Posted by shdon 13 hours ago
Later on there was a generation of two-conductor cables that used SPDIF/PCM Audio instead of analog audio for better fidelity.
(E.g. this one: https://pavel.network/using-cd-drive-as-poor-man-audio-playe...)
The hacker groups would be a little frustrated trying to find all of the different CDs.
It was not possible to manufacture at the time at scale.
Surfacing this gem of a razor here, as it's buried deep in the (fantastic) blog post. Indeed, all too often, what we attribute simply to stupidity/ignorance, as per the classic Hanlon's razor, is actually downstream of market/client/management/deadline etc. pressure.
> Described as is, there is no flaw in this process. The secret seed comes from the unlock server, tied to a CHALLENGE/SERIAL that could not be reused. But the hacker team GNOMON found a way.
> The QUAKE unlock program FLOW.EXE that ships on the CD is capable of generating the SERIAL from the CHALLENGE on its own. All it does is check that its own locally-generated SERIAL and the SERIAL entered by the user match! The entire protection mechanism relies on security by obscurity.
If phone support issued an encrypted decrypt code that could only be used with your challenge code to decrypt the decrypt code, replay wouldn't be as trivial.
Every CD is identical, so no matter how iD went about this there's only ever one decryption key (per title, I assume) and those keys must either have been encoded in iD support's response, or already stored on the CD. TestDrive sold iD on the notion that the process was too hard for hacker groups to reverse engineer, and it wasn't.
I'm pretty sure I bought it for $6.66