Slashdot Mirror


Controversial StarForce Copy Protection Creators Quizzed

Thanks to FiringSquad for its interview with the creators of the StarForce copy protection scheme for PC videogames. The author explains: "In recent months there's been an increasing awareness and alarm over StarForce copy protection. It's actually a driver that installs itself with the [Windows] games that come shipped with it, and originally it didn't uninstall when the game was uninstalled." StarForce's Abbie Sommer argues the advantages of "driver-level copy protection", explaining: "The drivers are what prevents the use of kernel debugger utilities such as SoftICE, Cool Debugger, Soft Snoop etc. Also the drivers prevent emulators from spoofing a drive, and thwart burning tools such as Alcohol 120%." The author concludes by injecting a little personal opinion into the mix, arguing: "PC games will never go away, but if the market keeps shrinking due to the increasing ease of piracy... then the number and quality of games will almost certainly decrease."

10 of 952 comments (clear)

  1. Re:missed something by JamesKPolk · · Score: 4, Informative

    They missed nothing.

    Read the StarForce webpage. Their goal isn't to stop determined experts, since that's impossible to do when the code runs on the adversary's computer. Their goals are to stop "industrial software piracy" (read: businesses buying one CD for all the computers in the office) and "casual copying" (read: Joe Teenager giving a copy to his friend Fred Teenager).

    If these people are thwarted then their mission is accomplished.

  2. Re:Brad Wardell's thoughts by Balorn · · Score: 5, Informative

    And for the lazy (or those behind an abusive proxy server):

    What concerns me about the PC game market is that I'm seeing publishers blaming everything but the real causes for PC game sales decline. It's not piracy. And it's not that everyone just prefers to play games in front of a TV. It's the games. It's the way people who buy PC games get treated.

    It's not like piracy on consoles doesn't exist either. Yet their sales are doing great.

    For a PC game I'm expected to keep track of a serial number -forever-, keep the CD in the drive despite it using gigs of hard drive space, AND I'm expected to have to download patches all too often just to make the game work correctly. That's assuming your computer works with the CD ROM protection in the first place.

    If your competitor (console games in this case) doesn't put you through that hassle, then some people are going to choose that. And others will simply not purchase games.

    People WILL buy stuff if you give them a reason. If you make it more rewarding to purchase it rather than pirating it then you'll get the sale.

    I'm sure, for example, that Object Desktop gets pirated. The whole thing is probably only 50 megs in size as a file. But it doesn't get pirated that much and we sell millions of dollars worth -one copy at a time- over the Internet. Each year. For years. Why? Because we give users a reason to purchase it. We keep updating it on a regular basis which adds value to it. We provide a way to seamlessly get those updates for verified customers which gives an convenience incentive to be a customer.

    As some of you know, we expanded the Drengin.net gaming network to TotalGaming.net. Basically, we moved the gaming network beyond being just Stardock games and into putting third party games on there. You can imagine the effort convincing some of the publishers of putting games on here that don't have any digital rights management, no time outs, no "renting", etc.

    It's not, however, that we want to do that because we're "nice guys". It's business. Just business. People just want to get the product/service and not be hassled about it. I buy WizBang IV and I expect to be able to install it to my regular machine and if necessary, put it on my laptop. And you know what? If I have it on my laptop I want that drive bay used for an extra battery, not used for a battery sucking CD drive that's in there just because the game checks to see if I have the CD in.

    At the end of the day, I'm just wondering why the industry is so afraid of some 15 year old kid downloading PC games off of Bit Torrent or whatever instead of looking at the demographics of PC gamers (which are older and tend to have more money) and start catering more to them -- people who have money and don't have time to be jerked around with nonsense.

    When I see "piracy" being blamed for sales decline (and I really think that other factors such as lack of mega releases this year and the migration to MMORPGs need to be considered heavily) it worries me. It worries me that publishers aren't really taking these other issues seriously and as a result are making development plans based on faulty data. After all, one can only imagine the justification for the PC port of Spider-Man II (as one example).

