I understand that sharing video, photos, documents etc. is relatively safe because the data is not executed in the processor as instructions. How come people are willing to download and install pirated software though? How can one be confident that it does not contain malicious addons? Are people just don't know the risks? Or are there protection mechanisms that I am missing? I mean since the software is usually cracked there is not much use in comparing checksums with the originals, is it?
Worth noting that paying for a license for software doesn't stop it being spying malware either. In fact the pirate versions often take out the spying and the reporting-to-homebase that proprietary software does.
The photoshop that phones home to check a license is arguably more malicious than the pirate version that has been cracked so it doesn't do that.
It's partly an honor system but also, anyone distributing malicious cracks are quickly called out whether its on public tracker comments like PirateBay or removed from private trackers.
Distributors of GOOD and CLEAN cracks often earn good rep in the community too, like Monkrus which I've had no issue with before.
Also, in my experience, installing a malware-packaged adobe app isn't actually all that bad if you run a malware scan immediately afterwards. With the scale and breadth of software piracy there isn't much money in making advanced malwares beyond bundling an existing one into an installer. I don't recommend it, but it's still easier and cheaper than paying Adobe!
TLDR the community polices itself pretty well considering.
Also, I would consider some legitimate licenced software more of a malware than a cracked one. If your software forces always-online license, comes with annoying startup processes, nagging ad screens, etc, it's malware. And if there's a cracked version without those things, I'll take the cracked version any day.
You're thinking too technical about this. This is a money thing. Personally speaking pirated software/games were chicken soup for my poverty ridden childhood.
How come people are willing to download and install pirated software though?
You can just remove "priated" from that statement and come to the same conclusions. Considering the amount of bugs, backdoors and 0-day exploits distributed via official software I sometimes wonder why people execute proprietary, closed source programs at all.
An no, "reputable" companies mean nothing, just look at Microsoft clowning around with their signing keys.
Exactly. Piracy extends the commercial ecosystem. Every software pirate is a potential user and contributor of FOSS projects who is instead spending their time and talents working on/with commercial offerings.
To a distributor of commercial software, a pirate user is preferable to a user of a competing product. The competing user is already locked into the competition's product line; the pirate is expanding your own product line's market share.
Below the competing user is the FOSS user: it is much easier to monetize a pirate user who likes the system enough to steal it, or a competing user who has demonstrated they are willing to throw money at their problems. FOSS users aren't willing to tolerate all the artificial limitations imposed on the product to increase profitability.
I have no moral or ethical qualms with piracy as a general concept, but software piracy inherently promotes commercial alternatives at the expense of FOSS products. The only software I have pirated in decades has been rare, niche software for very specific uses.
Your assumption is wrong mail can contain executables. Picture can hold executable instructions and so do videos. For example videos and pictures in mail can contain virus. You are not safe just because you download movies and pictures
You are thinking it wrong about malware in pictures. They don’t act like an executable rather then injecting instructions to an executable program you are opening your picture in. In that case you don’t need the +x flag on your file. Think of it as a Trojan horse
I think it is very rare to find or even craft a video file that is able to allow for arbitrary code execution on an updated video player software like VLC. The same is true for photos or documents with the exception of office documents using macros.
Meh, how is surgery a thing? You let people just open you up and dig around your insides?
it's a mix of need and belief in a proper vetting process. For computers there's the additional layer that any one machine is probably low stakes. In early internet days most software was prohibitively expensive but gave you the equivalent of super powers - as a teenager / young adult with ability to take that risk you're not going to do it?
And have something worth loosing on gheir PC. Many professional software users using cracks may worry of losing their work files which could be easily backed up.
As long as they dont have their financials or personal information thats worth stealing, the cost saving of the pirated software is worth infection, which at max needs a fresh install.
I installed trusted cracks from scene groups. Not everyone who can crack will be a scene group. To get into the scene you need to be well trusted. Scene groups would NOT damage their integrity to install something malicious through a crack
As another user said, check the files you have match the direct uploads from the scene with a site like predb.me
You can search online for more info on scene groups/warez/topsites
Most don't invest that much into anti-piracy protection and you can avoid it with simple firewall and GPEdit corrections for the unlimited premium spoof.
There are also the key gens that emulates the server or the software to receive the codes or give a confirmation to the software.
This is all very oversimplified and there are an infinite number of anti-piracy methods that the companies don't even want to try to solve since it's all free advertising and it gets people used to their software when they have to buy it.
Virtual machine testing is a good idea, but I wouldn't rely on it. Well written malware will check for a virtual environment and might even hold off executing if it detects it. Better malware will have already gained persistence as your testing for it.
It's one of those high-risk, high-returns case scenarios. You gamble. If you succeed, you will be saving some buck. Some software licences can be very, very expensive.
There is no way of knowing the answer to your questions. You just use your intuition and take a leap of faith.
top 50 comments