<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
    <title>Code Confidential</title>
    
    <link rel="hub" href="http://hubbub.api.typepad.com/" />
    <link rel="alternate" type="text/html" href="http://vilabs.typepad.com/vilabs/" />
    <id>tag:typepad.com,2003:weblog-369841</id>
    <updated>2009-10-26T15:01:15-04:00</updated>
    <subtitle>Discussions on piracy business intelligence, software protection, application hardening, reverse engineering, code theft and tampering from the team at V.i. Labs.</subtitle>
    <generator uri="http://www.typepad.com/">TypePad</generator>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/ViLabs" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><entry>
        <title>Seminar on Software Piracy Risks and Strategies</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ViLabs/~3/4TZFaWNfmhk/seminar-on-software-piracy-risks-and-strategies.html" />
        <link rel="replies" type="text/html" href="http://vilabs.typepad.com/vilabs/2009/10/seminar-on-software-piracy-risks-and-strategies.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453976a69e20120a678245e970c</id>
        <published>2009-10-26T15:01:15-04:00</published>
        <updated>2009-10-26T14:57:03-04:00</updated>
        <summary>We were in San Francisco at The Palace Hotel last week for a private luncheon and seminar on software piracy risks and strategies. The hour long session focused on: V.i. Labs’ software piracy research for high value applications Aggregate results...</summary>
        <author>
            <name>Michael Goff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Business Intelligence" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Piracy" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Revenue Recovery" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://vilabs.typepad.com/vilabs/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;span style="text-decoration: underline;"&gt;&lt;/span&gt;&lt;a href="http://vilabs.typepad.com/.a/6a00d83453976a69e20120a678665c970c-pi" style="float: right;"&gt;&lt;img alt="Banner" class="asset asset-image at-xid-6a00d83453976a69e20120a678665c970c " src="http://vilabs.typepad.com/.a/6a00d83453976a69e20120a678665c970c-150wi" style="margin: 0px 0px 5px 5px; width: 150px;"&gt;&lt;/img&gt;&lt;/a&gt; We were in San Francisco at The Palace Hotel last week for a private luncheon and seminar on software piracy risks and strategies.&lt;/p&gt;&lt;p&gt;The hour long session focused on:&lt;/p&gt;&lt;ul&gt;&#xD;
&lt;li&gt;V.i. Labs’ software &lt;a href="http://www.vilabs.com/offers/Software_Piracy_Report_2009_pt1.aspx" target="_blank"&gt;piracy&lt;/a&gt; &lt;a href="http://www.vilabs.com/offers/Software_Piracy_Report_2009_pt2.aspx" target="_blank"&gt;research&lt;/a&gt; for high value applications&lt;/li&gt;&#xD;
&lt;li&gt;Aggregate results and data from our deployed customers using piracy detection and reporting&lt;/li&gt;&#xD;
&lt;li&gt;New features and benefits in &lt;a href="http://www.vilabs.com/press/PR-091609-CodeArmor_Intelligence_Gets_Even_Smarter.aspx" target="_blank"&gt;CodeArmor Intelligence 2.0&lt;/a&gt; which give ISVs the ability to identify and report on unlicensed use of software&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;Our guests included representatives from various software vendors who are responsible for licensing, compliance or piracy efforts, and their feedback was overwhelmingly positive - especially the aggregate data and revenue recovery results from our deployed customers.&lt;/p&gt;&lt;div style="text-align: center;"&gt;&lt;a href="http://vilabs.typepad.com/.a/6a00d83453976a69e20120a6787784970c-popup" onclick="window.open(this.href,'_blank','scrollbars=no,resizable=yes,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" style="display: inline;"&gt;&lt;img alt="Infringements" class="asset asset-image at-xid-6a00d83453976a69e20120a6787784970c " src="http://vilabs.typepad.com/.a/6a00d83453976a69e20120a6787784970c-320wi" style="border: 0px dotted black;" title="Infringements"&gt;&lt;/img&gt;&lt;/a&gt; &lt;br&gt;&lt;/div&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;While it does seem odd to blog about an event and not include any photos of the audience, we do, of course, respect their privacy given the nature of the topics discussed.&lt;/p&gt;&lt;p&gt;Given their response to the information presented, we are happy to &lt;strong&gt;schedule private briefings&lt;/strong&gt; with qualified software vendors to review this new material - just email me at mgoff [at] vilabs.com.&lt;/p&gt;&lt;p&gt;- Michael&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=4TZFaWNfmhk:B6bERHocW1E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=4TZFaWNfmhk:B6bERHocW1E:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=4TZFaWNfmhk:B6bERHocW1E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=4TZFaWNfmhk:B6bERHocW1E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=4TZFaWNfmhk:B6bERHocW1E:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=4TZFaWNfmhk:B6bERHocW1E:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=4TZFaWNfmhk:B6bERHocW1E:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ViLabs/~4/4TZFaWNfmhk" height="1" width="1"/&gt;</content>


    <feedburner:origLink>http://vilabs.typepad.com/vilabs/2009/10/seminar-on-software-piracy-risks-and-strategies.html</feedburner:origLink></entry>
    <entry>
        <title>Software Piracy Research - Who Knew?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ViLabs/~3/yYUUSXFcd2Y/software-piracy-research-who-knew.html" />
        <link rel="replies" type="text/html" href="http://vilabs.typepad.com/vilabs/2009/10/software-piracy-research-who-knew.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453976a69e20120a63b16de970c</id>
        <published>2009-10-14T09:44:32-04:00</published>
        <updated>2009-10-14T09:44:32-04:00</updated>
        <summary>As frequent readers know, we do a lot of original research on software piracy to better understand and quantify the risks to software vendors. In July, we issued a report focused on a review of crack releases and piracy enablement...</summary>
        <author>
