Go Back   xda-developers > General discussion > General


Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 5th October 2009, 07:38 PM
Chainfire's Avatar
Chainfire Chainfire is offline
Senior Member
 
Join Date: Oct 2007
Posts: 2,113
Default Marketplace "copy protection" cracked

I will not do anything with this, or publish how. But you can be assured the "warez" guys from that one site will figure this out within a day or so as well...

As most of you will know I am a software developer by trade, with some commercial offerings from my company.

And then there was Marketplace. For commercial devs, something nice to have. But if you have followed the news, the piracy protection for commercial developers is not much to speak of. See this document http://download.microsoft.com/downlo...te%20Paper.pdf.

I will refrain from quoting the obvious mistakes in this document, if you give this thing a read, you will notice them soon enough. What it all comes down to is that there is no copy protection, not even at the advanced level, at least if they implement it in the way I interpret from reading that document.

So today I started up Marketplace and it worked. Hurrah. The current level of protection is making sure the CAB files are deleted upon install - which is obviously not a way to protect anything - but even this, I thought, should easily be circumventable.

Now, because I wanted to see how fast it could be done, I went with a hunch instead of doing any investigation. And that hunch worked like charm. It took me less than five minutes to circumvent this "protection", and get the ability to save the CABs the MarketPlace app downloads to a different folder. As the CAB file is the same for every downloader, you could just give this CAB you payed for out to all your friends.

Obviously I will not disclose the method, because that would be working against other commercial developers, and ultimately myself. It's just to let you know how ridiculously easy it is, and to give fair warning to those looking to sell apps on the Marketplace.

So, the moral of the story is... WTF MICROSOFT?

I know firsthand there is no such thing as perfect copy protection, but this is just plain ridiculous.

What we really need is for apps to be able to use our own copy protection schemes... you know, like the good web-based app stores out there.

EDIT: l3v5y has also succeeded in doing something similar, and it seems the WMPowerUser admin also found another easy way to do it... Yay, and it ain't even out yet!
__________________
BLOG - TWITTER

E-Mobile: EM-ONE
HTC: Wizard x2, Kaiser, Touch, Diamond, Pro, HD x2, Diamond 2, Pro 2 x2, HD2, Dream, Hero
Samsung: i780, i900 x2, i8000 x2, b7320, b7330, b7620 x2
BB: Storm

WMWifiRouter, KaiserTweak, FPU Enabler, MultASync, WMRegOptimizer, CFC+GUI, TF3D+v2 ports, Kaiser 3D, Omnia II GLESv1, ICSInstall, DriverWiz, WMLongLife, GfxBoost, MarketPlaceRegionSwitch, ETC!

IRC: #XDA-Devs, #WMWifiRouter, #EliteTeam @ irc.freenode.net

Donate if you like what I do! (link)


Last edited by Chainfire; 5th October 2009 at 10:19 PM..
Reply With Quote
Sponsored Links

  #2  
Old 5th October 2009, 07:45 PM
Blade0rz Blade0rz is online now
Senior Member
 
Join Date: Apr 2008
Location: Belfast
Posts: 228
Default

Not even 12 hours after launch...that's pretty quick
__________________
Device: HTC HD2 "Leo"
ROM: Miri v1.5 (23518)
Radio: 2.06.50.04
SPL: Cotulla/Bepe HSPL

IMDb Mobile
Reply With Quote

  #3  
Old 5th October 2009, 07:49 PM
maati maati is offline
Senior Member
 
Join Date: Aug 2006
Posts: 790
Default

Oh noes.... that's not good!
Imagine Microsoft reads this and decides to offset tomorrow's Marketplace launch...
Or even worse, Microsoft launches the Marketplace but developers decide not to submit their apps because they're concerned that their apps get pirated.
Reply With Quote

  #4  
Old 5th October 2009, 07:53 PM
ratchetnclank ratchetnclank is offline
Senior Member
 
Join Date: Nov 2008
Posts: 162
Default

Thats what happens when devices aren't locked down.
__________________
Proud Owner Of XPERIA X1i
Touch it 4.5 rom
Reply With Quote

  #5  
Old 5th October 2009, 08:06 PM
mr_Ray mr_Ray is offline
Senior Member
 
Join Date: Feb 2006
Posts: 303
Default

That sounds bad, but it's really no different to how things are today. Perhaps there are some apps that have more security than either nothing or a serial key, but none that I use have anything more sophisticated.

