Live data from Hacker News

How the Xbox 360 knows if your hard drive is genuine

eaton-works.com

161–170 of 266 posts

Re: How the Xbox 360 knows if your hard drive is genuine

#161

Earlier quoted context omitted.

The whole windows market has been an absolute dumpster fire lately. The "modern standby" issue is infuriating. In a year or two I think the Macbook might honestly be the best linux laptop you can buy. I've got Asahi set up on my M1 and it's borderline usable now. Just waiting on thunderbolt and power management to be done and I could work with this.

I would love to agree with you, were it not for this: https://news.ycombinator.com/item?id=34504752 https://www.vice.com/en/article/xgybq7/apple-macbook-activat...

This is a feature I want. If someone steals my MacBook, I want it to be worth the scrap aluminium.

Yes there is a case where someone forgets their Apple ID password and lost access to all their recovery methods, but I’ve got my password memorised and written down so I purely benefit from the theft protection.

The statement on the article is ridiculous too. Apple doesn’t prevent the second hand market, you just have to factory reset the thing before you sell it. The most likely case where this is impossible is the seller stole it.

Re: How the Xbox 360 knows if your hard drive is genuine

#162
post #56

Microsoft really seemed to be ahead of the curve with console security. They really thought this through back in 2005 or so, to the point where clearly, they knew people would hack the drives to rewrite the serial number. It's probably for the best that they never actually did anything about the knowledge that gave them, but they clearly stayed a step ahead of the game. As much as I hate it, their actions show a grea…

Nintendo is not far behind Sony in the (in)security department. The 3DS was hacked in several ways including an browser exploit that worked on recent firmware. The 3DS eShop was serving games via CDN with no authentication. And the first edition Switch has a hardware-based exploit that is unpatchable!

Re: How the Xbox 360 knows if your hard drive is genuine

#163

Earlier quoted context omitted.

Every time I hear about the XBox's platform security, I think back to this talk [1] about how Microsoft protected the XBox One. A lot of it boils down to clear requirements and good engineering, and many of these technologies are now showing up via Project Pluton. [1] https://www.platformsecuritysummit.com/2019/speaker/chen/

and many of these technologies are now showing up via Project Pluton. More awareness needs to be made of how this will have a devestating impact on end-user freedom. They're attacking the PC, one of the last holdouts of general-purpose computing freedom. Remote attestation will make it so you "can" technically run your own hardware and software (and that's what the FUD-spreaders will always say), but you'll be denied…

Apple (and to a lesser extent Android) have already gone this route, and Windows 11 originally wanted to push _hard_ on enforcing the presence of more platform security. DRM schemes already perform remote attestation before you can stream 4K Netflix.

Linux and Open Source may be one of the last remaining barriers to this becoming widespread. It's one of the main reasons I whole-heartedly support Valve and their Steam Deck ambitions, and encourage everyone to do the same. Money trumps everything else, so as long as the money to be made from supporting SteamOS > money thought to be saved from piracy, I believe we can still thwart this.

Re: How the Xbox 360 knows if your hard drive is genuine

#164

Earlier quoted context omitted.

To this day, there is significantly better security in your XBox account to protect your in-game collectables than can be achieved by huge enterprises trying to protect their corporate secrets on Microsoft 365. E.g.: the corporate default settings for MFA show zero additional information. Literally just an “accept” button. The XBox equivalent shows location, etc…

All of that is available in M365 though, it’s just off because many large IT departments optimize for ticket volume as opposed to quality or security.

[deleted]

Re: How the Xbox 360 knows if your hard drive is genuine

#165

Earlier quoted context omitted.

and many of these technologies are now showing up via Project Pluton. More awareness needs to be made of how this will have a devestating impact on end-user freedom. They're attacking the PC, one of the last holdouts of general-purpose computing freedom. Remote attestation will make it so you "can" technically run your own hardware and software (and that's what the FUD-spreaders will always say), but you'll be denied…

Apple (and to a lesser extent Android) have already gone this route, and Windows 11 originally wanted to push _hard_ on enforcing the presence of more platform security. DRM schemes already perform remote attestation before you can stream 4K Netflix. Linux and Open Source may be one of the last remaining barriers to this becoming widespread. It's one of the main reasons I whole-heartedly support Valve and their Steam…

> DRM schemes already perform remote attestation before you can stream 4K Netflix.

On Intel clients, this is done via the Management Engine, bypassing both the CPU and operating system, as the ME can control display output.

Re: How the Xbox 360 knows if your hard drive is genuine

#166
post #144

Earlier quoted context omitted.

The Steam Deck has sold fewer than 1% the number of Switches sold, which tells me there is far more to selling a console than the technology. Well, that’s an obvious statement, but I think many of us tech people commonly under-appreciate all the “non-engineering” components to making a product successful. I think “optimize the UX a bit” is what they did, and it falls very woefully short of what they need. Especially…

Huh? I don't even think there Are official Steam Deck sales numbers. The best I can find was that they shipped over 1 million last October, not sold. But that was actually not long after they BEGAN shipping units. Not only that, but we're comparing it to the Switch, which is one of THE best selling game consoles ever . However, in its first year, IIRC, it actually "only" sold around 10 million units. That suggests th…

The PS Vita is an apt point of comparison - a beautiful piece of hardware that performed fantastically (and in my opinion much more impressive for its time than the steam deck) - that is considered to have been a complete failure.

