[HN Gopher] Microsoft's 'unhackable' Xbox One has been hacked by...
___________________________________________________________________
Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'
Author : crtasm
Score : 458 points
Date : 2026-03-17 15:16 UTC (7 hours ago)
(HTM) web link (www.tomshardware.com)
(TXT) w3m dump (www.tomshardware.com)
| Simulacra wrote:
| One should never call something "unhackable" ...
| Arainach wrote:
| Given that it held up against 13 years of dedicated efforts by
| people with physical access to the device, many years after its
| successor was launched, it seems merited in this case.
|
| This talk about some of what went into it is fascinating:
| https://youtu.be/quLa6kzzra0
| WJW wrote:
| It literally got hacked, that's what the article is about. It
| is NOT unhackable.
| ralfd wrote:
| Microsoft stopped manufacturing in 2020. It was not hacked
| in its lifetime.
| lokar wrote:
| I agree, but also find it funny that by that standard the
| DRM in the original Google video streaming product was
| not hacked before the service was shutdown, after about 2
| years :)
| leoc wrote:
| And to think that sometimes people doubt the wisdom of
| Google's product-lifecycle decisions!
| max-m wrote:
| To the community it was unhackable, until very recently.
| It's security measures held up so long that it appeared to
| be unshakable. There were no obvious flaws. In hindsight it
| was hackable, but keep in mind how long it took. This
| console has long been obsoleted.
| Brian_K_White wrote:
| It was unhackable while it mattered. It was hacked 5 years
| after it no longer mattered. And all but the effectively
| beta release remain unhacked even now.
| devmor wrote:
| "Extremely hard to hack" or "Hackable only after it's
| retired" don't exactly roll off the tongue, but they are not
| synonymous with "Unhackable".
|
| In many cases the truth is simply that its not worth the
| time/effort to hack it, so only the most dedicated
| perverts(with a positive connotation) keep trying.
| joe_mamba wrote:
| I wish people would take statements in relative terms along
| with the whole context before attempting to refute them with a
| quick gotcha in absolute terms.
|
| Obviously nothing is ever unhackable, not even Fort Knox, given
| infinite time and resources, and Microsoft never made such
| claims, this is just media editorializing for clicks and HN
| eating the bait, but Xbox One was definitely the most
| unhackable console of its generation. Case in point, it took 13
| years of constant community effort to hack a 499$ consumer
| device from 2013. PS4 and iPhones of 2013 have also been
| jailbroken long ago.
|
| Therefore, even the click-bait statement with context in
| relative terms is 100% correct, it truly was unhackable during
| the time it was sold and relative to its peers of the time.
| devmor wrote:
| > Case in point, it took 13 years of constant community
| effort to hack it.
|
| Can you attempt to quantify this effort in comparison to
| other game consoles? I'm not very familiar with the Xbox
| scene, but I would assume that there was a lot less drive to
| achieve this given that Xbox has never really had many big
| exclusive titles and remains the least popular major console
| (with an abysmally tiny market presence outside of the US).
|
| As an aside, I wonder if Microsoft's extra effort into
| securing the platform comes from their tighter partnership
| with media distributors/streaming platforms and their off-
| and-on demonstrated desire to position the Xbox as a home
| media center more than just a gaming console.
| joe_mamba wrote:
| _> and remains the least popular major console (with an
| abysmally tiny market presence outside of the US)._
|
| TF are you on about? The xbox one of 2013(competitor of the
| PS4 who got hacked long before) had a ~46% market share in
| the US and ~35% globally. Hardly insignificant. And any
| Microsoft Product, even those with much lower market share,
| attracts significant attention from hackers since it's
| worth a lot in street-cred, plus the case of reusing cheap
| consoles as general PCs for compute since HW used to be
| subsidized. And of course for piracy, game preservation and
| homebrew reasons.
|
| I again tap the sign of my previous comment, of uring
| people to stop jumping the gun to talk out of their ass,
| without knowing and considering the full context.
