Quake Shareware, a CD-ROM just a little too full
Points and comments are a snapshot, not live.
id Software's Quake shareware CD security was broken because the unlock code was computed locally.
In 1996, id Software released a Quake shareware CD-ROM ($9.95) containing encrypted versions of their full catalog, intended to be unlocked via a phone call with a credit card. The TestDrive Corp system denatured executables, replacing the first 32 KiB with a header and encrypting it as a .ST3 file. The unlock program FLOW.EXE generated the SERIAL from the CHALLENGE itself; the phone agent merely provided a proof-of-payment checksum. Hacker group GNOMON released QCRACK.EXE 39 days later, which generated valid SERIALs locally. Additional flaws included a typo in SKU.17 that prevented unlocking Final Doom for paying customers, and plain-text configuration files left on the disc.
What commenters are saying
Commenters largely agreed that calling the system "security through obscurity" is accurate, as the CD master was identical for all copies and the symmetric key was derivable from data on the disc. Several noted that RSA or other asymmetric schemes would have been impractical over the phone in 1996. A significant subthread discussed the Quake CD's audio tracks: they use pre-emphasis, with the flag set in subcode Q but not the TOC, causing some rippers (notably Exact Audio Copy) to ignore it. Listeners unaware of the pre-emphasis for 30 years may prefer the "incorrect" playback.