            <name>Michael Goff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Business Intelligence" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Piracy" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://vilabs.typepad.com/vilabs/">&lt;p&gt;&lt;a href="http://vilabs.typepad.com/.a/6a00d83453976a69e20120a5e4a9fd970b-pi" style="float: right;"&gt;&lt;img alt="Pirate-q" class="asset asset-image at-xid-6a00d83453976a69e20120a5e4a9fd970b " src="http://vilabs.typepad.com/.a/6a00d83453976a69e20120a5e4a9fd970b-120wi" style="margin: 0px 0px 5px 5px;"&gt;&lt;/img&gt;&lt;/a&gt; As frequent readers know, we do a lot of original research on software piracy to better &lt;strong&gt;understand and quantify the risks&lt;/strong&gt; to software vendors. In July, we issued a &lt;a href="http://vilabs.typepad.com/vilabs/2009/07/software-piracy-risk-assessment-report.html" target="_blank"&gt;report focused on a review of crack releases and piracy enablement approaches&lt;/a&gt;. We followed up in September with a&lt;a href="http://vilabs.typepad.com/vilabs/2009/09/new-version-of-codearmor-intelligence-real-data-and-new-piracy-research.html" target="_blank"&gt; report on software piracy distribution channels and networks&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Our September research was the focus of recent articles on &lt;a href="http://www.computerworld.com/s/article/9139210/What_s_replacing_P2P_BitTorrent_as_pirate_hangouts_" target="_blank"&gt; Computerworld by Eric Lai&lt;/a&gt; and &lt;a href="http://www.channelregister.co.uk/2009/10/13/warez_hosting/" target="_blank"&gt;The Register by John Leyden&lt;/a&gt;. Not surprisingly, many of the comments to the articles (and on &lt;a href="http://news.slashdot.org/story/09/10/10/2312210/Warez-Moving-From-BitTorrent-to-Conventional-Hosting-Services" target="_blank"&gt;Slashdot&lt;/a&gt;) were variations on the theme of &lt;strong&gt;"This is not news"&lt;/strong&gt; (other comments weighed the relative merits of different channels for obtaining unlicensed software, and some defended/rationalized the practice of obtaining software without paying for it).&lt;/p&gt;&lt;p&gt;Our response? Of course this is not news to the people who have been downloading unlicensed software from these channels! &lt;strong&gt;It is, however, important for the software vendor community to understand the wide range of distribution channels where their unlicensed software can be downloaded.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;More than one commenter echoed our opinion that trying to take down file sharing sites is like playing "&lt;a href="http://en.wikipedia.org/wiki/Whack_a_mole" target="_blank"&gt;whack-a-mole&lt;/a&gt;" - even in the face of the &lt;a href="http://www.channelregister.co.uk/2009/10/14/bsa_piracy_takedown_efforts/" target="_blank"&gt;BSA doubling the number of takedown notices it had issued in the first half of 2009&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Given this, a &lt;a href="http://www.vilabs.com/solutions/antipiracy.aspx" target="_blank"&gt;piracy business intelligence&lt;/a&gt; approach makes more sense and is more effective. By leveraging these decentralized and well organized piracy distribution channels, vendors are recovering license revenue from the businesses that are actually using their software without paying for it.&lt;/p&gt;&lt;p&gt;-Michael&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=yYUUSXFcd2Y:js7jYaZQ0nY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=yYUUSXFcd2Y:js7jYaZQ0nY:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=yYUUSXFcd2Y:js7jYaZQ0nY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=yYUUSXFcd2Y:js7jYaZQ0nY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=yYUUSXFcd2Y:js7jYaZQ0nY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=yYUUSXFcd2Y:js7jYaZQ0nY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=yYUUSXFcd2Y:js7jYaZQ0nY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ViLabs/~4/yYUUSXFcd2Y" height="1" width="1"/&gt;</content>


    <feedburner:origLink>http://vilabs.typepad.com/vilabs/2009/10/software-piracy-research-who-knew.html</feedburner:origLink></entry>
    <entry>
        <title>New Version of CodeArmor Intelligence, Real Data, and New Piracy Research</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ViLabs/~3/a9zIlfEnT-U/new-version-of-codearmor-intelligence-real-data-and-new-piracy-research.html" />
        <link rel="replies" type="text/html" href="http://vilabs.typepad.com/vilabs/2009/09/new-version-of-codearmor-intelligence-real-data-and-new-piracy-research.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453976a69e20120a5cac306970c</id>
        <published>2009-09-16T09:21:59-04:00</published>
        <updated>2009-09-16T09:21:59-04:00</updated>
        <summary>Today we announced CodeArmor Intelligence 2.0 - here's a short three minute video that Vic did covering some of the aggregate data our deployed customers have shared with us along with highlights on some of the new features (including dynamic...</summary>
        <author>
            <name>Michael Goff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Business Intelligence" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Piracy" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Revenue Recovery" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://vilabs.typepad.com/vilabs/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Today we &lt;a href="http://www.vilabs.com/press/PR-091609-CodeArmor_Intelligence_Gets_Even_Smarter.aspx" target="_blank"&gt;announced CodeArmor Intelligence 2.0&lt;/a&gt; - here's a short three minute video that Vic did covering some of the &lt;strong&gt;aggregate data our deployed customers have shared&lt;/strong&gt; with us along with highlights on some of the new features (including &lt;strong&gt;dynamic notification capabilities&lt;/strong&gt; and &lt;strong&gt;enhanced data collection and reporting&lt;/strong&gt;):&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&lt;object height="265" width="320"&gt;&lt;param name="movie" value="http://www.youtube.com/v/-OtBSbg7CjI&amp;amp;hl=en&amp;amp;fs=1&amp;amp;rel=0&amp;amp;color1=0x2b405b&amp;amp;color2=0x6b8ab6"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed