A320-X DRM: What happened
forums.flightsimlabs.com
forums.flightsimlabs.com
It sounds like they distributed a tool that goes through your Chrome saved passwords database and if the installer thinks you're a pirate, it sends credentials from that database back to the author. The author is now saying they used credentials they learned from this to break into a private website to learn more about how their DRM was being bypassed.
This seems so incredibly illegal, I can't believe they admitted that this is what they're doing.
Unfortunately for me, things don't work that way. For most of Europe at least, you'd be perfectly justified in treating my 100 page EULA like the garbage it is and basically ignore everything in it that isn't already prescribed by law anyway.
I am not familiar with the flight sim license in question, but there are a number of general terms it might contain that would allow for the collection behavior. Telemetry, anti-piracy, anti-cheat, audit, fitness of purpose, and many other provisions could cover this particular behavior.
Further, if their claims are to be believed, they only initiated this action against a someone in already in breach of contract, so the law isn't going to protect the pirate anyway.
Again, I think the company's behavior is unethical - they should have contacted law enforcement. But illegal? That is not at all clear.
But just repeating a part in many contracts is enough to make a court say that it is not individually negotiated and is therefore treated differently (AGB in German).
A seemingly endless text wall with non-negotiabile terms that is considered agreed to by a click on "I have read this and agree to it" might only be binding to very limited extent, if at all.
In my contract I mentioned a part was considered invalid because it was an issue that cannot be agreed to in an AGB, and the part was considered to be sufficiently AGB-like.
To give another scenario, someone offers me a proprietary software. I don't know the terms and condition but I know that I need to pay for it. I then pay and receive the software. Upon starting it, it presents me with terms and conditions I need to agree to. In this scenario, the terms and conditions in the software are entirely void because the contract was established when the software was exchanged for money and the terms were not agreed to at that point. Only what is agreed to when the contract was established counts. If the software doesn't work for the intended purpose, I am free to modify it such that it does.
[1] https://www.fidusinfosec.com/fslabs-flight-simulation-labs-d...
[2] https://en.wikipedia.org/wiki/Data_Protection_Directive#Prin...
Parts in a contract can be void even if agreed by both sides.
In that scenario, the user has committed copyright infringement (i.e. it can/should result in a civil claim and a fine). If what is claimed has happened (the company used the passwords retrieved from pirates' computers to access private websites of those pirates), then the company employees who took and used their passwords have committed a crime (i.e. it can/should result in arrests and jail time). Many of the things that police can and will do in an investigation are crimes if you do try to do it yourself. The fact that your target seems to have committed a crime doesn't justify crimes against them; and they are innocent until proven guilty.
Those acts aren't comparable; what the company seems to have done is on a much higher level of illegality than software copyright infringement.
I mean, the apology seems legit and it's not that likely that anyone will press charges, but it still is a quite stupid risk that they've taken. In many cases "hack-back" may seem a practical alternative, but it's not, because it tends to be absolutely illegal (well, perhaps not if you're in NSA or something). Hopefully this case will be sufficient warning for others.
A tiny dedicated computer like Tomu[0] that fits into your computer, that provides authentication (and similar cryptographic functionality), with inpedentent input (touch) to receive manual ACKs and output (led) to provide feedback, with no other functionality, is a cheap, reasonably safe, and convenient solution. Maybe unlock it on boot (and after timeout) with a password/PIN for good measure.
Currently I'm using Chrome backed by KWallet backed by PGP key on a YubiKey 4. Upon launching Chrome I have to authenticate with/touch the Yubikey to unlock my session, which is spiffy, but after that seemingly random pages (even in an incognito window) will prompt Chrome to unlock my keychain. The Yubikey will flash, indicating something wants access to it, but I have no indication of what that something is. If I ignore the flashing, eventually a KWallet window pops up complaining about being unable to use the GPG key.
Chrome shouldn't access your credentials without telling you what it's used for. Chrome shouldn't expose cryptographic identities in incognito mode. The Yubikey's output is vague.
What can we learn from that?
Chrome has shortcomings in this domain. Just one monochrome LED is maybe not enough output to give reasonable feedback.
My online banking security system is called chipTAN and uses a small, monochrome, low-res display to give essential information for what is being processed which I need to acknowledge. That works well, but is also a single-purpose solution.
For identification on the internet, a solution based on GPG seems reasonable. Imagine a small display that shows the receiver you are identifiying to, the identity you are using, and for how long the identification is valid, and then you can acknowledge that.