Re: How the Xbox 360 knows if your hard drive is genuine

#167
post #29

Earlier quoted context omitted.

I have received other requests for this. I thought about it when I redesigned the site, but didn't think people really used RSS that much anymore. I have it on my list to implement (:

I use RSS, so you'd have at least two subscribers :)

Make that 3

Re: How the Xbox 360 knows if your hard drive is genuine

#168

Earlier quoted context omitted.

Every time I hear about the XBox's platform security, I think back to this talk [1] about how Microsoft protected the XBox One. A lot of it boils down to clear requirements and good engineering, and many of these technologies are now showing up via Project Pluton. [1] https://www.platformsecuritysummit.com/2019/speaker/chen/

and many of these technologies are now showing up via Project Pluton. More awareness needs to be made of how this will have a devestating impact on end-user freedom. They're attacking the PC, one of the last holdouts of general-purpose computing freedom. Remote attestation will make it so you "can" technically run your own hardware and software (and that's what the FUD-spreaders will always say), but you'll be denied…

Not to mention that no design is absolutely safe, and if security enclaves like Pluton get exploited to run backdoor, it'll be a lot harder for end user to detect.

Re: How the Xbox 360 knows if your hard drive is genuine

#169
post #85
post #56

Microsoft really seemed to be ahead of the curve with console security. They really thought this through back in 2005 or so, to the point where clearly, they knew people would hack the drives to rewrite the serial number. It's probably for the best that they never actually did anything about the knowledge that gave them, but they clearly stayed a step ahead of the game. As much as I hate it, their actions show a grea…

This was not a security feature at all, it wasn't securing anything? This is purely a feature to allow Microsoft to resell hard drives at 3x the price.

Sounds like semantics to me.

I think you will agree that security in computing is not just "prevent people from getting hacked" or some static goal like that, but rather security is the management of "threats" under a given "threat model".

DRM, for example, is DEFINITELY a form of security software. DRM is an attempt to uphold policies around the access and/or copying of digital data such that access, distribution, etc. is controlled by said policy. Like any security software, it is meaningless if it's trivial to bypass, so it employs techniques to prevent users from modifying it, inspecting it, and otherwise bypassing its security measures.

Similarly, technology that is meant to only allow licensed hardware is largely the same idea. Like SEGA's Trade Mark Security System, although instead of cryptographic signatures, they instead hinged on the threat of a lawsuit. This is still a form of security system, just with a very different model of the threat.

What I am not saying is that these security measures are any good for the consumer. Obviously, these measures are very largely anti-consumer. Arguably there are some potential consumer benefits in limited cases (the most honest answer is probably anti-cheat, because most online games are frustratingly unplayable without some strong approach to dissuade cheating) but that is still not really my point. How is this security? It's simple. It's security against the threat of the end user. It upholds policies that the device vendor would like to impose on the consumer.

A lock is still a security device even if you abuse it to lock somebody in a room against their will.

Re: How the Xbox 360 knows if your hard drive is genuine

#170

Earlier quoted context omitted.

Every time I hear about the XBox's platform security, I think back to this talk [1] about how Microsoft protected the XBox One. A lot of it boils down to clear requirements and good engineering, and many of these technologies are now showing up via Project Pluton. [1] https://www.platformsecuritysummit.com/2019/speaker/chen/

and many of these technologies are now showing up via Project Pluton. More awareness needs to be made of how this will have a devestating impact on end-user freedom. They're attacking the PC, one of the last holdouts of general-purpose computing freedom. Remote attestation will make it so you "can" technically run your own hardware and software (and that's what the FUD-spreaders will always say), but you'll be denied…

> Remote attestation will make it so you "can" technically run your own hardware and software (and that's what the FUD-spreaders will always say), but you'll be denied access to lots of, increasingly online, services.

It's good to raise awareness of the centralization risks of remote attestation. One pro-security, pro-freedom alternative is local attestation, e.g. to a USB security key running OSS firmware under user control. Widespread use of user-controlled attestations would make it harder for cloud services to impose unilateral requirements, requiring negotiation among competing objectives.

One remote attestation scenario could be disaggregation of critical apps into dedicated on-device VMs which look like cloud lambdas/functions/unikernels. Remote attestation could be done for a special-purpose VM (e.g. banking), leaving other general purpose OS VMs unrestricted. This is possible today with Windows Hyper-V on secured-core x86/Arm hardware, Android 13 with the pKVM hypervisor on Pixel 6/7 hardware, and the HP/Bromium AX hypervisor.

MS/Pluton thread, https://twitter.com/dwizzzlemsft/status/1511440279462563842

> what are they going to say when it's supported in Linux and we open source it ... the Pluton team also uses Linux daily, builds TWO Microsoft Linux distros, and upstreams Linux kernel features.

On servers, a forward-looking approach is being taken with OCP Caliptra, an open root of trust that will precede booting of the main SoC (including Pluton) and mandates open firmware that must be dual-signed by both the OEM and the datacenter owner. It is an early attempt to forestall ME/PSP/BMC Groundhog Day. If it succeeds on OCP servers (where datacenter owners have power to negotiate with OEM/ODMs), perhaps more transparency and owner control/veto can be brought to client devices, https://twitter.com/platformsec/status/1533398356088737793.

Post reply on HN