| debugnik wrote:
| I too forget sometimes that Wii U existed.
| deadbeef7f wrote:
| > Can you attempt to quantify this effort in comparison to
| other game consoles?
|
| The person who hacked the original Xbox wrote a book on the
| topic, which they've since made free:
| https://bunniefoo.com/nostarch/HackingTheXbox_Free.pdf
| scottyah wrote:
| This goes against information theory as a whole, and the
| point of words. How are you going to convey all this extra
| context to people who don't follow the space, and what
| word(s) do we use for something that is actually unhackable?
|
| Literally unhackable? XD
| joe_mamba wrote:
| Firstly, who made the claim that it was guaranteed to be
| "unhackable"? Was it Microsoft themselves when they sold
| it, or slop journalists looking to create false
| contrarianism in order to legitimize their own PoV and
| drive traffic to their articles? If it's the latter the
| we're just wasting our breath ehre over made up BS.
|
| Secondly, this is HN, not some generic town corner shop
| newspaper. It's assumed the readers who come here often and
| comment with no green profiles, have at least some basic
| technical know-how that nothing is ever unbackable, least
| of all a console from 2103, and therefore process
| information through that context lens, instead of feigning
| complete ignorance and arguing from the false pretext they
| gobbled up from editorialized titles created by slop
| journalists.
| close04 wrote:
| In the very strict interpretation probably nothing is
| unhackable, just not hacked yet. But one should also be
| pragmatic about what "unhackable" means in context. Without the
| power of hindsight, a consumer device that stayed unhacked for
| ~13 years can be reasonably called unhackable during this time.
| mikkupikku wrote:
| I think it's like calling a ship "unsinkable". Yes, you
| engineered it to not sink, in accordance with strict maritime
| standards no doubt, but just don't call it unsinkable. If you
| call it unsinkable you're just begging for a century of
| snickering at your hubris.
| applfanboysbgon wrote:
| It has no relation to hubris whatsoever if the "unhackable"
| label is not something self-proclaimed at launch but
| something descriptively applied by other people who were
| unable to hack it. Nobody would have snickered if the
| Titanic were described as unsinkable by people who had been
| trying to sink it for 10 years.
| inetknght wrote:
| > _Nobody would have snickered if the Titanic were
| described as unsinkable by people who had been trying to
| sink it for 10 years._
|
| Pedantic: I'm sure _somebody_ would have snickered about
| "unsinkable" if the Titanic sank after 10 years.
| Pragmatic: if the "unsinkable" Titanic lasted 10 years
| (or at least to profitability) before being sunk by
| people intending to sink it, that might certainly count
| as being "unsinkable" for the time it hadn't sunk.
|
| Hubris: Titanic was claimed to be unsinkable before it
| was launched.
| replooda wrote:
| We don't need to contribute to word inflation. There's
| "really hard," there's "nearly impossible," there's even
| "impossible - as far as we know." I don't think it shows a
| lack of pragmatism to assume a technological claim, made by a
| technology company, should't be taken at face value. On the
| contrary, I'd advise more pragmatism to anyone failing to
| disregard an "unhackable" claim made by Microsoft specially
| even after fixnum years without known exploits.
| stinmpy wrote:
| Marcus used to work for Microsoft, in the MSRC. I wonder if he
| used insider knowledge for this hack.
| Scaevolus wrote:
| Microsoft released a video that covers effectively all of the
| Xbox One security system, and it's referred to extensively in
| the talk. The specific methods of glitching don't require any
| insider knowledge.
| ZiiS wrote:
| They also told everyone they added more anti glitching to
| later hardware revisions; which by the process of elimination
| tells everyone they thought this was possible. The whole
| initiative was a success when it gave them a year; an
| unqualified triumph when it gave them the whole generation;
| they really are not going to be to sad after 12 years.
