Live data from Hacker News

Keyhole – Forge own Windows Store licenses

massgrave.dev

171–180 of 319 posts

Re: Keyhole – Forge own Windows Store licenses

#172
post #98

Earlier quoted context omitted.

Let me tell you a secret: it's because the gamers are demanding that. The game companies couldn't care less if there are cheaters in the game, but it's the players which put huge pressure on the game companies to detect and ban cheaters.

Gamers don't want cheaters, but gamers also don't want malware. Some people won't care, others will care. The real problem is that publishers don't give anybody a choice on this. They sneak these invasive anti-piracy measures into their games without asking since they don't want to fragment their player base. The reasonable, fair, common-sense pro-consumer thing to do is to split the online play in two: a non-antiche…

> The reasonable, fair, common-sense pro-consumer thing to do is to split the online play in two: a non-anticheat server and an anti-cheat server. Players can opt-in to installing a rootkit/sharing their SSN/whatever if they want to play on the hardened server. This costs nothing, and makes all types of gamers happy.

This is a very good point! And I'd like to point out that there is an analogue to the problem of smurfing in online video games, and the corresponding solution, which is to require semi-unique ID to play (e.g. a phone number which can only be tied to one account at a time with a cool-off period when transferring between accounts). Valve does this for Dota 2, and smurfing is far, far less common than it is in League of Legends.

Some League players complain that they don't want to give their phone number to Riot (which is entirely reasonable given that it's a subsidiary of Tencent), but if enough people don't want that, then Riot could simply split the ranked queue into two: one where (soft, ie phone #) identity verification is required, and one where it isn't.

Riot won't do this, though, not because it wouldn't fix the problem (it would, as demonstrated by Valve), but because they profit from smurf accounts buying skins.

Re: Keyhole – Forge own Windows Store licenses

#173
post #151

Earlier quoted context omitted.

Because a root kit is the only way to do anti cheat? CS2 ban wave begs to differ.

I haven’t played valorant, so I don’t know about them, but what I can say is that definitely other anti-cheats are highly ineffective (VAC being one that is highly ineffective), with blatant cheaters going years without ever being caught. Hell, blatant cheaters literally stream themselves cheating and their own communities do not recognize the cheating till the stream makes a mistake and selects the wrong scene. This…

> activision admitted in their lawsuit that they leave cheaters on a safe list so long as the cheaters have any semblance of an audience streaming

That is absolutely wild, and completely characteristic of Activision.

Do you have a link that I can share with my CoD-playing friends?

Re: Keyhole – Forge own Windows Store licenses

#174
post #128

> As it turns out, data after the signature block isnt checked at all... and it can even override data that came before it. Whenever two blocks of the same type are stored together, the last one overrides all the others before it. So, if we want to change any license data, we can just make a block for it and put it after the signature block! Amazing.

[deleted]

Re: Keyhole – Forge own Windows Store licenses

#175
post #52

Earlier quoted context omitted.

People who are concerned about this should realize: Microsoft will never create a situation where alternative operating systems can’t be installed. They already went through the antitrust ringer on that issue. They don’t even control what hardware vendors do for the most part. This requirement will only hit multiplayer games where cheating and security threats are rampant. Also, if you have a PC with secure boot enab…

> Microsoft will never create a situation where alternative operating systems can’t be installed. They already went through the antitrust ringer on that issue. They have shipped ARM Surfaces where alternative operating systems could not get installed, enforced with Secure Boot permanently on. Have they been through any such "antitrust ringer" in the past 10 years? > Also, if you have a PC with secure boot enabled, th…

You can in fact disable secure boot on the arm surfaces.

The problem is nobody really has put enough effort to port Linux to it. Some people started but haven't gotten very far

https://github.com/orgs/linux-surface/projects/1 https://github.com/linux-surface/aarch64-firmware https://github.com/linux-surface/aarch64-packages

>, a Windows update added a number of Linux distributions to the Secure Boot blacklist

It was due to a bug/and or not being able to detect all manners of dual boot correctly.

The goal was not to blacklist old distros, it was to blacklist vulnerable boot managers

Microsoft's response and fixes were provided: https://learn.microsoft.com/en-us/windows/release-health/sta...

Re: Keyhole – Forge own Windows Store licenses

#176

MAS (which is also hosted on Github) is the perfect example of Microsoft not caring about end user piracy. Just use it.

In the long run, pirated copies of Windows are noise level: The vast majority of people are going to get a license via an OEM (which survives reinstallation), businesses aren't going to risk running unlicensed windows machines (especially if they're paying for it elsewhere) and have easy means to acquire OEM licensed machines that are supported by the OEM for parts & service, and people who run an up to date but pira…

I suppose the other aspect is the gradual death of the white-box PC shop.

The large OEMs have contracts to pay 9 cents per license.

They'll never crack the individual enthusiast building his own PC from Newegg parts and installing a hack, but he's small potatoes.

But back in the day, there there was a fair chance your local midsize business, government, university, didn't necessarily buy from Dell or HP-- they bidded out a few hundred PCs to a local shop, which had both the motivation and technical knowledge to use the same license key on each one, and the scale where it could represent significant lost revenue.

Introducing activation was probably a significant sabotage for them. Although I'd suspect the stick on license certificate was almost as big a deal in that regard.

Re: Keyhole – Forge own Windows Store licenses

#177

Can this be used to enable the HEVC extension without a M$ account? It's so frustrating they can't license the patents as a lump sum.

You don't need to pay. You just need the direct link

ms-windows-store://pdp?productId=9N4WGH0Z6VHQ

ms-windows-store://pdp?productId=9PMMSR1CGPWG

ms-windows-store://pdp?productid=9MVZQVXJBQ9V

ms-windows-store://pdp?productid=9N4D0MSMP0PT

ms-windows-store://pdp?productid=9N95Q1ZZPMH4

Re: Keyhole – Forge own Windows Store licenses

#178

Earlier quoted context omitted.

Wow, so it's a ticking time bomb, that should be illegal.

I agree that the device updating without your consent should be illegal, but new games requiring the updates seems fair enough: the Xbox can still run all of the games it was advertised to be able to do so at launch, and if game developers could not rely on the presence of system updates, Microsoft would just release an entirely new, incompatible Xbox instead. I think that updates are fine so long as you can update a…

Depending on if you consider "authorization" to require consent or informed consent, it already is illegal behavior under CFAA.

Re: Keyhole – Forge own Windows Store licenses

#179

Earlier quoted context omitted.

I’d imagine most people would like some insurance in the event of loss or theft, but are not worried about government. I’m vulnerable to the $8 wrench attack, but enjoy knowing it is only a VISA problem if I leave it a laptop the bus.

I'm genuinely curious to know how VISA helps (or doesn't) in your analogy - what is a 'VISA problem'?

VISA as in the credit card not a travel permit

Re: Keyhole – Forge own Windows Store licenses

#180

Earlier quoted context omitted.

I agree that the device updating without your consent should be illegal, but new games requiring the updates seems fair enough: the Xbox can still run all of the games it was advertised to be able to do so at launch, and if game developers could not rely on the presence of system updates, Microsoft would just release an entirely new, incompatible Xbox instead. I think that updates are fine so long as you can update a…

Depending on if you consider "authorization" to require consent or informed consent, it already is illegal behavior under CFAA.

That would require a pretty creative interpretation of the CFAA.
Post reply on HN