Live data from Hacker News

Keyhole – Forge own Windows Store licenses

massgrave.dev

121–130 of 319 posts

Re: Keyhole – Forge own Windows Store licenses

#121

Earlier quoted context omitted.

you have tp hold a key longer and then there it is. i think it was „s“

Typing this from a German iPad keyboard. It’s the ampersand key (& → §).

oh interesting, using "section" as footnote marker is more alien to me than using yen

Re: Keyhole – Forge own Windows Store licenses

#122
post #56

So, just stating the obvious, you can now (¥) download all xbox games directly from the microsoft store for free? I.e. the xbox is - for now - as completely hacked as the PS Vita? (¥) you might have to figure out some details

Total tangent, but extremely interested in the use of the Yen/Yuan sign as a footnote marker. Is there some history here I’ve overlooked or is this just arbitrary?

[deleted]

Re: Keyhole – Forge own Windows Store licenses

#123

Earlier quoted context omitted.

> Does tying those keys to your MS account fix that failure method? Yes. Bitlocker recovery keys are escrowed to the Microsoft account. I've relied on this recover data from a family member's PC when it failed and they had unknowingly opted-in to Bitlocker (a Microsoft Surface Laptop running Windows 10 S Mode).

>> Does tying those keys to your MS account fix that failure method? >Yes. Bitlocker recovery keys are escrowed to the Microsoft account. Which then opens the door to other attack vectors, even government.

As opposed to just not encrypting their data at all and letting everyone who ends up with the drive have their data.

So one scenario, everyone can access the data if they get the drive. The other, the government might get Microsoft to release the encryption keys.

Re: Keyhole – Forge own Windows Store licenses

#124
post #84

Earlier quoted context omitted.

You're being disingenuous here, or just missing the point. The point being made was the gamers are demanding game developers stop cheaters... and that secure boot (and related ways to lock down the computer) is one of the primary tools they know to use to do that.

> The point being made was the gamers are demanding game developers stop cheaters... and that secure boot (and related ways to lock down the computer) is one of the primary tools they know to use to do that. That's akin to saying that, as people want security on the street, mandatory strip search as soon as your exit your home is fair game. Asking for a result doesn't give a blank-check for all the measures taken tow…

I agree, but it doesn't change the fact that it's one of the primary reasons they're doing it. And "strip searches on the street" may not happen, but "Stop and Frisk" certainly is/was. And it was very much done because people were complaining about crime and safety. And it was done regardless of whether or not it was right, or effective, or even legal.

Re: Keyhole – Forge own Windows Store licenses

#125
post #100

Earlier quoted context omitted.

Well yeah, that's the correct way to run a server, don't send information you don't want the user to get. But as you are pointing out, forcing client-side intrusive anti-cheat is cheaper, thus this as nothing to do about preventing cheating, but about reducing cost.

The end state of your argument is the game runs entirely on hosted hardware and you pay for a license to stream the final rendered output to your monitor. This is already happening. Soon games won’t be able to be “bought” at all, you’ll just pay the server a number of dollars per hour for the privilege of them letting you use their hardware. You will own nothing and like it.

Making occlusion calculation sever-side during multiplayer have nothing to do with "owning" a game or not.

You can even do this calculation on community-run private server.

Re: Keyhole – Forge own Windows Store licenses

#126

Earlier quoted context omitted.

>> Does tying those keys to your MS account fix that failure method? >Yes. Bitlocker recovery keys are escrowed to the Microsoft account. Which then opens the door to other attack vectors, even government.

I’d imagine most people would like some insurance in the event of loss or theft, but are not worried about government. I’m vulnerable to the $8 wrench attack, but enjoy knowing it is only a VISA problem if I leave it a laptop the bus.

I mention that only because it's one avenue. I figured obviously on a place like Hacker News that malicious agents aside from government could also compromise the security of 3rd party-held keys; as always security is a matter of difficult tradeoffs and anticipated threat categories.

Re: Keyhole – Forge own Windows Store licenses

#127
post #77

Earlier quoted context omitted.

[flagged]

Back in my day we all played on private, community ran servers where you could easily vote to kick/ban folks, the server owner was your buddy, or you played with people you trust. Now everything is matchmaking, private servers, live service and that sense of community is gone.

Why isn't it still like that? Don't players want small communities?

Re: Keyhole – Forge own Windows Store licenses

#128
> As it turns out, data after the signature block isnt checked at all... and it can even override data that came before it. Whenever two blocks of the same type are stored together, the last one overrides all the others before it. So, if we want to change any license data, we can just make a block for it and put it after the signature block!

Amazing.

Re: Keyhole – Forge own Windows Store licenses

#129
post #120
post #108

Earlier quoted context omitted.

> The server is all-seeing, if there is no way for the server to discriminate cheater from other player, then no player can possibly know there a cheater on the server, thus cannot complain about cheating is either irrational or the server-side detection is severely flawed. It's impossible to tell in-game if a baseball player is using steroids, yet there's a laundry list of banned substances and players who got banne…

> It's impossible to tell in-game if a baseball player is using steroids, yet there's a laundry list of banned substances and players who got banned for taking them because the MLB believes it gives them an unfair advantage. It's called competitive integrity. This is relative to meat-space, not videogame, but we could go there and say caffeine or Adderall use is cheating, thus making anti-cheat a little more invasive…

Many games have ranked ladders now which are taken fairly seriously. Success at high levels of ladder player often translates into career opportunities, especially in League of Legends.

> Any ELO-based matchmaking will solve this, cheater will end-up playing against each-other or against very skilled player.

Well, first, you're wrong, because cheating only makes them good at one part of the game, not every part of the game. e.g. in League of Legends, a scripting Xerath or Karthus who hits every skillshot is going to win laning phase hard. However, scripting isn't going to help if they have bad macro and end up caught out in the middle of the game, causing their team to lose. Most cheaters don't end up at the top of the ladder, they end up firmly in the upper-middle.

Secondly, you're basically saying "cheating is OK because they'll end up at the top of the ladder." You don't realize how ridiculous this sounds?

Third, ranked and competition aside, playing against someone who's cheating isn't fun, even if you end up winning because they make mistakes that their cheats can't help them with.

You don't play competitive games, that's fine, but a lot of people do and they demand more competitive integrity than casual players.

Re: Keyhole – Forge own Windows Store licenses

#130
post #100

Earlier quoted context omitted.

Well yeah, that's the correct way to run a server, don't send information you don't want the user to get. But as you are pointing out, forcing client-side intrusive anti-cheat is cheaper, thus this as nothing to do about preventing cheating, but about reducing cost.

It's not just about cost. Theoretically yes, you shouldn't send information that you don't want users to get and abuse. However, in the context of games, this is not always possible because most games are realtime and need to tolerate network latency. There is no perfect solution - there will always be tradeoffs. Ideally player A shouldn't be networked player B if there is a wall between them but what happens when th…

> Or your game design might require you to hear sounds on the other side of the wall (footsteps, gunshots, etc.) which allows cheats to infer what what may be behind the wall better than a person would.

Yes, and you cannot prevent this except in in-person tournament.

Any output send toward the player, even a faint audio queue could be analyzed, and use to trigger an action or display an overlay to the screen, and no amount of kernel-level stuff will prevent that, as you can do this outside of the computer running the game.

Post reply on HN