Live data from Hacker News

How the Xbox 360 knows if your hard drive is genuine

eaton-works.com

181–190 of 266 posts

Re: How the Xbox 360 knows if your hard drive is genuine

#181
post #56

Microsoft really seemed to be ahead of the curve with console security. They really thought this through back in 2005 or so, to the point where clearly, they knew people would hack the drives to rewrite the serial number. It's probably for the best that they never actually did anything about the knowledge that gave them, but they clearly stayed a step ahead of the game. As much as I hate it, their actions show a grea…

I don’t think Xbox Dev Mode is really worth a damn. You can sideload apps but it’s not a vector for piracy or running Windows or Linux.

PS3 Linux was about as useless as PS2 Linux, because the PS3 had only 256MB of RAM. I put Ubuntu Server on one and used it as a Squid proxy server to route P2P traffic through to the university’s college of computing since P2P was blocked in the dorms. For some stupid reason I totally got away with it. PS3 running in one of the research labs 24/7 routing traffic all day.

Re: How the Xbox 360 knows if your hard drive is genuine

#182

Earlier quoted context omitted.

>TBH the Xbox 360 console was like a refresh of XBMC. According to sources, a modified original Xbox running the latest XBMC was put on the center podium, was shown off, and the executives had ordered the engineers to "make the new xbox do this"...and it was.

The 360's early media capabilities were absolutely unheard of for the time I was blown away when half way through the setup of my 360 my desktop running Vista helpfully chimed in saying it found the 360 and offered to let me stream all my MP3's right to it while playing games

Apple and Amazon are only now adding the group watch functionality that Netflix had on the 360. I really don’t know why this fell off because it was really popular within my friend group and we’d watch a movie together a couple times a month.

Re: How the Xbox 360 knows if your hard drive is genuine

#183

Earlier quoted context omitted.

I had an xecuter mod on the first Xbox and a 2TB hard drive, you could do so many many things with Xbox Media Center on the very first Xbox - FTP your games over. TBH the Xbox 360 console was like a refresh of XBMC. One of the greatest things about the 360 out of the box was it played popular video codecs directly from USB storage - unmodded! Unheard of at the time. I had an early model PSX console in high school and…

>TBH the Xbox 360 console was like a refresh of XBMC. According to sources, a modified original Xbox running the latest XBMC was put on the center podium, was shown off, and the executives had ordered the engineers to "make the new xbox do this"...and it was.

I have an Xbox 360 that has never played a game in its life, but served many years as a media center extender. Microsoft really did get that thing right.

Re: How the Xbox 360 knows if your hard drive is genuine

#184

Earlier quoted context omitted.

This is only possible for server-controlled experiences, and it doesn't stop people from botting and aimhacking. Basically unworkable for action games.

And yet there are plenty of action games that remain fun to play while running on platforms that ain't locked down tighter than a jelly donut stash in a weight loss clinic. Botting and aimhacking do happen, but apparently not with sufficient frequency to be a problem.

It's so much of a problem that most PC games make you install a rootkit, you mean?

One of the big ones (Valorant) requires a rootkit that actively disables running unrecognized software, specifically to stop you from cheating.

Re: How the Xbox 360 knows if your hard drive is genuine

#185
post #56

Microsoft really seemed to be ahead of the curve with console security. They really thought this through back in 2005 or so, to the point where clearly, they knew people would hack the drives to rewrite the serial number. It's probably for the best that they never actually did anything about the knowledge that gave them, but they clearly stayed a step ahead of the game. As much as I hate it, their actions show a grea…

I don't get this. Hacking was huge on the 360, as was piracy that JTAG thing using the cooler runner and browning out the processor after slowing it, there were multiple mod chips and finally the ODEs coming out the wazhoo. The funny thing about security is it's about the weakest links they find. So you can harden link A as much as you want if link B is a dud all the extra work on A was wasted energy. What's most imp…

> Hacking was huge on the 360

It was! I was a pre-teen then but I remember modded controllers and getting into modded lobbies. The only modding I did was USB modding my avatar and gamerscore, only to login a month or so later to the prompt that my account was banned forever.

Re: How the Xbox 360 knows if your hard drive is genuine

#186

Earlier quoted context omitted.

and many of these technologies are now showing up via Project Pluton. More awareness needs to be made of how this will have a devestating impact on end-user freedom. They're attacking the PC, one of the last holdouts of general-purpose computing freedom. Remote attestation will make it so you "can" technically run your own hardware and software (and that's what the FUD-spreaders will always say), but you'll be denied…

> Remote attestation will make it so you "can" technically run your own hardware and software (and that's what the FUD-spreaders will always say), but you'll be denied access to lots of, increasingly online, services. It's good to raise awareness of the centralization risks of remote attestation. One pro-security, pro-freedom alternative is local attestation, e.g. to a USB security key running OSS firmware under user…

One pro-security, pro-freedom alternative is local attestation

What's the point? That's about as useful as running your own CA. The fact is, those pushing remote attestation want remote centralised control and they're going to care that you have your own attestation infrastructure as much as they'll care that you have your own CA, i.e. they're not going to be satisfied because they're trusting their own, and not yours.

the Pluton team also uses Linux daily, builds TWO Microsoft Linux distros, and upstreams Linux kernel features.