| mike_hearn wrote:
| Right, as Markus says - even gods can bleed. And he's
| right: Tony Chen's team did god-level work with the Xbox
| One security system, so what must have followed in the Xbox
| Series S is truly unknowable. I don't think there's even a
| tech talk on it. This talk is probably the most elite
| hacking talk I've ever watched. Everyone who worked on this
| stuff at MS can and obviously should be very proud of what
| it took - especially as this probably won't have any
| commercial impact on Xbox game devs or multiplayers.
| nxc18 wrote:
| I think it counts as effectively unhackable since it remained
| unhacked until five and a half years after its successor went on
| the market.
|
| I wonder if, assuming they continue making Xbox, they find a way
| to mitigate this in the next generation.
| fredoralive wrote:
| The presentation notes that this hack currently only works with
| the first revision of silicon. Later variants have more
| protections, like some anti-glitching tech that wasn't quite
| debugged for the early units being enabled for later runs, and
| further changes with the security / reset subsystems being
| split into two separate cores with revised consoles like the
| the One X. So these would be more of a challenge, even if
| there's now an angle of attack to investigate.
| darknavi wrote:
| > assuming they continue making Xbox
|
| It sounds like that's the plan:
|
| https://news.xbox.com/en-us/2026/03/11/project-helix-buildin...
| babypuncher wrote:
| The new Xbox is going to be a specialized PC running Windows
| with full access to third party game stores (Steam, Epic,
| etc). It won't need to be "hacked" because anyone will
| already be able to run any software they want on it.
| SteveNuts wrote:
| What is the point of a device like this if the only
| difference is form factor? Why wouldn't someone just buy a
| pre-configured gaming PC?
| delecti wrote:
| I mean, at that point it _is_ a pre-configured gaming PC.
| Hardware that 's uniform across millions of units
| provides advantages, both for developers and users. IMO
| that's a big part of why the Steam Deck outsells more
| powerful competitors: there are so many of them that it
| gets targeted by developers, so more people buy them, in
| a virtuous cycle.
| mitkebes wrote:
| The main goal is money, an Xbox branded windows PC has
| potential to drive sales.
|
| Microsoft can also hopefully target a smoother user
| experience than a typical windows PC provides. They want
| this to be a valid console competitor, but just slapping
| xbox brand on a windows PC isn't enough to do that.
|
| Having a first party hardware device to target for PC
| games can also help devs with having a clear performance
| target for PCs, similar to how the Steam Deck is
| currently a minimum spec performance target for a lot of
| games.
| ThrowawayB7 wrote:
| It's a device with a fixed, known-good set of hardware
| for developers to target, which is all that any of the
| major consoles is. Your question applies just as much to
| the Steam Deck and upcoming Steam Machine.
| axus wrote:
| Let's speculate that they need a carrot for Windows
| developers when they attempt to use a monopoly stick on
| the Steam Deck.
| hbn wrote:
| There's something to be said for having a standard, known
| SKU, both as something for developers to target if enough
| people own it, and for users to troubleshoot if they're
| e.g. having an issue running X game.
|
| This kind of already exists with the "Deck Verified"
| label on Steam games.
|
| That said, this sounds similar to Valve's upcoming Steam
| Machine and I'd much prefer that to be the standard
| console/PC hybrid to keep the Linux gaming momentum
| going, and perhaps one day I can ditch Windows for good.
| babypuncher wrote:
| There are a few points I can see
|
| 1. Console-like living room ready experience. It's
| surprisingly hard to get a PC made with off-the-shelf
| parts to integrate cleanly with a home theater system
| (think features like HDMI CEC, One Touch Play, etc). A
| custom SoC can solve this, something we are seeing Valve
| also do with the Steam Machine.
|
| 2. As the target hardware for basically all Xbox games,
| end-users who don't want to fret over system specs can
| easily just buy this and know they are getting the
| intended experience.
|
| Whether that's enough to move units remains to be seen.
