From: Assaph Mehr Date: 2005-02-08T12:20:12+09:00 Subject: Re: Ruby for closed source projects > Bundle public keys for each unlockable feature and require a "key" to > unlock it which is actually the signed name of the user (signed using > the private key for the feature. > > Cryptographically secure feature unlocking, with the side effect of > letting you know the initial source (though possibly not purposeful) of > any pirated versions. Doesn't help. At some point in the program there is the (conceptual) if statement: if user_has_rights do_this else yell_at_user_to_buy end For any piece of software it is possible for a human to find this if statement and change 'user_has_rights' to true. No matter how you complicate it with public keys, the routine that checks the keys can always be altered to return true. What you should be aiming to achieve is protection from casual piracy: it should not be obvious to the user how to break your software. The user must always think 'I can pay $x for this, or spend y amount of time intentionally breaking it. Is it worth it?'. There will always be people for whom cracking the software is the prefered option (and indeed, the higher the protection the greater the itch to break it). In the long run you cannot stop them. It's just a matter of making the others agree to pay rather than crack the software. This is not security by obscurity, rather a simpler model of cost-effective security: both for you to develop and for the user to crack. Make evreyone happy by supplying cost effective solutions. Cheers, Assaph