Copy protection, is this going to far?

Miscellaneous Forums/General Discussion/Copy protection, is this going to far?

Im using molebox pro to protect my media.

Is it going to far to compile a exe for each customer that displays there user name, email address on the bottom of the title screen so if the game is put on emule or torrent you know who shared it and can deactivate there account for updates and downloads.

i want to have a update system avalable only to the people who have an web account, a bit like blitzmax?

Yes. If anyone wants to pirate your program, cracking it will be no problem, or they will simply register it with a fake name using a stolen credit card, like they do for apps like Photoshop.

I haven't added any protection to my texture generator, and from what I can tell nobody's bothered to post it on any warez sites either.

The thing about warez nowadays is that it's mostly done with bittorrent, and with bittorrent, someone has to seed the file. So if there is only the occasional person looking for the program, it's probably not going to get seeded much, and if it's not seeded, people can't download it.

And if your program does become successful enough that warez is a problem, then is there really a problem? Cause at that point you're probably gonna be making a nice chunk of change on it from the people who do pay for it.

I don't think this is a very good idea. Well, it is, but what if you get a lot of sales? Are you going to have the time and motivation to keep compiling exe after exe?

I haven't added any protection to my texture generator, and from what I can tell nobody's bothered to post it on any warez sites either.
I can say with 99% certainty that having no protection did not play any part in you not being able to find it on warez sites. I'm not saying its crap, but a texture generator simply doesn't have the appeal of a game, app, movie, whatever else.

The thing about warez nowadays is that it's mostly done with bittorrent, and with bittorrent, someone has to seed the file.
I disagree. Torrents might be 99% illegal material, but a bigger concern should be file sharing sites which have grown in popularity at such a rate they can no longer be adequately policed.

Gfk:
Well that's what I'm saying. Whatever it is Pete has that he's trying to protect, probably doesn't have the kind of appeal that neccessitates that he worry about piracy.

Of course games do have a wider appeal than my texture generator. I know for a fact that you can sell as many copies in a day of a good game as I sell in a half a month with my texture generator, but most games still don't have enough appeal to appear on the radars of today's warez sites for more than a short time after release, if at all.


As for file sharing sites that can't be policed... To what are you referring? Download.com?

Or just the millions of crappy shareware sites that link to the same stuff as everyone else, have poor site designs, and do no checks of the stuff they offer? I've never seen those sorts of sites offering any pirated software, cause they don't host the files themselves.

If you want to protect your app, write a VT based protection sheme. Anything else will be broken or has already "automatic break" applications.

I think for most people putting in a simple protection (like you've already done with Molebox) that will prevent 99% of people from being able to casually copy it is as far as it's sensible to go.

Personally I'm not sure that products like molebox can even justify their costs. You've basically got three types of people who will "acquire" your product: The Customers, The Poor and Freeloaders.

Customers will just buy your product anyway as long as it's: good enough, easily available and at the right price point. The only way a customer will obtain a dodgy copy is if you don't meet these three conditions.

Slapping the customers details all over the product and trying to tie them in is far more likely to alienate more customers than it will force people to become customers and the illegal people will just bypass this anyway. Always avoid punishing the customer.

Poor people, there are lots of people who would like to buy your product they just can't afford to buy what they want so they will look at other ways to get it. Generally I would just keep your products availble and eventually (hopefully) they will eventually become customers. You can't get blood from a turnip.

Freeloaders: These are people who could buy your product they just wont' and you'll never convince them that they should. There are people who regularly rip off and post stuff from DigitalBlasphemy all over the internet which I think is disgusting as that is a small solo artist who is working to support his family and totally dependant on people paying subscriptions and who provides a large free gallery. No amount of software protection will stop these people, you just have to hope eventually they will change their point of view.

Darkheart

VT based protection sheme? i googled it but still dont understand it?

I just want to put it off as long as possible i know if someone want a game they will crack it in the end

but most games still don't have enough appeal to appear on the radars of today's warez sites for more than a short time after release, if at all.
Do you live on the moon? I can find pretty much anything I want, new or old, within minutes (for the purposes of reporting links to anti-piracy sites, before you assemble a firing squad).

As for file sharing sites that can't be policed... To what are you referring? Download.com?
No - I'm talking about sites like rapidshare etc.

I think for most people putting in a simple protection (like you've already done with Molebox) that will prevent 99% of people from being able to casually copy it
I doubt it, since Molebox is for compression/encryption, not copy protection.

Ive been doing some software protection work for a small company. this work will add features to my protectors that enables you to generate single use licence keys containing info about the registerd user. these keys are self-decoding and can contain usage period before the key expires. email address ect...

type "indie games torrent" into google, seams there are alot of indies games avalable on torrents. i take your point the most of them dont have seeds after a few months but its still a problem.

Kev: thats cool but supplying usb key to each customer would really work for games money wise.

Pete there not usb keys there standard serial number keys like your blitz one.

I have Kev's software protector (the BlitzMax one) although I haven't got around to using it yet (nothing to use it on until a few months time).

Game companies will often send out personalised press discs to magazines, presumably because they see a potential security hole there. I think the practise falls down a bit when applied to the consumer though -- not only is it a bit insulting in a similar sort of way to those 'Your key appears to be valid' messages, it also does you little good: So what if there's a joe.bloggs@... tagged copy floating around? Joe Bloggs just has to tell you that his computer got nicked and he's no longer accountable. Deactivate his account after being told that and you've potentially got a PR disaster on your hands.

