Flight Sim Company Embeds Malware to Steal Pirates’ Passwords
torrentfreak.com
torrentfreak.com
We installed spyware on your PC, but trust us, we didn't use it, we only used it on the people we didn't like...
>“This method has already successfully provided information that we’re going to use in our ongoing legal battles against such criminals,” Kalamaras revealed.
We're going to introduce documents into a legal process that were obtained through illegal means and hope we don't get counter-sued.
It looks like once again, a gaming company has decided to stop working on making games, and start working on a convoluted game of cat and mouse with unemployed anonymous nerds. What could go wrong...
And, yes, your AV is showing a false positive ;) [0]
Also, piracy doesn't seem to have a huge impact (if any) on sales[1]
[0] https://www.fidusinfosec.com/wp-content/uploads/2018/02/Oct-... , from https://www.fidusinfosec.com/fslabs-flight-simulation-labs-d...
[1] https://juliareda.eu/2017/09/secret-copyright-infringement-s... https://juliareda.eu/wp-content/uploads/2017/09/displacement... see page 79 for games
That being said, what FSLabs did is of course inexcusable.
I tend to agree with you though, if you make a game that requires incredible attention to detail, hugely time intensive modelling work, and know that the target market is a tiny niche then maybe the product is just not viable.
None of this excuses them, but I do wonder about how the piracy data actually pans out for small, expensive shops like this.
Nonetheless, several plugin companies do seem to be able to nicely balance the ability to protect their software, while avoiding arduous copy protection methods. The method I think seems to work best is a combination "honey pot + time bomb" type method, where you provide an "easy" method for the pirates to "crack" and get on the usual sites, while also including a more difficult to reverse engineer that activates at some point later. (This kind of nudges those who kind of use piracy to "try and buy" but sometimes, er, need a bit of motivation to actually purchase the product. Even people who can afford the software and make a pretty decent living with the product have been caught with pirated plugins in interviews (https://torrentfreak.com/avicii-and-other-djs-produce-hits-u...).
You definitely don't need to include malware to protect your product.
The problem is nobody really knows that because it's nearly impossible to do a controlled experiment for this.
What happens in practice is that a company's first product is unprofitable. So they go back and make significant improvements, spend five times as much on marketing, and add anti-piracy code. Then the new version is more profitable.
The people who want the solution to have been the anti-piracy code credit it with the improvement, but there is no way to know if it was that or the product improvements, or the marketing, or more favorable market conditions at the time of the second launch, or the fact that the same marketing effort now produces 50% more customers because there is now an existing user base (including the pirates) who are easier to convert because they're familiar with the previous version, etc.
To actually know the answer you would need a statistically valid sample of product launches where the determination of whether anti-piracy measures are taken is made at random. But as far as I'm aware no one has ever attempted this, and the choice to use anti-piracy measures has to be randomized or you could trivially be measuring the wrong thing, e.g. larger products with more resources are both more successful and more often include anti-piracy measures but the causation is reversed.
So nobody really knows the answer and it's all just wild speculation.
The impression I get is that coding some degree of protection is worth it, as long as the protection does not impact the user experience that much (and judging from what I see, this is quite possible). There's no excuse however for emulating the warez guys and bundling malware with your software... there's smarter ways to protect products.
That still doesn't really tell you the answer though. The hypothesis is that pirates can be converted to users, but that doesn't necessarily happen immediately.
Suppose the product hits the piracy sites and 100,000 people download it. 5000 of them would have bought it, so you "lost" 5000 sales right away and you have your dip. But then over the course of the next year or two 7000 of those pirates realize they like the product and go on to buy it.
That's definitely a thing that happens, the question is what the real numbers are and whether they balance.
> I also know that there's one plugin developer (u-He) who has posted that the "time bomb" method he uses does drive sales the instant those "time bombs" go off.
Same problem here. Obviously you're going to get an uptick when the timer expires. But suppose you timebomb 100,000 people and as a result you immediately get 4000 sales, but then 96,000 people stop using your software. If 7000 of the 100,000 would eventually have paid you anyway, now you've just kicked 3000 of them out.
I don't think the number is zero, as seen in this thread. But overall I don't think humans are that altruistic. :) This is probably particularly true for user-oriented niche software (like the software in question, premium flight sim DLC). Some software in the past (eg Adobe Photoshop) that was marketed primarily for businesses possibly benefited a little from consumers pirating it, but again, that "benefit" is hard to quantify as well.
