Adobe modifies hosts file to detect whether Creative Cloud is installed
osnews.com
osnews.com
Between this and the fact that they've just 1. Changed all the old accounts to "Adobe Creative Cloud Pro" 2. DOUBLED the monthly fee, now charging you for the AI features whether you want them or not, and 3. Removed any tiers that have full program access but no AI, I am walking away forever when my current month expires.
Not to mention, students now only get the old $19.99 membership for the first year.
I teach visualization and representation tools to architecture students. I had always taught them Adobe products before. Now I can't in good faith sign them up to have their expertise tied to using this program stack forever. So tomorrow I am giving them a lecture on free to use and FOSS versions of the same tools. And I'm going to teach the class from them in perpetuity. Congratulations, Adobe that's 50+ students a year who won't be using your products when they graduate.
…now that I think about it, don't architects predominantly work in smaller companies?
I wish someone would come and take Adobe’s monopoly down for good, but as it stands, shunting Adobe for something else in a professional environment is more trouble than it’s worth.
For example, the GNU Image Manipulation Program now has non-destructive workflows and adjustment layers - and can easily easily be configured with photoshop-like keybinds anyway.
That's not to mention free-to-use tools like Affinity.
The things an architecture student needs it for are:
Photo adjustment:
Lightroom -> Darktable
Photo retouching:
Photoshop -> Affinity Pixel or Gnu Image Manipulation Program
Vector drawing (which for us is mostly processing from 3d modeling programs):
Illustrator -> Affinity Vector or Inkscape
Board and Book Layout
InDesign -> Affinity Layout or Scribus or VivaDesigner
Plus, for motion graphics and video processing, my partner and I have had great luck replacing AfterEffects and Premiere with Blender and DaVinci Resolve, respectively.
And ... believe it or not, I've had excellent luck with LibreOffice Draw as a PDF editor, so anything they would have needed Acrobat Pro for is covered by that (and / or PDF SAM).
The real "sticky wicket" is Revit. Autodesk has been a FAR more abusive company for FAR longer, but it's what we're stuck with - although the emergence of the BIM Workbench (Building Information Modeling) with the release of FreeCAD 1.0 [0] and the continued development of BlenderBIM (oh, now called BonsaiBIM) [1] at least gives some hope.
Anyway, for the Adobe replacements, here's more [2] based on [3]
[0] https://wiki.freecad.org/BIM_Workbench
[2] https://github.com/KenneyNL/Adobe-Alternatives?tab=readme-ov...
[3] https://x.com/XdanielArt/status/1799474607055102257/photo/1
I believe AutoCAD is the epitome of what is wrong with Autodesk. It's expensive, there is no permanent license, there is basically no real alternative, and they aggressively go after pirated copies.
If I were a vibecoder, instead of silly toys like a half-broken compiler that nobody uses, I'd focus all my energy and tokens on creating a real Autodesk alternative. And if it really worked, including seamless witch, the authors would quickly make tons of money.
Additionally, Rhino has always been a good drafting tool [1] but my understanding in the current WIP (which if I'm guessing will probably be released as 9.0, within the next 6-12 months) is making a huge push to include better drafting tools. McNeel, the developer, has no plans to go to a subscription model.
As for any After Effects-style NLE capabilities - DaVinci Resolve knocks those out of the park. You'll also probably hear a lot of people singing the praises of Natron for NLE and Motion Graphics, and from our experience with that it seemed like the learning curve was non-trivial, but anything AE (and some aspects of Premiere Pro) could do, it could match... Good luck!
Detrimental would be to subject students to the whims of Adobe, which doesn't really have that much moat any more.
[0] https://x.com/XdanielArt/status/1799474607055102257/photo/1
I know you all know this but companies will do this knowing that exploiting all of us.
I use Linux and agreed on all those points. when I used adobe before it wanted to charge me a fee to cancel my subscription and wouldn't let me just 'cancel' in their system so I just blocked the payments on my card and dipped out.
good software, garbage company
So I switched banks. It was a interesting call with my previous banks support folks.
Yup same. The software I install as root are those shipping stock with the distro. Others I compile and run from user accounts (like Emacs, which I always compile from source).
Funny enough macOS, iOS, iPadOS and Android do this and they are constantly attacked for it.
I do think there needs to be more strict adherence by developers to standards like XDG but I don’t know how it could be enforced.
I'm not sure what the purpose of the question is, because a unixy command line doesn't use phone-style permissions. I didn't say everything works this way.