Now, personally, I don't believe anti-piracy measures are worth the hassle and, let's face it, keeping Puki out of your media is surely the main thing. BUT if you really do want to be able to cripple instances of your game/app that have been spread then I'd maybe think about doing so on the basis of that copy's unique key (which need not be an actual name nor even displayed normally) rather than its owner's account. Then, presuming they're bold enough to approach you for a fresh copy when theirs refuses to update, you give them one along with the reason why the old one is broken and some friendly advice about checking their computer for malware because they'd obviously never have intentionally pirated it. And then you see what happens.

I'd give them three strikes. That way you're extremely unlikely to ban an unfortunate who really has had their computer nicked, or hacked, or whose mates copy stuff off their laptop's hard-drive when they're borrowing it. At the same time you're building up a much more watertight case for deactivating someone's account entirely: It's going to be hard for Joe Bloggs to kick up a fuss when three of the unique copies assigned to his account have been spread in succession, and you still get to cripple them all.

Unrealistic? Convoluted? High maintenance? I would say the system I just described is all three of those things, but it's the reality of the lengths you'll have to go to if you want to avoid alienating good customers while ensuring you have defensible grounds for deactivating bad accounts. It's also why you should give deep consideration to whether your time and energy couldn't be better spent elsewhere.

Sledge: Some very good points there.
Kev. : sorry i miss read you post.

one thing i dont see the point of is cd protection, where the cd has to be in the drive. its really anoying for the end user too.

This is a bit of a whacky thought but I thought I would share it.. even if just for the comedy value.
The idea is not to annoy people with copy protection but rather inform them of what is happening.

It would only work for apps that go off to t'internet get updates.

When an app goes off for the latest patch a window is shown to the user with information about what is happening.

So it might show total sales of the application and then show how many hacked/copied versions are also logging in.

For example if I bought a copy of an app and then gave it away my update screen might show something like.

this registered version of the application has been seen running on 34 other machines.

Totals sales : 1000.
x% of people are using an unregistered copy.

A hacked version might display an additional message asking for feedback on why the user has chosen not to buy the product and asking for suggestions on what could be done to pursuade them to register this product or other products in your range.

Actually now I have written it down it sounds stupid.. but what the heck.

its not that bad an idea, although i dont think anyone who had an hacked version would own up?

I think one of the things being overlooked here is that it doesn't matter where you put the customer's details, whether it be as an image as part of a title screen, or text in the exe, a hacker can change that. Once they change your title screen to either show no name or some fake name they can just distribute that one version.

There is no such as perfect security protection. If you give up thinking that there is that takes a big weight of your shoulders from all the worrying and anxiety produced from thinking that you should pursue that. You can put in some protection `attempts` which will `control` a number of users but never all of them. It's really up to you, and your own sanity, to decide what you are comfortable with and where to draw the line.

I don't think I'd custom compile stuff for customers unless you really don't have many customers, and if you do it I'd make it as automated as possible.

I would suggest to you that attempting to protect or defend something suggests that that thing has something `to hide`, which actually arouses suspicion and mistrust, encourages hacking and theft, is really an attack shrouded as defense, will arouse the ego in most people, and will generally misrepresent your product. You can only gain true protection from the vulnerability of innocence. Of course, this world looks upon innocence as something to attack, too, so people will do what they want either way. Given that you can't and shouldn't control folks, it doesn't really matter what you do unless you are attempting to force an outcome such as a perceived gain in profits, which is high on many people's lists but is actually not of primary importance.

I think if a bunch of people were eating at a picnic table in a park, with nothing protecting them from invasion, some other person could come along and attack them and steal their food. But what joy would a picnic be if you surrounded yourself with brick walls and blocked out the sun? They would remain protected if in their minds they believe they have not been attacked, despite what the invading person tries to suggest. Protection is a state of mind, not something you can create in form.

In the world people can and will try to attack that which is innocent in others. It's reasonable to defend yourself on the physical level but not if it cripples you.

Pete, people who want to steal your software -will- steal your software. Like all other people paranoid about illegal copies, you are only punishing your paying customers.

Here's what I think ANYBODY should do:

Just don't worry about illegal copies. You cannot avoid them. Serial numbers and license certificates are ok, because that is like giving a key to the customer. Nobody has a problem with that. But EVERYBODY has a problem with copyprotection and otherwise crippled software.

Make life as easy and comfortable for your paying customers as possible. You want them to be happy with your product and to RETURN to your shop and purchase more. But that's not gonna happen if you treat them as suspects.

Just my 2 cents. I am sick and tired of DVDs that don't let me fast forward through the "license agreements" and company screens, and I am also sick and tired of software that wants to be activated and that can only be activated two or three times or whatever. The people who steal that shit from emule are better off than me: They get the full functionality without having paid for it and without having an idiot stealing their precious lifetime. I'm still paying for my crap because I believe in getting paid for my own work, so I also pay others. But life is easier and cheaper on the other side, and it's up to us content providers to make things easy for those who -want- to give us their money.

Its probably better to encrypt their details into the EXE and not let them know its there.

That won't stop it being pirated, but you'll know where it came from.


I think one of the things being overlooked here is that it doesn't matter where you put the customer's details, whether it be as an image as part of a title screen, or text in the exe, a hacker can change that. Once they change your title screen to either show no name or some fake name they can just distribute that one version.



my software protectors check for .exe integrity this protection detects if your .exe has been modifyed.


