A while ago a person I know has had a pretty significant issue that could have ended badly.

Thinking back it is a very silly oversight, but I document it here so you don’t need to repeat it.

Here is a summary

Before the situation

The user got an Adobe license from their education facility or work, the usual scenario. They were trained on Adobe software so switching is really hard.

It is possible to switch to cracked versions of every app in the creative cloud suite, but before you do that, you need to make sure to remove any trace of the account from your machine!

In practice I would recommend to reinstall Windows. Maybe keep a copy of a very barebones debloatet Win11 install and clone it with Clonezilla.

If you don’t go that far, there are many ways Adobe could re-identify you!

The user was logged into their Adobe account in Firefox, which was the crucial mistake here.

About the cracked software

I only recommend to get cracked software from reputable private trackers! I will not give names, but they could be invite-only, so join Signal/SimpleX/Session groups to get in contact with peers.

There is a release group that somehow acquires offline installers of the entire creative suite, which are not available to consumers normally.

They also include scripts to cleanup the system of previous installs, which is very difficult! Even BulkCrapUninstaller or ChrisTitus’ WinUtil had issues removing the last pieces of that install. Adobe refuses to distribute sandboxed .appx packages through the Microsoft Store, assume they have invaded your system deeply, run in the background constantly and cannot easily be removed.

Adobe is malware, treat it like that.

The patched release also contains a script that adds a lot of domains and IPs to the system etc/host file, which blocks connections to those domains, which would otherwise make the use of the cracked software impossible. When done right, this is a big privacy improvement! But the IPs and domains could change, the people could have missed some rarely occuring connections etc.

What happened

The user got an email to the mail that they had previously used for their account, greeting them “welcome back strange_username123!”

We assume this username was somehow saved in the cracked versions of the adobe software and might be the same across all installs, which would be very problematic.

How could this happen?

  1. Any app even without internet access can tell the OS to open a link. This link opened in Firefox (hey, at least not Edge /s)
  2. Firefox autofills username and password by default! This means even without any cookies, if you have saved an old login, it will autofill the email which the website can see. Instant breach. You can turn this off in about:preferences#passwordsAutofill
  3. Even without that, Firefox saves all cookies by default, because they don’t care enough to develop a nicely usable UI. Website owners can choose how long their cookies should persist and first-party-cookies (adobe.com for adobe.com) will always be accepted. Even with cookie deletion enabled, you might have set adobe.com to the allowlist, because well, you used that in the past! Check in about:preferences#privacy

Some Adobe software had opened this link, which opened in Firefox, which doesnt use the system etc/host file for DNS lookup. Firefox either sent the website that cookie, or autofilled the email, doesn’t matter!

We were able to find that link in the browsing history and inspect it. It contains the application version number, language, a long token and other information.

No guarantees!

Even with a wiped browser, Adobe has access to basically the entire system. It could have saved a key somewhere, maybe in the registry, that allows re-linking your identities anywhere.

You can only be sure on a clean install, best inside a VM without any internet access.

  • Lupin@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 days ago

    I don’t know if anyone else mentioned it, but GIMP is free and apparently has a plugin that makes it look and feel exactly like Photoshop. It’s entirely legal as well, so Adobe can’t do anything about it.

    Might be good to know, if you OR your friend wanna use Phototshop, but don’t wanna give Adobe any money. Edit: I can’t say anything about other Adobe software, though. This is just for Photoshop, as far as I know.

    • exdor@programming.devOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      2 days ago

      PhotoGimp is not a plugin but a set of config files (including random session files from the dude that made it XD)

      One thing missing is algorithmic tools like auto-removal or auto-selecting people and objects. It is not very complex but I dont know a gimp plugin for that

      • Lupin@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        2 days ago

        Well, today I learned. But if both OP and their friend are tech savvy enough to get a cracked copy of Adobe stuff, then they’re probably tech savvy enough to get PhotoGimp working. Both are simple things, after all. Plus, if they can’t get PhotoGimp working or need the auto-removal or auto-selecting stuff, then I saw someone mention a couple of other alternatives. So they could use one of those, assuming those fit their needs.

    • FoxAlive@lemmy.zip
      link
      fedilink
      English
      arrow-up
      0
      ·
      9 days ago

      I’m glad I’m too stupid to ever be acussed of being ai out put. I’m going to say its intentional my spelling and grammer is so bad to seem more genuine.

  • 0x0@infosec.pub
    link
    fedilink
    English
    arrow-up
    0
    ·
    8 days ago

    This entire post just sounds alarming for no reason… How could this have ended badly? Too many words and no real answer, is this just a buzzfeed article?

  • cecilkorik@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    9 days ago

    My solution to Adobe is: Gimp, Inkscape, Krita, Kdenlive, etc.

    Fuck Adobe malware forever. It’s a bait and switch, and I’m never going to be taking the bait.