allowfullscreen="true" allowscriptaccess="always" height="265" src="http://www.youtube.com/v/-OtBSbg7CjI&amp;amp;hl=en&amp;amp;fs=1&amp;amp;rel=0&amp;amp;color1=0x2b405b&amp;amp;color2=0x6b8ab6" type="application/x-shockwave-flash" width="320"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;We also announced the latest report in our &lt;strong&gt;Piracy Risk Assessment research series&lt;/strong&gt;. &lt;strong&gt;&lt;a href="http://www.vilabs.com/offers/Software_Piracy_Report_2009_pt2.aspx" target="_blank"&gt;Part 2&lt;/a&gt;&lt;/strong&gt; focuses on &lt;strong&gt;"Software Piracy Distribution Channels and Networks"&lt;/strong&gt; and is available today (&lt;a href="http://www.vilabs.com/offers/Software_Piracy_Report_2009_pt1.aspx" target="_blank"&gt;Part 1&lt;/a&gt; focused on &lt;a href="http://vilabs.typepad.com/vilabs/2009/07/software-piracy-risk-assessment-report.html" target="_blank"&gt;Crack Releases and Piracy Enablement Approaches&lt;/a&gt;). Part 3 of the series will assess the trends and overall piracy activity levels for specific software markets using metrics based on piracy group activity.&lt;/p&gt;&lt;p&gt;- Michael&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=a9zIlfEnT-U:r0vFZK3Dvk4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=a9zIlfEnT-U:r0vFZK3Dvk4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=a9zIlfEnT-U:r0vFZK3Dvk4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=a9zIlfEnT-U:r0vFZK3Dvk4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=a9zIlfEnT-U:r0vFZK3Dvk4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=a9zIlfEnT-U:r0vFZK3Dvk4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=a9zIlfEnT-U:r0vFZK3Dvk4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ViLabs/~4/a9zIlfEnT-U" height="1" width="1"/&gt;</content>


    <feedburner:origLink>http://vilabs.typepad.com/vilabs/2009/09/new-version-of-codearmor-intelligence-real-data-and-new-piracy-research.html</feedburner:origLink></entry>
    <entry>
        <title>Holy Piracy Twist Batman!</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ViLabs/~3/s5CU6_bjBEs/holy-piracy-twist-batman.html" />
        <link rel="replies" type="text/html" href="http://vilabs.typepad.com/vilabs/2009/09/holy-piracy-twist-batman.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453976a69e20120a55ba83a970b</id>
        <published>2009-09-09T08:05:30-04:00</published>
        <updated>2009-09-09T08:05:30-04:00</updated>
        <summary>OK, so forgive the title of this post, but how often do I get to talk about anti-piracy approaches from the gaming world that have interesting implications for the larger ISV community? I came across "Eidos Sets Sneaky Trap for...</summary>
        <author>
            <name>Michael Goff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Piracy" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://vilabs.typepad.com/vilabs/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;a href="http://vilabs.typepad.com/.a/6a00d83453976a69e20120a5b211b4970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"&gt;&lt;img alt="Batman" class="at-xid-6a00d83453976a69e20120a5b211b4970c " src="http://vilabs.typepad.com/.a/6a00d83453976a69e20120a5b211b4970c-320wi" style="margin: 0px 0px 5px 5px;"&gt;&lt;/img&gt;&lt;/a&gt; OK, so forgive the title of this post, but how often do I get to talk about anti-piracy approaches from the gaming world that have interesting implications for the larger ISV community?&lt;/p&gt;&lt;p&gt;I came across &lt;a href="http://playstationlifestyle.net/2009/09/09/eidos-sets-sneaky-trap-for-arkham-asylum-pirates/" target="_blank"&gt;"Eidos Sets Sneaky Trap for Arkham Asylum Pirates"&lt;/a&gt; and was really impressed by one approach Eidos took to address piracy. &lt;/p&gt;&lt;p&gt;According to the article: "On the Eidos forums, a user by the name of Cheshirec_the_cat&#xD;
announced a problem he was having with the game, which he apparently&#xD;
downloaded for free. Let’s just say Eidos’s response is absolutely&#xD;
hilarious."&#xD;
&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;Cheshirec_the_cat (The Pirater):&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;“Hi!&lt;br&gt;&#xD;
I’ve got a problem when it’s time to use Batman’s glide in the game.&#xD;
When I hold , like it’s said to jump from one platform to another,&#xD;
Batman tries to open his wings again and again instead of gliding. So&#xD;
he fels down in a poisoning gas. If somebody could tel me, what should&#xD;
I do there.”&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Keir (Eidos Admin):&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;“The problem you have encountered is a hook in the copy&#xD;
protection, to catch out people who try and download cracked versions&#xD;
of the game for free.&lt;/p&gt;&#xD;
&lt;p&gt;It’s not a bug in the game’s code, it’s a bug in your moral code.”&lt;/p&gt;&lt;/blockquote&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;Now, we all know that the gaming world is very different from business software and high value applications, &lt;strong&gt;but the approach taken here is very interesting and could be applied by a wider range of ISVs&lt;/strong&gt;. &lt;/p&gt;&lt;p&gt;When your application detects that it has been tampered with to enable piracy, have it escalate through an appropriate series of responses to alert the user or company to the fact that the application is being used illegally. This could start with a simple notification and eventually lead to altering the behavior of the application.This approach gives ISVs more control and lends itself to a dialogue with the infringing organization.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What do you think of this approach?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;As a side note, I enjoyed "MartinDude's" comment on the &lt;a href="http://playstationlifestyle.net/2009/09/09/eidos-sets-sneaky-trap-for-arkham-asylum-pirates/" target="_blank"&gt;article&lt;/a&gt; and his (grudging?) respect for this approach:&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;"Although I can’t say I never pirated anything, I can really appreciate a thing like this against “us pirates” :D Keep it up! :)"&lt;/p&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=s5CU6_bjBEs:eia_3-OcvgM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=s5CU6_bjBEs:eia_3-OcvgM:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=s5CU6_bjBEs:eia_3-OcvgM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=s5CU6_bjBEs:eia_3-OcvgM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=s5CU6_bjBEs:eia_3-OcvgM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=s5CU6_bjBEs:eia_3-OcvgM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=s5CU6_bjBEs:eia_3-OcvgM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ViLabs/~4/s5CU6_bjBEs" height="1" width="1"/&gt;</content>