If I installed photoshop with phone-style permissions, it wouldn't be able to invoke chmod and wouldn't even be able to access my downloads folder.
(Trying to tighten down a command line shell ends up being a tangent, but the short answer is that zsh itself would need to be trusted and hardened, and wget would not be allowed to run chmod. When it comes to downloading a script and then running that script on purpose, you probably just have to accept that doing so bypasses the permission system. Thankfully I very rarely need to do something like that.)
Now what should happen if the text editor decides to modify /etc/hosts without your knowledge?
Pop up a UAC prompt of course. It worked so well for Vista.
This works better with a GUI, but you can adapt it to a console too.
Even if users don't read the permission dialogs, you can make one path a lot easier. And you can flag anything too tricky as malware behavior.
OSes are doing a bad job of this, but they could do much better. Linux is making the most progress on various package formats.
It can't be enforced. Developers can and will always do whatever they want with the tools available. For good ends (Adobe) or for ill (malware).
If you try to fix it with sandboxing and closed app stores (Apple forcing sandboxing and using SIP), you get attacked. If you don't try to fix it and let devs do as they please (Microsoft allowing host file editing), you get attacked. The conclusion of these incompatible goals? HN and nerds have zero relevance in policy discussions, because they don't have a consistent policy to offer [1].
[1] Unless, of course, you define "devs shouldn't be able to do anything bad even if they choose" and "users should be able to anything bad if they choose" and "users should be able to write their own software capable of bad things while simultaneously not being held to the standard of devs" as a compatible principled position.
The problem with things like iOS is the user can't make that choice. Also what you call 'bad' is up to the user. At the end of the day a user should be able to adjust things even at root level or request other software to do that on their behalf. Heck for iDevices owners should be able to load their own signing keys at a minimum for the Boot-ROM.
As for Adobe most people would not expect their software to touch the host file, so it's fine to call them out here. Someone using a utility or tool that you would expect to edit the host file that's fine, and people should be able to use or make such a tool. (The os should not prevent the user/owner if that's what they want).
I used to have this opinion too.
Then I decided that I actually don't want random things to install to `/usr/local/bin`. They should install to `${HOME}/.local/bin`. I should be perfectly capable of installing any application without modifying the system for every user.
Speak for yourself. For installing via system packages, yes. Otherwise absolutely no.
Most of the time if I install something on my computer without using the package manager, I am the administrator of that computer and I want the thing I installed to be available to a specific run-user, not to all users.
That's an overly strong rebuttal given they said "most" and weren't talking about a specific style of install.
Are you saying you use root access to install something to a specific user's home directory? That's gross.
A user installing something for themselves should not need administrator access. You only need admin access for making system-wide changes.
s/free rein/the ability/
I am a big believer in read only operating systems. /etc should not be writable.
And whatever you do use to configure things, what if photoshop accessed it directly? I'm sure you'd be upset with that even if it didn't touch /etc.
Everything else should be in its own folder without the ability to change anything outside of that folder.
Isolating things to a specific folder is what actually gives any security here, and you can do that on a writable /etc too.
But I might be making this up so not being specific lest I do a cheeky libel
...and then Adobe (unintentionally) gave away free downloads of CS2, with valid serial numbers, once they shut down the activation servers. You can still find them on the Internet Archive.
Doing this again, now (well into adulthood): recently gifted a "broken" 2013 MacPro[0], and have set it up as my retro CS4 workhorse (decades old software on a decade old machine). Hosts/PiHole ready, blocking "*adobe*" entirely.
Only problem now is I cannot find four's `FCKGW-RHQQ2-`... my oldmanfish surfs onwards, Santiago remaining uncertain. For now I just don't quit and never shut down (fresh install allows limited launches).
[0] RAM slot was jamming, not allowing proper seating
For anyone hand-wringing over this, this used to be normal. The hosts file was invented a decade before DNS. The end user, or app, would edit their hosts file purposefully after downloading a master copy from the Stanford Research Institute which was occasionally updated.
People editing hosts files for other reasons was normal (a long time ago-- and it stopped being normal for valid reasons, as tech evolved and the shortcomings of that system were solved). A program automatically editing the hosts file and its website using that to detect information about the website visitor is not the same thing; that usage is novel and was never "normal."
This claim strikes me as obviously wrong.
Your shadow IT example is perfectly valid, and also isn't a 1:1 comparison with a company doing it automatically for a much larger number of external users.