Even as a developer myself, I'd easily take this over some DRMfest.
__________________
Current - HTC HD2 (Leo)
Retired - Raphael, Hermes, Wizard, Loox 720, iPAQ 2210
Reply With Quote

  #6  
Old 5th October 2009, 08:09 PM
Farmer Ted Farmer Ted is offline
Senior Member
 
Join Date: Nov 2008
Posts: 1,266
Default

So, if I'm reading this correctly, when you buy something from marketplace it's not tied into your username with a password like most apps? Instead, you just buy it and it installs the app, but doesn't give you a cab? Yeah, I don't think it's that hard to work around that and get a cab for yourself. Some of the cheaper apps at Handango are like that. Can you re-download an app onto a new device or if you have to hard reset, and is it free or do you need to buy download protection like form Handango?
__________________
ROM: Retro ROM
Radio: 1.17.25.09
Reply With Quote

  #7  
Old 5th October 2009, 08:52 PM
loomx loomx is offline
Senior Member
 
Join Date: Apr 2005
Posts: 348
Default

Good, copy protection pisses me off, all it does is piss of the genuine users. We have to deal with codes and activation to be legit, while people getting it free, just click here and there, copy a code here and huzah.

Copy protection doesnt work, someone will always find a way around it. Unless its linked to a windows live profile/xbox live profile. Which I can see probably happening when they bring out Zune on mobile phones, which sounds like it might be sooner rather than later!

Last edited by loomx; 5th October 2009 at 08:59 PM..
Reply With Quote

  #8  
Old 5th October 2009, 09:54 PM
l3v5y's Avatar
l3v5y l3v5y is offline
Moderator
 
Join Date: Sep 2007
Location: Bristol
Posts: 7,149
Default

I did something like this earlier... MS haven't quite got security done yet, though my guess is the iPhone is no better...
__________________


My ROMs:
Diamond 28217/23529 + kitchen
Leo 28014 ROM - also, WMPowerUser HD2 ROM

My devices:
HTC Prophet - 23529 Light
HTC Diamond - 23529 Light
HTC Leo - getting repaired (for £155 )

Reply With Quote

  #9  
Old 6th October 2009, 12:17 AM
vexingv vexingv is offline
Member
 
Join Date: Oct 2008
Posts: 82
Default

I'm really surprised by the lack of any drm; what's the point of signing in w/ one's Windows Live account? The easiest thing to do is to associate valid applications w/ one's Window's Live account. That's what itunes does for music at least (I don't know about apps as I don't have an iphone/ipod touch). Of course, what would happen is that an internet connection of some form is needed when the application is first installed, which could become inconvenient.
Reply With Quote

  #10  
Old 6th October 2009, 12:54 AM
alabij alabij is offline
Senior Member
 
Join Date: Mar 2006
Location: Atlanta
Posts: 198
Default

The truth of the matter is that the percentage or ratio of people who would bother to do this is pretty small. Most WinMo usersbarely even know how to setup e-mail not to mention install a cab file.

Most of the people in this forum already know how and where to get cracked apps or warez if they wanted too. I don't see this so called "flaw" as being an issue to MS or developers.
__________________
Kyocera QCP 6035 -Sprint - 1.5 yr
T-Mobile PPCPE - T-Mobile - 1.5 yr
HP Ipaq 6315 - T-Mobile - 1 yr
T-Mobile MDA - T-Mobile - 1.5yr
Sprint Mogul - Sprint - 1 yr
Samsung EPIX - AT&T - 3 mts
AT&T Fuze - AT&T - 3 mts
SE XPERIA X1 - AT&T - 6 mts
Touch Pro 2 - T-Mobile - current
===================
Where there is life there is hope
Reply With Quote

Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 07:34 PM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.