Just don't worry about illegal copies. You cannot avoid them. Serial numbers and license certificates are ok, because that is like giving a key to the customer. Nobody has a problem with that. But EVERYBODY has a problem with copyprotection and otherwise crippled software.



is it not better to limit them, when software requires un-lock keys. if these are contained within a online database we should block know illegal keys.

Hello.

Sod'Em all! Only sell your software via an online site that states explicitly that your software will not be hacked into/redistributed/etc from the copy they've bought, irrespective of potential naughtiness, otherwise tough kacka-poopies on them. Pre-conditional contracts are really quite tough to dispute, especially if you put in a "are you really, really, really sure?" clause in.

Put the onus back on the consumer, make them responsible for their purchases (a game is for life, not just for Christmas), sue their arses to ballyminwhahwahwhaw and we're all laughing.

Make sure the content is worth it, mind.

Um, by the way I'm not a Nebula Bot, honest.

Goodbye.

lol. Good points Soggy and Winni n'all.

Maybe we need to come up with some kind of new revolutionary hack-proof security system?

my software protectors check for .exe integrity this protection detects if your .exe has been modifyed.

So do lots of systems. What's to stop them just disabling your check? Presumably you have some kind of anti-debugger code?

Pre-conditional contracts are really quite tough to dispute,

And completely illegal in most jurisdictions, meaning that you can agree to them without ever having to abide by them because no court will enforce them. (I couldn't tell if you were being jokey about a serious point or if you were being completely jokey, but it is a point people seriously make so I thought it was worth mentioning either way.)

I think the idea of putting the user's name and e-mail in the EXE is pretty good. It should be fairly effective to deter casual piracy, but I wouldn't recommend you spend any length of time trying to make your EXE hacker-proof.

You can go on forever trying to make your program anti-hackable, but unfortunately the fact is pirates will always crack them.

No matter how hard you work covering up "security holes" in your protection system, a hacker will always find one that's left open.

For example:
- If your EXE can detect it was changed, a hacker can remove the detection code.
- If your EXE can detect if it's detection code was removed, I hacker can remove the code that detects the detection code, etc.
- If you have a license key activation system, a hacker can find the key verification code and make it accept any key.
- If your license key activation takes place on a server, a hacker can modify the client to think the server verifies an incorrect key
- If license key activations are kept track of on a server (so an activation key can't be used more than once/twice), not only can that be bypassed, but if a hacker figures out how keys are generated, then legitimate users will be rejected when they find someone else has already used their license key
- etc., etc., etc.

IMHO, any copy protection scheme that has the potential to inconvenience the user at all should never be used. It's only going to make your legitimate users unhappy, while giving hackers something fun to do.

If your EXE can detect it was changed, a hacker can remove the detection code.


You can make that a lot more difficult by having a delayed deactivation sequence -- e.g. not having your CRC checks and such kick in until after a certain date.

That way hacker X will break the initial restrictions, appear to end up with a fully functional cracked game, and spread it. Three months later the game all of a sudden starts checking its CRC code, and the game can deactivate itself after giving a message and instructions on how to buy a legit copy.

Of course it can be found, but if a mechanism like this can be hidden in a completely seperate part of the program from the other authenticity checks. (e.g. check the date when you give the high-score screen, and for the first three months after the release date don't take any action, after that call your CRC-check function.

Most hackers wouldn't necessarily spot it, so it would remain in the final cracked executable.

Copy protection is pure evil.


No matter how hard you work covering up "security holes" in your protection system, a hacker will always find one that's left open.



thats true, i would try and close them once there found.


So do lots of systems. What's to stop them just disabling your check? Presumably you have some kind of anti-debugger code?



yes theres detection support of all known mainstream cracking tools. there's other pitfalls for the cracker behind the scence filesize validation ect...

@xlsior, correct and this is the best way to do it, dont let the cracker know they was detected until sometime later.

Prince of Persia, (Warrior Within I think it was...) had a clever scene. If it detected that it was a copied version of the game, you'd get stranded on a beach part way through the game :-) but it would still let you play up until that point.

Hello.

[quote]And completely illegal in most jurisdictions, meaning that you can agree to them without ever having to abide by them because no court will enforce them. (I couldn't tell if you were being jokey about a serious point or if you were being completely jokey, but it is a point people seriously make so I thought it was worth mentioning either way.)

[\quote]

There is a difference between an EULA and pre-conditional contract. An EULA is only signed upto after the software is purchased making it a post-conditional contract term, and therefore hard to enforce. A pre-conditional contract is signed/agreed to prior to purchase and the user is free to purchase while agreeing to those terms or if they don't wish to agree, then not purchasing.

Acceptance of the terms prior to purchase make it part of a legally binding contract and fully enforceable.

Goodbye.

Nothing will stop people giving something to someone else. Unless you're selling thousands right now dont worry about it.

I think one of the main problems with trying to protect software is the whole way of thinking about a product and selling it.

If you try to make a product exclusive, ie it is only available to the select few who have done something for you in return (ie pay for it), and it is denied to other people, those other people will in many cases take it as an attack or offsense and will want to take revenge for what they perceive as being discriminated against.

IF you were treating everyone equally you would make the product available to *everyone*, ie the full product is just as accessible to someone who wants to pay for it as to someone who doesn't. Then the question of what you get back for it is really supposed to be your secondary concern. You actually only really receive something by giving it to others in the knowledge that you're really giving it to yourself, since they are you. IF they then consider it appropriate to send you money, this should be an *option* for them, and the amount should not be fixed. It must be their choice.

