Live data from Hacker News

Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

tomshardware.com

21–30 of 311 posts

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#22
post #6

One should never call something "unhackable" ...

In the very strict interpretation probably nothing is unhackable, just not hacked yet. But one should also be pragmatic about what "unhackable" means in context. Without the power of hindsight, a consumer device that stayed unhacked for ~13 years can be reasonably called unhackable during this time.

We don't need to contribute to word inflation. There's "really hard," there's "nearly impossible," there's even "impossible – as far as we know." I don't think it shows a lack of pragmatism to assume a technological claim, made by a technology company, should't be taken at face value. On the contrary, I'd advise more pragmatism to anyone failing to disregard an "unhackable" claim made by Microsoft specially even after fixnum years without known exploits.

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#23
post #18

Earlier quoted context omitted.

I wish people would take statements in relative terms along with the whole context before attempting to refute them with a quick gotcha in absolute terms. Obviously nothing is ever unhackable, not even Fort Knox, given infinite time and resources, and Microsoft never made such claims, this is just media editorializing for clicks and HN eating the bait, but Xbox One was definitely the most unhackable console of its ge…

> Case in point, it took 13 years of constant community effort to hack it. Can you attempt to quantify this effort in comparison to other game consoles? I'm not very familiar with the Xbox scene, but I would assume that there was a lot less drive to achieve this given that Xbox has never really had many big exclusive titles and remains the least popular major console (with an abysmally tiny market presence outside of…

>and remains the least popular major console (with an abysmally tiny market presence outside of the US).

TF are you on about? The xbox one of 2013(competitor of the PS4 who got hacked long before) had a ~46% market share in the US and ~35% globally. Hardly insignificant. And any Microsoft Product, even those with much lower market share, attracts significant attention from hackers since it's worth a lot in street-cred, plus the case of reusing cheap consoles as general PCs for compute since HW used to be subsidized. And of course for piracy, game preservation and homebrew reasons.

I again tap the sign of my previous comment, of uring people to stop jumping the gun to talk out of their ass, without knowing and considering the full context.

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#24
post #6

Earlier quoted context omitted.

In the very strict interpretation probably nothing is unhackable, just not hacked yet. But one should also be pragmatic about what "unhackable" means in context. Without the power of hindsight, a consumer device that stayed unhacked for ~13 years can be reasonably called unhackable during this time.

I think it's like calling a ship "unsinkable". Yes, you engineered it to not sink, in accordance with strict maritime standards no doubt, but just don't call it unsinkable. If you call it unsinkable you're just begging for a century of snickering at your hubris.

It has no relation to hubris whatsoever if the "unhackable" label is not something self-proclaimed at launch but something descriptively applied by other people who were unable to hack it. Nobody would have snickered if the Titanic were described as unsinkable by people who had been trying to sink it for 10 years.

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#26
post #15
post #11

Earlier quoted context omitted.

It literally got hacked, that's what the article is about. It is NOT unhackable.

Microsoft stopped manufacturing in 2020. It was not hacked in its lifetime.

I agree, but also find it funny that by that standard the DRM in the original Google video streaming product was not hacked before the service was shutdown, after about 2 years :)

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#27
post #25

This just again shows that given enough time skill, and resources, any security is pointless if the attacker has physical access to the device.

I’m pretty skeptical of that lesson. This took 13 years and it’s cheap mass-market hardware.

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#28
post #25

This just again shows that given enough time skill, and resources, any security is pointless if the attacker has physical access to the device.

This seems like an unqualified win for the security measure. The future value of Xbox One DRM is probably close to zero. They already got what they wanted out of it.

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#29
post #18

Earlier quoted context omitted.

I wish people would take statements in relative terms along with the whole context before attempting to refute them with a quick gotcha in absolute terms. Obviously nothing is ever unhackable, not even Fort Knox, given infinite time and resources, and Microsoft never made such claims, this is just media editorializing for clicks and HN eating the bait, but Xbox One was definitely the most unhackable console of its ge…

> Case in point, it took 13 years of constant community effort to hack it. Can you attempt to quantify this effort in comparison to other game consoles? I'm not very familiar with the Xbox scene, but I would assume that there was a lot less drive to achieve this given that Xbox has never really had many big exclusive titles and remains the least popular major console (with an abysmally tiny market presence outside of…

I too forget sometimes that Wii U existed.

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#30

Created a voltage drop that exactly occurred to be timed to the key comparison, then a spike at the continuation. Irl noop and forced execution control flow to effectively return true. B e a utiful

The earliest example I know of for this is CLKSCREW, but security hardware (like for holding root CA private keys) was hardened against this stuff way before that attack.

Has anyone heard of notable earlier examples?

Post reply on HN