The reason I like the "time bomb" approach though is that I think it gives a bit of a "push" to anyone who is actually using your product extensively. If they aren't using your product enough to care to pay for it, it's probably not a big deal if they stop using your software. If the "time bomb" is at a reasonable period, I have serious doubts that they'd suddenly decide n months later (with no time bomb) that it's all of a sudden worth it to pay for software the have for "free".
I don't think niche products unfortunately can do what mass market products are doing these days... which is switching business models towards ones where piracy can be controlled a bit more or is less of a big deal. (Freemium / DLC, cloud-based, subscription-based, etc.) In fact the only alternative model I see for niche is the Kickstarter one where the consumers themselves front the initial business costs (which can work out for consumers sometimes, and not work out other times).
I hear this argument a lot but can't see how it possibly be correct. Sure, not everyone who pirates would buy instead but at least some people would (it probably is a small percentage, but it is not zero).
One can imagine that the effect of those few is amplified for titles with high costs per unit.
There's also the "photoshop effect", where piracy helps ensure that the application remains the de-facto standard. Admittedly this is less applicable for games but it might help with 3rd party controller support, modding community etc...
I also believe that in the age of Steam specials, refunds, etc, people who pirate your game are not "lost sales". They are usually doing it because their appetite for games outstrips their budget, and they were highly unlikely to pay for it in the first place. But there is a significant chance may convert to a paying customer, or at least market the game by word of mouth.
I also regularly NOT buy games (but nowadays also don’t pirate them, in the past I might have) if they hnave intrusive DRM
If we've already start speculating, such part might be offset by people like me, who tend to buy games only they like. I often pirated new game just to see if it's worth buying. And I've recently bought most of games on GOG I had played as pirate versions when I was a poor teenager, even though I barely play computer games anymore.
I didn’t read it, but apparently that EU funded study found that piracy doesn’t harm sales. At least, that’s what the news reporting said about it.
Consider that for lack of a demo, or other scenario, people who pirate the game but end up purchasing it later. Sure, not all pirates would buy the game they've pirated, but at least some people would (it probably is a small percentage, but it is not zero).
>One can imagine that the effect of those few is amplified for titles with high costs per unit.
I would argue mainstream titles would make up that difference through volume of pirated copies though.
Piracy isn't a non-issue, but it's just not a dire threat either. Decades of video game piracy has demonstrated that.
Averages don't mean that the small development house with the high cost per unit product doesn't go out of business when a small percentage of those who would have bought their product pirate it instead.
I've seen numerous people who could absolutely afford games, stealing them. Hacked Xbox's filled with every game imaginable. These people would have bought some of these if they couldn't steal them, without a doubt. Would they have just gave up video games? No way. So, it absolutely displaces sales.
Before CD-RW lots of games were available on floppy disk, which were simple to copy. And even without a CD-RW you could copy the data off the CD. Perhaps you don't know about no-CD cracks? They were everywhere. There were plenty of ways to pirate CD based games without a CD-RW. It might seem difficult or complicated compared to 2018, but only if you didn't live through those times. At the time that's the way it was, and it was relatively easy.
>Everyone had their own copy of an album. A select few would make cassette tape copies, but you were never satisfied with that.
Forgive me, I never say this, but it's appropriate in this case: LOL
-- Do you have any evidence, data, metrics of any kind to support that?
The study only looks out the count of games and not the dollar amount spent. A non-pirate who buys a $60 game and all the DLC and microtransactions is counted the same as a pirate who buys one $0.99 steam sale game. It does say that sales for blockbuster movies are heavily impacted by piracy.
What that means is that those games can have <$15 from me, or nothing. $60 was never on the table. And the games I buy at launch others won't bother with at full price.
The only difference between me and the pirate in your example is that the pirate hypothetically would have bought "some" games at full price if piracy wasn't available, like I do. But that's not an assumption you can naturally make. Some people just don't care about playing games when they're new.
I'm just as inclined to assume that a pirate only buying bargain games would have the same legal consumption without piracy.
For my part, it was not a lack of money, but rather ease of getting the game (when I was directly given an ISO) or because I don't want to wait for a sale, but the game still seems too expensive. I ended up buying two of them (KotOR on a sale and transistor full-price). But now I have a big enough library and I have less time to play, so it's not as appealing as before (and I also have more to lose on my computer).
At least they were smart enough to make this AV-proof. One of my favorite lines is: "please disable your AV while XYZ application is installed". I do understand that some applications require access to files/registry keys/etc, but this means they've done a crappy work on building the thing, and they cut corners by asking us to compromise our security for their lack of due process. Random example [1].
[1]: https://www.taxslayerpro.com/kb/676/temporarily-disabling-a-...
which makes it available to any other third party that breaks in, looks for it and uses it.
