Show HN: Keygen – A dead-simple product licensing API built for developers
keygen.sh
keygen.sh
I mean, sure, I licence one of my own products with a RSAPSS signature on an environmental constraint .. but if somebody went to the effort they could just flip a single instruction to bypass it. However, I am pretty sure nobody in my target market will bother.
However, I don't think that would hold with something like this. What stops people releasing a bunch of generic bypass/crack tools against your client SDKs?
Spoiler alert: nothing can stop cracking (but that's not the point of licensing): https://wyday.com/limelm/features/why/
But I'll just give you the benefit of the doubt and say you didn't actually understand the question.
(Also, I'm certain I'll be downvoted for commenting on a competitor's product, but licensing companies that lie to customers is a particular pet peeve of mine).
Doesn't sound very useful.
It went from 5 minutes in a hex editor to being a rather involved job. So it stopped it for a while.
Then people realised that instead of cracking licensed program, it was much more simple to crack the license server. (this also made detection much harder.) It also had the advantage of allowing rafts of other software not made by us work as well.
There will always be ways to bypass licensing, especially for apps built on web tech, e.g. web apps, Electron apps, NW.js apps, etc. There are ways around it, sure. But that part isn't what Keygen is for. Keygen uses a combination of serial keys for licensing, as well as hardware-locked licensing by tracking machine fingerprints. It's up to the developer to enforce these, however.
Also, Keygen solves a very different problem that Nalpeiron, Lime LM, Agilis, Cryptlex, etc. do not solve: easy licensing for web-based apps. All of the solutions I've seen are cumbersome, unintuitive and are of course primarily designed for compiled apps. All of that has lead me (and others) to developing licensing systems in-house that behave more or less identically.
> The resource at “https://mc.us14.list-manage.com/subscribe/form-settings?u=0d... was blocked because tracking protection is enabled.[Learn More]
"Traditional" license management servers (like FlexLM) are a scary piece of software for sysadmins: think of it like a black box that will shut down everything if you mess up.
This license-as-a-service makes operations very easy.
I wonder if you have in mind something about concurrent users. I mean, some software is licensed on a _concurrent_ user basis, not just per seat.
If a user logs-in twice, usually the LM revokes the license for the session that was active, and assigns a new one to the user that just logged-in.
Also, license reporting is also a good idea for answering questions like... how much do I have to pay for next year maintainance?
The website design is REALLY refreshing and feels professional.
Question: I guess this is software as a service, what happens if the service would shut down - for whatever reason?
I'm just kinda confused that there are not more self hosted libraries for this.
It doesn't look like it has the built in monetization, but it should be fairly easy to smash a payment provider and API management together.
I know this is not the focus of this particular product but since it has come up in multiple comments. How could this be solved?
Works best with an external license server. If you have to be offline make the checks more involved.
It seems like this is either insecure or you pay an RTT latency penalty on every authenticated request. Is this correct? Is there something I'm missing here?
Not sure there's anything practical you can do about that. You're not going to be able to stop hackers figuring out a bypass. Your goal should be to make the license check bypass inconvenient enough that regular users would rather pay for a license (e.g. requires a new bypass each version upgrade).
In the end, it all depends on the product.
It would be integrated the same way you would integrate something like Stripe; you request information when required, and keep your own records up to date via webhook events.
For example, a desktop app would really only need to validate a users license after they have successfully logged in after booting the app; you likely wouldn't need to validate the license again for at least 24 hours, and that's assuming you wanted to perform periodic license validations for long-running sessions.
How can you allow people to install and update commercial packages, without the problem that anyone can use any key?
I'm thinking particularly in terms of software which is licensed to run on 1 domain, 3 domains, 5 domains etc - but as soon as you use a CLI package installer, you don't know the domain being used.
I assume you've addressed this issue, but I'd love to know how.
Edit: From reading a bit more, I understand that this service is mainly aimed at web/online apps, so piracy is a non-issue.
If you trust the client to say "yes, validate via the keygen.sh API", then without loss of generality you can probably trust it to validate using a public key and a timestamp.
EDIT: Definitely enjoying the slightly creepy visual haxor effects, though.
You only need a key management service like this when you go from SaaS to on-prem/equivalent, at which point PHP is in the unenviable position of having readable source files.
It's possible to patch out license checks from any language, but PHP makes it pretty easy - what's your approach to solving this? Ioncube-style binary extensions? If so, PHP7/opcache compatibility?