    --
    http://www.balorn.net/
    ?
  3. Safedisk by Anonymous Coward · · Score: 5, Informative

    Yeah - I'll correct that.

    Safedisk is a PAIN to implement.
    It works by changing the geometry of the disc - the tracks are actally spread out more (it makes it look a bit like the gaps between songs on old vinyl disks)

    Then it measures the TIME it takes the drive to seek across these areas compared to the time it takes to seek across normal areas.

    Their driver is very flaky, due to the large numbers of strange drives it has to cope with. This in turn makes it very difficult to build a drive which co-operates with it reliably.

    Most disks produced with safedisk are within the spec - the spec just says that the track density must lie within such and such limits (I'd have to look them up) - they are expected to vary due to quality of disk and so forth. They AREN'T expected to vary on a single disk (much) - but nothing says that they can't. So they are in the CD/DVD spec.

    The audio protections usually used fall into two camps. The polite camp simply has an audio session and a data session, and relies upon windows preferring to show the user the data session. These are within the redbook spec, and easy to break.

    The slightly dodgier protection issues the same track number to tracks in both sessions, and relies upon data drives mounting the last session first and audio drives mounting the first session first. This DOES break the redbook spec. Quite horribly.

  4. Re:And punish legitimate users? by Anonymous Coward · · Score: 5, Informative

    Has anyone found/compiled a list of games that use this copy protection so that we can vote with our wallets?

    There's an entire website devoted to that now; It's here.

  5. Re:Games List ? by shepd · · Score: 5, Informative

    Thanks for the list. According to the interviewee, no StarForce games are cracked.

    According to google, cracks appear to exist for:

    Breed
    Cycling Manager 3
    Dead to Rights
    Fire Department
    Gangland
    Korea Fogotten Conflict
    Prince of Persia Sands of Time
    Rally Championship Xtreme
    Restaurant Empire
    Runaway A Road Adventure
    Soldiers Heroes of World War 2
    Track Mania
    XIII
    X2 The Threat

    Now, being that I don't want to get my system all infected with virus laden garbage, I'm not going to download any of the cracks I found. I wonder how many work? Perhaps none of them. Or perhaps they all do. In that case, We have a 58% success record. That's not worthy of saying your protection is crack proof, IMHO.

    --
    If you could be told what you can see or read, then it follows that you could be told what to say or think - BoC
  6. StarForce stole technology? by jdonnis · · Score: 5, Informative

    Persistent rumours in the copy protection industry tells that the technology used in StarForce3 is actually reverse engineered from CD-Cops http://www.linkdata.com/index.htm#cdcops, by StarForce's russian team.

    This is supposed to be one of the reasons the pricing of the StarForce3 systems does not reflect the perceived development costs for the technology.

  7. Re:And punish legitimate users? by leeroybrown · · Score: 5, Informative

    Perhaps you should try the the 'removal tool':

    sfdrvrem.zip

  8. More info on Starforce protection by MtlDty · · Score: 5, Informative

    Copy/paste from www.theisonews.com

    Im by no means a l33t hax0r but I know my way around icing/dumping procedures and messed around with SF3 a bit.

    First of all, whenever someone writes SF3 uses physical fingerprints, STOP READING - it DOES NOT, and yes a lot of wannabe experts will say that. If you wanna know how the SF3 discs are produced I can write another post here, but for now I'll tell you about the protection itself;

    The Devil (=StarForce3) is INSANELY coded to avoid debugging, and by INSANELY I mean NOTHING COMES CLOSE : you can find over 200 RDTSCs on a SINGLE procedure. WTF is a RDTSC? Its an instruction to read the time stamp on the CPU, that is, they use it to MEASURE the amount of time some routine takes to complete: if you debug+trace the operations, stopping them before they are complete, the reply from the CPU will tell the app they are taking a long time to finish - and you get rebooted while the SF3 creators laugh at you.

