WZProtect - Game copy protection concept

Miscellaneous Forums/General Discussion/WZProtect - Game copy protection concept

This topic can be deleted :-)

You should fix all the spelling mistakes, really.

"yay" 3 typo's.. well i fixed them. anything else?

Nm.

Any comments on the system? :)

Bottom left. "temponarly".

it says temporarily :/?

Product temponarly unlocked.

Press Ctrl+F5

shematic, Its strenght, meen, sush , ofcorse

If someones attention to detail and/or care is clearly lacking, should they be trusted to do security?

lol.

anyway, im amazed people go all about 3 typo's.

I think allowing the customer to actually see and enter the key is a bad idea.

No. Crap spelling doesn't exactly inspire confidence.

GfK, right, but not all people on the world are born in the UK you know. And your talking about 3 typo's in a conceptual design. pfff.. and that where typo's, not that i don't know how to write it -_-

It looks overly complicated.

Gobbo, I appreciate English my not be your first language, however, if I were trying to sell something to a German speaking market I would make sure the presentation had perfect German on it.

.

You'll need to post at least 15 years ago then.

yeah, baby class :-P

Who cares about the spelling!!

You'll need to post at least 15 years ago then.
Probably nearer 17... when Gobbo was probably still flailing about in the bottom of a test tube somewhere.

Ok, back on topic now. play time is over. thank you.

Well, if you've seen my other recent post on piracy then you know I'm interested. But this seems more complex than what I was shooting for.



@big10p
[imghttp://www.icetec.net/screwit.jpg]

Break it down.

Show each process step by step - at the moment that diagram is confusing.

Okedokie :) i will post a more userfriendly version when i get back.

It looks overly complicated.
And ineffective.

Any comments on the system? :)
Sure:

a) What happens when I reinstall my computer? My key is now "useless", so how do I get to play the game I've legally paid for?
b) Anyone with a packet sniffer and a bit of imagination, could brute force themselves a nice list of keys in a relatively short time.
c) Once they've done that, they can run them through pattern recognition software, and get all the keys you have invalidating any future purchases.

Nothing's going to stop people from warezing, just making something harder to pirate just encourages more to try.......look at what happened with StarForce for example.

@FlameDuck
In reply to:
a) You missed the part: "A system unique key is then generated...". That new key is just like with WindowsXP only usable on THAT specific PC.

b) lol, that made me laugh. we got both hardware and software protection against these baby-booms. Right now we reject over 1000 attacks each day of sush kind. I hope you understand i cannot disclose any more information on that. The more i tell the more hackers and crackers know.

c) There are also other aspects about the way we build keys, there is not pattern. But lets say there is, the only way to make or get a key, is trough our servers. There is information ON the server you need to get a working key. So that would meen they need to buy over 1000 keys. And i think you wouldnt mind making 1000 sales? Then, if we noticed your specific game is cracked, we click a button and the dynamics of our system are changed so a totaly new type of key rolls out.

But i would say, i say nothing more. Its the books about "how do i secure something" that make everything insecure. That is the first book a hacker reads. If there is enough interest i will think about building this sytem.

I think you're talking rubbish, to be honest.

This was only a 'concept' 20 hours ago, and now you all of a sudden are using this system for whatever purpose and have single handedly beaten piracy?

Sorry, but I don't think so.

.

How come your website doesn't work? New is it?

In my country i have quite a big name
...and on that willy-waving note, I can't be bothered communicating with you any further.

Hey Grey Alien, you meen Goldstar PC Games? That is just for my personal hobby and has nothing todo with business. I registered the domain yesterday or the day before. I haven't had time to put it up. The domainname was registered so that none else can register it. You may call it "Domain parking" but without "Parking notice" :)

This system needs an internet connection.
If you intend to use other distribution channels offer alternative routes for buyers without such a connection.
If not then this will suffice. Some sort of password retrieval will become nescessary.

applepie

But may i ask, who is really interested in this at Blitz3D community? You don't have to say your going to buy it or not, but if it is something you can consider when it is proved working and secure, would you do it?

If its only a few people, i doubt i even start on this as it will be to non-profitable, because with this technique i already have sush a small market.