    <feedburner:origLink>http://vilabs.typepad.com/vilabs/2009/09/holy-piracy-twist-batman.html</feedburner:origLink></entry>
    <entry>
        <title>Relying on Anonymous Tipsters to Confront Software Piracy?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ViLabs/~3/-pb3v6SKhYU/relying-on-anonymous-tipsters-to-confront-software-piracy.html" />
        <link rel="replies" type="text/html" href="http://vilabs.typepad.com/vilabs/2009/08/relying-on-anonymous-tipsters-to-confront-software-piracy.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453976a69e20120a50433f9970b</id>
        <published>2009-08-19T12:05:20-04:00</published>
        <updated>2009-08-19T12:05:20-04:00</updated>
        <summary>Ars Technica has an interesting article about a company accused of software piracy that has sued the anonymous tipster claiming defamation. The DC Court of Appeals has allowed the case to proceed with instructions to the trial judge on the...</summary>
        <author>
            <name>Michael Goff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Business Intelligence" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Code Theft" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://vilabs.typepad.com/vilabs/">&lt;p&gt;Ars Technica has an &lt;a href="http://arstechnica.com/tech-policy/news/2009/08/court-offers-guidelines-on-when-to-unmask-anonymous-posters.ars" target="_blank"&gt;interesting article about a company accused of software piracy that has sued the anonymous tipster claiming defamation&lt;/a&gt;. The DC Court of Appeals has allowed the case to proceed with instructions to the trial judge on the guidelines to apply when determining whether to reveal the identity of the anonymous tipster. The case highlights the importance of vetting sources and having solid evidence before pursuing businesses using pirated software.&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;&lt;span class="Apple-style-span" style="border-collapse: separate; color: #000000; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial,sans-serif; font-size: 13px; line-height: 18px;"&gt;&lt;p style="margin: 0px 0px 1em;"&gt;"The case started with an anonymous complaint submitted to the&lt;span class="Apple-converted-space"&gt; &lt;/span&gt;&lt;a href="http://www.siia.net/" style="color: #ff5b00; text-decoration: none;"&gt;Software &amp;amp; Information Industry Association&lt;/a&gt;, which (much like the Business Software Alliance), allows anyone to finger institutions for using pirated software. In this case, the person who submitted the complaint suggested that a company that makes software for the Defense Department, Solers, Inc., was engaged in piracy. The SIIA sent Solers a threatening letter, suggesting it undertake an audit of its compliance and return the results.&lt;/p&gt;&lt;p style="margin: 0px 0px 1em;"&gt;Solers argued that it was in compliance, and requested the identity of the John Doe who had turned it in. When the SIIA declined to identify him, the company filed a complaint, alleging that the anonymous tip amounted to defamation, and that it interfered with the company's ability to do business. As part of the suit, Solers subpoenaed the SIIA, demanding it turn over all the information it had on John Doe. The SIIA went to court in an attempt to quash the subpoena. The presiding judge agreed, but Solers appealed, leading to the current decision.&lt;/p&gt;&lt;p style="margin: 0px 0px 1em;"&gt;...&lt;/p&gt;&lt;p style="margin: 0px 0px 1em;"&gt;&lt;span class="Apple-style-span" style="border-collapse: separate; color: #000000; font-family: 'Times New Roman'; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"&gt;&lt;span class="Apple-style-span" style="color: #333333; font-family: Arial,sans-serif; font-size: 13px; line-height: 18px;"&gt;In short, the plaintiff [Solers] has to provide evidence that its claims are reasonable and the identity of the defendant [the anonymous tipster] is needed before the suit could continue. The defendant should also be given the opportunity to attempt to block his or her unmasking in court."&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;This is a great example of one of the big challenges that ISVs have when trying to recover revenue from businesses using their software without paying for it. In many cases, &lt;strong&gt;ISVs rely on someone to &lt;a href="http://en.wikipedia.org/wiki/Drop_a_dime" target="_blank"&gt;"drop a dime" &lt;/a&gt;and report the infringement&lt;/strong&gt;. After that, there is a request/demand/court order for a software license audit that the accused infringing business often challenges (as happened in the Solers case).&lt;/p&gt;&lt;p&gt;Beyond the additional time and steps required to address these challenges, the accused business will likely challenge the motives of the tipster (especially if it is a "disgruntled ex-employee"), distracting attention from the underlying claims and issues at hand. Interestingly, Ars Technica used a picture of the &lt;a href="http://static.arstechnica.com/2009/08/18/anonymous_ars.jpg" target="_blank"&gt;mask&lt;/a&gt; from "&lt;a href="http://en.wikipedia.org/wiki/V_for_Vendetta" target="_blank"&gt;V for Vendetta&lt;/a&gt;" to illustrate its &lt;a href="http://arstechnica.com/tech-policy/news/2009/08/court-offers-guidelines-on-when-to-unmask-anonymous-posters.ars" target="_blank"&gt;article&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;It seems like a better solution for ISVs (and the SIIA and BSA) is to &lt;strong&gt;have evidence of infringement before confronting or accusing&lt;/strong&gt; a business of using its software illegally. Faced with detailed data showing actual and continued use of unlicensed applications, the accused business loses its ability to delay and distract by shifting the focus to the anonymous tipster.