You might've heard about Radiohead selling their recent album along similar lines where customers could elect to pay whatever they wanted for it. They clearly still made millions of dollars and many many more people were able to enjoy the album than if they all had to pay, and there are thus no pirate copies.

Piracy does not begin with a consumer electing to gain access to something that you've denied them access to. It really begins with YOUR denial of access, whereby YOU are the pirate, stealing away freedom from a select group of individuals in the name of your personal gain. Making payment mandatory is the equivalent of not giving at all, or only giving conditionally, rather than unconditionally. If you only give under certain conditions you can only receive under certain conditions and the only thing you will receive is money, not spiritual satisfaction.

You really can't blame people for wanting to escape from an emprisonment that you've enforced on them. Deep down, people do not know of or understand limitations. They know that we are `all one` and that everything is shared equally. When we try to impose limits like `this is mine, you can't have it`, or `you can only have this if you give me something that I want`, is an imposition of restriction and enprisonment onto people. They WILL rebel against that because you're clamping down on their personal freedom.

Attempts to steal, or to hack, or to gain `illegal access`, or to pirate, or to copy, or to use something that you spent a long time working on for their own benefits, are all actually quite natural behaviors, and none of them would have to be thought of as wrong or sinful or illegal if in the first place we had a fully sharing and open mindset about it.

It is mainly industry, commercialism and traditional business which drives forward the notion that it is wrong to share and it is wrong for everyone to access your product regardless of return. Just because these commercial interests deem themselves likely to lose out if they don't get something from everyone, and just because they go to great lengths to get the law on their side to enforce such sharing as being something wrong, does not mean they are right to do so. Who is the pirate here?

This is why I continue to insist that, actually, threats against security are created by those who try to conceal, hide or protect something from any select group of people.
Those who are claiming to be `protecting your security` are actually creating a climate of and an invitation to attack that protection. So long as there are people trying to conceal, own, and protect, there will be people claiming their right to equal sharing in what will be perceived as an illegal attack. This supposed `trusted computing` is not based on trust AT ALL, it is based in mistrust to create a false illusion of trustworthiness, which at the same time actually creates its opposite.

Truly trustable computing means that everyone who is using the computers are trustworthy themselves. That's where the real responsibility for being trustable is. It's not up to software to protect us from ourselves. The only way we'll get trust in computing is for people to share equally and to be okay with it, with people respecting each other as equals and not as exclusive owners.

What's needed is a radical shift in thinking, not a radical kind of security system.

thus no pirate copies
sorry no they still copied it along with the extra tracks from the boxed set.

If the world didnt operate on a money basis id be happy to let people have what you call access to it, ie have it for free! but as in the uk i can't have access to free electric and food, im afraid your living in a dream world.

Using radiohead is a bad example because they already have a large fan base who will feel guilty if they done at least pay a little amount for the album. were as if i put my game on a site and asked people to pay what they feel like paying, id bet a you id make only a small pecentage of what i would have made asking a set low price.

You have not understood what I wrote if you are saying that there is still piracy. I quite clearly explained that if you take a view that everyone is allowed access with no limitations then there can BE no piracy. Piracy is created by denial of access. It doesn't matter how many people copy it for free because you are already offering that service yourself. You can't say that freely giving results in piracy. Piracy only exists while you do NOT give freely.

I do agree that in certain aspects of life where it seems that we need things that are material forms, such as food, or things which seem to have a limited supply, such as energy, this model of thinking does not work. So long as there seems to be `only so much to go around`, there cannot be equal fair sharing. But just like music, software is not limited by form. It can be duplicated limitlessly. There is no restraint on its form or how many copies there are, so yes this `ideology` is achievable.

And yes who knows, maybe you would make less money by letting people create their own price, or no price at all. But being equal and fair is good for your spirit, it may not necessarily be good for your ego's interests. And who's to say you would not make lots of money, or at least `enough`, anyway? What does it take to satisfy you?

Also Radiohead is one of only a few examples of this kind of approach and I don't care about what motivations select groups of individuals had for paying or not paying. That is irrelevant.

Company policy should be to go out of your way to extraordinary lengths to make everything you create as freely accessible to everyone as possible. All of your media, all of your code, all of your data, even the way that your product is able to share parts of itself with other products, its availability, the documentation you supply, mod-ability, etc you should be giving all of it to your fullest capacity.

There is a difference between an EULA and pre-conditional contract.

Yes there is. I wasn't talking about a EULA.

Acceptance of the terms prior to purchase make it part of a legally binding contract and fully enforceable.


No, acceptance of terms prior to purchase is called "conditions of sale" and while they're completely legal in the sense that you can make people agree to them, they're also completely unenforceable. The only terms of sale you can enforce (in practice) are the ones that you already had through existing legislation. The law says that you may agree to those terms and ignore them because they are not enforceable.

A very simple example. Shops which have a sale on will often display signs saying "no returns on sale goods." They may even ask you to acknowledge and agree to this before selling them to you. You can refuse if you want, but there is no need to do so because they have no legal right to make this a condition of sale. They just hope they can get away with it.

Now if you think that putting these conditions of sale on your product will work as a deterrent, then that's great, but I don't think it would have any such effect on the kind of people we're talking about and your original message seems to suggest you agree. But you're not going to get any additional rights or any help to taking legal action against them because as far as the law is concerned, they haven't agreed to anything additional.

