board logo
manuel.valenzuela@toolengaged.com.mx
a day ago
As a Kubotek distributor, I've been thinking about how quickly AI models are improving at code analysis and reverse-engineering tasks, and I wanted to raise a question for the community and ideally get Kubotek's perspective.

Our licensing appears to rely on FlexNet Publisher (FlexLM), with signed INCREMENT lines tied to a host ID. My understanding is that the signature itself is protected by the vendor's private key and isn't something that can be forged. But my concern is less about the signature and more about the surrounding implementation and infrastructure:

- How robust is the license validation logic against implementation-level bypasses (as opposed to breaking the cryptography itself)?

- For network/floating licenses, how exposed is the license server, and what's the recommended hardening for it?

- Does Kubotek have a security contact or responsible-disclosure process if a distributor or customer notices something concerning?

I'm not looking to break anything — I'd just like to understand how seriously licensing robustness is being treated as these tools get more capable, and what customers should be doing to protect their license servers.