to bury itself in the infected system.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#65
post #23

Earlier quoted context omitted.

I don't subscribe to "never attribute to malice that which is adequately explained by stupidity". I'm not citing sources - hence it's just my opinion. Reminds me of google wifi slurping and hundreds of other cases where everyone plays dumb and swears it was all a misunderstanding. It never is. Until you get caught. And if not that it's a rogue trader, rogue reporter, rogue programmer, rogue scapegoat.

Since we have no additional evidence to select between the two options, do you really think that malice is simpler than stupidity?

I'm not going to do any kind of full disclosure here (I know this is lame) but I work in video games so I know what it looks like from the other side. We're not all idiots here, we just do as we're told.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#66
post #63

This does not 'install a backdoor that allows any website to take over your computer', right? It just makes it possible to launch any previously installed executable if you know the path.

If someone can launch any executables on your machine, you can consider it to be fairly dangerous.

I know, but that's not what the submissions says. It feels a bit sensationalized.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#67

Earlier quoted context omitted.

Batman: Arkham Asylum requires a Windows Live account, not sure about the new one. Perhaps it is not listed if it is only used to enable "social gaming" but DRM is done by some other software.

Just spotted it, the Batman games hide it in the System requirements: > Online play requires log-in to Games For Windows – Live So I guess it's in the DRM list if you need it to play singleplayer, and in system reqs if you don't. Seems fair, but I'd still rather have it be consistent. No reason S8 couldn't list it in both spots.

Still, I habitually don't read System Reqs. I'd expect something more like one of the "Single Player", "Multi Player" bullets under the ESRB rating. "Requires 3rd party bullshit"

Re: Ubisoft "Uplay" DRM exposed as rootkit

#68

This does not 'install a backdoor that allows any website to take over your computer', right? It just makes it possible to launch any previously installed executable if you know the path.

> It just makes it possible to launch any previously installed executable if you know the path.

Well yes, it allows "offline" privileges to essentially any online site (if you can launch arbitrary executables, you can download and execute arbitrary payloads). And considering there is still a rather prevalent culture of running Windows as an administrator account (if only because some softs fail rather annoyingly and without trying to escalate when launched without adminstrator priviledges) for all intents and purposes it gives pretty wide control of the machine to any URL you connect to.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#69
post #43
post #13

Earlier quoted context omitted.

Do you have any evidence they put that here on purpose or are you just spreading rumors? It could as well be shoddy programming.

The fact that the line contains "dev" twice is probably indicative of forgetting to disable it.

Or really tight dates to meet and rushing.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#70
post #13

Earlier quoted context omitted.

Do you have any evidence they put that here on purpose or are you just spreading rumors? It could as well be shoddy programming.

If they are going to install low level software on my computer they better be very sure it's properly coded. Instead, they ask for their interns to build the "solution" that makes my computer part of the Borg. I really don't feel compassion in this case towards the company (towards the users is a different story, no doubt)

If they are going to install low level software on my computer they better be very sure it's properly coded.

Companies are often incompetant with security code. If you are expecting high quality secure code with consumer level software, you will often be disappointed.

Post reply on HN