| ziml77 wrote:
| If this is true then the reason that a console would be
| better than a custom PC is that it would also be designed
| to work better for that purpose. Turning on the device
| when the controller turns on and sending CEC commands are
| two huge things that aren't well supported outside of the
| console space. Also it would likely run a trimmed down
| version of Windows and would be set up to "just work" in
| a way that a system that can have any arbitrary set of
| hardware will never be able to do.
|
| But the really nice thing about the concept of treating a
| PC and console as the same platform is that you don't
| have to worry about why people might prefer to go the
| route of buying the console. You can go with a regular
| gaming PC if that's what you prefer and your library will
| have all the same options.
| genthree wrote:
| Every PC I've ever tried to repurpose as a gaming console
| of any sort has had way more jank to it than I'd ever
| tolerate in a console, in the 25ish years I've been
| hooking computers up to TVs. Even the Bazzite box I've
| got is pretty bad by comparison. Hell, my actual _Steam
| Deck_ has a lot more undesirable "enthusiast" behavior to
| it, let's say, than I'd want out of a Nintendo product
| for example, even though it's just about the best I've
| seen (the actual best is Retroarch with a skin mimicking
| the PS3's menu, on a dedicated distro that could take it
| from cold boot to interactive in like three seconds flat
| _even on an rpi2_ ... but that won't play actual modern
| PC games, just emulated consoles and such, so it's not a
| fair comparison)
|
| A common failure is the controllers. It's hard to get a
| combo of OS stack, Bluetooth chip, and controller that
| Just Works like they do on consoles. Something always
| needs fiddling-with.
|
| Video or audio out are also often a problem. Glitched
| audio or audio mode-switching, trouble switching video
| modes, screwed-up HDR, all kinds of stuff. Maybe fine on
| your monitor with headphones. Not fine on a TV or
| projector with 5.1+ audio receiver.
|
| The UIs also bug out or crash more often, and usually
| aren't that great at being a TV UI in the first place
| (even Steam IMO is worse than most consoles, as far as
| the Big Picture UI)
|
| It also gives devs a stable target with a known market,
| which is nice for both the devs and the owners of the
| devices.
| glenstein wrote:
| A conversation for another day and I can't wait to have it,
| but something about this seems seriously doomed, because
| Steam already owns this lane, owns it well, and these days
| I think Linux is objectively the better desktop for _most_
| personal, PC-style use cases.
|
| Windows stopped feeling like it meant PC a long time ago,
| and there's a major risk of the whole Xbox identity
| disappearing into the PC computing. Probably a conversation
| for another day but when everything is an Xbox, nothing is
| an Xbox, and when an Xbox is a PC it might as well be
| fading away Marty McFly style from our plane of existence.
|
| I suppose what would really impress me is a Roku-style
| omnivore approach that gives a first class console-style
| experience and interface to Epic, Steam, Itch.io, GOG and
| of course Xbox.
| jfim wrote:
| You can run steam in big picture mode, and there are ways
| to add links to games from other game stores to steam
| such as https://github.com/PhilipK/BoilR
|
| It's not automatic or perfect but it does work.
| glenstein wrote:
| I'm aware, but that is indeed a great thing Steam offers.
| I think it's janky enough that if there's one way to out-
| steam Steam it might be making the broader PC gaming
| universe as plug-and-play into a console experience as
| possible.
| Jerrrrrrrry wrote:
| Created a voltage drop that exactly occurred to be timed to the
| key comparison, then a spike at the continuation.
|
| Irl noop and forced execution control flow to effectively return
| true.
|
| B e a utiful
| hedora wrote:
| The earliest example I know of for this is CLKSCREW, but
| security hardware (like for holding root CA private keys) was
| hardened against this stuff way before that attack.
|
| Has anyone heard of notable earlier examples?
| bri3d wrote:
| In terms of fault injection as a security attack vector (vs.