And even then, malware can still just steal your cookies.
They should have at least sought legal advice before trying to do what they did, but failing that at least sought it before posting this message.
That being said, I'd be very interested to learn more about why it would be illegal. Could you elaborate/source?
The publisher pinky-swears that they only steal passwords from bad people. That is not an interesting argument to me.
unfortunately we could not be able to enter the registration-only web sites he was using to provide this information to other pirates.
We found ... that the particular cracker had used Chrome to contact our servers so we decided to capture his information directly
.. to dump that cracker's information needed for us to gain access to those illicit web sites
this method worked, in fact, and we were able to receive this information
This all followed by screenshots from the "registration-only web sites" they could not previously reach.Also, at least one of the initial reddit reports which set off this whole thing was due to A/V software detecting an executable file included in the installer (which was dropped but not executed on all user installs) as "Chrome Password Dump" malware.
Edit: The earliest responses about this from FSLabs seem to confirm that they were running the password dumps on anyone who was using known pirated serials; it looks safe to say that the linked post is overstating how targeted their actions actually were.
This method has already successfully provided information that we're going to use in our ongoing legal battles against such criminals.
If they truly believe that they have any hope of using any information thus gathered to aid them in their 'legal battles' against crackers and pirates, this is one deeply confused company.In terms of jurisdiction, the company seems to be incorporated out of Delaware (though I may have mis-searched there), but employs EU nationals residing in the EU. At least one of them seems to be in England, and thus subject to at least both the Computer Misuse Act of 1990 and the Data Protection Act of 1998, which in turn ties in more generally to the 1995 EU Data Protection Directive (which has further been implemented in other countries). Multiple levels of their actions would definitely fall under the CMA and if they actually gathered anything the DPA would kick in also. All of the actions they are known to have performed and may have performed are illegal in most first world jurisdictions. You cannot install malware even if it's not used. It's extra offense to use it, worse to take any data off, to store that data, and further to use it in anyway. Vigilantism is not generally considered at all acceptable by developed governments worldwide.
In the USA, precedent for this sort of thing appears to exist already in the form of major examples like the 2005 Sony BMG rootkit situation. Sony's malware prompted actions at the state and federal levels as well as multiple class action lawsuits. The FTC brought charges under Section 5a of the Federal Trade Commission Act and Sony was forced to settle. The FTC chair at the time stated that "Installations of secret software that create security risks are intrusive and unlawful." [2]
Really, this sort of thing is just crazy dumb to even attempt in this day in age, it's genuinely surprising that developers could still think that it wouldn't open them up to massive potential trouble particularly in the EU. That's not to say anyone will necessarily go after them, as always that's a matter of discretion at the governmental level and at the civil level whether anyone cares to devote the resources to it, but there is plenty of cause to at least make a go of it and it's not clear that they recognize that. Legitimate developers just don't install malware on peoples' computers, period. That they may be bad people isn't any defense at all. Furthermore, bugs of course can happen. Even if it's not intended to be activated, it may do so, or may open the way to later malicious use by a 3rd party. The original developer who was responsible for it being there can be expected to be liable.
Surreptitious actions in general should be a real red flag: if you have to hide it from your users and it affects anything but your own software, think twice. Then think three or four more times after that too. EULAs (or any contract in general) cannot overrule higher level non-exempted law requirements and will not provide protection against civil or criminal enforcement.
-----
1: https://www.reddit.com/r/flightsim/comments/7yh4zu/fslabs_a3...
2: https://web.archive.org/web/20070929111043/https://www.consu...
https://www.fidusinfosec.com/fslabs-flight-simulation-labs-d...
(Long-retired cracker, no longer active in the scene but still fights from time to time. ;-)
As I read it, they had a function to grab various bits of data from a specific machine that was linked to a specific cracker. Did it misfire and started to pilfer data from other unrelated machines?
Edit - for the record, the original post title was somehing like "Flightsimlabs attempts to explain their password-stealing DRM malware".
I'm shocked that the company admitted to doing this.
That's all it was. They are in a lot of trouble, potentially, and it will be interesting to see how this plays out. I am hoping that charges will be pressed, because this is not the first time developers have "booby trapped" pirated software, but it could be the last if justice is served.
I still find it interesting how many people don’t realize that generosity could be a valuable part of your product. That growing the industry as a whole may be more important than getting back at people who weren’t going to buy your product anyhow.