One for which you can earn hard time. Even if you don't use the spyware. I wouldn't dare work for a company that did this.
Copyright violation is merely a civil matter, cracking a serial number generator is not even copyright violation. Breaking DRM is still illegal, but that's all. I'm not even sure we've established that's it's illegal to distribute information on how to crack DRM. Certainly, not in all jurisdictions.
It's not illegal in all jurisdictions and even then there are cases that allow you to do it.
And distribution information on how to break DRM is even less likely to be illegal.
It's the same reason you don't try to brick someone's computer even if you can prove with certainty that they were, say, cheating and griefing on your game's multiplayer. None of that matters, it would still be a crime.
In which country are these guys based?
The only mistake they're admitting to is that their malware ran on all installations, when they meant for it to only run on pirates computers. Or that they got caught doing it.
There's no recognition that collecting this data from [innocent until proven guilty] "pirates" was wrong. There's no confession of what they did with the data they collected, but I can only imagine it amounts to a serious infringement of global Computer Misuse Acts.
Just because you think somebody didn't pay for your software doesn't give you carte blanche to anything on their computer. Again, that is almost certainly a criminal offence.
[0] https://forums.flightsimlabs.com/index.php?/announcement/11-...
I've wondered why copyright holders don't do this more in general. I've seen a few cases where a downloaded movie for example just gets borked towards the end ... presumed it was deliberate and surely some form of a deterrent!
Also to be fair, even if the cracker wasn’t paranoid I expect doing it in a VM is much more convenient since you can trivially reset your environment.
They got the logins for some other websites they did not had access to before. Logged in and found out how they could generate the keys.
At least that was my understanding.
It did not take long for me to realize how crazy I was being over this. My time was better spent improving the software and focusing on customers who would pay.
Disclaimer: I don't know the exact implementation, but this stinks from every angle you approach this.
[1] https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act
To make matters worse, the additional statement at the bottom of the article they outright admit they used the tool and it wasn't a mistake:
>We found through the IP addresses tracked that the particular cracker had used Chrome to contact our servers so we decided to capture his information directly
Hopefully they can. We need to make it clear that 'just following orders' is no excuse for criminal behaviour.
The second, leading to the first, which then naturally leds to the third. The AMA, APA, and many others operate this way. Very effectively. Journals need to buy in, schools do, and eventually employers and licensing bodies.
This is not really a new concept, just new for the increasingly unacceptable Wild West or software. Software is not a frontier anymore, it’s the biggest thing going, in our medical devices, cars, banks, etc. it is time to grow up.
But they've really dug themselves a hole though. Reading the article indicates this wasn't just a 1-off decision, but a multi-level decision made by several people over a long time frame. That all of this was premeditated and well thought out / given enough consideration to go ahead and install a backdoor on all their PCs.
In any case, this is also why I don't save any passwords via chrome. Its not secure at all for storing passwords, so long as you have access to the localdb, you have a vulnerability.
The CEO’s LinkedIn Page says he is Greek. “Flight Sim Labs” produces no hits in the Athenian corporate registry [2]. I did find a Flight Sim Limited in the U.K., but registered to a different person [3]. This British Flight Sim Ltd was formed about a month ago.
TL; DR Consider whether you, or customers like you, have legal recourse before executing someone’s blob.
[1] https://forums.flightsimlabs.com/index.php?/announcement/11-...
[2] http://www.acci.gr/acci/shared/index.jsp
[3] https://beta.companieshouse.gov.uk/company/11142081/officers
The company appears to be a shell registered in Cyprus [5]. The address on an older SSL certificate [6] matches the one in the registry.
[4] http://www.flightsimlabs.com/index.php/privacy-policy/
[5] https://efiling.drcor.mcit.gov.cy/DrcorPublic/SearchForm.asp... (search for "flight", 2nd page. Can't link to it directly, apparently)
[6] http://www.herdprotect.com/signer-flight-sim-labs-ltd-020d17... (link fixed, sorry)
But the worst that can happen for them short term is that PayPal (and credit card vendors if they use them) block their account if they get too many charge backs as a result of that.
What makes you sure of this? Corporations can be criminally prosecuted, at least in the United States and the United Kingdom.
The issue is that IP/computer != single person. If they dump and steal the Chrome credentials of the computers using pirated serials, they are most probably stealing the credentials of law-abiding partners, parents, siblings, children, etc. who also use that computer. Which is, of course, illegal.
In fact, probably more serious offence than copyright infringement, if these credentials are related to protected information such as financials, healthcare, etc.
