I keep on pointing this out. Compare the two groups:
- Sony a big company with big company HR bureaucracy
- The worldwide interest group re: Hacking
Sony might have one or several groups within the company involved with a given project. The population interested in hacking a popular Sony project is not only very large, but constitutes a frictionless global meritocracy interacting via the Internet.
Conclusion? When it comes to big companies vs. the hacker communities, it's asymmetrical warfare, and the big companies are the underdogs. Big companies are outnumbered and outclassed.
However, instead of behaving like the outclassed guerillas they are, they keep acting like they're the empire, and keep getting bloodied in losing fights. All it takes is a few minutes of thought to realize that DRM is the worst possible tactical position they could possibly take. Companies that do this are deluded.
But here's the real kicker: It is possible for companies to use the principles of asymmetrical warfare and win fights. You have to pick your battles based on sound economic principles. You have to pick your battles, such that the huge numerical and training advantages of the adversary are moot.
I know how to do this.
EDIT: Here's a hint. Take a look at your bug tracker. Imagine that it only has reports where the bugs are hard or impossible to reproduce. Imagine that the consequences of the bug are separated by several weeks time from the probable causes. Imagine that there are tens of thousands of such reports. Imagine that the reports only constitute a small fraction of actual occurrences.
It is quite possible to put parties trying to crack your system in exactly this position. If you make it easy to "crack" your program, and instead put all of your effort towards clandestine detection, then there is no incentive for people to fully crack your system, such that they can find the detection mechanisms. Separate the consequences of detection from the actual detection by a time span of several weeks. Use detection to protect value-add and up-sell revenue which is inherently dependent on server-side implementation.
Use honeypots. Your "easily cracked" version 1 becomes a kind of honeypot for detection, which protects your real revenue stream. Present a hack-y feeling loophole that lets people acquire your value-add content for a sizable discount from full-price.
Remember, you're fighting an asymmetrical conflict. Be sneaky. Don't even let your opponent know she's even in a contest if you can help it. Fool them into thinking they've "won."
Savvy fighters of asymmetrical conflict don't announce their location to their enemies. Savvy fighters are prepared ahead of time and have security in place before they open hostilities. Savvy fighters of asymmetrical conflict compartmentalize their assets, so losing one doesn't entail the loss of others. Savvy fighters of asymmetrical conflict have contingency plans.
I've always thought that adding subtle bugs that only appear in cracked versions would be a good idea as well, but: consider the effect on your product's reputation. Disgruntled pirates can give you a real PR headache, since they don't self-identify as anything but "ordinary users" when they post comments to forums.
I've always thought that adding subtle bugs that only appear in cracked versions would be a good idea as well but: consider the effect on your product's reputation
No! That is not what I'm advocating! Under no circumstances should you introduce faux bugs. The "bugs" I am referring to are incomplete cracks, and they are only bugs for those providing the cracks.
Disgruntled pirates can give you a real PR headache, since they don't self-identify as anything but "ordinary users" when they post comments to forums.
Forums are a bad idea because they take so much effort to curate. The downside is huge -- to the point of creating pernicious fictions such as this.
If you are in the business of selling software, you are probably not making money off of a community forum. Why have it if it has such huge downsides? Have the community meet only in-game.
The scenario you propose is slander and complete falsehood. If your userbase is so corrupt that this works, then I posit you have the wrong customer base. The strategy I am advocating requires that you can control the message in your userbase. This again fits the asymmetrical warfare analogy. Any group of successful guerilla fighters has a well crafted message. If this message can't be communicated properly, then there is no point to the fight.
Here, the message should be: Those warez guys are providing you defective cracks. Just buy the real game -- it's much less hassle. (Then someone else points out that there's a loophole if you purchase the "competitive upgrade" that will work even with the standard version, and only have to pay 50% of retail etc...)
Comments
I keep on pointing this out. Compare the two groups:
Sony might have one or several groups within the company involved with a given project. The population interested in hacking a popular Sony project is not only very large, but constitutes a frictionless global meritocracy interacting via the Internet.Conclusion? When it comes to big companies vs. the hacker communities, it's asymmetrical warfare, and the big companies are the underdogs. Big companies are outnumbered and outclassed.
However, instead of behaving like the outclassed guerillas they are, they keep acting like they're the empire, and keep getting bloodied in losing fights. All it takes is a few minutes of thought to realize that DRM is the worst possible tactical position they could possibly take. Companies that do this are deluded.
But here's the real kicker: It is possible for companies to use the principles of asymmetrical warfare and win fights. You have to pick your battles based on sound economic principles. You have to pick your battles, such that the huge numerical and training advantages of the adversary are moot.
I know how to do this.
EDIT: Here's a hint. Take a look at your bug tracker. Imagine that it only has reports where the bugs are hard or impossible to reproduce. Imagine that the consequences of the bug are separated by several weeks time from the probable causes. Imagine that there are tens of thousands of such reports. Imagine that the reports only constitute a small fraction of actual occurrences.
It is quite possible to put parties trying to crack your system in exactly this position. If you make it easy to "crack" your program, and instead put all of your effort towards clandestine detection, then there is no incentive for people to fully crack your system, such that they can find the detection mechanisms. Separate the consequences of detection from the actual detection by a time span of several weeks. Use detection to protect value-add and up-sell revenue which is inherently dependent on server-side implementation.
Use honeypots. Your "easily cracked" version 1 becomes a kind of honeypot for detection, which protects your real revenue stream. Present a hack-y feeling loophole that lets people acquire your value-add content for a sizable discount from full-price.
Remember, you're fighting an asymmetrical conflict. Be sneaky. Don't even let your opponent know she's even in a contest if you can help it. Fool them into thinking they've "won."
HBGary?
Savvy fighters of asymmetrical conflict don't announce their location to their enemies. Savvy fighters are prepared ahead of time and have security in place before they open hostilities. Savvy fighters of asymmetrical conflict compartmentalize their assets, so losing one doesn't entail the loss of others. Savvy fighters of asymmetrical conflict have contingency plans.
None of the above applies to HBGary.
I've always thought that adding subtle bugs that only appear in cracked versions would be a good idea as well, but: consider the effect on your product's reputation. Disgruntled pirates can give you a real PR headache, since they don't self-identify as anything but "ordinary users" when they post comments to forums.
I've always thought that adding subtle bugs that only appear in cracked versions would be a good idea as well but: consider the effect on your product's reputation
No! That is not what I'm advocating! Under no circumstances should you introduce faux bugs. The "bugs" I am referring to are incomplete cracks, and they are only bugs for those providing the cracks.
Disgruntled pirates can give you a real PR headache, since they don't self-identify as anything but "ordinary users" when they post comments to forums.
Forums are a bad idea because they take so much effort to curate. The downside is huge -- to the point of creating pernicious fictions such as this.
(Laura Roeder's take, is that community forums are most often not worth the effort. http://mixergy.com/laura-roeder-interview/ )
If you are in the business of selling software, you are probably not making money off of a community forum. Why have it if it has such huge downsides? Have the community meet only in-game.
The scenario you propose is slander and complete falsehood. If your userbase is so corrupt that this works, then I posit you have the wrong customer base. The strategy I am advocating requires that you can control the message in your userbase. This again fits the asymmetrical warfare analogy. Any group of successful guerilla fighters has a well crafted message. If this message can't be communicated properly, then there is no point to the fight.
Here, the message should be: Those warez guys are providing you defective cracks. Just buy the real game -- it's much less hassle. (Then someone else points out that there's a loophole if you purchase the "competitive upgrade" that will work even with the standard version, and only have to pay 50% of retail etc...)