Without signed executables, and if someone is willing to spend the time to look for the exact spots in a disassembler in non-verified executables, they can either negate the condition or skip over the license check. This assumes it only happens in 1 location. Every upgrade of that particular file would likely need to be re-patched each time.
The least work semi-automated way to find it is through tracing a initial failure run and then binary search inverting logic of branch instructions.
That can only happen if Treacherous Computing wins. If you actually have control over the things you own, you'd be able to tell your device to lie about the first stage's signature.
It has already happened.
Until they make it so we need corporation or government signatures to run software on "our" machines. Until they finally destroy our computing freedom.
This has been the case for over a decade on smartphones, and corporations like Microsoft are currently hard at work bringing it to traditional computers.
Only now is hardware remote attestation putting an end to all that.
> Only now is hardware remote attestation putting an end to all that.
And then hackers will graduate to side-channel attacks... it's a game of cat and mouse. The best bet, IMHO, is to make the cost of cracking exceed the value of what's being cracked.
Hardware remote attestation means your local physical device is as accessible as a distant server. Dumping RAM does not work, tapping the bus does not work, writing your own firmware does not work. It is exactly like an ISP performing a machine-in-the-middle attack on a TLS connection; impossible unless without some way of obtaining the certificate private key.
Probably, but I'm not the type who likes to rule anything out completely.
The fellow working on the project with me had a lot of specialized domain experience in such things, and told me the actual cracking teams would never put malware in their own cracks, because it would ruin their reputation in the scene.
I'm sure some cracks have had malware added after release by other people, of course, but I wonder how much of it was fearmongering by software companies.
The higher risk thing tends to be downloading cracks from torrents or usenet where there's 3rd parties between you and a scene group.
The problem is, the scene usually isn't about making piracy mainstream. Many release groups only released their cracks within closed circles to show off that they managed to crack a game. The cracks that made it out to the web often came through leaks, hosted on a shady site or distributed through torrents. For an outsider, these cracked files weren't all that trustworthy.
That, together with antivirus software being made completely unreliable because of false positives, made it very hard to trust the .exes/.dlls that I used. Piracy is still a major infection vector today, and I imagine it will always be because of all the fake cracks on SEO hacked websites and shady operations necessary for the original crackers to distribute a crack without copyright lawyers sending you very scary letters.
It’s not perfect but it does make a significant difference.
Most local software cracking doesn't involve fixing the license key check or the crypto code at all. You just remove the conditional jump that exits the program if the check fails.
IMO best way to implement license check is: using asymmetric crypto (so it's impossible to write keygen) and online activation (so it's impossible to share key).
I believe from my experiences downloading CLASS and MYTH game rips from sketchy IRC channels on DALnet that even this method can be subverted by simply patching out the online activation check.
The only feasible way to combat this that I'm aware of is to have some required code/data live on the company's server and thus force always-online to use the software.