&lt;/p&gt;&lt;p&gt;That is the benefit of &lt;strong&gt;&lt;a href="http://www.vilabs.com/solutions/antipiracy.aspx" target="_blank"&gt;piracy business intelligence&lt;/a&gt;&lt;/strong&gt; - it's automatic software auditing that lets the ISVs know when their applications are being used unlicensed and who is using them.&lt;/p&gt;&lt;p&gt;- Michael&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=-pb3v6SKhYU:ZILxxFpClDc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=-pb3v6SKhYU:ZILxxFpClDc:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=-pb3v6SKhYU:ZILxxFpClDc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=-pb3v6SKhYU:ZILxxFpClDc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=-pb3v6SKhYU:ZILxxFpClDc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=-pb3v6SKhYU:ZILxxFpClDc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=-pb3v6SKhYU:ZILxxFpClDc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ViLabs/~4/-pb3v6SKhYU" height="1" width="1"/&gt;</content>


    <feedburner:origLink>http://vilabs.typepad.com/vilabs/2009/08/relying-on-anonymous-tipsters-to-confront-software-piracy.html</feedburner:origLink></entry>
    <entry>
        <title>Software Piracy Initiatives Forum</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ViLabs/~3/d_Dq3BIhiv4/software-piracy-initiatives-forum.html" />
        <link rel="replies" type="text/html" href="http://vilabs.typepad.com/vilabs/2009/08/software-piracy-initiatives-forum.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453976a69e20120a51c8e1e970c</id>
        <published>2009-08-04T09:06:35-04:00</published>
        <updated>2009-08-04T09:06:35-04:00</updated>
        <summary>How big is the software piracy problem globally? How big is the impact on your company's bottom line? How does your company measure it? What are you doing to address it? The piracy scene is well organized and successful in...</summary>
        <author>
            <name>Michael Goff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Business Intelligence" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Piracy" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Software Protection" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://vilabs.typepad.com/vilabs/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt; &lt;a href="http://vilabs.typepad.com/.a/6a00d83453976a69e20120a4c53bc7970b-pi" style="float: right;"&gt;&lt;img alt="SPIF" border="0" class="at-xid-6a00d83453976a69e20120a4c53bc7970b " src="http://vilabs.typepad.com/.a/6a00d83453976a69e20120a4c53bc7970b-800wi" style="margin: 0px 0px 5px 5px;" title="SPIF"&gt;&lt;/img&gt;&lt;/a&gt; How big is the software piracy problem globally? How big is the impact on your company's bottom line? How does your company measure it? What are you doing to address it?&lt;/p&gt;&lt;p&gt;The &lt;a href="http://www.wired.com/wired/archive/13.01/topsite.html" target="_blank"&gt;piracy scene is well organized and successful&lt;/a&gt; in its efforts to obtain and distribute software. &lt;strong&gt;Shouldn't the software industry be even more organized and successful in its efforts to address and confront it?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;V.i. Labs is sponsoring a new group on LinkedIn - the &lt;strong&gt;&lt;a href="http://www.linkedin.com/groups?gid=2118560" target="_blank"&gt;Software Piracy Initiatives Forum&lt;/a&gt;&lt;/strong&gt; to give software&#xD;
vendors a venue for discussing these issues and share their&#xD;
experiences to minimize piracy's impact on the industry.&lt;/p&gt;&lt;p&gt;If you are responsible for analyzing and addressing the impact of overt&#xD;
piracy and license overuse or interested in getting a better understanding of the software piracy scene in general, please &lt;strong&gt;&lt;a href="http://www.linkedin.com/groups?gid=2118560" target="_blank"&gt;join the group&lt;/a&gt;&lt;/strong&gt; and contribute to advancing the industry's efforts to combat piracy.&lt;/p&gt;&lt;p&gt;- Michael&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=d_Dq3BIhiv4:0mM0i6X4z1I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=d_Dq3BIhiv4:0mM0i6X4z1I:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=d_Dq3BIhiv4:0mM0i6X4z1I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=d_Dq3BIhiv4:0mM0i6X4z1I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=d_Dq3BIhiv4:0mM0i6X4z1I:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=d_Dq3BIhiv4:0mM0i6X4z1I:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=d_Dq3BIhiv4:0mM0i6X4z1I:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ViLabs/~4/d_Dq3BIhiv4" height="1" width="1"/&gt;</content>


    <feedburner:origLink>http://vilabs.typepad.com/vilabs/2009/08/software-piracy-initiatives-forum.html</feedburner:origLink></entry>
    <entry>
        <title>Free Automated Software Piracy Alerts from V.i. Labs</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ViLabs/~3/5-Tib0odx1g/free-automated-software-piracy-alerts-from-vi-labs.html" />
        <link rel="replies" type="text/html" href="http://vilabs.typepad.com/vilabs/2009/07/free-automated-software-piracy-alerts-from-vi-labs.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453976a69e201157133531d970c</id>
        <published>2009-07-23T09:31:14-04:00</published>
        <updated>2009-07-23T09:31:14-04:00</updated>
        <summary>Leveraging the infrastructure we have built to conduct our original research, we are now offering a free automated software piracy alert service for ISVs. Verified employees of software vendors can now receive an email alert when new piracy activity on...</summary>
        <author>
