Live data from Hacker News

Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

tomshardware.com

241–250 of 311 posts

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#241
post #72

Earlier quoted context omitted.

The other major incentive for hacking the console Microsoft removed was for the first time on a modern mainstream home console to allow side loading of homebrew code/emulators etc. The console supported a developer mode that allowed side loading of third party applications, so folks could get emulators and other traditionally "banned" content on the console through an officially supported route. There's a great prese…

"side loading", I know this term is the one used but I think should be pushed back against with just using the standard "installing"/"install". It makes the control point clearer and (should be) unsettling when you can't "install" software on hardware you own.

Yeah I listened to a podcast with Corey Doctorow (inventor of the term "enshittification") and he made this point quite well, to the point where I have completely removed "side loading" from my vocabulary. It's installing software on the computer I own.

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#242

So, they are spending like billions and they are the top tech company in the world, still not able to make a thing unhackable?

I mean, considering that it's been 13 years since the release, I think they did pretty well!

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#243
post #72

Earlier quoted context omitted.

The other major incentive for hacking the console Microsoft removed was for the first time on a modern mainstream home console to allow side loading of homebrew code/emulators etc. The console supported a developer mode that allowed side loading of third party applications, so folks could get emulators and other traditionally "banned" content on the console through an officially supported route. There's a great prese…

"side loading", I know this term is the one used but I think should be pushed back against with just using the standard "installing"/"install". It makes the control point clearer and (should be) unsettling when you can't "install" software on hardware you own.

It's a great point. As a geek I used to think those details don't matter, but it turns out language shapes society and how humans think way more than I understood.

We need to catch up on this because the people who know how to use language for propagandizing don't have the best intentions in mind.

But using the original term is not enough. We need to combat their word-twisting by upping them. We need a way to convey "their way of installing stuff by default is inferior and an attack on liberty".

Something like:

- direct install: installing as we always did

- caged install: installing through a locked store.

Maybe somebody better at marketing can find a good way to do this. In fact, we should have a whole site and community to organize together and shift the narrative on all nerdy things: formats, open web, DRM, patents, etc.

We have been weak on these points for so long because we care much more about solving tech problems than selling them. But openness is being eaten away under our noses. Has been for years.

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#244
post #72

> Whether PC users, our core readership, will be interested in actually emulating Xbox One, looks unlikely. The 2013 system’s game library is largely overlapped in better quality on the PC platform. And this explains why it's stayed unhacked so long. There was very little incentive to hack the system when the games are all playable on a PC. Pirates, cheaters, archivists, and hackers could just go there. Microsoft's b…

The other major incentive for hacking the console Microsoft removed was for the first time on a modern mainstream home console to allow side loading of homebrew code/emulators etc. The console supported a developer mode that allowed side loading of third party applications, so folks could get emulators and other traditionally "banned" content on the console through an officially supported route. There's a great prese…

Now if only Sony would let us even have a smidgen of our own code on our Playstations. But nope, Sony would rather gatekeep that one to Hell and back.

Instead, they keep stripping stuff off the console. I'm still so annoyed that PS5 doesn't even have an integrated web browser anymore (especially trying to troubleshoot network issues from the console itself).

But hey, Sony can leave bullshit exploit vectors open like PPPoE clients on the console itself (why? just use a router?)...

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#245

Earlier quoted context omitted.

The new Xbox is going to be a specialized PC running Windows with full access to third party game stores (Steam, Epic, etc). It won't need to be "hacked" because anyone will already be able to run any software they want on it.

What is the point of a device like this if the only difference is form factor? Why wouldn't someone just buy a pre-configured gaming PC?

Microsoft are in a tough spot (as far as Xbox hardware goes at least). PlayStation is selling much better on the console side, and Valve with the Steam install base has a good shot at making a non-Windows OS a serious platform for gaming.

Their hand was forced in the end. They have to consolidate PC and Xbox users to compete.

The idea of a machine with a locked down mode that can boot legacy Xbox titles and probably run competitive games with very little chance for cheating is interesting. But given Microsoft's track record with consumer devices I await to be convinced.

Valve should be worried if they do turn out something good, maybe this will mean the Steam machines are pushed more aggressively price wise. We can hope...

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#246
post #94
post #49

Earlier quoted context omitted.

> how does one defend against an attacker or red-team who controls the CPU voltage rails The xbox does have defences against this, the talk explicitly mentions rail monitoring defences intended to detect that kind of attack. It had a lot of them, and he had to build around them. The exploit succeeds because he found two glitch points that bypassed the timing randomisation and containment model.

I hope Apple is paying attention, since their first gen AirTags are vulnerable to voltage glitching to disable the speaker and the tracking warning.

Apple has a team that works on glitching protection for their phones. Disabling the speaker on AirTags is a very different threat model.

Re: Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

#247

Earlier quoted context omitted.

The Nintendo switch 2 uses DCLS (Dual-core lockstep) in the BPMP and PSC (PSC is PSP-like but RISC-V). So yes, it helps - I'm unsure if/where msft uses it on their products.

DCLS actually makes sense for this scenario as the fault tolerance gained from having three processors isn't needed here. The system can halt when there's a mismatch, it doesn't have to perform a vote and continue running if 2 of 3 are getting the same result. Also I just thought of this but it should be possible to design a chip where the second processor runs a couple cycles behind the first one, with all the input…

You could glitch both processors?
Post reply on HN