<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/">
<channel>
<title>Techdirt. Stories filed under &quot;uplay&quot;</title>
<description>Easily digestible tech news...</description>
<link>http://www.techdirt.com/</link>
<language>en-us</language>
<image><title>Techdirt. Stories filed under &quot;uplay&quot;</title><url>http://www.techdirt.com/images/td-88x31.gif</url><link>http://www.techdirt.com/</link></image>
<item>
<pubDate>Wed, 10 Apr 2013 05:45:56 PDT</pubDate>
<title>Ubisoft uPlay Launcher Exploit Strips DRM From All Publisher's Games</title>
<dc:creator>Timothy Geigner</dc:creator>
<link>http://www.techdirt.com/articles/20130409/13010922637/ubisoft-uplay-launcher-exploit-strips-drm-all-publishers-games.shtml</link>
<guid>http://www.techdirt.com/articles/20130409/13010922637/ubisoft-uplay-launcher-exploit-strips-drm-all-publishers-games.shtml</guid>
<description><![CDATA[ <p>
<a href="http://www.techdirt.com/blog/?company=ubisoft">Ubisoft's</a> history of DRM use has been...interesting. One could nearly write an entire book on how to fail at DRM using nothing but examples from the company. DRM that allows hackers to take <a href="http://www.techdirt.com/articles/20120730/04291119876/ubisoft-drm-fiasco-allows-any-website-to-take-control-your-computer.shtml">control</a> of gamers' machines. DRM <a href="http://www.techdirt.com/articles/20120203/07550617650/ubisoft-cuts-off-legit-players-with-drm-server-migration-pirates-play.shtml">punishing</a> only paying customers when Ubisoft decides to move their servers. DRM that is, seriously, comprised of f$#%ing <a href="http://www.techdirt.com/articles/20101203/09510612115/ubisofts-new-drm-vuvuzelas.shtml">vuvuzelas</a>. What you'll notice as a trend in these examples, however, is that at least Ubisoft was content to punish only their own customers or themselves, depending on the situation.
<br /><br />
Not so, any longer. Their uPlay client for PCs was built so poorly that a simple tool developed by hackers can fool the client into thinking users already own copies of games, allowing for completely <a href="http://paritynews.com/security/item/950-ubisoft-uplay-launcher-hack-leads-to-far-car-3-blood-dragon-leak">DRM-free versions of games from <i>other</i> publishers</a> to be downloaded for free from their platform. As an apparent sign of solidarity by Ubisoft, they also managed to offer up their own unreleased game via the exploit as well.
<blockquote>
<i>The vulnerability is allegedly present in the uPlay launcher, which when exploited gives DRM free access to gaming titles from almost all game publishers including the likes of EA Games and Square Nix. Far Cry 3: Blood Dragon, which hasn&rsquo;t been released yet, is lying on Ubisoft servers which hackers have downloaded. As a proof of the exploit, hackers even posted an 1 hour 30 mins <a href="http://www.dailymotion.com/video/xyv493_far-cry-3-blood-dragon-leaked_videogames">long footage of the game</a>.</i>
</blockquote>
Typically, when one does something over a long period of time, one gets better at it. Ubisoft appears to be an anomaly in this respect, going so far backwards on the practice of DRM that even their own client software can strip it out with but a little assistance from hackers. Nevermind how stupid and useless DRM is to begin with; now publishers can't even trust the software that is supposed to deliver it. With enemies of DRM hidden everywhere, even in inanimate software, perhaps it's time to give it up entirely.