            <name>Michael Goff</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Business Intelligence" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Piracy" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://vilabs.typepad.com/vilabs/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;a href="http://vilabs.typepad.com/.a/6a00d83453976a69e2011571335047970c-pi" style="float: right;"&gt;&lt;img alt="Alert" border="0" class="at-xid-6a00d83453976a69e2011571335047970c " src="http://vilabs.typepad.com/.a/6a00d83453976a69e2011571335047970c-800wi" style="margin: 0px 0px 5px 5px;" title="Alert"&gt;&lt;/img&gt;&lt;/a&gt; Leveraging the infrastructure we have built to conduct our &lt;a href="http://vilabs.typepad.com/vilabs/2009/07/software-piracy-risk-assessment-report.html" target="_blank"&gt;original research&lt;/a&gt;, we are now offering a &lt;strong&gt;free automated software piracy alert service for ISVs&lt;/strong&gt;. Verified employees of software vendors can now receive an email alert when new piracy activity on their applications is detected.&lt;br&gt;&lt;br&gt;&lt;strong&gt;Each piracy alert will let you know:&lt;/strong&gt;&lt;br&gt;&lt;ul&gt;&#xD;
&lt;li&gt; Which software title and version has been cracked&lt;/li&gt;&#xD;
&lt;li&gt; When the cracked version was released&lt;/li&gt;&#xD;
&lt;li&gt; The name of the crack group responsible for the release&lt;/li&gt;&#xD;
&lt;li&gt; The piracy crack approach used&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;strong&gt;Sign up now: &lt;a href="http://www.vilabs.com/piracyalerts" target="_blank"&gt;www.vilabs.com/piracyalerts&lt;/a&gt;&lt;/strong&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=5-Tib0odx1g:ZFhaiRX4TYA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=5-Tib0odx1g:ZFhaiRX4TYA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=5-Tib0odx1g:ZFhaiRX4TYA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=5-Tib0odx1g:ZFhaiRX4TYA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=5-Tib0odx1g:ZFhaiRX4TYA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=5-Tib0odx1g:ZFhaiRX4TYA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=5-Tib0odx1g:ZFhaiRX4TYA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ViLabs/~4/5-Tib0odx1g" height="1" width="1"/&gt;</content>


    <feedburner:origLink>http://vilabs.typepad.com/vilabs/2009/07/free-automated-software-piracy-alerts-from-vi-labs.html</feedburner:origLink></entry>
    <entry>
        <title>V.i. Labs Software Piracy Risk Assessment Report - July 2009</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ViLabs/~3/DfRdxFKD0hU/software-piracy-risk-assessment-report.html" />
        <link rel="replies" type="text/html" href="http://vilabs.typepad.com/vilabs/2009/07/software-piracy-risk-assessment-report.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453976a69e201157127df1a970c</id>
        <published>2009-07-21T14:38:56-04:00</published>
        <updated>2009-07-21T14:34:19-04:00</updated>
        <summary>We have been continuing to gather and analyze data on software piracy since we issued our first reports last summer and are ready to issue the first part of our Software Piracy Risk Assessment Report. The first installment is a...</summary>
        <author>
            <name>Vic</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Business Intelligence" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Piracy" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Revenue Recovery" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Reverse Engineering " />
        
        
<content type="html" xml:lang="en-US" xml:base="http://vilabs.typepad.com/vilabs/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;We have been continuing to gather and analyze data on software piracy since we issued our &lt;a href="http://vilabs.typepad.com/vilabs/2008/07/initial-analysi.html" target="_blank"&gt;first&lt;/a&gt; &lt;a href="http://vilabs.typepad.com/vilabs/2008/08/new-piracy-data.html" target="_blank"&gt;reports&lt;/a&gt; last summer and are ready to issue the first part of our Software Piracy Risk Assessment Report.&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;The first installment is a detailed review of &lt;strong&gt;crack releases and piracy enablement approaches&lt;/strong&gt;. Tampering or bypassing the embedded license enforcement is a key enabler of piracy. Most high value applications have adopted third party licensing systems to enforce software entitlements for their customer base. &lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;We reviewed &lt;strong&gt;83 separate piracy group distributions of cracked software&lt;/strong&gt; that were released between 2007 and 2009 from &lt;strong&gt;39 Independent Software Vendors (ISVs)&lt;/strong&gt;. These high value applications have an &lt;strong&gt;average list price exceeding $4,000 (USD)&lt;/strong&gt; per user seat and are used for Architecture&#xD;
Engineering and Construction (AEC), Computer Aided Design (CAD), Computer Aided&#xD;
Machine (CAM), Computer Aided Engineering (CAE), Electronic Design Automation&#xD;
(EDA), Product Lifecycle Management (PLM), and other specialized engineering&#xD;
and scientific modeling and analysis.&lt;/p&gt;&lt;p&gt;Interestingly, the &lt;strong&gt;top five piracy groups&lt;/strong&gt; (out of 212) &lt;strong&gt;contributed 59% of the cracked releases&lt;/strong&gt; in the study.&lt;/p&gt;&#xD;
&#xD;
All of the pirated software releases used a crack mechanism or other approach to tamper with license enforcement and enable illegal use. However, there was a great range in terms of how well documented the cracks were and the level of expertise required to configure the crack. Three general approaches were used &lt;strong&gt;(click image to enlarge)&lt;/strong&gt;: &lt;br&gt;&#xD;
&#xD;
&lt;ul&gt;&#xD;
&lt;li&gt;Binary patches (52% / 43 releases)&lt;/li&gt;&#xD;
&lt;li&gt;Key maker (36% / 30 releases)&lt;/li&gt;&#xD;
&lt;li&gt;Vulnerability (12 % / 10 releases)&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;&lt;a href="http://vilabs.typepad.com/.a/6a00d83453976a69e20115721c5bd0970b-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="display: inline;"&gt;&lt;img alt="Crack_methodology" class="at-xid-6a00d83453976a69e20115721c5bd0970b " src="http://vilabs.typepad.com/.a/6a00d83453976a69e20115721c5bd0970b-320wi"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The analysis also revealed that the piracy groups and the reverse engineering talent they recruit can tamper with a variety of hardware and software based licensing systems to enable overt piracy. &lt;strong&gt;Strengthening licensing using hardware dongles or tamper resistant licensing may be useful prevention for overuse within a licensed customer environment, but it should not be viewed as a defense against overt piracy. &lt;/strong&gt;&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;&lt;strong&gt;&lt;a href="http://www.vilabs.com/offers/Software_Piracy_Report_2009_pt1.aspx" target="_blank"&gt;To learn more about the results of the research, the complete report is available for download here.&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&#xD;
