Frequency: Consistently
Severity: Blocker
Context: All packages released in MSFS Marketplace before August-September 2023
Bug description: Our Marketplace‑exclusive products released before the 2022 DRM breach remain vulnerable. Although these packages now appear as .fspackage in the Official folder, the content is still accessible, and updates do not restore proper encryption. Other Marketplace‑exclusive developers have confirmed the same behavior, so this does not appear to be an isolated case.
When the Marketplace DRM system was compromised in 2023, previously encrypted content became readable. It appears that older Marketplace packages were never re‑encrypted with new keys after the breach, which means the vulnerability persists even when the product is updated (Including premium deluxe content). The original decrypted versions continue to circulate, and the current DRM pipeline does not seem to apply retroactively to products released before August–September 2023.
I spoke directly with Martial from Asobo at FSExpo and explained the situation. He told me he was not aware of this issue and advised me to open a formal topic here so the team can investigate it properly. I have also reported this several times through Teams but did not receive a response.
This is a blocker for any developer relying on Marketplace‑only distribution, as there is no way for us to restore protection on our side. Updates do not fix the issue, and the affected products remain exposed indefinitely.
We would like to request a full re‑encryption pass for all Marketplace‑exclusive packages released before August–September 2023 so that updated encrypted versions fully replace the legacy unprotected ones. I can provide a private list of affected packages if needed.