news.volyx.in

Quake Shareware, a CD-ROM just a little too full (fabiensanglard.net)

492 points by shdon · 9 days ago · 226 comments on HN

Article summary

The article discusses the Quake shareware CD, which was released in 1996 with a unique distribution model that allowed users to unlock the full game by calling a phone number and receiving a password. However, the security system was broken by a hacker group just 39 days after the CD's release, allowing users to unlock the game for free. The article explores the technical details of the security system and how it was compromised. The failure of the security system led to significant financial losses for id Software, with nearly 150,000 CDs left unsold.

Main themes

  • game distribution models
  • security systems
  • hacking and piracy
  • CD technology
  • game development history
  • id Software and Quake history

What commenters say

  • The security system used by id Software was flawed and relied on security by obscurity, making it vulnerable to hacking.
  • The use of symmetric crypto would not have provided sufficient security for the Quake shareware CD due to the identical nature of the CDs.
  • The implementation of the security system was incorrect, and it was not Testdrive's fault, but rather id Software's mistake.
  • The phone support's simple checksum was not sufficient to prevent replay attacks, and a more secure system would have been needed to protect the game.
  • The Quake shareware CD's security system was not designed to withstand determined hackers, and its failure was inevitable.
  • The article's criticism of the security system is unfair, as it was a reasonable attempt at the time, given the technological limitations.
  • The security system's flaws were exacerbated by the inclusion of unnecessary files and data on the CD, which provided clues for hackers to exploit.