Live data from Hacker News

Ubisoft "Uplay" DRM exposed as rootkit

news.ycombinator.com

81–90 of 148 posts

Re: Ubisoft "Uplay" DRM exposed as rootkit

#81
post #9

Why does Tavis Ormandy ( http://seclists.org/fulldisclosure/2012/Jul/375 ) keep putting fully usable proof of concept exploits out for widely deployed software without giving a vendor time to prepare a patch, or in this case, even notifying them? Off the top of my head, I remember he did this for the windows help center exploit and the java web start exploit. I can't understand why you would do this. You could at lea…

Because the company wasn't acting in good faith? IMHO they put that there on purpose and they deserve to be exposed as evil bastards that they are.

What would "they" have to gain from this ability? Ubi has already capability to execute arbitrary code on your machine via it's uplay software, they don't need a hole in browser plugin for that.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#82
post #76
post #34

Earlier quoted context omitted.

Short of doing extensive background research on a title, Steam has no indication of a game's dependence on some third party launcher or cloud service, so every time I run a new game for the first time I have to clench and pray the Windows Live overlay doesn't drop down. Meaning: I feel your pain, brother.

Couldn't Steam pull the game from their shop? Prevent new people from buying it and remotely de-activate/remove existing installs of the game? Proponants of the walled garden 'App Store' model point out how it's good for users, since it's more secure. Well, is this a case for that? Will the closed app store model step up to the plate now? Or is the walled garden no better for users, but much better for the sellers of…

When a walled garden actually is better for users, they could choose to participate. When users aren't allowed to choose, you can be pretty sure who the primary beneficiary is.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#83
post #46

Earlier quoted context omitted.

"I can't prove it through fact, but I feel it to be true."

Not subscribing to malice what can explained by stupidity is just a feeling too. The question is: do you believe the perpetrator to be malicious or dumb?

It's not a "feeling" when all evidence points to the fact that, like every security vulnerability ever, a feature was added that had unintended consequences. There's no way it's malicious: Ubisoft can't do anything with this that they can't do everywhere else in the actual applications themselves!

Re: Ubisoft "Uplay" DRM exposed as rootkit

#84
post #70

Earlier quoted context omitted.

If they are going to install low level software on my computer they better be very sure it's properly coded. Instead, they ask for their interns to build the "solution" that makes my computer part of the Borg. I really don't feel compassion in this case towards the company (towards the users is a different story, no doubt)

If they are going to install low level software on my computer they better be very sure it's properly coded. Companies are often incompetant with security code. If you are expecting high quality secure code with consumer level software, you will often be disappointed.

Which is why going the full disclosure route prevents them from being insulated from their mistakes - otherwise, it becomes a moral hazard to keep playing nice with the approach to disclosure.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#85
post #46

Earlier quoted context omitted.

"I can't prove it through fact, but I feel it to be true."

Not subscribing to malice what can explained by stupidity is just a feeling too. The question is: do you believe the perpetrator to be malicious or dumb?

Usually both. (Note that with the internet you also have to be dumb, too, to believe you are not eventually going to be caught, no matter how malicious you are.)

Re: Ubisoft "Uplay" DRM exposed as rootkit

#86
I have several of these games (SWS, PoP, Heroes MM VI) installed as well as UPlay but do not have any file associations for the type listed. Nor is "x-uplaypc" anywhere in the registry for the Windows shell.

I also have titles that use online login from Ubi such as ANNO 2070 installed.

I think the list of affected titles is far smaller than listed.

How and when is this associate set? Has someone identified which application in the installer performs it? Is it a particular UPlay version?

I don't doubt they are setting this up to allow them to run games from a browser. EA does it with Origin, Valve does it with Steam, as well as numerous other applications.

I don't doubt its existence but I think people are starting a wildfire without enough facts. I can't even seem to research this because it's not on my machine.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#87
post #49

Earlier quoted context omitted.

Just for your information; rootkits can exist in any of the rings[1]. However, kernel-mode rootkits are most often harder to detect and get rid off. There are several definitions of a rootkit, a common definition is "software designed to hide the existence of certain processes or programs from normal methods of detection and enable continued privileged access to a computer."[2] [1] http://en.wikipedia.org/wiki/Ring_(…

It doesn't seem like they went to any particular lengths to hide it, just nobody bothered to look very hard, and you wouldn't expect them to be installing browser plugins. Sony's DRM system, on the other hand, was an actual rootkit and went to a lot of effort to bury itself in the infected system.

Maybe people would prefer to call it a "backdoor" instead, but this is quite disconcerting. I'm very glad I don't play any of those games.

Re: Ubisoft "Uplay" DRM exposed as rootkit

#89

This does not 'install a backdoor that allows any website to take over your computer', right? It just makes it possible to launch any previously installed executable if you know the path.

> It just makes it possible to launch any previously installed executable if you know the path.

You say that as though it's some kind of hurdle.

C:\>ftp -h

Transfers files to and from a computer running an FTP server service (sometimes called a daemon). Ftp can be used interactively.

FTP [-v] [-d] [-i] [-n] [-g] [-s:filename] [-a] [-w:windowsize] [-A] [host]

Re: Ubisoft "Uplay" DRM exposed as rootkit

#90
post #46

Earlier quoted context omitted.

Not subscribing to malice what can explained by stupidity is just a feeling too. The question is: do you believe the perpetrator to be malicious or dumb?

It's not a "feeling" when all evidence points to the fact that, like every security vulnerability ever, a feature was added that had unintended consequences. There's no way it's malicious: Ubisoft can't do anything with this that they can't do everywhere else in the actual applications themselves!

Who says it was malicious on Ubisoft's part? It could easily have been a rogue developer that saw an opportunity to install a backdoor on a ton of machines.
Post reply on HN