Live data from Hacker News

Keyhole – Forge own Windows Store licenses

massgrave.dev

41–50 of 319 posts

Re: Keyhole – Forge own Windows Store licenses

#41
post #18

Earlier quoted context omitted.

People have been saying that for more than 10 years now, since the TPM was introduced. Yet you can still install Linux on PCs sold with Windows, you can still install third party software on Windows not from a Store, you can still watch pirated movies downloaded from torrents. You can even run an unregistered/unpaid version of Windows if you don't mind that it will not let you change the desktop background image.

Or you can recognize that app/game developers are starting to require Secure Boot enforcement if you want to continue to use their apps or play their games. RIOT requires users to enable TPM-enforced Secure Boot starting with Windows 11 to play Valorant: https://support-valorant.riotgames.com/hc/en-us/articles/100...

And why is that? It isn't for DRM (the game is free). It is for anti-cheat, and it is great.

The libertarian maximalist i-can-do-what-i-want-with-my-computer ignore the many use cases where I want to trust something about someone else's computer, and trusted computing enables those use cases.

Re: Keyhole – Forge own Windows Store licenses

#42

Earlier quoted context omitted.

I’m using Linux and LUKS but have never been convinced Secure Boot adds anything for me. It does sometimes add extra steps though, or block a driver from loading.

> What does that do for me to stop malware? Bitlocker is only protecting an offline system LUKS also only protects an online system. So why are you using it? Oh, I think I know, if you are on Windows it's bad to use BitLocker because it's made by Microsoft and it doesn't protect against malware, but if you're on Linux of course you use LUKS, it's a sensible thing to do. Got it.

Back in my retail computer technician and sales days, it wasn’t uncommon for somebody to lose their Bitlocker keys, and encryption did what it was designed to do - make the data unreadable without them. Sometimes they didn’t even understand what they enabled.

To that customer, Bitlocker itself was a threat.

In my small sample size, I’ve seen that more often than lost laptops. I’ve also seen many more malware infections.

Tying encryption to the TPM, which is the default, makes it easier to lose those keys. With LUKS I choose my own password.

It’s an important implementation difference, especially if it is going to do it by default. Warning a person “you will lose all data if you don’t write this down” in big bold red text is sometimes not enough.

Does tying those keys to your MS account fix that failure method?

Re: Keyhole – Forge own Windows Store licenses

#43

After reading the article, and specially the remarks about this engine being copy-pasted from the Xbox DRM engine , does anyone still believe that Pluton, also copy-pasted from the Xbox, is about end user security? And not totally about MS finally having enforceable DRM on PCs? Oh and by the way Pluton is now on the latest batch of Intel laptop chips. And has been on AMDs for a while. How soon until Windows requires…

>does anyone still believe that Pluton, also copy-pasted from the Xbox, is about end user security? I never did. The worst part is explaining it to people drinking the MS coolaid. I'm an MS admin so people at work love Win11, Intune etc all that max lockdown shit. To me that's not what Windows is about, for me Windows is excellent because of the admin tools and backwards compatibility. But hey that's just me. Proton…

> But hey that's just me.

There are more of us out there!

Re: Keyhole – Forge own Windows Store licenses

#44

MAS (which is also hosted on Github) is the perfect example of Microsoft not caring about end user piracy. Just use it.

Maybe it's beneficial for Microsoft that solutions like that are FOSS so they can more easily inspect the code for prevention purposes in the future?

Re: Keyhole – Forge own Windows Store licenses

#46
post #40
post #25

Earlier quoted context omitted.

Gamers arent demanding this. There are tons of ways to detect cheaters, the most effective one being human moderation. But no, companies wont do MaNuAl WoRk because it doesnt sCaLe, even though they have more than enough cash in the bank.

How do you do manual moderation on a massive fast-paced game like Valorant? It’s correct, that doesn’t scale

maybe not manual ... but ... log behavior, find outliers, make outliers play with outliers only

Re: Keyhole – Forge own Windows Store licenses

#47
post #35
post #30

Earlier quoted context omitted.

> Let me tell you a secret: it's because the gamers are demanding that. Citation needed. Whose these gamers ? I surely didn't ask for this neither any of the gamers I know, nor seen any demand about that in gaming forums. > The game companies couldn't care less if there are cheaters in the game, but it's the players which put huge pressure on the game companies to detect and ban cheaters. The jump from this to "requi…

Go on steam and look at the recent reviews for older but still popular fps games. Gamers complain about cheaters constantly and will negatively review games cause of it

They're demanding a way to handle or ban cheater, not requiring TPM, that's a non sequitur.

Re: Keyhole – Forge own Windows Store licenses

#48

Earlier quoted context omitted.

> What does that do for me to stop malware? Bitlocker is only protecting an offline system LUKS also only protects an online system. So why are you using it? Oh, I think I know, if you are on Windows it's bad to use BitLocker because it's made by Microsoft and it doesn't protect against malware, but if you're on Linux of course you use LUKS, it's a sensible thing to do. Got it.

Back in my retail computer technician and sales days, it wasn’t uncommon for somebody to lose their Bitlocker keys, and encryption did what it was designed to do - make the data unreadable without them. Sometimes they didn’t even understand what they enabled. To that customer, Bitlocker itself was a threat. In my small sample size, I’ve seen that more often than lost laptops. I’ve also seen many more malware infectio…

> Does tying those keys to your MS account fix that failure method?

Yes. Bitlocker recovery keys are escrowed to the Microsoft account. I've relied on this recover data from a family member's PC when it failed and they had unknowingly opted-in to Bitlocker (a Microsoft Surface Laptop running Windows 10 S Mode).

Re: Keyhole – Forge own Windows Store licenses

#49

MAS (which is also hosted on Github) is the perfect example of Microsoft not caring about end user piracy. Just use it.

more like the license process is so bad that they dont bother to go after them

There is ultimately no way to get a good license process on consumer PCs. The owner and operator of the hardware is also the adversary. It’s like DRM for video and other content: you are giving the ciphertext and the keys to the attacker. It’s only a matter of time until it is broken.

Re: Keyhole – Forge own Windows Store licenses

#50

Earlier quoted context omitted.

Another TPM thing? What problem do you have with the TPM?

TPM end game is to have identity tied to a device on pcs, just like the monopolies already have on Android and IOS. you know how google and apple dropped actual totp 2nd factor for their own accounts and force you to sign on another device to confirm signing on new devices? same thing.

Apple has SMS if you don’t own an Apple device. In fact, they require SMS to set up 2FA.

They probably dropped totp because non-technical people can’t figure it out.

Post reply on HN