I assume there’s some historical reason for this, but currently, the way scene releases reach most people seems to consist of:

  1. Sites that track releases post the nfo file of the release; these sites generally don’t provide the release itself.

  2. People then look for the release via various channels and download it.

Wouldn’t it make sense for the nfo to contain the checksum of the actual release, letting pirates verify unmodified copies of it and making it easier to avoid versions that have been modified in various ways?

Obviously you’d still have to trust both the site where you got the NFO (and therefore the checksum) and the people who made the original release, but those are usually relatively trustworthy, being known people who have handled a lot of releases with no problems - a lot of the danger of viruses and the like in software piracy comes from the risk of middlemen adding something.

Chewie
link
fedilink
139M

@Yglorba

Good question. I guess people thought naively that .sfv files were enough, but of course that’s not true.

Some .nfo files contain md5s for things, but that would be easily changeable.

It would have to be a cryptographic checksum, using something like GPG/PGP with a distributed fingerprint to be any good.

I’ve seen one or two over the years, but not as many as you’d expect for people that should be worried about security and image.

deleted by creator

@readme@lemmy.dbzer0.com
link
fedilink
English
19
edit-2
9M

Modern scene dosn’t even require strict .nfo files. Most TV groups in WEB or HDTV sections just basic mediainfo and imdb link. Only the oldest and best scene groups do ascii art in nfo files.

P2P groups don’t even have .nfo files and if they do its mostly foum html with mediainfo. Some include .txt with mediainfo only. I’ve only seen EVO p2p group do decent .nfo files.

However all scene groups are required to include .sfv rar checksum files. I’ve never seen any p2p groups do this. Most p2p groups .nfo files are forum html of mediainfo.

But when scene releases leak to public and unrared, files like .sfv deleted by uploaders. But you can use srrDB.com most of there .nfo include .sfv files.

@Cycloprolene@lemm.ee
link
fedilink
English
19M

most of there .nfo include .sfv files.

But they are mostly crc32, that’s 100% useless.

I’ve noticed some scene game/software releases have blake3 hashes now. That doesn’t account for everything else, but I’d say it’s a good step.

@MonkderZweite@feddit.ch
link
fedilink
English
1
edit-2
9M

What is a .sfv file some mention here?

Lemmy Tagginator
bot account
link
fedilink
19M

removed by mod

The SFV file contains checksums.

@drunkensailor@lemmy.dbzer0.com
link
fedilink
English
1
edit-2
9M

deleted by creator

Point 2: “Sites which track NFOs” track NFO files of scene releases because noone cares about P2P NFOs. Scene releases are intended to spread on FTP, not BitTorrent. They also come with CRC-32 checksums in file extension .SFV

@drunkensailor@lemmy.dbzer0.com
link
fedilink
English
1
edit-2
9M

my bad. deleted my previous guesses since it seems i missed a few key words there

@Cycloprolene@lemm.ee
link
fedilink
English
4
edit-2
3M

93A1A71EABD6B6CD658458CC1F4

Uh… If they messed with the iso, they could very easily mess with the NFO

@Yglorba@lemmy.dbzer0.com
creator
link
fedilink
English
3
edit-2
9M

Yes, I mentioned that - but trusted public sources, who often post on places like Reddit or personal websites run out of the US and the like, can post NFOs but can’t post the actual game. If you knew the correct checksum, you could then turn around and grab the game from an untrusted source.

Distributing the game itself is the dangerous part (in terms of making the copyright pinkertons come after you) so it’s better if it can be done as anonymously as possible, but that conflicts with the need to have it distributed by someone trusted. Putting the checksum in the nfo, which is widely reposted by trusted sources, would help avoid this problem.

@Cycloprolene@lemm.ee
link
fedilink
English
2
edit-2
3M

93A1A71EABD6B6CD658458CC1F4

Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ
!piracy@lemmy.dbzer0.com
Create a post
⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.

Rules • Full Version

1. Posts must be related to the discussion of digital piracy

2. Don’t request invites, trade, sell, or self-promote

3. Don’t request or link to specific pirated titles, including DMs

4. Don’t submit low-quality posts, be entitled, or harass others


Loot, Pillage, & Plunder


💰 Please help cover server costs.

Ko-FiLiberapay


  • 1 user online
  • 219 users / day
  • 509 users / week
  • 927 users / month
  • 4.94K users / 6 months
  • 1 subscriber
  • 3.23K Posts
  • 79K Comments
  • Modlog