Just make a system where the user creates an account on a database server and the server admin can go through and check which products they have access to. Programmers like me want it as simple as possible, with no regkeys or other BS to deal with. We're busy with our own projects. Piracy protection isn't "interesting" to us, it is an annoyance we don't want to deal with. Don't expect us to be interested in your brilliant scheme, we don't care and we don't want to think about it.

I want a system where a user can just sign up for an account without me doing anything, and a bmx module that signs into their account and verifies they are a registered user.

Like Steam, except silent, and I only want it to run one program, not a bunch of different things. I want it all inside a single module, with some server tools for me to view and modify user accounts.

And it should be able to run offline for a week or so before it requires an internet connection again.

If it worked, it didn't get hacked, and it was easy to use, I would pay up to $1000 for something like that.

im working on it. but i am going to use sincere encryption and hashing, with even in blitz already crypted tables, so its going to be SOME include. cause otherwise i cannot garantuee your safty.
for those who never tried, edit your EXE with notepad, you can read about every string used in the game just like that.
what is the e-mail adress i can use to post my demo when it is done?
i will provide a fully functional demo, you are then allowed to ask everybody to try and hack an crack it. However, do you want a hosted solution or not? because hackers will aim for the server in your case.

a) You missed the part: "A system unique key is then generated...". That new key is just like with WindowsXP only usable on THAT specific PC.
And much like with the WindowsXP, privvy to all the same problems, like reinstalling the computer, or upgrading the graphics card.

that made me laugh. we got both hardware and software protection against these baby-booms.
I'd call your bluff - but since we haven't even seen a proof of concept yet, I wouldn't be able to prove it.

Right now we reject over 1000 attacks each day of sush kind.
Try 1000 attacks a minute. If you're only getting about 1000 attacks a day, it's probably a bunch of legit users who can't figure out why their software isn't working.

The more i tell the more hackers and crackers know.
Nobody (except perhaps Microsoft) relies on obscurity for security. The crackers are a lot smarter than you.

So that would meen they need to buy over 1000 keys.
No. In theory, they just need 2. The more they get, the quicker they can reverse engineer it - but if you have a cluster of PS3's or something two should just about do it.

That is the first book a hacker reads.
Wrong. That's the first book a hacker writes.

Listen, you may have missed i do this by profession.
I can't imagine a very good one.

it only works for a small segment in the industry.
No, it doesn't work at all. If you knew the first thing about security, you would know that the security of a system, like the tensile strength of an alloy is something that needs to be proven. Since you don't even have a prototype, the best you can do at this moment is hope it's secure. Judging by your security through obscurity approach it's obvious that hope is all you have! Why do you think the Feistel cipher is considered one of the strongest encryption algorythms there are? Why do you think PGP/GPG are considered virtually unbreakable? Because they have been under more intense scrutiny than any other systems.

for those who never tried, edit your EXE with notepad, you can read about every string used in the game just like that.
Or if you can't be bothered opening it in a text/hex editor, open it with a debugger. Then you'll also be able to see your encrypted strings as they're stored in memory, as well as the algorithm used to encrypt/decrypt it.

otherwise i cannot garantuee your safty.
Well my company could sure use a guarantee like that - if for nothing else, then so we can sue you for breach of contract when your system is busted wide open! So how long have you been doing this exactly?

pff, lot to reply. hold on...

That is for people selling games online trough download format. Their customers need an internet connection to buy and download and thus have internet.

Bad assumption. Many of my customers download it on one PC and install it on a completely different PC. At least they do as long as I don't implement some copy protection scheme which prevents them from installing the game they just bought.

