Amazon’s Kindle DRM Update Cripples Bookfab: Pirates Face New Encryption Hurdles

A recent update to Amazon’s Kindle for PC application has severely impacted the ability of e-book cracking tool Bookfab to bypass DRM, making the process significantly more challenging for users seeking unauthorized access. While still functional, the latest version of Bookfab now fails to decrypt a substantial percentage of e-books. Attribution confidence level: High.

The Attack

The core of the issue lies within changes to the Kindle for PC application’s DRM (Digital Rights Management) scheme. Bookfab, designed to remove DRM from downloaded e-books, has struggled to adapt to Amazon’s updates. Users are experiencing a substantial decrease in successful decryption rates. One test case saw only seven out of ten books from a Kindle Unlimited subscription successfully decrypted, a notable decline from previous success rates. The update essentially introduces a new layer of obfuscation, forcing users to repeatedly attempt decryption, restart the applications, or revert to older versions of the Kindle software.

The Actors

This is a classic example of a cat-and-mouse game between content providers and those seeking unauthorized access. There is no specific threat actor in this case, however it is an ongoing struggle between Amazon and the developers of tools like Bookfab. Bookfab itself is not a malicious actor but a tool that enables copyright infringement. Amazon, in response, updates its Kindle application’s DRM to prevent the tool from working as intended, to protect its content.

The Fallout

The immediate impact is a degradation in the user experience of Bookfab users. While the decryption process is not completely blocked, it is now more time-consuming, frustrating, and prone to failure. Users are advised to disable software updates to maintain functionality. The update also indicates that Amazon is actively fighting against tools that undermine its DRM, which is a consistent strategy to protect its intellectual property. Amazon has not released a public statement regarding Bookfab.

Cybercrime Economics

  • Cost of Attack: Minimal, as it involves internal software development and updates.
  • Potential Payout (Lost Revenue): The long-term loss for Amazon depends on the scale of DRM circumvention and the number of users who would have legitimately purchased the e-books.
  • Affiliate Revenue: Not applicable, since there are no affiliates involved.


Leave a Reply

Your email address will not be published. Required fields are marked *