Live data from Hacker News

Keyhole – Forge own Windows Store licenses

massgrave.dev

231–240 of 319 posts

Re: Keyhole – Forge own Windows Store licenses

#231
post #199

Earlier quoted context omitted.

the "but muh security" argument is absolute horseshit 99% of the time. and the 1% that actually need it, are going well beyond automatic updates to secure their systems.

No, this is a crazy take, old versions of software are usually rife with exploits, where everyone knows about the bug.

It's really not, I never upgrade anything and I haven't been pwned in like a decade. (Or maybe I have been pwned but not in a way that's affected me at all so you know, whatever)

Re: Keyhole – Forge own Windows Store licenses

#232

Earlier quoted context omitted.

Financially supporting games which do a thing you disapprove of is so counter productive it defies rational explaination. You aren't "speaking out", you're joining the party and paying membership dues. How could you get so twisted around? Brain damage, that must be it.

Sure and today it's games, and tomorrow it'll be something you care about.

Yeah so give money to the companies that do it, that'll show them! Boycotting those products is capitulation somehow, because brain damage.

Re: Keyhole – Forge own Windows Store licenses

#233
post #112

Earlier quoted context omitted.

Haha - i was looking for ¹, ² or § but couldn‘t find them on my german ipad onscreen keyboard, so i improvised.

Interesting that you'd use "Section", "§", as a reference marker. Asterisk (*), and dagger (†) are common reference markers in British English, but not the section sign, aka "silcrow". Is that a common usage /auf Deutsch/? Such use is listed on the Wikipedia page, but it's a use I don't ever recall having seen before.

It's common in some contexts, in particular ¹/²/... is common for footnotes in handwritten and digital texts.

§ is a bit less common but iirc used in some legal texts. It's also easy to use on ANSI German keyboards with shift+3.

Re: Keyhole – Forge own Windows Store licenses

#234

After reading the article, and specially the remarks about this engine being copy-pasted from the Xbox DRM engine , does anyone still believe that Pluton, also copy-pasted from the Xbox, is about end user security? And not totally about MS finally having enforceable DRM on PCs? Oh and by the way Pluton is now on the latest batch of Intel laptop chips. And has been on AMDs for a while. How soon until Windows requires…

People have been saying that for more than 10 years now, since the TPM was introduced. Yet you can still install Linux on PCs sold with Windows, you can still install third party software on Windows not from a Store, you can still watch pirated movies downloaded from torrents. You can even run an unregistered/unpaid version of Windows if you don't mind that it will not let you change the desktop background image.

Yes, and Microsoft will still have regular "accidents" where they wipe out your ability to boot your Linux install, oh oopsy.

They should be prosecuted for that shit.

Re: Keyhole – Forge own Windows Store licenses

#235
post #51

Earlier quoted context omitted.

It being a Win11 requirement. It failing and triggering Bitlocker on our machines. It's just shit :) No I don't have another solution. Let me complain.

What garbage hardware are you running where TPM is failing?

Had about 25% of our Dell laptops' TPM fail, got to know the repair technician well.

Re: Keyhole – Forge own Windows Store licenses

#236

Earlier quoted context omitted.

No, this is a crazy take, old versions of software are usually rife with exploits, where everyone knows about the bug.

It's really not, I never upgrade anything and I haven't been pwned in like a decade. (Or maybe I have been pwned but not in a way that's affected me at all so you know, whatever)

On an internet exposed server?

Re: Keyhole – Forge own Windows Store licenses

#237
post #219

Earlier quoted context omitted.

The CFAA's broad enough so as to allow a lot of creative interpretation. A journalist using view source was breaking the CFAA was one district attorneys view.

This is the only carve out I could find for manufacturers of computers: > No action may be brought under this subsection for the negligent design or manufacture of computer hardware, computer software, or firmware. I guess Microsoft could argue their entire operating system business, app store, and update infrastructure are intentionally negligent, and so not covered. I’d think a reasonable court would say that it’s…

[deleted]

Re: Keyhole – Forge own Windows Store licenses

#238

Earlier quoted context omitted.

Hell technical people can't figure it out. Everyone complains that it's fragile because what if their phone breaks, and those that think they know better, think it's because of the dozen one-time-use emergency codes. It's not their fault though. Every web site or service that offers totp and the most user-facing apps like google authenticator all scrupulously avoid telling you to save the seed value in the initial se…

Where can I read more about how this is done.

Just when you enable 2fa on some site and it shows you a qr code (or however it gives you the code, it might be a regular url, and sometimes they even display the string in plain text) save that string. If it's a qr code, save the qr code and read it with a regular qr code reader (probably just your camera app these days) and it will have a string or a url with the string as the query string.

That string is not just one-time use. You can just save it and enter it into totp apps all over the place all day for the next n years.

keepass apps all support it now for one example, so you could save the string in a notes field in keepass, but they have a dedicated totp field now too. You paste it in, and now that password entry not only stores your name & password for that site, it stores the totp seed for setting up totp apps, and also displays the current totp time code just the same way the totp app like google authenticator does.

It's all stored in the keepass db file just like the normal passwords, so to set up a new device, all you need is access to any copy of the keepass db file. Install any keepass app like keepassxc on a laptop, load the db, and there's your working current totp codes for all sites. You want a more convenient dedicated totp app than having to dive in to keepass, just copy the totp seed from keepass into gnome authenticator or whatever. The different apps have different ways to supply the string when not taking a picture directly with the camera. Some like google hide it from direct access. Last time I used google authenticator I think it had no usable export, but it just recently got the ability to store the seeds in googles cloud, but not like in an ordinary google drive file that would be useful, just some internal magic that all it does is if you can somehow manage to log in to your account on a new phone, it will pull the seeds down and start working on the new phone. It doesn't let you set up any other apps or devices, and Google has a copy of your seeds in a form they can read, even though you can't!

But the same seeds could be just as cloud-enabled by being inside a password manager db, which is still sitting on a google cloud server, but this time in a file that you own, and in a form that google can't read but you can.

Re: Keyhole – Forge own Windows Store licenses

#239
post #203

Earlier quoted context omitted.

The same is the case with the Xbox Series X/S. I was shown three options for the last update: [Update Now] [Continue Offline without Updating] [Shut Down Xbox].

right, so at this point you dont own the device any more, you are renting it.

Which is exactly what you agreed to in the terms of service you evidently did not read

I want to be the only cheater in my lobby.

Re: Keyhole – Forge own Windows Store licenses

#240
post #112

Earlier quoted context omitted.

Haha - i was looking for ¹, ² or § but couldn‘t find them on my german ipad onscreen keyboard, so i improvised.

Interesting that you'd use "Section", "§", as a reference marker. Asterisk (*), and dagger (†) are common reference markers in British English, but not the section sign, aka "silcrow". Is that a common usage /auf Deutsch/? Such use is listed on the Wikipedia page, but it's a use I don't ever recall having seen before.

I'm wary of using the asterisk in internet forums, or really in almost any textual exchange online these days, because everything tries to parse text as markdown, and I am never sure whether or not my asterisks will get eaten.

Especially on sites like this one, which have no previews.

Post reply on HN