It would be ironic if a bunch of pirates sued a software developer and won.
Just to be clear, nobody should let it go. Everyone needs to be taught right from wrong in their lives. Publishing malware is always wrong.
I don't think so. I'd guess a lawyer would've told them to get rid of the feature, delete all collected passwords, never use any of it in the future and most importantly, don't admit to anything. It's rare that a lawyer advises you to admit to a crime. Before they admitted to it no one even knew if they ever used the collected data.
Aren’t there laws that basically invalidate evidence gathered by illegal means?
They do mention that they kept seeing repeated personal information being used on registration, but also that the cracked version was changed to use a different activation server. Confusing.
*or even impossible
I get that a lot of time and effort goes into developing a product and it's really frustrating when you find out that your product is being pirated. I can't imagine if I'd happened upon a whole community sprung up around pirating my product; they had to be incredibly angry and this likely led to this terrible idea. And no matter how often you repeat to yourself that "piracy does not represent lost sales", when you've poured your time into something -- time that you hope will make you a nice living, time that you took away from your family or other enjoyable pursuits -- you tend to get really angry when you find out there are people that think it's perfectly OK for you to work for free.
I like to repeat the mantra that "piracy does not equate to lost sales" and tell myself that those wouldn't be paying customers anyway, or they're not my real target audience, or that it speaks to the popularity of the product if someone went to the trouble to crack it. And I'm a believer that effort spent on DRM is wasted (especially efforts like this). It's not entirely, true, of course. I always think back to the story I read a few years ago about the TCP/IP stack that nearly every DOS PC used -- a piece of shareware that, at the time, was probably the most popular piece of shareware in existence. I'm sure I, like many, didn't even think to pay for it and operated under the assumption that large corporations were probably using it and the developer was probably using $20 as kindling by now when in reality I think he netted somewhere in the thousands of dollars for his efforts.
At the same time,... well... this.
This is exactly what happens when you focus on piracy so hard. Developer time is a finite resource and this company wasted that time developing a piece of DRM that is indistinguishable from malware. It succeeded in not stopping the pirates, not catching the pirates, angering their paying customers, easily exposing them to civil legal issues and possibly exposing them to criminal legal issues. That little bit of wasted developer effort could very well end the company that made this product in a way that piracy probably never would have. Assuming their customers like the product and would like it to continue to exist, this company basically did everything in their power to not serve their customers.
To be clear, I'm not completely against purchase verification in software products. If it's light-weight, and doesn't get in my way as a customer, it's fine (i.e. provide the ID/password used when it was purchased with a fallback to an offline serial number ... asked one time and never again). I get it. A small road block is enough to keep my mom or dad from grabbing a copy that a friend attached to their e-mail. Heck, in the case of my mom or dad, they may not even realize that it's not a free product if it doesn't ask for some form of verification. I don't mind how Steam works or how the variety of stores handle these sorts of things. If your DRM effort goes any beyond this, it's wasted effort. You're not going to stop a determined pirate even (especially?) if the product your selling is an anti-piracy product. Just don't. Don't waste the effort. It's never worth it.
Even as I write this I'm still amazed. I get frustrated when I upgrade my CPU/memory/GPU and Office won't run without some extra steps. I can't imagine if step #2, after falsely identifying me as a pirate, was "send a bunch of personal data to the authors"[1] so they can turn me in to the authorities. Pro-DRM folks like to equate piracy with theft, so I'll make an equally poor analogy and say that'd be like if I purchased bed sheets at Wal-Mart, and the processor in those sheets[2] decided I stole them, so they started sending the GPS location of my house along with pictures of my bedroom to corporate so that they could turn that information over to the police.
[0] Sure wouldn't be difficult to compare this with any other piece of malware in its behavior, but IANAL.
[1] And yes, I realize that they've stated that they're looking for specific information from a specific pirate that they consider to be the source of the problem, but including that payload in the installer makes me question the truth of this statement. I don't have any reason to dis-believe them, especially considering they've basically written up a post admitting to a bunch of activity that may very well be illegal in nature, but having no way to verify that they are telling the truth, or that there isn't a circumstance that could false-positive flag someone who isn't that very specific case, I will err on the side of assuming the worst in this case.
[2] I laughed when I wrote that, then I thought ... there's probably already sheets with processors in them. If there isn't, there will be. Shortly followed by the first case of DDoS by IoT bed-sheets.