Relay-Version: version B 2.10 5/3/83; site utzoo.UUCP Posting-Version: version B 2.10.2 9/18/84; site ptsfb.UUCP Path: utzoo!watmath!clyde!bonnie!akgua!whuxlm!harpo!decvax!genrad!panda!talcott!harvard!seismo!lll-crg!dual!ptsfa!ptsfb!che From: che@ptsfb.UUCP (Mitch Che) Newsgroups: net.micro.pc Subject: Re: Re: software protection - dongles Message-ID: <204@ptsfb.UUCP> Date: Sat, 27-Jul-85 00:54:53 EDT Article-I.D.: ptsfb.204 Posted: Sat Jul 27 00:54:53 1985 Date-Received: Mon, 29-Jul-85 06:43:41 EDT References: <566@alberta.UUCP> <10800011@uiucdcsp> <176@entropy.UUCP> <922@mtgzz.UUCP> <200@sesame.UUCP> Reply-To: che@ptsfb.UUCP (Mitch Che) Organization: Pacific Bell, San Francisco Lines: 42 Summary: new "black box" business In article <200@sesame.UUCP> slerner@sesame.UUCP (Simcha-Yitzchak Lerner) writes: >As the Principal Engineer of ADAPSO's "Software Authorization >System (SAS) Proposal", I would like to make a few BRIEF comments >in response to your remarks. > ........ > >2. "Any programmer with debug will be able to defeat this type > of system." This is NOT correct. While a poorly designed > software lock could be defeated this way, most manufacturers > that I have talked to are putting in a few features that > will make this very difficult if not impossible: > > A. The program generates a random "question" which is > sent to the key. The key returns an answer which is > verified by the host. > > B. A part of the program code and/or structure is stored > in the key for downloading. Some more adventurous > firms are actually having several critical routines (of > an inobvious nature) execute WITHIN the key. > Unfortunately, the same drop in price ($) of silicon technology (e.g. ROM, etc) that make dongles economical is going to make intelligent "peripherals" which passively monitor the RS-232/dongle link and learn the "protocol" relatively cheap (compared to the software+dongle). (I can see it now, CopyXVI PPC!! Think about the problems trying to stop the sale of these on the grounds they're used for pirating-- "Yes, your honor, we're just selling advanced datascopes. We can't control how they're used... Yes, they are beauties, why you can even upload/download instructions to them...") Hmm, now if you can figure out a way to sell the software to the user but not let him/her have it at all, you may have something. (After all, users are just such vile, bothersome creatures.) -- Mitch Che Pacific Bell --------------------------------------- disclaimer, disclaimer, disclaimer, too (415) 823-2438 uucp: {ihnp4,dual}!ptsfa!ptsfb!che