But just like music, software is not limited by form. It can be duplicated limitlessly. There is no restraint on its form or how many copies there are, so yes this `ideology` is achievable.

I guess that depends on your defintion of achievable. If you had your way and software was distributed without limits ( as indeed technology makes possible ) then the vast majority of people writing it would stop writing it and go and do something that could afford them to feed their family instead. Thus there would indeed be no piracy but there would be nothing left to pirate either.

I'm not saying that you should not display a notice asking the customer to pay something - but just that it should be *optional* to do so. I heard that Radiohead gained `on average` around $5 per copy of their album which would normally sell for $10-15. That's not a high average but they did sell a lot more copies to make up for it.

Let's face it, when you're thinking about whether to buy something you're trying to ask yourself if you would pay as much for it as is being asked, and in many cases you decide not to, not so much because you don't have money but because you wouldn't pay the amount being asked. But maybe you WOULD still want to use it if you paid what you are comfortable with, or even nothing.

All you need is enough people who want to pay something for it to give you enough income.

Of course the whole `you gotta work for a living` and `you'll die if you don't get money` argument is going to surface. I don't think it's really relevant here. If you are not making enough money with my approach then get a `proper job` or take a different approach. If it doesn't work for you don't do it, but that doesn't mean others should not do so or that it is inherently flawed.

And besides, my main reason for saying this in this thread is to provide a real answer to the issue of piracy. The whole issue disappears completely if you approach it correctly. Given that the only solution to piracy is the correct approach as outlined earlier, and given that people probably DON'T want to take this appraoch, then obviously this indicated that they don't actually want to get rid of piracy. They want piracy to exist and then they want to attack it, making sure that their attack is not successful so that the problem still persists, which is what they want. Good luck with that insanity.

And this is without even mentioning how much satisfaction you will feel knowing that so many more people have downloaded and are playing/enjoying your game. Let's face it, if you can download a full quality game for free or little cost that is very attractive. It really depends on what you value, I guess. If you are all out to make as much money as conceivably possible, good luck to you but that route will not bring you lasting happiness.

The radiohead album isnt a good example, the online sale was a preview, you can now buy it in shops.
My main bugbear with software protection are schemes that punish the legitimate buyer; theres plenty of examples of games where the cracked version is less hassle to play.

like nodisc for example
most is on the feking hdd as it is

i was uninstalling alot of games that i dont play and alot were 4+gb
startopia was only a couple of meg it streamed off the cd like a console would (i kept that one on)

And besides, my main reason for saying this in this thread is to provide a real answer to the issue of piracy. The whole issue disappears completely if you approach it correctly. Given that the only solution to piracy is the correct approach as outlined earlier, and given that people probably DON'T want to take this appraoch, then obviously this indicated that they don't actually want to get rid of piracy. They want piracy to exist and then they want to attack it, making sure that their attack is not successful so that the problem still persists, which is what they want. Good luck with that insanity.

Are you serious? This is like saying you can eliminate wars by killing everyone on earth.

Yeah, distributing software to everyone for free is going to make piracy useless when there's no software to pirate, but there will be no future software (due to lack of profit to sustain developers) so what's the point?

Similarly, killing everyone on earth would eliminate wars since there's no people to kill, but there will be no more life so what's the point?

Yeah, distributing software to everyone for free is going to make piracy useless when there's no software to pirate, but there will be no future software (due to lack of profit to sustain developers) so what's the point?

I understood it as taking away the need to make profit itself, which is the root of the problem.

Similarly, killing everyone on earth would eliminate wars since there's no people to kill, but there will be no more life so what's the point?

Thats not really the same thing. And its not about removing the people who make war, but rater taking away the need for war, which incidentally has the same solution as "piracy": sharing.

edit: it might sound to simplistic, but as ImaginaryHuman said, what is needed is a change in mindset. as making a profit (or taking what you want from others) is too ingrained in peoples minds today.

I understood it as taking away the need to make profit itself, which is the root of the problem.

In a profit-less or reward-less society, what reason would there be to work? None, unless you essentially become slave labor.

Profits are not the root of software piracy. Companies charge for their work, and they either sell copies or they don't. If the public is willing to pay, they will. That's the way economy works.

Piracy, however, comes from people who break the law in order to steal free copies of software that companies put a lot of their resources into.

edit: it might sound to simplistic, but as ImaginaryHuman said, what is needed is a change in mindset. as making a profit (or taking what you want from others) is too ingrained in peoples minds today.

So basically you're hypothesizing a completely different system of economy, in which piracy cannot exist? Even if such a system were realistically possible (not likely, given human nature), I don't really understand why you're even posting this here. This is a thread about copy protection in this universe, not a hypothetical one. However, if you do want to discuss fictional governments and economies, I'm sure it would make an interesting thread of it's own.

In a profit-less or reward-less society, what reason would there be to work? None, unless you essentially become slave labor.

A lack of profit doesnt mean there is a lack of reward, the reward just becomes personal like it should be. Money just gets in the way.

Piracy, however, comes from people who break the law in order to steal free copies of software that companies put a lot of their resources into.

Piracy is just one of the many effects of not sharing. You could say its the system itself that creates a divide between the haves and have nots, which leads to the have nots to take what they feel the haves have taken from them and the haves to protect what they have even more feverishly (DRM, Trusted Computing, DMCA, take your pick)

I don't really understand why you're even posting this here. This is a thread about copy protection

And piracy both of which are ethical or even philosophical problems. Hence my reply.

