Page 1 of 1

Question about safety of Enigma

Posted: Fri Jan 27, 2012 1:16 pm
by greg_733
Hello, I am a developer interested in purchasing a software protector, and I've been following Enigma development for about a year now. I've always found it a very strong protector, and lately I've been wondering about purchasing the full version, but a few days ago I noticed that version 3.50 got cracked... so I'm wondering about the safety of this packer. Does it happen to have any "vulnerabilities" that would make it easy to unpack, and if so, are there any plans on fixing those? I found an old topic on this forum in which a person said it was really easy to disable plugins on protected executables... was this other "weakness" fixed? Also, as far as I know the leaked 3.50 version comes with a "patcher" which replaces the asymmetric encryption key and allows you to register with any name/serial combination. Does that mean antiviruses will now detect even legally-acquired-enigma-packed ( weird adjective ._. ) executables as viruses, since they can't really "blacklist" specific keys?
Thanks for your time.

P.S.: If possible, can anyone tell me if this packer is better than Themida, and if so, in which ways? Thanks again.

Re: Question about safety of Enigma

Posted: Fri Jan 27, 2012 2:38 pm
by Enigma
Hi greg_733,

This could be a long discussion.

Regarding patched version - yes, you are correct. I can say it is our fault that this version has appeared. Too many licenses had been leaked last time due to our order processing system and crackers got it too. As they said, if the file is executing then it can be cracked, so deal of protection is a time that cracker need to bypass a protection. But, anyway, this does not mean that protection is not safe, because everything depends on an options you are using. For example, if you use Registration Features - Common - Encrypt with Encryption Constant and/or RegCrypt markers, then application can't be cracked at least without valid registration key. Also, if the public key had been patched, it does not mean that protection/virtualization and other features had been bypassed too.
Our company is going forward with the software developers, and we specially make weak places in Enigma Protector itself to eliminate limitation for our clients, but same time we reduce protection for ourselves. For example, Enigma Protector itself, does not check if debugger is present (because developers often use debuggers, and we do not want to limit usage of Enigma Protector together with debuggers), license for Enigma Protector is not locked to particular PC (because developers may have few development PCs and protection, to our mind, should not be limited to one PC only).
So to make the work of our clients more comfortable, we reduce own safety.

I want to remind you, that there is no any protection which public key can't be patched. If you find a protection that is not patched, then probably it is just not popular, but not so strong.

Regarding antivirus false detection. I always recommend to digitally sign protected files with Comodo or VeriSign certificates. This usually solves all the problems with false detections.

Moreover, are you aware of the coming ability for software protection vendors to sign protected files with IEEE Taggant system http://standards.ieee.org/news/2011/icsg_software.html ? This system will be completed soon, and Enigma Protector will be one the the first of protection system who implement it.

Regarding plans and protection improvements - yes, sure. Huge improvements will be coming soon for protection. I can't share more details, but believe it will be great. Btw, we are always monitoring many forums where the protection of Enigma is being discussed, and we fix every vulnerability very quickly. So the issue with plugins you are talking is already fixed.

Unfortunately, I can't give you comparison between Enigma and Themida, because as a developers of software protection systems we often communicate with each other, help each other, so customer should decide himself what product he prefer.

Re: Question about safety of Enigma

Posted: Fri Jan 27, 2012 3:05 pm
by greg_733
Hello Enigma,
thank you for your quick and exhaustive reply. I can see that development of this packer is REALLY active, one can say that by just looking at the release dates of evey new version. I'm glad to read about that feature you mentioned, it surely is a great way to prevent cracking and boost sales (since anyone who would want to attempt to unpack the program would have to buy it first anyway). As for code signing, the IEEE Taggant System seems a great solution and seeing it coming to Enigma is great. I'm almost positive I will be a customer of yours soon, I have a few projects I'm still working on, and as soon as I complete them I'll need a packer, and Enigma looks like the perfect solution to me. Thank you again for your patience!

Re: Question about safety of Enigma

Posted: Fri Jan 27, 2012 3:34 pm
by Enigma
Yes ok, really we have many already implemented ideas and features in background.

Soon we plan to release Online Activation service, that had been made about a year ago, but still was not released due to lack of documentation.

Curious thing, but we have strong code polymorphic engine, that is not implemented in the current version of Enigma Protector. From one side I agree that it may help to improve the protection, but from other side it will make analyzing of protected files so difficult, that even legal customers will get huge amount of false detections (because antivirus engineers will also not able to reverse protected file quickly). This is because we pray in IEEE Taggant system, and hope that this will allow us to release all our background protection features.