There are also other reasons to do it, like if you want a device on the local network to be accessible via HTTPS. Getting the certificate these days is pretty easy (have the device generate a random hostname for itself and get a real certificate by having the developer's servers do a DNS challenge for that hostname under one of the developer's public domain names), but now you need the local client device to resolve the name to the LAN IP address even if the local DNS refuses to resolve to those addresses or you don't want the LAN IP leaked into the public DNS.
Or the app being installed is some kind of VPN that only provides access to a fixed set of devices and then you want some names to resolve to those VPN addresses, which the app can update if you change the VPN configuration.
The fact that this is largely seen as acceptable or even sensible is rather silly in this day and age.
Most windows apps aren't sandboxed so the concept of "permissions" doesn't make any sense. The most there is is "asks to run as admin", but most installers do.
At least the system prevented me from seeing or modifying the files the last time I tried. I did not try very hard, admittedly, but by contrast modifying something in C:\Program Files is just one UAC confirmation away.
There’s no need to have an executable program just to essentially unzip some files to disk
What if you need to install some registry keys? What about installing shared dependencies (redistributables)? What if you want granny to install your app and left to her own devices, it'll end up in some random folder in the downloads folder?
It is just a really bad design without built-in sandboxing.
I inquired about it and got some BS about how they absolutely _had_ to do this to intercept MSAA instantiations across the system, when in reality they were using a global solution to solve a local problem.
> At what point does a commercial software suite become malware?
The vast majority of commercial software is malware.
_______
Oh helllll no. Let's imagine an analogy for Adobe leadership:
1. You hired a night janitor to clean and vacuum your executive offices.
2. That janitor secretly stops at every desk-phone to alter the settings of voicemail accounts.
3. After the change, any external caller can dial a certain sequence to get a message of "Yes, this office was serviced by Adobe Janitorial!"
What's your reaction when you discover it? Do you chuckle and say something like "boys will be boys"? No! You have a panic-call, Facilities revokes access, IT starts checking for other unauthorized surprises, HR looks into terminating contracts, and Legal advises whether you need to pursue data-breach notifications or lawsuits or criminal charges.
* Is it acceptable because they had some permission to touch objects in the rooms? No.
* Is it acceptable because the final effect is innocuous? No.
* Is it acceptable because the employment contract had some vague sentence about "enhancing office communication experiences"? No.
* Is it acceptable if they were just dumb instead of malicious? No.
No person that would blithely cross those lines can be trusted near your stuff, full-stop.
> 3. After the change, any external caller can dial a certain sequence to get a message of "Yes, this office was serviced by Adobe Janitorial!"
Theoretically, it's not "any external caller." Only the janitor's department calling in can dial that sequence and get "Yes, you serviced this office!" If anyone else tries to dial the extension, the desk-phone pretends it doesn't know what it means. (Because it seems Adobe's server serving the analytics image checks the request origin and only serves the image if the origin is Adobe's own website.)
The origin "security" doesn't excuse the complexity and the potential for both exploits and human-error breakage in the future.
Is this the case though? Cannot any website use the same trick Adobe does to check whether you have Creative Cloud installed? Like, the entries in /etc/hosts are not magically scoped to work just on Adobe's web, no?
That is specifically what I was talking about.
> (Because it seems Adobe's server serving the analytics image checks the request origin and only serves the image if the origin is Adobe's own website.)
It's additional complexity on the server side, per a Reddit comment on the topic: https://old.reddit.com/r/webdev/comments/1sb6hzk/adobe_wrote... The example curl commands given seemed convincing to me, although they also demonstrate that you can fake the origin pretty easily on the client side.
This is an extremely common practice.
I am tired of inconsistent logging, opaque system changes, and vendors generally being malicious with endpoint security in the name of protecting profit.
Screw the "show me the log" option that scrolls by in a flash and you can't get back to, show me the damn diff first.
They're doing this because the localhost shenanigans got blocked. This is pure internet requests, but the IP changes (or fails to resolve) based on what's in your hosts file.
I must be missing something.
To exploit this kind of thing you'd either need to have access to someone's computer to change the hosts file yourself, pointing to a different IP address, or somehow gain control of Adobe's IP address and point it to a different server. For the former, if you have local root permission, you already own the machine, why bother with this slow of an option. And the latter is already such a takeover that the involvement of this hosts file change is basically irrelevant.
I cannot stomach Thom's articles. So borderline judgmental, holier than thou, feels like he only writes whenever there's something to criticize.
No, it's not a stupid reason. Reason is OK, the execution is controversial.
And even then, only controversial to nerds with opinions. Nothing else about it is controversial.