Anyway, if i went too off-topic i apologize to the forum gods =)

which leads to the have nots to take what they feel the haves have taken from them

Face it, some people have more possessions and wealth than others, often because they worked very hard for it. To feel that you "deserve" more because someone else has something you want is not only childish but completely wrong.

Piracy is just one of the many effects of not sharing.

Unfortunately an economy can't function on sharing alone, because there will always be those who are less willing to share.

Personally I love to share my work (like my various open-source libraries), and I think it's great when someone shares their work (conversely, I think people who beg others to share and do little work themselves should be ashamed of themselves). But the concept of sharing loses it's value when it's taken for granted, and an economy based on this principle would destroy itself.

Anyway, if i went too off-topic i apologize to the forum gods =)

I guess it's not too far off-topic, since the original question has been answered already.

Thanks for the support and clarifications Grable.

John I think you misunderstood what I said and then took it to an extreme.

I don't know how you conclude that not forcing people to pay would result in no income. That would only be true if you were holding on to the current mindset and were trying to figure out what would happen if you didn't charge money. Obviously within that mindset you'd think that not charging means you will not get any money. But that is not what I am saying.

There are people out there who will voluntarily pay for something they value. What you were suggesting or implying was that if you didn't force people to pay then nobody would buy anything and you'd have zero customers. That can't be true. All I'm doing is putting the focus where it should be, completely removing the divides which create all piracy issues, levelling the playing field and then inviting customers to voluntarily exercise their free will choice to make a contribution of appreciation. This is how it should be. The people who respect such a system will oblige and show their appreciation, but not because they `have to`. And the people who don't respect it will think they are stealing or copying or getting something for nothing but that's absolutely okay - they can interpret it however they want to. I'm the one who will be sleeping peacefully at night knowing that I don't have a problem with them.

We somewhat are talking about a different kind of economy, but for the moment just a different way of doing business. I quite expect to still make adequate money from a voluntary payment system. People actually do like to buy stuff honestly sometimes. I will simply ask the customer to value for themselves on their own terms what the software means to them and whether or not they think it's worth paying for and if so how much. That's all you need to do, you can let go of the rest - it's just an uphill struggle.

I disagree that people should be ashamed for wanting full access and rights to your work, having made no contribution themselves. If they are not in a place where they can or want to contribute, that is their free choice and that's ok. You would only be upset by it if you wanted to restrict access and limit freedom. Let them have their free copy. In fact, encourage them to take it for nothing if that's what they want. If you don't they will take it anyway, and that is not a crime in my book.

I agree the world is not entirely ready for an entire economy based on total sharing and maybe never will be. Until everyone is thinking the same and is equally willing to share, it will not work, but by that time you probably wouldn't have an economy of any kind, anyway.

At least by being willing to share freely there can actually be peace.

Ok, I think I understand what you're saying now, and agree. Letting customers choose the cost of a product on their own before downloading makes sense in many ways - like you say it can smooth the line between people who download for free (called pirates when illegal) and people who pay for the product. But whether or not this business strategy actually works, I don't know.

I don't know if it works either, but it's worth a shot ;-)

ImaginaryHuman: I understand and maybe ill try releasing a later game with no set price but for now i wanted to talk about good methods of pirate protection not why we shouldnt use them.

There is none.

Either your game is trash and they are not interested or your game is interesting and it gets cracked.

The more popular the protection is the larger the chance that a "common deprotection" already exists.

Either your game is trash and they are not interested or your game is interesting and it gets cracked.


Yup.

Think about it -- If even multi-billion dollar companies like Microsoft and Adobe can't prevent their entire product lines from getting cracked within days of their release, neither can any of us. :-?

"The more popular the protection is the larger the chance that a "common deprotection" already exists. "

That's a good point, Dreamora. You almost need a completely unique and previously unknown protection scheme in order for nobody to easily crack it.

What does that really mean then? That you can only protect something by making it obscure and unknown?

Pete: Yeah I understand. If you really want to continue with the approach that you want to only let a special group of people access your product, then you have little choice but to either not care that it gets pirated, or try to defend it. If you're going to defend it, then you've pretty much gotta come up with a clever way to create an illusion that acts as a smokescreen to throw people off the scent of where the true representation of the application really is. That's really all you can do - create lies in the hope that most people won't be able to see through them. Only lies can hide truth. That means changing your application in such a way that it appears on the surface to be something it is not - through obscuring, encrypting, hiding, encoding, whatever.

I think what ill end up doing is what i said at the start of the post by printing the registered users info on the intro screen and molebox to protect my data from being pukied. I tested how long it would take me to package up a download for a registered buyer and its just over 2mins so thats ok.

thanks for your input everyone.

Maybe you could somehow modify larger portions of your software based on the users info, kind of like encryption using a key, but in a way that it still executes.

If you are all out to make as much money as conceivably possible, good luck to you but that route will not bring you lasting happiness.

Whereas watching my family starve while I bask in the warm fuzzy glow of my ethical stance of freeing intellectual property from the constraints of capitalist oppression will presumably cheer me right up.

Sorry, but I think JohnJ's comparison to a solution for ending war was pretty accurate.

Also, your Radiohead analogy is fatally flawed, as it was actually a huge capitalist success, not an idealistic success. Had it not been for the worldwide physical cd release ( which went straight to number 1 just about everywhere ) it would have been a dismal flop.