That's even scarier. If the only form of "supported" Linux becomes Microsoft Linux (with its own unique brand of spyware and other crap forced on you due to RA), don't say we never saw it coming: Embrace, Extend, Extinguish... or perhaps that last E should now be Enslave.

If it succeeds on OCP servers (where datacenter owners have power to negotiate with OEM/ODMs), perhaps more transparency and owner control/veto can be brought to client devices,

We already had "owner control" until they started trying to take that away from us. We don't need nor want attestation at all. No means NO!

Re: How the Xbox 360 knows if your hard drive is genuine

#187
post #179

Earlier quoted context omitted.

and many of these technologies are now showing up via Project Pluton. More awareness needs to be made of how this will have a devestating impact on end-user freedom. They're attacking the PC, one of the last holdouts of general-purpose computing freedom. Remote attestation will make it so you "can" technically run your own hardware and software (and that's what the FUD-spreaders will always say), but you'll be denied…

The PC will eventually lock up more. Free general-purpose computing will remain on things like Raspberry Pi (and many other variants). There will be Windows computers, like we now have Macs, and Windows-incapable computers to run Linux (or whatever else open OS).

Free general-purpose computing will remain on things like Raspberry Pi

Leaving aside the debatable nature of how open and free a RPi is, what's the point of "general-purpose computing" when it can't actually be used? When/if you need a locked-down machine controlled by some central authority to do what you can still do today with a free and open one, i.e. create and consume media, interact with services, communicate with others, etc., how much value does a truly libre computer have? It's almost like the "just build your own platform" argument when it comes to censorship.

Re: How the Xbox 360 knows if your hard drive is genuine

#188

Earlier quoted context omitted.

> Remote attestation will make it so you "can" technically run your own hardware and software (and that's what the FUD-spreaders will always say), but you'll be denied access to lots of, increasingly online, services. It's good to raise awareness of the centralization risks of remote attestation. One pro-security, pro-freedom alternative is local attestation, e.g. to a USB security key running OSS firmware under user…

One pro-security, pro-freedom alternative is local attestation What's the point? That's about as useful as running your own CA. The fact is, those pushing remote attestation want remote centralised control and they're going to care that you have your own attestation infrastructure as much as they'll care that you have your own CA, i.e. they're not going to be satisfied because they're trusting their own, and not your…

> they're not going to be satisfied because they're trusting their own, and not yours.

This cuts in both directions. Unlike signing certificates, attestation is not a zero-sum fight over a single monolithic measurement attribute that can only be A or B, it can support a goal of having A and B, e.g. as disaggregated VMs. If a cloud wants subset B, then the user/owner/enterprise local attestation can insist that the client must also have subset A, otherwise it can reject subset-B-without-A. Also applies to multiple clouds with conflicting requirements.

Enterprise clients connected to centralized clouds are not the same as consumption-oriented DRM, where the decision is grant/deny. Enterprise client devices generate business data that is sent to the cloud, and they consume data/compute/apps from the cloud. If businesses stop sending data to the cloud, the hybrid workflow breaks down. It's not as one-sided as Netflix DRM.

> We already had "owner control" until they started trying to take that away from us.

With the exception of IBM POWER / Talos servers that have open firmware including the BMC, most servers depend on many blobs, so there has been little transparency for owners, never mind control. One has to start somewhere, and Caliptra starts at the beginning, with an open silicon+firmware RoT that can potentially evaluate some of the myriad blobs and processors and devices needed to bring a server online.

E.g. DMTF SPDM can be used for local PCI (or virtualized I/O like NVMe-over-TCP) device attestation of firmware integrity to the server, before the device is authorized for use in the server, https://www.dmtf.org/standards/SPDM & https://www.platformsecuritysummit.com/2019/speaker/plank

Re: How the Xbox 360 knows if your hard drive is genuine

#189

Earlier quoted context omitted.

Apple (and to a lesser extent Android) have already gone this route, and Windows 11 originally wanted to push _hard_ on enforcing the presence of more platform security. DRM schemes already perform remote attestation before you can stream 4K Netflix. Linux and Open Source may be one of the last remaining barriers to this becoming widespread. It's one of the main reasons I whole-heartedly support Valve and their Steam…

> DRM schemes already perform remote attestation before you can stream 4K Netflix. On Intel clients, this is done via the Management Engine, bypassing both the CPU and operating system, as the ME can control display output.

Is there any mechanism for it to validate that the thing connected to the display output is an unmodified monitor which also implements DRM? Otherwise it would be almost trivial to have a device with HDMI-in that gets a pixel perfect feed of the protected stream.

Re: How the Xbox 360 knows if your hard drive is genuine

#190

Earlier quoted context omitted.

> DRM schemes already perform remote attestation before you can stream 4K Netflix. On Intel clients, this is done via the Management Engine, bypassing both the CPU and operating system, as the ME can control display output.

Is there any mechanism for it to validate that the thing connected to the display output is an unmodified monitor which also implements DRM? Otherwise it would be almost trivial to have a device with HDMI-in that gets a pixel perfect feed of the protected stream.

Yes, that's called HDCP. The master key was cracked long ago for older versions.
Post reply on HN