Live data from Hacker News

Keyhole – Forge own Windows Store licenses

massgrave.dev

311–319 of 319 posts

Re: Keyhole – Forge own Windows Store licenses

#311

Earlier quoted context omitted.

You're making a lot of weird assumptions here, and seem to have completely missed the point I am making.

I said that people shouldn't play games with rootkit anticheat and you gave me that damned "first they came for" crap as though I am the one capitulating to the abusive practice. How else am I meant to take it?

It's about the

> and I did not speak out

bit. They're going to keep coming for stuff until it's something you care about.

For more information please refer to this wikipedia article: https://en.wikipedia.org/wiki/First_they_came_...

Re: Keyhole – Forge own Windows Store licenses

#312

Earlier quoted context omitted.

It's not property theft by most definitions, but it's still harmful in much the same way as property theft is harmful -- and in exactly the same way that me watching you type in your password is harmful, even though afterwards you still know your own password.

One of our two mental models of property theft is incorrect: someone downloading Photoshop does not deprive Adobe of its ability to sell the Photoshop it manufactured to someone else And I adamantly disagree with your password analogy if for no other reason than your password scenario creates temporal harm (assuming I do not change my password, of course) in a way that someone pirating version 1.0 does not automatica…

No, I think they're the same. Probably they feel different to you, depending on who you're stealing from, but ripping a DVD and putting it up on the internet during the theatrical window can really hurt filmmakers – who already make peanuts.

https://en.wikipedia.org/wiki/Film_distribution#Shrinking_of...

One person breaking and entering is bad. But in my example, this person broke-and-entered and then gave all of my future earnings away to literally everyone on the planet, thanks to the multiplicative power of technology – that's an outrageous violation.

Re: Keyhole – Forge own Windows Store licenses

#313

Earlier quoted context omitted.

>I don't think machines with ipv6 enabled that are behind a NAT are likely to be vulnerable to this Would you be interested in educate yourself about IPv6? https://ipv6.he.net/certification/

No, I'd rather just keep turning it off. Though if you're interested in telling me why I'm wrong concisely instead of being snarky I'll read that.

NAT and IPv6......you really should educate yourself about it IPv6 is not "that" new...trust me (bro). You know, keep learning is a big part of life ;)

Re: Keyhole – Forge own Windows Store licenses

#314
post #40
post #25

Earlier quoted context omitted.

Gamers arent demanding this. There are tons of ways to detect cheaters, the most effective one being human moderation. But no, companies wont do MaNuAl WoRk because it doesnt sCaLe, even though they have more than enough cash in the bank.

How do you do manual moderation on a massive fast-paced game like Valorant? It’s correct, that doesn’t scale

While there are solutions, I won't comment on Valorant - free to play games are a whole can of worms the companies have nobody but themselves to blame.

I will comment on a game I used to play though: Escape from Tarkov. The game costs somewhere between 40$ and 250$+tax, depending on what pack you buy. Banning cheaters for this game is literally a profit center. Every time you ban a cheater and they re-buy the game, you made at least 40$. The majority of cheating in the game was due to real money trading - cheaters would make in-game millions quickly, sell them, get banned, buy the game again at a profit.

The solution to this is brain-dead simple - more manual moderation (these cheaters are very obvious to spot). What the developers did instead just killed the game.

Re: Keyhole – Forge own Windows Store licenses

#315

Earlier quoted context omitted.

more like the license process is so bad that they dont bother to go after them

>the license process is so bad that they dont bother to go after them For a person, yes go for it they won’t bother. For a company… we have had some annoying MS audits. So how everything has to be retail WITH the cards. I have a stack ready for our next audit if it ever happens again.

sorry with cards? what do you mean?

Re: Keyhole – Forge own Windows Store licenses

#317
post #206

Earlier quoted context omitted.

so true - the few who are at risk of real exploits are already aware of this and do more than just system updates I only let my browser autoupdate (somewhat reluctantly) since I view that as the most likely security issue on my winpc but when I used to let win10 autoupdate (and other garbage dell drivers), things would start breaking after each update this also applies to phone app updates - I only update if there's…

> the few that are at risk… Boxes get popped all the time. Why are you painting such a dishonest picture? > and people wonder why I have the best working phone and pc at the office... Probably because you know about computers. Nothing to do with your poor security practice. And this still doesn’t say anything about the explicitly absolutist advice in the parent comment. “No matter the circumstance, turn auto-update o…

> Probably because you know about computers. Nothing to do with your poor security practice.

IME knowing about computers is what causes auto-update to break things. Because you actually rely on the kind of things that it would break.

Re: Keyhole – Forge own Windows Store licenses

#318

Earlier quoted context omitted.

Just when you enable 2fa on some site and it shows you a qr code (or however it gives you the code, it might be a regular url, and sometimes they even display the string in plain text) save that string. If it's a qr code, save the qr code and read it with a regular qr code reader (probably just your camera app these days) and it will have a string or a url with the string as the query string. That string is not just…

I'm a bit late but FWIW Google Authenticator has a QR code export option, it generates a giant QR code (potentially multiple) that contain all the accounts and secrets. It's designed for you to scan into Google Authenticator on another device, but you can also read the contents of that QR code yourself with various open source utilities to get the accounts and secrets (or just print a copy for a physical backup of th…

Thank you. This is mostly new to me and I am thankful for the hints.

Re: Keyhole – Forge own Windows Store licenses

#319
post #199
post #196

Earlier quoted context omitted.

Golden rule to get exploited

the "but muh security" argument is absolute horseshit 99% of the time. and the 1% that actually need it, are going well beyond automatic updates to secure their systems.

Attacks get automated and targets are no longer hand-picked. Having many unpatched systems makes the environment ripe for self-replicating worms.
Post reply on HN