back to article Flight Simulator's DRM fighter nosedives into Chrome's cache

A Chrome password dump tool found in the latest update from Microsoft's Flight Simulator Add-On wrangler, Flight Sim Labs, has virtual pilots up in arms. The download featured updates to the Airbus A320 model including improvements to the engine crank and flare mode logic and, er... a password harvester for Chrome. Noted in a …


    1. dubious

      Re: They are probably Android developers as well

      It is concerning how much data apps can extract, either directly or as part of the analytics framework, without triggering a request for permission.

      Don't use Android without xposed+xprivacy!

      I don't suppose it is any different with ios though?

  1. IneptAdept

    Oh and also not sending the passwords in encrypted format.. Bastards

    An update from a pentest company that describes that the passwords are sent in plaintext to their heztner hosted server

  2. Anonymous Coward
    Anonymous Coward

    After this farce the last thing they'll be worrying about is piracy....

    a) no one in their right mind will ever buy or install anything from them again

    b) they may well end up in court.

    1. Anonymous Coward
      Anonymous Coward

      Actually the pirated version, assuming from a, ehem, reputable ripping group, is probably safer than the official version, as all the malware/DRM would have been removed or bypassed as part of their packaging.

    2. Mayday Silver badge


      I have a pretty good Prepar3d based flight sim setup. It is rather helpful for my current level of flight training.

      Now I have not, and as from now I never will, purchase a product from these clowns ever.

  3. FuzzyWuzzys Silver badge

    They'll get away with wouldn't!

    They can install what they like, capture they like, apologise and it's all good. If you did this, your feet wouldn't touch the ground before you'd be in front of the beak!

    1. John Brown (no body) Silver badge

      Re: They'll get away with wouldn't!


      No idea why you got downvoted, but you are spot on. If an individual does this to a company, if they get caught they go to court because a Police complaint is made and it's taken seriously. All it should take is one single complaint to the Police over this case and investigation should start. But you know it won't happen, If, and it's a big if, there is enough of an outcry, then maybe some government department might be persuaded to start some sort of weak investigation and wrists might be slapped, maybe a small fine.

    2. Voland's right hand Silver badge

      Re: They'll get away with wouldn't!

      They can install what they like, capture they like, apologise and it's all good.

      I would not be so sure. Depends who deals with this. If they pissed off a flight sim fan who happens to be a lawyer or work in CPS they may be up to a very unpleasant experience. Unfortunately as with many other things the only exemption to "we, in the UK, have one of the best legal system money can buy" is when you are dealing with members of said system.

  4. Anonymous South African Coward Silver badge

    Mind. Boggle.

  5. TrumpSlurp the Troll Silver badge

    All your passwords

    Are belong to us.

  6. Dwarf Silver badge

    Blunt weapon

    Of course the fact that they sniffed passwords from innocent people's PC's too is fine, sure they won't mind at all - because <insert bad phrase>

    Its malware however you look at it. Trust is built up slowly but lost in an instant.

    Does this affect those who play flight sim through Steam too ?

    1. Anonymous Coward
      Anonymous Coward

      Re: Blunt weapon

      They did, as far as it has been described, not sniff passwords from all users.

      Flight Simulator in itself was not affected. It was the installer of the FSLabs products, which are FS Addons.

  7. Rob Crawford

    Crucify them

    Well that's about all I have to add really

  8. Anonymous Coward
    Anonymous Coward

    Has anyone reported them to the FAA?