Also note that receiving a pirated copy is not a crime in most jurisdictions I know, just a civil law injury. Stealing their passwords, however, is a crime.
I'm not sure that's even illegal to distribute, since there is no copyright violation. There are some places that forbid breaking DRM, but telling other people how to break DRM is even weaker.
This brings up a thought I've had lately: The endgame of IPv6 -let's say, 100% adoption, and the retirement of IPv4- will be IPv6=single device, no? I would think that ends (in however many years it takes to get there) what little anonymity IPv4 currently provides.
(A couple of caveats. One is that attackers can still correlate different connections within a short period of time, between temporary address rotations. Another is that temporary address support is broken on some Windows versions, so you may be leaking your MAC address all over the ace without knowing it.)
[1] https://scholar.google.com/scholar_case?case=107551340662323...
[2] https://scholar.google.com/scholar_case?case=641943334909742...
OK, so what were they going to do with the evil
cracker's passwords.... steal from him?
Presumably get access to invitation-only torrent sites? To distribute more malware / gather IP addresses for prosecution?When sifting through the files i found a method called 'fillHDD' which would recursively create files to fill your HD. I imagine this method was called when people were caught cheating.
>“[T]here are no tools used to reveal any sensitive information of any customer who has legitimately purchased our products. We all realize that you put a lot of trust in our products and this would be contrary to what we believe.
Ok, so I guess there's no malware in the official downloads then.
>“Test.exe is part of the DRM and is only targeted against specific pirate copies of copyrighted software obtained illegally. That program is only extracted temporarily and is never under any circumstances used in legitimate copies of the product,”
Well, nevermind then.
>“This method has already successfully provided information that we’re going to use in our ongoing legal battles against such criminals,”
That's easily the stupidest thing I've read this week. Are they so oblivious to how legal systems work that it didn't even occur to them to consult a lawyer before attempting to distribute malware and steal people's information?
This is a desktop program, if they wanted to perform something bad on a condition, why not just code it in their own program? The chrome browser history and password db could just be decrypted and uploaded, for example. It's exactly the same thing and just as bad, but at least they didn't install third party malware that shows up in AV, at their paying customers. It's also MUCH easier to deny since at the legitimate users there is neither any suspicious signature, nor any suspicious network activity.
Where is the company, Flight Sim Labs Ltd., registered? It's difficult to find an address. They also removed info from their About page. From their posts it looks like they might be in the Netherlands.
Anyway, I'll contact the FBI and local authorities about this if I can find out what jurisdiction they're in and I hope others do the same. This crap is absolutely unacceptable.
There's a history of extradition to USA from UK for relatively minor unauthorised access; this seems pretty major in comparison.
So companies aren't getting anything from anti-piracy measures. Rather, they are wasting time and money on implementing these measures.
If I were to make a software, I'd keep it DRM free. Maybe I'll give occassional discounts to attract people who won't pay otherwise, but that's it.
But business pressures aside, I do avoid DRM encumbered products and I direct my clients to as well in most cases. You ARE hurting your bottom line with DRM.
We probably should run our games in containers. Anyone got an idea about how to do this? Isolate Steam/Origin/Games into their own little sandbox
As far as isolating software, there are a few possibilities, but sandboxing doen't always work. VMs are the way to go for now, but they're not foolproof either, and they come with a myriad of downsides.
Plus I would imagine that most gaming will require entering passwords at some point, whether that's into Steam, Origin, signing into humblebundle.com/etc.
>“This .exe file is from http://securityxploded.com and is touted as a ‘Chrome Password Dump’ tool,
Maybe that's another reason to use Firefox?
Even if my PS4 was online it still only has gaming related data on it.
Running apps in a sandbox should be the default behaviour for any OS by now. No app should have the privileges to access any file by default, except for files that are either created or owned by that app & user.
Sharing files between apps should be done as an opt-in basis, with explicit permission by the user, either file-by-file or per group of files.
"Trivial file conversion" tool can be implemented the same. The app tells the OS "hey, I want some files to convert" and the OS either grants access to a set of files/folders, or queries the user which file(s) (s)he wants to provide. IE the "open file" modal is the only window to accessing files. You can think of it like the HTML5 File upload & Drag/drop APIs, but a bit extended & more user-friendly.
Obviously smart engineers can think this through for longer than 3 minutes like I just did, and come up with better/user friendlier/safer solutions. But it breaks all backwards compatibility in almost any desktop OS
Only my backup tool gets root and can access other application's data - random trash games I download or even if I were to install them from pirated sources are unable to do that.
It's a vast improvement at the very least, even if not a perfect one.
