Live data from Hacker News

Keyhole – Forge own Windows Store licenses

massgrave.dev

131–140 of 319 posts

Re: Keyhole – Forge own Windows Store licenses

#131
post #79

Earlier quoted context omitted.

There's cheaters even on consoles which are vastly more locked-down than a PC. Those technical shenanigans clearly aren't working, be ready to be disappointed if you thought that a TPM would help against cheaters. Cheaters always find a way, what those game needs is proper moderation. Yes that does cost money but that's the only known thing that works in the long run.

This seems like the old “any imperfect solution is no better than doing nothing” argument. Moderation is expensive, hard to scale, and can only address problems after other users have bad experiences. It’s like saying seatbelts are useless because some people still get hurt, so instead of seatbelts we need a lot more ambulances and hospitals. Like any complex system, games have a funnel. These technical measures redu…

> It’s like saying seatbelts are useless because some people still get hurt

Alternatively, it's like saying poisoning your customers is a bad way to reduce complaints, because some of them survive. Matter of perspective.

Re: Keyhole – Forge own Windows Store licenses

#132
post #118
post #91

Earlier quoted context omitted.

Yep. This seems to be the most overlooked part of the article, although maybe the most interesting. Unfortunately not for anyone who has activated the auto-update feature on his/her Xbox, as the latest system software version seems to include a higher kernel version than supported by the collateral-damage exploit.

Exactly why you should never, ever, enable auto update, for anything. Too often it ends up breaking something or patching something you don't want patched. It allows a profit seeking company to enable or disable software functionality on your device, regardless if it's in your interest.

It should be noted that unless you've modified an Xbox One, from what I understand you cannot stop it from auto updating unless you permanently disconnect it from the internet (which will cause your licenses to eventually expire, in the year timespan or so), new launch games won't run (they're tied to a minimum version of the OS).

Re: Keyhole – Forge own Windows Store licenses

#133
post #125

Earlier quoted context omitted.

The end state of your argument is the game runs entirely on hosted hardware and you pay for a license to stream the final rendered output to your monitor. This is already happening. Soon games won’t be able to be “bought” at all, you’ll just pay the server a number of dollars per hour for the privilege of them letting you use their hardware. You will own nothing and like it.

Making occlusion calculation sever-side during multiplayer have nothing to do with "owning" a game or not. You can even do this calculation on community-run private server.

If all surfaces are fully opaque, maybe. The second particle effects and volumetric effects and all sorts of advanced techniques play a role in actual gameplay, no. And that’s only for this one type of cheating.

Re: Keyhole – Forge own Windows Store licenses

#134

Earlier quoted context omitted.

>> Does tying those keys to your MS account fix that failure method? >Yes. Bitlocker recovery keys are escrowed to the Microsoft account. Which then opens the door to other attack vectors, even government.

As opposed to just not encrypting their data at all and letting everyone who ends up with the drive have their data. So one scenario, everyone can access the data if they get the drive. The other, the government might get Microsoft to release the encryption keys.

>As opposed to just not encrypting their data at all and letting everyone who ends up with the drive have their data.

You are presenting a false dilemma where either Bitlocker is in use or the drive is entirely unencrypted; there are other ways to ensure data integrity in the face of physical compromise.

Re: Keyhole – Forge own Windows Store licenses

#135
post #44

MAS (which is also hosted on Github) is the perfect example of Microsoft not caring about end user piracy. Just use it.

Maybe it's beneficial for Microsoft that solutions like that are FOSS so they can more easily inspect the code for prevention purposes in the future?

Instead I think that they let people use it unauthorized, so that Windows is even more entrenched. Same with what Adobe did with Photoshop. These companies are lucky that their product gets home and office use as well, because they can let the noncommercial use slide, and just squeeze the office users more.

It's more of a business move, than a technical move. Microsoft has plenty of capable people, they don't need such software to be FOSS to successfully inspect it.

Re: Keyhole – Forge own Windows Store licenses

#136
post #129
post #120

Earlier quoted context omitted.

> It's impossible to tell in-game if a baseball player is using steroids, yet there's a laundry list of banned substances and players who got banned for taking them because the MLB believes it gives them an unfair advantage. It's called competitive integrity. This is relative to meat-space, not videogame, but we could go there and say caffeine or Adderall use is cheating, thus making anti-cheat a little more invasive…

Many games have ranked ladders now which are taken fairly seriously. Success at high levels of ladder player often translates into career opportunities, especially in League of Legends. > Any ELO-based matchmaking will solve this, cheater will end-up playing against each-other or against very skilled player. Well, first, you're wrong, because cheating only makes them good at one part of the game, not every part of th…

> You don't play competitive games, that's fine, but a lot of people do and they demand more competitive integrity than casual players.

Little difference : I don't play competitive game with completes strangers on company run servers.

I've played competitively on community based server, with people being screened by other players and the community able to regulate itself (ban or unban players).

The problem space is vastly different, you don't need intrusive ring 0 anti-cheat for this.

The whole kernel-level anticheat stuff is a poor solution to a self-made problem by the developer : they wanted to be the one in charge of the game and servers, so they needed to slash human moderation need. They also wanted to create a unique pool of player and didn't want the community to split between itself and play how they want.

Re: Keyhole – Forge own Windows Store licenses

#137

MAS (which is also hosted on Github) is the perfect example of Microsoft not caring about end user piracy. Just use it.

In the long run, pirated copies of Windows are noise level: The vast majority of people are going to get a license via an OEM (which survives reinstallation), businesses aren't going to risk running unlicensed windows machines (especially if they're paying for it elsewhere) and have easy means to acquire OEM licensed machines that are supported by the OEM for parts & service, and people who run an up to date but pirate-licensed copy of Windows are at least running an up to date version instead of sitting on an EOL copy that is barely getting security updates.

Allowing piracy at that level is actively safer in the long run.

Re: Keyhole – Forge own Windows Store licenses

#139

Earlier quoted context omitted.

Another TPM thing? What problem do you have with the TPM?

TPM end game is to have identity tied to a device on pcs, just like the monopolies already have on Android and IOS. you know how google and apple dropped actual totp 2nd factor for their own accounts and force you to sign on another device to confirm signing on new devices? same thing.

You can use FIDO2 keys as 2nd factor for Apple accounts now

Re: Keyhole – Forge own Windows Store licenses

#140
post #60
post #50

Earlier quoted context omitted.

Apple has SMS if you don’t own an Apple device. In fact, they require SMS to set up 2FA. They probably dropped totp because non-technical people can’t figure it out.

SMS is not really great.

SMS is trivially exploitable. It has negative security value.
Post reply on HN