    The most low-level interrupts cant be traced as well since the SF3 driver replaces them with their own evil, custom, devilish, encrypted drivers - and thats where the problems for LEGIT buyers start, drivers messing around with system resources = always dangerous. Theres even a INT 2E routine used into SF3, thats an undocumented but widely known backdoor to run COMMAND.COM-based programs!! ... Also kind of a cheap trick, it leaves me no doubt the creators themselves were/are hella good crackers.

    What happens then is, one would actually need to recreate the drivers removing all those ( hundreds of ) evil anti-debugging checks - that would take a *LOT* of time/work already, considering the drivers are encrypted as and when executing - to ONLY THEN start working on breaking the games' protection itself. And for every new SF3 version/update/whatever ( = another game) , you would have to do everything again. Of course after ending up with a working crack, you can remove the "custom driver" thing and just emulate everything with an .exe file - but that would take more work again.

    Truth is, it becomes much more of a challenge than a way to play the game for free, since its much (much much) easier - even cheaper considering the hours a cracker would spend starforcing - to simply buy the damn original.

  9. Re:And punish legitimate users? by Rew190 · · Score: 4, Informative

    Doom 3 wouldn't let me play until I had deleted CloneCD. There might be a setting I could've just turned off, but when I first got the game (the day it came out), it wasn't clear what it was. Not cool. I uninstalled anyhow (this isn't a huge loss, just a pain in the ass), but the whole thing left a bad taste in my mouth.

  10. Re:And punish legitimate users? by ultranova · · Score: 4, Informative

    When you buy from a travel agent, you don't own the building you'll spend your weeks vacation in, nor the plane that takes you there.

    That's because the travel agent is a service provider and not a store. They don't sell me any items there; they simply agree to do something for me (namely, arrang the aeroplane seat and hotel room) in exchange for money. Software store, on the other hand, sells software on nice, shiny, oversized cardboard boxes (or nice, shiny, small and handy plastic DVD packages).

    If you walk into an insurance store...

    You mean an office of an insurance company ? Presumably I want to enter into a contract with them, in which I pay them money (usually in a monthly basis) and they pay me money in certain conditions (usually if something bad happens). Why you compare an office for signing contracts to a store that sells objects is beyond me.

    If you walk into a mobile phone store...

    I walked out with a mobile phone. It sits on my bookshelf currently. It's mine, all mine, to do with whatever I please.

    Why ? What did you expect ?

    As a side note, you shouldn't confuse the mobile phone that I bought from the mobile phone store with the contract I entered with a mobile phone service provider, which allows me to use the service providers network for a monthly fee. While I did sign the contract in the same place as I bought the phone (a matter of convenience), the two events are completely separate events.

    When you buy a computer game (or music), you are buying the physical CD, the box it came in, some assorted bits of paper inside the box, and a LICENSE to use the software (or music).

    No, I'm buying the box and everything it contains, including the physical media and whatever data it contains. Since I own said data, I don't need any license to use it in whatever way I please. The only limitation is that I can't distribute copies of it, since I'm not a copyright holder (but I can wallpaper the rooms of my own home with copies if I so wish - just as long as I don't give any away).

    Do not confuse copyright with ownership; they are not the same thing. A writer might own the copyright to a book, but that doesn't change the fact that this particular copy is mine.

    Now, there has been some typical lawyer tricks about needing a specific license to use computer programs since I'm making a temporary copy into the memory of the machine (which is absurd; if I read something, it gets copied to the back of my retinas and then to the back of my skull where the vision-related brain centers are, and presumably copied forward in some form to my thoughts, where it affacts my every action somewhat (meaning they contain some information about the book); so do I need a license to read a book ?), but, as I already said, the copyright law only forbids distribution of copies, not making of them. Furthermore, the Finnish law specifically grants me a permission to change the data I've purchased into whatever form is most convenient for me (in this case, from the packed installation files in the CD to the run-time data and code structure in the main memory).

    Oh, you were talking about the US law ? Sucks to be American ;).

    --

    Forget magic. Any technology distinguishable from divine power is insufficiently advanced.