Why does Tavis Ormandy ( http://seclists.org/fulldisclosure/2012/Jul/375 ) keep putting fully usable proof of concept exploits out for widely deployed software without giving a vendor time to prepare a patch, or in this case, even notifying them? Off the top of my head, I remember he did this for the windows help center exploit and the java web start exploit. I can't understand why you would do this. You could at lea…
Because the company wasn't acting in good faith? IMHO they put that there on purpose and they deserve to be exposed as evil bastards that they are.
Ubisoft "Uplay" DRM exposed as rootkit
81–90 of 148 posts
Re: Ubisoft "Uplay" DRM exposed as rootkit
#82Earlier quoted context omitted.
Short of doing extensive background research on a title, Steam has no indication of a game's dependence on some third party launcher or cloud service, so every time I run a new game for the first time I have to clench and pray the Windows Live overlay doesn't drop down. Meaning: I feel your pain, brother.
Couldn't Steam pull the game from their shop? Prevent new people from buying it and remotely de-activate/remove existing installs of the game? Proponants of the walled garden 'App Store' model point out how it's good for users, since it's more secure. Well, is this a case for that? Will the closed app store model step up to the plate now? Or is the walled garden no better for users, but much better for the sellers of…
Re: Ubisoft "Uplay" DRM exposed as rootkit
#83Earlier quoted context omitted.
"I can't prove it through fact, but I feel it to be true."
Not subscribing to malice what can explained by stupidity is just a feeling too. The question is: do you believe the perpetrator to be malicious or dumb?
Re: Ubisoft "Uplay" DRM exposed as rootkit
#84Earlier quoted context omitted.
If they are going to install low level software on my computer they better be very sure it's properly coded. Instead, they ask for their interns to build the "solution" that makes my computer part of the Borg. I really don't feel compassion in this case towards the company (towards the users is a different story, no doubt)
If they are going to install low level software on my computer they better be very sure it's properly coded. Companies are often incompetant with security code. If you are expecting high quality secure code with consumer level software, you will often be disappointed.
Re: Ubisoft "Uplay" DRM exposed as rootkit
#85Earlier quoted context omitted.
"I can't prove it through fact, but I feel it to be true."
Not subscribing to malice what can explained by stupidity is just a feeling too. The question is: do you believe the perpetrator to be malicious or dumb?
Re: Ubisoft "Uplay" DRM exposed as rootkit
#86I also have titles that use online login from Ubi such as ANNO 2070 installed.
I think the list of affected titles is far smaller than listed.
How and when is this associate set? Has someone identified which application in the installer performs it? Is it a particular UPlay version?
I don't doubt they are setting this up to allow them to run games from a browser. EA does it with Origin, Valve does it with Steam, as well as numerous other applications.
I don't doubt its existence but I think people are starting a wildfire without enough facts. I can't even seem to research this because it's not on my machine.
Re: Ubisoft "Uplay" DRM exposed as rootkit
#87Earlier quoted context omitted.
Just for your information; rootkits can exist in any of the rings[1]. However, kernel-mode rootkits are most often harder to detect and get rid off. There are several definitions of a rootkit, a common definition is "software designed to hide the existence of certain processes or programs from normal methods of detection and enable continued privileged access to a computer."[2] [1] http://en.wikipedia.org/wiki/Ring_(…
It doesn't seem like they went to any particular lengths to hide it, just nobody bothered to look very hard, and you wouldn't expect them to be installing browser plugins. Sony's DRM system, on the other hand, was an actual rootkit and went to a lot of effort to bury itself in the infected system.
Re: Ubisoft "Uplay" DRM exposed as rootkit
#88This does not 'install a backdoor that allows any website to take over your computer', right? It just makes it possible to launch any previously installed executable if you know the path.
Re: Ubisoft "Uplay" DRM exposed as rootkit
#89This does not 'install a backdoor that allows any website to take over your computer', right? It just makes it possible to launch any previously installed executable if you know the path.
You say that as though it's some kind of hurdle.
C:\>ftp -h
Transfers files to and from a computer running an FTP server service (sometimes called a daemon). Ftp can be used interactively.
FTP [-v] [-d] [-i] [-n] [-g] [-s:filename] [-a] [-w:windowsize] [-A] [host]
Re: Ubisoft "Uplay" DRM exposed as rootkit
#90Earlier quoted context omitted.
Not subscribing to malice what can explained by stupidity is just a feeling too. The question is: do you believe the perpetrator to be malicious or dumb?
It's not a "feeling" when all evidence points to the fact that, like every security vulnerability ever, a feature was added that had unintended consequences. There's no way it's malicious: Ubisoft can't do anything with this that they can't do everywhere else in the actual applications themselves!