Nokia Engineer Shares How to Pirate Games From Windows 8 Store
December 11, 2012 12:44 PM
comment(s) - last by
Microsoft is not going to be happy about this
, an engineer working on Finnish phonemaker Nokia Oyj.'s (
) Windows Phone team, has made the curious decision of going public with details of security flaws in partner Microsoft Corp.'s (
) Windows 8, which allow users to pirate games.
Windows 8 users can grab games via
. Paid titles typically come with a "Trial" option, which allow users to play a level or two of the game, before being prompted to purchase the title if they want to keep playing. The trial process is controlled by a Microsoft API.
But Mr. Angel reveals a fatal flaw in the scheme: Microsoft stores the key/hash in plaintext and the algorithm to encrypt/decrypt the data next to the app itself. In other words, while not for the novice, power users can write small programs to decrypt the program's permissions, write new permissions to make the game look legitimately purchased, and then re-encrypt the permissions.
By exploit the flaws users cannot only get games for free, but they can rid themselves of ads, albeit in a somewhat unethical manner.
Cut The Rope
Microsoft Windows Store apps are vulnerable to piracy due to poor security implementation. [Image Source: ZDNet]
The flaws are a big deal as they could rob developers of essentially every way to monetize their content on Windows Store. Microsoft has not yet responded on these issues.
Mr. Angel's page has been overloaded with traffic (or maybe yanked after Nokia brass realized what he posted) and is
. However, a cached version is
. Just remember, readers, every time you pirate a game another kitten dies.
On his Twitter account, responding to criticism about the post he writes, "These are fundamental flaws in the app platform, not individual apps. No secure storage, no wrote protection, etc.... Offline activation & execution mandate secure local storage. That's how apps differ from fully connected web pages."
The issues echo those of Apple, Inc. (
experienced rampant piracy
in the early days of the Mac App Store, due to poor rights management implementation. The take-home message is that it's a lot harder to manage apps on a personal computer, where users have full access to the files, versus on a smartphone, where user access to the file system is limited.
Justin Angel [Google Cache]
This article is over a month old, voting and posting comments is disabled
Does it matter?
12/11/2012 6:50:42 PM
Compared to piracy on Android (and even Jailbroken iPhones), I would imagine this is just a drop in the bucket.
"This is about the Internet. Everything on the Internet is encrypted. This is not a BlackBerry-only issue. If they can't deal with the Internet, they should shut it off." -- RIM co-CEO Michael Lazaridis
Microsoft to Give Windows Store Developers More Money Than Competitors
December 7, 2011, 6:01 PM
As Apple Boasts of One Million Downloads for Mac App Store, Piracy Already a Problem
January 7, 2011, 11:00 AM
Quick Note: With Windows 10, the Windows Source Hits Build 10,000
January 20, 2015, 2:05 PM
Microsoft Kills "Mainstream Support" Windows 7
January 13, 2015, 1:01 PM
Windows 10's "Spartan" IE11 Variant Will Get Firefox/Chrome-Like Extensions
December 30, 2014, 1:30 PM
Cortana, Xbox App, OneDrive Apps/Settings Backup Added to Windows 10 Build
December 15, 2014, 3:43 PM
Quick Note: Windows Phone Finally Gets Candy Crush Saga
December 13, 2014, 2:03 PM
Next Windows 10 Test Build Likely to Land on Jan. 21, Press Event Announced
December 11, 2014, 5:49 PM
Most Popular Articles
Microsoft Shows Off Latest Windows 10 Build, Preps it for Next Week Release
January 21, 2015, 2:57 PM
Under the Hood: How DirectX 11.3 and 12 Will Supercharge Windows 10 Gaming
January 23, 2015, 12:34 PM
IDC: 2014 Sales Show PC Isn't Dead, But Desktop May be Dying
January 19, 2015, 1:50 PM
Police are Using New Handheld Radar Sensors to Peer Into Houses w/out Warrant
January 20, 2015, 1:35 PM
Report: HTC One M9 (2015) is Tied to Under Armour-Powered HTC Smartwatch
January 19, 2015, 11:10 AM
Latest Blog Posts
Sceptre Airs 27", 120 Hz. 1080p Monitor/HDTV w/ 5 ms Response Time for $220
Dec 3, 2014, 10:32 PM
Costco Gives Employees Thanksgiving Off; Wal-Mart Leads "Black Thursday" Charge
Oct 29, 2014, 9:57 PM
"Bear Selfies" Fad Could Turn Deadly, Warn Nevada Wildlife Officials
Oct 28, 2014, 12:00 PM
The Surface Mini That Was Never Released Gets "Hands On" Treatment
Sep 26, 2014, 8:22 AM
ISIS Imposes Ban on Teaching Evolution in Iraq
Sep 17, 2014, 5:22 PM
More Blog Posts
Copyright 2015 DailyTech LLC. -
Terms, Conditions & Privacy Information