&#xD;
&lt;p&gt;- Vic&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=DfRdxFKD0hU:X1g8_TPGc1k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=DfRdxFKD0hU:X1g8_TPGc1k:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=DfRdxFKD0hU:X1g8_TPGc1k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=DfRdxFKD0hU:X1g8_TPGc1k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=DfRdxFKD0hU:X1g8_TPGc1k:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=DfRdxFKD0hU:X1g8_TPGc1k:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=DfRdxFKD0hU:X1g8_TPGc1k:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ViLabs/~4/DfRdxFKD0hU" height="1" width="1"/&gt;</content>


    <feedburner:origLink>http://vilabs.typepad.com/vilabs/2009/07/software-piracy-risk-assessment-report.html</feedburner:origLink></entry>
    <entry>
        <title>Goldman Sachs Code Theft - Mitigating the Risks</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ViLabs/~3/VF1yZc3f8q0/goldman-sachs-code-theft-mitigating-the-risks.html" />
        <link rel="replies" type="text/html" href="http://vilabs.typepad.com/vilabs/2009/07/goldman-sachs-code-theft-mitigating-the-risks.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453976a69e2011571e5f9c8970b</id>
        <published>2009-07-09T10:54:57-04:00</published>
        <updated>2009-07-09T10:54:57-04:00</updated>
        <summary>Software Protection is not the panacea for code theft issues like the one that occurred with Goldman Sachs. In fact, this case is very similar to the 2004 insider code theft of Cisco’s IOS code. However, outside of just stronger...</summary>
        <author>
            <name>Vic</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term=".NET protection" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Application Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Business Intelligence" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Code Theft" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Reverse Engineering " />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Secure Outsourcing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Software Protection" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://vilabs.typepad.com/vilabs/">&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;Software Protection is not the panacea for code theft issues like the one that occurred with &lt;a href="http://www.boston.com/business/articles/2009/07/07/alleged_theft_has_broad_implications/" target="_blank"&gt;Goldman Sachs&lt;/a&gt;. In fact, this case is very &lt;a href="http://news.cnet.com/British-police-arrest-suspect-in-Cisco-code-theft/2100-7349_3-5371807.html" target="_blank"&gt;similar to the 2004 insider code theft of Cisco’s IOS code&lt;/a&gt;. However, outside of just stronger access control and perimeter security measures, &lt;strong&gt;these threats do suggest a closer look at how to securely share valuable IP contained within code in a distributed and rapid software development process.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Although there are few details in terms of the development platform of the application and the exact access the alleged thief had, organizations should consider a few &lt;strong&gt;options to mitigate the risk of theft of sensitive IP within code&lt;/strong&gt;:&lt;/p&gt;&lt;ul&gt;&#xD;
&lt;li&gt;&lt;strong&gt;If managed code is involved, protect it&lt;/strong&gt; - If the development language is managed (Microsoft .NET or Java), code obfuscation and encryption most be used. Even once the applications are compiled, it is only partially compiled into an intermediate language which is easily decompiled into source code representation. Another alternative is to place the sensitive IP into an unmanaged component to minimize exposure.&lt;/li&gt;&#xD;
&lt;li&gt;&lt;strong&gt;Create protected APIs&lt;/strong&gt; - If the software development process requires the use of outsourced development partners or contractors, create an application programming interface that contains the sensitive IP within compiled application components versus sharing the source. Although this would obviously require additional work by the organization, an API option that uses compiled binaries allow more options to use software protection and harden the API against reverse engineering. &lt;/li&gt;&#xD;
&lt;li&gt;&lt;strong&gt;Embed threat detection and reporting&lt;/strong&gt; – Add threat detection and reporting mechanisms (sometimes referred to as phone home systems) to the application itself. This approach can be used to continuously test for tampering or installation in unauthorized networks, and if a threat exists, notifies the owning organization in real-time. This presumes that the enterprise application (or in the context of this discussion a protected API) is designed to be deployed within specific networks, data centers or hosting partner networks.&lt;/li&gt;&#xD;
&lt;/ul&gt;&#xD;