</p><br /><br /><a href="http://www.techdirt.com/articles/20130409/13010922637/ubisoft-uplay-launcher-exploit-strips-drm-all-publishers-games.shtml">Permalink</a> | <a href="http://www.techdirt.com/articles/20130409/13010922637/ubisoft-uplay-launcher-exploit-strips-drm-all-publishers-games.shtml#comments">Comments</a> | <a href="http://www.techdirt.com/articles/20130409/13010922637/ubisoft-uplay-launcher-exploit-strips-drm-all-publishers-games.shtml?op=sharethis">Email This Story</a><br />
 ]]></description>
<slash:department>oopsie</slash:department>
<wfw:commentRss>http://www.techdirt.com/comment_rss.php?sid=20130409/13010922637</wfw:commentRss>
</item>
<item>
<pubDate>Mon, 30 Jul 2012 04:38:01 PDT</pubDate>
<title>Ubisoft DRM Fiasco: Allows Any Website To Take Control Of Your Computer</title>
<dc:creator>Mike Masnick</dc:creator>
<link>http://www.techdirt.com/articles/20120730/04291119876/ubisoft-drm-fiasco-allows-any-website-to-take-control-your-computer.shtml</link>
<guid>http://www.techdirt.com/articles/20120730/04291119876/ubisoft-drm-fiasco-allows-any-website-to-take-control-your-computer.shtml</guid>
<description><![CDATA[ It's been nearly seven years since the great <a href="http://www.techdirt.com/articles/20051101/1514209.shtml">Sony rootkit fiasco</a>, when it was discovered that Sony Music was using some DRM on its CDs that self-installed a rootkit (without letting users know) that had all sorts of security problems and vulnerabilities.  The company took a massive hit for this, and you would think that others would be a lot more careful with their own DRM.  You would think.  But, then you don't know Ubisoft.  The vast majority of times we've ever <a href="http://www.techdirt.com/search.php?cx=partner-pub-4050006937094082%3Acx0qff-dnm1&cof=FORID%3A9&ie=ISO-8859-1&q=ubisoft">discussed Ubisoft</a> in these pages, it's been because the company was doing something ridiculous with DRM.  The company loves its DRM and seems to refuse to recognize that pissing off legitimate customers isn't such a good idea.
<br /><br />
So would it come as any surprise that it may now be facing a "rootkit moment" of its own?
<br /><br />
As a whole bunch of folks have been submitting, some hackers have figured out that Ubisoft's Uplay DRM <a href="http://www.rockpapershotgun.com/2012/07/30/psa-possible-security-risk-in-some-ubisoft-pc-games/" target="_blank">appears to install an unsecure browser plugin</a>.  The details came out over the weekend, first on a <a href="http://seclists.org/fulldisclosure/2012/Jul/375" target="_blank">security mailing list</a>, and were then followed up with some <a href="http://news.ycombinator.com/item?id=4311264" target="_blank">test exploit code</a> posted to Hacker News.  
<br /><br />
Basically, it appears that Ubisoft's DRM is installing an accidental backdoor that makes it possible for <i>any website</i> to effectively take control over your computer.  That's... uh... pretty bad.
<br /><br />
From the details, the real problem sounds to be one of exceptionally poor coding, rather than maliciousness.  Basically, they wanted to let you launch the game via a website, but failed to limit it to just the game -- meaning that a site can make use of the plugin to basically do a whole bunch of stuff on your computer (including things you don't want it to do).  The browser plugin is easy to remove (and you should, um, immediately, if you've installed any Ubisoft games), so it's not quite as messy as Sony's rootkit, which was pretty deeply buried.  But it's still really bad.
<br /><br />
Yet another case of DRM really making life difficult for <i>legitimate customers who paid money for your product</i>.  When will companies figure out that DRM does nothing to stop piracy, but makes life really difficult for the people who actually give you money?<br /><br /><a href="http://www.techdirt.com/articles/20120730/04291119876/ubisoft-drm-fiasco-allows-any-website-to-take-control-your-computer.shtml">Permalink</a> | <a href="http://www.techdirt.com/articles/20120730/04291119876/ubisoft-drm-fiasco-allows-any-website-to-take-control-your-computer.shtml#comments">Comments</a> | <a href="http://www.techdirt.com/articles/20120730/04291119876/ubisoft-drm-fiasco-allows-any-website-to-take-control-your-computer.shtml?op=sharethis">Email This Story</a><br />
 ]]></description>
<slash:department>punishing-your-paying-customers</slash:department>
<wfw:commentRss>http://www.techdirt.com/comment_rss.php?sid=20120730/04291119876</wfw:commentRss>
</item>
</channel>
</rss>