I would think you'd only end up starving if not enough people wanted to voluntarily pay for your product, which is quite possible but not necessarily the outcome. Presumably it wouldn't be much different from starving as a result of not enough people paying for a `you must pay for the full copy` approach. Who knows, maybe it's possible to make greater earnings by letting reluctant purchasers set a lower price and still buy, than to lose that person's contribution altogether. This is probably an approach which has to be actually tried and tested to see how the public responds, rather than jumping to fearful conclusions.

I also agree the Radiohead thing is flawed because if you want to find a flaw in something you will, and pretty much all examples have the potential to seem flawed to someone. With so few really `good examples` of a sharing-based system it was just something `along those lines` which I thought people might relate to. Clearly they were doing what they were doing for additional capitalist reasons but there was also a measure of treating everyone equally and not imposing limitations on the customer, which are admirable.

Saying that someone can only have your product if they give you something of value that you want, is basically holding them to ransom. There's no two ways about it. It doesn't matter if they are perfectly happy to hand over the cash or if it's some kind of `adult consent` scenario, the underlying premise of the transaction is still one of mistrust, enprisonment, and serves only the ego.

And if the only two options you see in life are:

a) sell your soul and don't be happy so that you can survive, or
b) nurture your soul and be happy but die

then maybe you need to reconsider how you look at life because there is another way.

Being able to read the cpu serial number would be the best way imo. The key is generated from the cpu sn# during the purchase and sent to the user. Then the key is checked against the computer each time it's ran. If it doesn't match then it doesn't run.

But from what everyone says here, all security is crackable so why bother?

EDIT:
If even multi-billion dollar companies like Microsoft and Adobe can't prevent their entire product lines from getting cracked within days of their release, neither can any of us. :-?
Exactly. I feel for you Kev. You spent all this time making a security app but why should I buy it? What does it offer that's not already available? I mean if they want to crack it, it'll get cracked.

Being able to read the cpu serial number would be the best way imo. The key is generated from the cpu sn# during the purchase and sent to the user. Then the key is checked against the computer each time it's ran. If it doesn't match then it doesn't run.

Not all cpus has an ID, and what about when the cpu is replaced?

There are valid ways of doing this though, feks by taking serial numbers of several key components, HD, NIC etc and composing a hash of all of them.
But using it to lock a product to a particular machine can be cumbersome for both you and your costumers.
Just look at XP/Vistas re-activation trouble and other DRM sollutions using this method that requires you to contact whomever you bought the software from whenever your hardware changes.

Being able to read the cpu serial number would be the best way imo. The key is generated from the cpu sn# during the purchase and sent to the user. Then the key is checked against the computer each time it's ran. If it doesn't match then it doesn't run.

But from what everyone says here, all security is crackable so why bother?

Exactly, it would probably take no more than an hour for an experienced hacker to find the code that compares the CPU sn# to the recorded one and modify it to accept anything.

Saying that someone can only have your product if they give you something of value that you want, is basically holding them to ransom.

I have to say that's one of the weirdest points of view I've heard in a while.

There's no two ways about it.

Wrong. Selling items to your customers isn't holding them to ransom unless the items belonged to them in the first place. If what you say was true, then I could say that you're holding me to random because you won't let me have your house, and various other items I may believe I deserve from you, without me paying for them.

Being able to read the cpu serial number would be the best way imo. The key is generated from the cpu sn# during the purchase and sent to the user. Then the key is checked against the computer each time it's ran. If it doesn't match then it doesn't run.


Catch #1: the majority of motherboards ship with the CPU ID # *disabled*, after the initial consumer uproar after intel first released the CPUID feature.

Apparrently people don't like to be tracked -- who knew.

I think that in general just by virtue of the fact that we're dealing with `soft` ware, ie it is not fixed or hardwired like hardware is, that automatically means *it can be changed*. The whole purpose of software is to provide flexibility and the possibility of alteration, so being changeable is its inherent quality and its entire foundation. I don't think there will ever be software which isn't hackable unless the software is stored in hardware like on a non-modifyable rom. Even if you're using the software to detect something about the hardware that isn't going to ultimately help either because like John said you can always change whatever part of the software is talking to the hardware. It's an impossible battle.

John - you commented about the holding people to ransom point of view. Given that everyone is really entitled to access everything as their natural birthright, then if you segregate a portion of the world off and say `sorry you can't have that unless...`, then yes that is holding it `captive` and asking for a ransom (ie some condition which must be met). It's just a metaphor to say its a ransom situation but that's basically what is happening. Compared to what should be their freedom to access everything freely, saying that they can't unless a condition is met is quite literally withholding value and not releasing it until some need is met. Sounds like ransom to me. It's just that many people are not willing to look at it in this way. Paying for stuff seems so commonplace that people (often begrudgingly) accept it.

Also you said that I was wrong to suggest `there's no two ways about it`, and you said that it would only be a ransom situation if the items belonged to them in the first place. The items DO belong to them! Everything belongs to everyone, automatically, regardless of who seems to be the author or source. As soon as I create something, it is yours too. That's what sharing means. Denying people their right to co-own everything IS taking something away from them that is rightfully theirs (and everyone else's). It's just that it wasn't *exclusively* theirs.

