They should have at least sought legal advice before trying to do what they did, but failing that at least sought it before posting this message.
They should have at least sought legal advice before trying to do what they did, but failing that at least sought it before posting this message.
That being said, I'd be very interested to learn more about why it would be illegal. Could you elaborate/source?
The publisher pinky-swears that they only steal passwords from bad people. That is not an interesting argument to me.
unfortunately we could not be able to enter the registration-only web sites he was using to provide this information to other pirates.
We found ... that the particular cracker had used Chrome to contact our servers so we decided to capture his information directly
.. to dump that cracker's information needed for us to gain access to those illicit web sites
this method worked, in fact, and we were able to receive this information
This all followed by screenshots from the "registration-only web sites" they could not previously reach.Also, at least one of the initial reddit reports which set off this whole thing was due to A/V software detecting an executable file included in the installer (which was dropped but not executed on all user installs) as "Chrome Password Dump" malware.
Edit: The earliest responses about this from FSLabs seem to confirm that they were running the password dumps on anyone who was using known pirated serials; it looks safe to say that the linked post is overstating how targeted their actions actually were.
This method has already successfully provided information that we're going to use in our ongoing legal battles against such criminals.
If they truly believe that they have any hope of using any information thus gathered to aid them in their 'legal battles' against crackers and pirates, this is one deeply confused company.In terms of jurisdiction, the company seems to be incorporated out of Delaware (though I may have mis-searched there), but employs EU nationals residing in the EU. At least one of them seems to be in England, and thus subject to at least both the Computer Misuse Act of 1990 and the Data Protection Act of 1998, which in turn ties in more generally to the 1995 EU Data Protection Directive (which has further been implemented in other countries). Multiple levels of their actions would definitely fall under the CMA and if they actually gathered anything the DPA would kick in also. All of the actions they are known to have performed and may have performed are illegal in most first world jurisdictions. You cannot install malware even if it's not used. It's extra offense to use it, worse to take any data off, to store that data, and further to use it in anyway. Vigilantism is not generally considered at all acceptable by developed governments worldwide.
In the USA, precedent for this sort of thing appears to exist already in the form of major examples like the 2005 Sony BMG rootkit situation. Sony's malware prompted actions at the state and federal levels as well as multiple class action lawsuits. The FTC brought charges under Section 5a of the Federal Trade Commission Act and Sony was forced to settle. The FTC chair at the time stated that "Installations of secret software that create security risks are intrusive and unlawful." [2]
Really, this sort of thing is just crazy dumb to even attempt in this day in age, it's genuinely surprising that developers could still think that it wouldn't open them up to massive potential trouble particularly in the EU. That's not to say anyone will necessarily go after them, as always that's a matter of discretion at the governmental level and at the civil level whether anyone cares to devote the resources to it, but there is plenty of cause to at least make a go of it and it's not clear that they recognize that. Legitimate developers just don't install malware on peoples' computers, period. That they may be bad people isn't any defense at all. Furthermore, bugs of course can happen. Even if it's not intended to be activated, it may do so, or may open the way to later malicious use by a 3rd party. The original developer who was responsible for it being there can be expected to be liable.
Surreptitious actions in general should be a real red flag: if you have to hide it from your users and it affects anything but your own software, think twice. Then think three or four more times after that too. EULAs (or any contract in general) cannot overrule higher level non-exempted law requirements and will not provide protection against civil or criminal enforcement.
-----
1: https://www.reddit.com/r/flightsim/comments/7yh4zu/fslabs_a3...
2: https://web.archive.org/web/20070929111043/https://www.consu...