&lt;p&gt;Gartner's Neil MacDonald &lt;a href="http://blogs.gartner.com/neil_macdonald/2009/07/07/security-no-brainer-7-if-you-have-intellectual-property-embedded-in-software-protect-it/" target="_blank"&gt;blogged about this news&lt;/a&gt; ("Security No-Brainer #7: If You Have Intellectual Property Embedded in Software, Protect it") and Gartner's "Hype Cycle for Cyberthreats (2006) coined a term for the emergence of software IP threats as &lt;strong&gt;enterprise code reverse engineering&lt;/strong&gt; (&lt;em&gt;“Definition: Enterprise code reverse engineering is reverse engineering of enterprise application&lt;br&gt;code for the purposes of targeting vulnerabilities or stealing intellectual property.”&lt;/em&gt;).&lt;/p&gt;&lt;p&gt;We believe as general perimeter, application, and physical security improves, hackers, foreign governments and competitors will increasingly turn to reverse engineering tactics to access valuable software IP or alter it for malicious purposes. In these threat scenarios software protection and threat detection reporting can play an important role in mitigating these risks.&lt;/p&gt;&lt;p&gt;- Vic&lt;/p&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=VF1yZc3f8q0:rnPAZaaB2Bk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=VF1yZc3f8q0:rnPAZaaB2Bk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=VF1yZc3f8q0:rnPAZaaB2Bk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=VF1yZc3f8q0:rnPAZaaB2Bk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=VF1yZc3f8q0:rnPAZaaB2Bk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=VF1yZc3f8q0:rnPAZaaB2Bk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=VF1yZc3f8q0:rnPAZaaB2Bk:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ViLabs/~4/VF1yZc3f8q0" height="1" width="1"/&gt;</content>


    <feedburner:origLink>http://vilabs.typepad.com/vilabs/2009/07/goldman-sachs-code-theft-mitigating-the-risks.html</feedburner:origLink></entry>
    <entry>
        <title>Latest Spam uses Yahoo! Profiles and Cheap Software prices to Capture Credit Card Data</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/ViLabs/~3/MJsxCX9wJRA/latest-spam-uses-yahoo-profiles-and-cheap-software-prices-to-capture-credit-card-data.html" />
        <link rel="replies" type="text/html" href="http://vilabs.typepad.com/vilabs/2009/06/latest-spam-uses-yahoo-profiles-and-cheap-software-prices-to-capture-credit-card-data.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00d83453976a69e201157192ea28970b</id>
        <published>2009-06-30T15:07:51-04:00</published>
        <updated>2009-06-30T15:07:51-04:00</updated>
        <summary>For the last month (at least from my inbox perspective) spammers have been using the Yahoo! personal profile interface to send spam with cheap software offers (see image 1). Image 1: Email with Yahoo profile reference (click to enlarge) The...</summary>
        <author>
            <name>Vic</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Application Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Piracy" />
        
        
<content type="html" xml:lang="en-US" xml:base="http://vilabs.typepad.com/vilabs/">&lt;p&gt;For the last month (at least from my inbox perspective) spammers have been using the Yahoo! personal profile interface to send spam with cheap software offers (see image 1).&lt;/p&gt;&lt;p&gt;&lt;a href="http://vilabs.typepad.com/.a/6a00d83453976a69e201157192e393970b-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="display: inline;"&gt;&lt;img alt="YahooGroup" class="at-xid-6a00d83453976a69e201157192e393970b " src="http://vilabs.typepad.com/.a/6a00d83453976a69e201157192e393970b-320wi"&gt;&lt;/img&gt;&lt;/a&gt; &lt;br&gt;&lt;strong&gt;Image 1: Email with Yahoo profile reference (click to enlarge)&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The ploy attempts redirect users to an authentic looking web site offer software at prices too good to be true (image 2). The IP address of the site can tracked to an IP address assigned in China and hosted on a server that includes over 400 other gambling and software commerce sites.&lt;/p&gt;&lt;p&gt;&lt;a href="http://vilabs.typepad.com/.a/6a00d83453976a69e20115709dbfa6970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="display: inline;"&gt;&lt;img alt="Homepage" class="at-xid-6a00d83453976a69e20115709dbfa6970c " src="http://vilabs.typepad.com/.a/6a00d83453976a69e20115709dbfa6970c-320wi"&gt;&lt;/img&gt;&lt;/a&gt; &lt;br&gt;&lt;strong&gt;Image 2: Homepage of Web site offering to sell pirated software (click to enlarge)&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Further navigation of the site reveals a checkout form with all the right images to lure the unsuspecting user to enter their credit card information and buy low priced software.  However, it should be obvious to most users who purchase anything on the Web that this site is a scheme to grab credit card data.  Although a secure connection symbol is shown, the form itself asks for credit card information over a non-SSL session. Also, the BBBOnline program (which no longer is operational) VISA, and TRUSTe seals do not provide a link for verification (image 3).&lt;/p&gt;&lt;p&gt;&lt;a href="http://vilabs.typepad.com/.a/6a00d83453976a69e20115709dc28b970c-pi" style="display: inline;"&gt;&lt;img alt="Checkoutform" class="at-xid-6a00d83453976a69e20115709dc28b970c " src="http://vilabs.typepad.com/.a/6a00d83453976a69e20115709dc28b970c-320wi"&gt;&lt;/img&gt;&lt;/a&gt; &lt;/p&gt;&lt;p&gt;&lt;strong&gt;Image 3: Checkout form on false commerce site (click to enlarge)&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;I would hope that it is completely obvious to users with some internet experience that they should not trust this site or the method used to arrive at the site. However, given that it is relatively cheap to host hundreds of these sites using virtual servers and leverage Yahoo! to promote them, it probably only takes one uninformed user to justify this criminal approach.&lt;/p&gt;&lt;p&gt;- Vic&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=MJsxCX9wJRA:grecbVCKyt4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=MJsxCX9wJRA:grecbVCKyt4:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=MJsxCX9wJRA:grecbVCKyt4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=MJsxCX9wJRA:grecbVCKyt4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=MJsxCX9wJRA:grecbVCKyt4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?i=MJsxCX9wJRA:grecbVCKyt4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ViLabs?a=MJsxCX9wJRA:grecbVCKyt4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ViLabs?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ViLabs/~4/MJsxCX9wJRA" height="1" width="1"/&gt;</content>


    <feedburner:origLink>http://vilabs.typepad.com/vilabs/2009/06/latest-spam-uses-yahoo-profiles-and-cheap-software-prices-to-capture-credit-card-data.html</feedburner:origLink></entry>
 
</feed><!-- ph=1 --><!-- nhm:dynamic-ssi -->