But you have to be careful about mixing mindsets here. The idea of ownership is not a part of an `everyone accesses everything` viewpoint. You can say that everyone owns everything equally, which really is the same thing as saying everyone shares everything and nobody has exclusive rights. That IS the ultimate form of ownership if you take ownership to an extreme. If you really want everyone to be able to own whatever they like, then that must mean that more than one person can own the same thing at the same time.

Equal ownership means sharing. What we come to think of as ownership, commonly, is usually that one person has access and nobody else does. But this idea of ownership that applies only to one person and nobody else must mean the idea only applies in limited situations and not globally, so it is flawed. This idea of owning stuff is a poor reflection of the ownership that everyone is really entitled to - ie to share in the ownership of everything so that nobody is left out. Electing one person to be the only one who is `left in` is the total opposite of that.

So yes I am effectively holding my computer and my home and my `belongings` hostage and denying you access. I'm claiming that it's mine and that you can't have it. Maybe if you gave me a couple thousand dollars I might part with my computer - so you see now I have a condition placed on it. You can have it, but ONLY IF you meet my condition. I am holding it to ransom. It is not truly `my` possession. I am just fighting you for it and the law happens to be made to say that it is rightfully mine and not rightfully yours. The law is nonsense, of course.

So really although we're all being `civilized` and abiding by `the law` and behaving ourselves, I am not expecting you to come steal my stuff, but *reality* doesn't say you can't and does not stop you doing so. Reality says that you have access to everything in the world. It's just a matter of other people claiming ownership of stuff and the law `protecting them` so that you don't typically go taking it for your use in conflict with their interests.

Ownership creates a scenario of theft. Denying access creates a scenario of theft. You cannot fully protect anything. As soon as you say `I have kept this apart and now it is safe` you are also saying `I am keeping this from other people and that's going to make them mad because it attacks their freedom`. Now you've *created* a threat against yourself where there wasn't one. Either you protect and create need for protection, or you do not protect and do not need to. People go to war trying to prove that they are entitled and all because they just can't put aside their differences and see each other as equal.

So you have basically two choices. Either you believe in ownership and you believe it serves your best interests and you do whatever you can to defend your `rights`, or you believe in equal sharing and actually meet your best interests.

So if you're deciding okay, I've labored and made this product and put personal value into it and its mine and now if you want to have it you have to pay me some money, then you basically now have to devise ways to be manipulative and justified. The law says you are justified but that doesn't mean you are. Your ego says you are justified but that isn't true either. You might then set about overinflating the value and importance of your creation so that it now competes with others - competition is an attack even if it is mutually agreed to. If the only thing special about your creation is the way in which it has something which other products do not, which sets it apart and makes it special, then really you are just emphasizing differences and not equality. I say let your creation be whatever people interpret it to be, let them decide what they think it is and what it is for, let them use it for whatever they like, let them pay whatever they choose, let them copy it as much as they want to, let them change it to their hearts content, and be okay with it. Surely there are enough honest and appreciative people in the world who will stand up and say, you know what, I appreciate your honest representation and the love you've put into this product, thankyou, here's some money to help address your worldly needs. How hard can that be?

As to security, if you really want to *try* to make something secure then you basically have to do everything that the ego does to try to conceal something. You have to separate and hide its true meaning, you have to conceal it and change its appearance and make it seem to mean something else. You have to put up smokescreens and things which seem to indicate where the truth might be but which actually is a wild goose-chase. You have to be manipulative and clever and deceitful. You have to devise mechanisms to pull the wool over the eyes of people trying to get past your security. You have to create the impression of security mechanisms where there actually are none. You have to convince them that your software IS secure so that they will be thrown off the path of being more resourceful in finding a way around it. You have to use fear and attack and warning to try to prevent them proceeding further. Actually the way things are heading, if you really were interested in protecting your software you would ultimately end up trying to take someone's life. Is it worth it? That's the way to the dark side of the force.

Given that everyone is really entitled to access everything as their natural birthright,
[...]
The items DO belong to them! Everything belongs to everyone, automatically, regardless of who seems to be the author or source. As soon as I create something, it is yours too.

Since when?

... I suppose this has something to do with your theory that everyone is actually an "imaginary human", merely a fragment of a singular all-powerful mind in which all reality exists, and that we all have the power to manipulate space/time at will, although each individual is conveniently unaware of this, and therefore can't actually make use of these powers.

I am holding it to ransom. It is not truly `my` possession. I am just fighting you for it and the law happens to be made to say that it is rightfully mine and not rightfully yours. The law is nonsense, of course.

Fine, hand it over then. After all, we're both the same person, so what difference does it make, right? :)

This is probably an approach which has to be actually tried and tested to see how the public responds, rather than jumping to fearful conclusions.

I know you've been around the home computer scene long enough that you remember when virtually all shareware games were sold this way. So to suggest that no one's tried it and everyone's jumping to fearful conclusions because they disagree with you is disingenuous to say the least. Even now there are still loads of people giving away their games and accepting donations. They're lucky if they cover the web hosting bill.

It's been tried for decades, it's still being tried now. When people have an option not to pay, most of them will take it. Is it a sad indictment of the World? Sure? Does it mean that the world is full of nasty selfish people who couldn't give a toss about anyone else? Of course! Does it make you any less likely to starve if you ( to borrow a line from Tennessee Williams ) rely on the kindness of strangers? Nope, sorry.

I'm not saying I entirely agree with your last post ImaginaryHuman, but I enjoyed it.

Thanks for the acknowledgment, DavidDC.

Gabriel, it's not about the money.