There should be some very good definition for "App". I expect xz(1) to to be able to read any file I give to it (% xz myfile).
I would however expect chromium to only modify stuff in ~/.config/chromium ~/Downloads and be able to read only the libs it needs in /lib. But what about if I need to render an HTML page that's in ~/git/my.blog/index.html?
OpenBSD did some great things with pledge(2)[0] but truly fine-grained control like SELinux, AppArmor have met only limited success because of how complex they are to setup.
[0] http://man.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man2/...
Although I'm not sure what people are going to do. Run pirated copies with the malware removed?
(Which reminds me: when I ran a jailbroken iPhone years ago I had a fix for a PDF exploit much sooner than people having to wait for Apple to fix it, making running a jailbroken phone more secure (at that time).)
In my case, the gaming VM is shared by all windows games, but with some extra effort it is possible to isolate each game in a separate VM. (What comes to mind is using qemu qcow2 format for the base windows image, plus a snapshot file for each game installation)
Yes, we do it already. We pack Windows games into WINE, WINE into Flatpak, distribute it on torrents:
There you go, games in a container supported by piracy, with privacy out-of-box included: [DTH crawler website with magnets, might be blocked in your country] -> https://skytorrents.unblockall.org/search/all/ed/1/?l=en-us&...
Why people do have to do it? Some companies install spyware, other companies install a lot of 3rd party crap, DRMs that slow down games for paying users, don't support Linux platform despite promises...
Pirates will always be one step ahead, you can make a game with good user/buyer experience like CD-Project or great customer support - Darkwood [1] and make it win-win for literally everyone, or lose at some point.
https://www.gamingonlinux.com/articles/the-developers-of-dar...
ATM, I was focusing on e.g. fez from HumbleBundle through the AUR [0] and factorio [1]
You can either run Steam sandboxed which in turn will sandbox all the games it runs, or you have to do a bit of finagling if you want to individually sandbox your games.
It is mostly trial and error fiddling with the level on f restrictions you want while not breaking apps. In my case, i have a template profile of permissions, most of which are for restricting access to personal/confidential files/folders like Documents, Browser profiles, etc. Instead of blocking access outright though , i usually make the files/folders write-only..
So, for example the other day i wanted to download a 60fps video from youtube, and the only practical option was to use an adware ridden java downloader.. So i just downloaded it created a new sandbox (based on the template sandbox) for the app, installed it (i recall i had some minor kinks in the install process but managed to get it to work in the end). After i was done with it , i deleted the sandbox and i was off on my way without having to worry if the application had left some unsavoury bits on my system..
edit: I might add that a key advantage of Sandboxie as opposed to other solutions like VMs is that afaik, Sandboxie mostly works by intercepting API calls to the underlying OS.. This maybe more leaky than a VM, but it is also much more lightweight, and as a consequence it has given me good performance for stuff like games, etc.
What's to prove that sandboxie is not worse?.. [/tinfoil]
Seriously though, has it been audited?
"So for example the other day i wanted to download a 60fps video from youtube, and the only practical option was to use and adware ridden java downloader.. So i just downloaded it, created a new sandbox (based on the template sandbox) for the app, installed it (i recall i had some minor kinks in the install process but managed to get it to work in the end); after i was done with it , i deleted the sandbox, and i was off on my way without having to worry if the application had left some unsavoury bits on my system.."
edit: It seems Sandboxie was acquired by Sophos, so now you have to decide whether you trust Sophos or not.
Most law enforcement agencies have e-crimes, digital crimes, Internet crimes, et cetera divisions.
Let me say loudly that I will never download any software from flightsimlabs.com anymore and that any copy of their software I might have had has been nuked to hell.
The second you admit to adding a keylogger to your software is the second I lose all trust in you.
I pretty much left the flight sim community because it's so toxic and full of these weird companies
When someone is stealing from me, or causing harm to my business and my clients using my products, damaging my reputation, then I go to the Police, I don't wait for them to read an article on torrentfreak.com or the comments section in HN (which I think any security angency worth its salt must have an eye in here too).
I'm going to help them out!!!!!
Hey FSLabs people!!!
FBI website is https://www.fbi.gov/contact-us/ (these guys know their e-crime stuffs, they can help you out!)
Lefteris Kalamaras is definitely Greek, so.. http://police.gr/ (I hear they got a decent e-crime fighting unit over there)
(don't say I never did anything for you FSLabs, and NO I don't want a free copy of your game on my PC)
Some user downloaded an illegal copy that had malware and is trying to blame the company, when that malware doesn’t appear for legitimate copies. Don’t want malware? Don’t steal software hat could have been tampered with.