1. right
2. fine, but its true.
3. *sigh* that is due to the protection. once they start, the system kicks their ass and they can't do anything anymore. Imagine how a server would function if it needs to reject 1000 attacks a minut. We rather prevent that then letting it go that far.
Why do you think your bankpass get blocked after 3 fails?
4. i do not agree. if security is good, each leaked information about it is used against it.
5. well, that could be both. you know as much as me about what all hijackers on the world read or write. we never know for sure. another argument i have with that statement is that hijackers would be silly if they do that, unless it earns them money.
6. lol, beleive what you want. i was entrusted by a company that stores financial information of i'ts people. it has todo with online-banking. imagine what it takes to secure that? now im not going to disclose any more information on that because i want to keep my business seperate of this understandeble but anoying discussion im having here at the forums.
7. how can you say? you have not even tested. nor any of what i made before. what i say is based on experiance.
"Why do you think PGP/GPG are considered virtually unbreakable? Because they have been under more intense scrutiny than any other systems."
right, than any other systems? and i suppose you work there? how can you tell what on earth is going on? you can't be in all bussiness at the same time to say sush a thing... but it doesn't really matter either. it has nothing todo with the system i talk about.
8. sure, next time i post a tutorial. im just pointing the most easy for everyone to discover thing out. you cannot expect all readers to understand how that works.
9. im not talking about 100% as you are assuming. and please stop the breach of contract nonsense... as if i would sign a contract saying i 100% garantuee their safty and they can make claims if i fail. ofcorse not.

now, may i ask what that was all about? it seems you try to proof me wrong but that won't work.

After i made my demo for Leadworks you will talk otherwise.

@Gabriel, -_- ... you also? i get tired. What are you on about anyway? its a silly cooperation in proofin me wrong. Anyone who read it in the context must understand im not using it as an argument to defend myself. I said it attmitting my market is small. You just made it smaller. So what?
I meen you want protection or not. If you dont go with this one, then go with another one, each has its advantages and errors. System A can hardly be cracked but requires Internet. System B can easly be cracked but is portable, and so there are a lot of other systems.

Please all remember i started this thread not to sell something that has not yet even been build. But to workout an idea together.
Some are confused by off-topic stuff that others posted. This is going nowhere.

I suggest we close this topic as it has no purpose anymore. Other than to be negative about.

We can continue in this one http://blitzbasic.com/Community/posts.php?topic=69354 as it has more sence.....

Can a mod lock this? thanks.

2. Just because you say so, doesn't make it true.
3. The bankpass comparison is absurd. The way you described your system, and the way most banks authorize users (Kerberos or X.509) are completely different.
4. Well you're entitled to your opinion, but if security is good any leaked (or published) information doesn't matter, because it's not going to be able to present a threat to the security policies of the system.
5. Yes. Somewhat surprisingly writing books about computer security earns you money. Also apart from the various "underground" ezines, most are at the very least regular readers of 2600.
6. I don't have to imagine. I know people who design banking systems. I help them do system specification analysis and threat assessment.
7. You don't know the first thing about what I have or haven't done. And yes, since Feistel Cipher and OpenPGP have yet to have a demonstrable "better than bruteforce" attack strategy, and potentially use enormous key spaces, I can say quite a bit about their relative security.
8. I think you've just managed to insult the intelligence of everyone here. I doubt anyone had any illusions that "your EXE" contained string constants in anything but plaintext.
9. Maybe you and I don't have the same definition of "guarantee", but Merriam-Webster doesn't seem to suggest that there is such a thing as a 50/50 guarantee, or I'm reading it wrong.

it seems you try to proof me wrong but that won't work.
I don't have to prove you wrong - you're the one with the secure system,, you're the one who has the burden of proof. I'm just pointing out the various flaws in your understanding of security.

I think it's the developer's responsibility to protect the actual EXE from hacking. There are third-party tools that will make this much more difficult.

I am not offering to buy anything from you right now, so please don't take it that way, but I am saying if I had something reliable and pretty well-guarded, I would be pretty interested, wherever it comes from. Otherwise, I'll have to write it myself, and I am not very knowledgable about network stuff.

I am hoping someone here comes out with something good within the next year.

2. maybe not for the one reading. but i know whats true or not.
3. its just how you want to look at it. they share the same fact that after XX tries another try is denied. Our hardware may work different but after XX tries it bans the hijacker.
4. i do not agree. if they would post the whole project etc..etc.. it could be reversed engineerd.
6. nice, you just met another one. but at this point i need to say not all banks on the earth use the same security, and there is a difference in culture.
7. ofcorse i know what you have or have not done when it comes to my projects. i was saying the same to you. lol, where i had a point b.t.w. because it concerned my projects. you miss the point -_-
8. dude... its just how you want to see it. i think its a fair assumption that not everyone knows how to use HEX/editor etc.. but maybe im wrong. That doesn't meen im insulting people. If so, imagine on how much i was insulted? please, people that participate in this topic are as much as not whatever.
9. oh boy... there comes tge "Merriam-Webster" lol... ok, lets see what it says, uhm "an assurance for the fulfillment of a condition". That condition can be anything.
Do not webhosts often garantuee 99.5% uptime? the garantuee its self is 100%, but if you garantuee something for 50% that is like 100% of 50%. 50% of 50% would be 25%. Get it?

