What would you say about a set of anti-piracy technologies that allows -

R

Rob Harmer

..................software developers to easily mark features as "licensable
entities"
that can later be controlled through various kinds of digital
licenses.......
........... a business or product-marketing group to create digital licenses
for certain feature bundles, where they can easily turn on and off those
features that were marked as protected and deliver only the desired
functionality to the end-user.

.........the gathering the monitoring data, which can be used for things like
billing, such as utility based billing at the end of the month, or to create
statistics on what usage has happened within the application for future
product planning. Note: Application monitoring is an optional feature, and
we expect the ........ end-user to opt in to such a process.

- the ability to fine tune software offerings even after the product has
been shipped. for example; If it's five or six months after the product has
shipped, and it turns out that the .....market, for example, really wants a
package that has certain features, we can generate new licenses .......on
demand............ All they need to do is create a new digital license and
make it available, and it will unlock and enforce those features.

.................the flexible distribution and license application in any way
they want to, even after the product has been released, depending on their
business model.

.............being able to target customers in a direct way, where you're
giving them exactly what they need and only what they need.

What security implications would you see with this approach?

Rob
 
V

VanguardLH

Rob Harmer said:
.................software developers to easily mark features as
"licensable
entities"
that can later be controlled through various kinds of digital
licenses.......
.......... a business or product-marketing group to create digital
licenses
for certain feature bundles, where they can easily turn on and off
those
features that were marked as protected and deliver only the desired
functionality to the end-user.

........the gathering the monitoring data, which can be used for
things like
billing, such as utility based billing at the end of the month, or
to create
statistics on what usage has happened within the application for
future
product planning. Note: Application monitoring is an optional
feature, and
we expect the ........ end-user to opt in to such a process.

- the ability to fine tune software offerings even after the product
has
been shipped. for example; If it's five or six months after the
product has
shipped, and it turns out that the .....market, for example, really
wants a
package that has certain features, we can generate new licenses
.......on
demand............ All they need to do is create a new digital
license and
make it available, and it will unlock and enforce those features.

................the flexible distribution and license application in
any way
they want to, even after the product has been released, depending on
their
business model.

............being able to target customers in a direct way, where
you're
giving them exactly what they need and only what they need.

What security implications would you see with this approach?


You've never worked (developed or QA'ed) enterprise software. Running
license servers that can regulate the number of seats or other
attributes of the software is the norm for many high-priced enterprise
software. The customer buys a product. It only runs when you provide
them with a license which must run from a server to which that product
connects to validate that it can run. The license specifies how many
"seats" the program can use (i.e., how many total instances can run
that use that license, to how many other host that product can
connect, or whatever other quotas want to be enforced).
 
R

Rob Harmer

I don't have a problem with licensable entities or enterprise license
distribution - but I do have a problem with software that has features that
can be turned on and off at the behest of the vendor and also the ability to
monitor for marketing or other purposes.

Microsoft are the ones who are offering this capability to ISVs and I see
significant security risks within the approach. see
http://www.microsoft.com/presspass/features/2007/jul07/07-10slpservices.mspx
and
http://www.softwarepotential.com/

Cheers Rob
 
P

Poprivet

Rob Harmer wrote:


I'd say you need to do a lot more research yet; you're not ready for prime
time yet.

Pop`
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top