If anything, knowing whether the app is installed or not is kinda important? If you open a file shared with you in the browser, the option to "Open in Desktop" versus "Install Desktop App" actually works correctly?
- Registering an url handler?
- Asking the user?
As for option 2; ask them every time, or edit their hosts file. Easiest decision in the world: Edit their hosts file, every time, no question. The 1% of nerds who care, and oddly enough don't buy Adobe software, are completely meaningless to the 99% of customers who experience the decision positively.
Why does Adobe need to exfiltrate some information from my machine anyway? If I'm a customer, then they should know this when I sign into my account. They absolutely don't need this information if I'm visiting their website without logging in.
Modifying a global system file is something their software shouldn't be doing in the first place, but relying on this abuse to track me on their website is on another level of insidious behavior.
This is not an approach any other app on any platform has historically used, and it doesn't seem sustainable if every app you install has to modify your hosts file to use a hack like this to detect whether it should handle files or not.
If you want the browser to be able to give the OS a file handler and have the OS present an option to install the app if it's not installed, that should be handled at the platform level, not on the website using a hack like this.
Why can a file not simply be downloaded with a page displayed showing a link to install the app and also instructions to open the file, trusting the user will know if they already have it installed? At best, you're talking about a very small UX optimization. Emphasis on the "kinda" in "kinda important."
Actually it's completely sustainable. DNS was invented a decade after hosts files. The idea of your host file being almost completely empty is a modern aberration from the days it used to be thousands of lines long.
Do I wish there was a better mechanism? Sure. Would HN ever agree on a OS-level app-detection API for the browser? Never.
> Why can a file not simply be downloaded with a page displayed showing a link to install the app and also instructions to open the file, trusting the user will know if they already have it installed? At best, you're talking about a very small UX optimization. Emphasis on the "kinda" in "kinda important."
A small UX decision, adding up to tens of millions of times per day, affecting 99.9% of people who don't give a darn - versus a matter of slight software engineering principles of "we just don't do it that way." Easiest decision ever.
There already is one. It just asks the user whether it's okay before it tells the website, as you acknowledged: https://news.ycombinator.com/item?id=47664546
What you're arguing for is not good UX. It's lack of user privacy & control. You just think you're being hip or whatever for being blasé about it.
The current implementation defines a way to launch (w/ the user's approval) but it lacks any signaling of success or failure of the request. Without such feedback, it falls short of being a detection API.
How many apps are you installing that it becomes "unsustainable"? Host file entries are extremely cheap, and it's not like the app needs more than one. Of all the arguments against this, sustainability is a comically weak one. If anything, it's using less contested resources than the "hitting random ports on localhost" approach...
Do you really not see scripted editing of shared system-wide text files as a step back compared to the general containerization that app development has moved towards? This sort of approach would be explicitly incompatible with sandboxes. Adobe can only get away with it because they're already very entrenched with their own app store on their users' machines.
Sir, this is Windows. This is not Android, this is not iOS, this is not macOS. Wait until you learn about the registry.
From the first sentence of the featured article:
> If you’re using Windows or macOS
Also, Microsoft has attempted to reign in and standardize app developers on numerous occasions over the past couple of decades, and their failure to do so doesn't impact my statement regarding the direction of app development in general (or the weaknesses of people doing whatever they want on Windows).
Also, I think writing only when you have things to criticize is a valid enough thing to do; what's the point of writing a glorified "I agree!" article?
I only ever blog when I have something that I think is unique to say, and as such a lot of the time my posts end up being kind of negative. I don't think I'm that negative of a person, I just don't see the point of flooding the internet with more echo-chambers.
(I have nothing against LLMs but have little interest in reading text generated from them.)
But I think for things like blogs, without opinions being clear, posts can feel kind of soulless. Even before LLMs I felt that way, and now it has been amplified ten fold with people just cranking out low-effort posts with ChatGPT for reasons that I do not understand.
When I write stuff for my blog, I like to think of it as a time capsule of the entirety of the thing I'm writing about. This doesn't just include the raw subject matter, but also my mood and opinions about the subject matter. I'm egotistical enough to occasionally read through my old posts and the ones that I like the best are the ones where I feel like I was expressing myself the most, and where I make no effort whatsoever to try and be impartial.
This is a muddled statement. It is a stupid reason to "execute" the act of silently modifying your host file.
If I murder somebody to keep them from stepping on my foot, and the judge says that it's a stupid reason to murder somebody, it's silly to say that the reason is "OK" because it hurts to have one's foot stepped on.