@Leadwerks
"I am hoping someone here comes out with something good within the next year."

I said im working on it :)

That does not enforce you to buy anything. But i have been so slamed at, that i want to proof it after all, that i can provide a working system.
You can be the first to test when its done.
And i can take care for EXE protection also so the developer can be less concerned about it.

its a silly cooperation in proofin me wrong.

I'm interested in neither cooperation nor "proofin" you wrong. I'm simply pointing out that your claim that everyone who buys downloadable game is installing it on a machine with an internet connection is a bogus claim. If you don't want to be "proofed" wrong, you should probably stop making claims until you've done some more research.

And for a good example of said research. Since many downloadable games are going to be distributed on portals who use their own copy protection, you might like to explain the purpose of preventing copy protection on your own version of your game only to find out that the three other versions of it are already cracked and being distributed like crazy.

Thats not what i said. See, somehow some people get confused. Lol..
I said:
People that buy and download it HAVE INTERNET. lol.
Im not claiming that games are thus only installed on systems with internet and not on other systems.
That is totaly your interpretation.

"If you don't want to be "proofed" wrong, you should probably stop making claims until you've done some more research."

Maybe that is what i do wrong. I say things in the form of as it is a claim, but i actualy intent to say im so very sure of it. I do do reasearch and have a lot of experiance, but when i say something people take it as if im claiming it. I will be a bit more carefull at that. Thanks for the tip!
I hope that solves a lot of the communication issues.

After i made my demo for Leadworks you will talk otherwise.
Nah. After you make a demo for Leadworks [sic], I'll be the first one to break it. Wanna take odds? Here are the odds the way I see them. 2/1 I'll break it in one week. 5/1 I'll break it in one month. 10/1 it'll be broken by someone the first year. 100/1 it'll be broken within 5 years. 1000/1 it'll never be broken within 5 years of operation.

People that buy and download it HAVE INTERNET. lol.
Yes. By far the lions share have dial-up, and chances are they're not going to have it switched on when they're playing a single player game, that apart from a crippled copy protection scheme, should have no reason to use the Internet. Do you think they're going to ask for a refund when their legally purchased game refuses to work for no apparent reason?

@FlameDuck: neat. Your on it! try me! haha! Bring it on... we have a challange.

Well one of us does... :o>

lion's share on dial-up? I dunno how these figures are in countries other than the Netherlands, but right here the vast majority has ADSL or Cable..

xD

I dunno how these figures are in countries other than the Netherlands, but right here the vast majority has ADSL or Cable.
While the Netherlands are high on the list 32% is not so much a "vast majority" as "nearly 1/3".

I had an interesting conversation about this with the Nordic game guys. Broadband=more money flowing into your country=better economy. I've noticed some of the Scandinavian countries are starting to do quite well with game development, and I hope that trend continues.

BTW, I will be in Northern Europe in September if all goes well. If you know of any happenings I'd be interested in checking them out.

Dunno about that OECD page.

It talks about subscriptions per 100 inhabitants.. What if a family of 4 persons has 1 familly-subscription? That would mean 25% coverage, while 100% of the persons enjoys this subscription.

Additionally, there're subscriptions here of 64k and 128k ADSL (cheap, not really fast, but online all the way) and they're not included in those OECD stats..

linky

I happen to know that in the Netherlands some already started with fiberglass. I wonder how long that would take before ist a standard.

[edit]
just a quick note: the WZ Protect project has been aborted.

a new project has started under the name "AntiPirate"
this new system also works different than the one talked about in this topic.

Link: http://www.icetec.net/AntiPirate.html

If you want to join the discussion on "Warez, crackers and Protection" go here:
www.blitzbasic.com/Community/posts.php?topic=69354
It also has a part where we talk about how secure/insecure AntiPirate would be/is.