| just a test vector, where it of course dates back to the
| beginning of computing) in general, satellite TV cards were
| attacked with clock glitching at least dating back into the
| 1990s, like the "unlooper" (1997). There were also numerous
| attacks against various software RSA implementations that
| relied on brownout or crowbar glitching like this - I found
| https://ieeexplore.ieee.org/document/5412860 right off the
| bat but I remember using these techniques before then.
| btown wrote:
| It's fascinating - how does one defend against an attacker or
| red-team who controls the CPU voltage rails with enough
| precision to bypass any instruction one writes? It's an
| entirely new class of vulnerability, as far as I can tell.
|
| This talk https://www.youtube.com/watch?v=BBXKhrHi2eY indicates
| that others have had success doing this on Intel microcode as
| well - only in the past few months. Going to be some really
| exciting exploits coming out here!
| phantom784 wrote:
| Could a chip detect this and reset?
| johncolanduoni wrote:
| Yes, and the Xbox One has mechanisms to do just that. But
| they turned out to not be fully sufficient.
| jolan wrote:
| This attack is on the early models that didn't have those
| protections enabled. The researcher surmised that later
| models do indeed have anti-glitching mechanisms enabled.
| mkipper wrote:
| I'm not at all familiar with the Xbox One, but this is a
| feature that's generally available if you're designing
| "closed" hardware like a console. Most SoC these days have
| some sort of security processor that runs in its own little
| sandbox and can monitor different things that suggest
| tampering (e.g. temperatures, rail voltages, discrete
| tamper I/O) and take a corrective action. That might be as
| simple as resetting the chip, but often you can do more
| dramatic things like wiping security keys.
|
| But this exploit shows that it's still almost impossible to
| protect yourself from motivated attackers with local
| access. All of that security stuff needs to get initialized
| by code that the SoC vendor puts in ROM, and if there's an
| exploit in _that_ , you're hooped.
| msla wrote:
| You can't. Console makers have these locked-down little
| systems with all the security they can economically
| justify... embedded in an arbitrarily-hostile environment
| created by people who have no need to economically justify
| anything. It's completely asymmetrical and the individual
| hackers hold most of the cards. There's no "this exploit is
| too bizarre" for people whose hobby is breaking consoles, and
| if even one of those bizarre exploits wins it's game over.
|
| And if you predict the next dozen bizarre things someone
| might try, you both miss the thirteenth thing that's going to
| work _and_ you make a console so over-engineered Sony can
| kick your ass just by mentioning the purchase price of their
| next console. ( "$299", the number that echoed across E3.)
| xnyan wrote:
| > You can't
|
| It's a moot point, they are not trying to prevent it. They
| only need to buy enough time to sell games in the lifespan
| of the hardware, which they did.
|
| > all the security they can economically justify...
|
| It seems like they did a perfect job, it lasted long enough
| to protect Microsoft game profits.
| PUSH_AX wrote:
| > how does one defend against an attacker or red-team who
| controls the CPU voltage rails
|
| The xbox does have defences against this, the talk explicitly
| mentions rail monitoring defences intended to detect that
| kind of attack. It had a lot of them, and he had to build
| around them. The exploit succeeds because he found two glitch
| points that bypassed the timing randomisation and containment
| model.
| poemxo wrote:
| I hope Apple is paying attention, since their first gen
| AirTags are vulnerable to voltage glitching to disable the
| speaker and the tracking warning.
| Vexs wrote:
| They're also, as it turns out, vulnerable to a drillbit
| mikepurvis wrote:
| It's pretty trivial to just open it up and disconnect the
| speaker too. I took one apart to make a custom wallet
| card out of it and broke the speaker in doing so; the
| rest of it worked perfectly fine (though obviously the
| warning would still work).
| tjoff wrote:
| Isn't airtags completely and utterly broken, or has
| anything changed?
| nitros wrote:
| I don't see much motivation for fixing that when I can
| purchase a nrf52xx Bluetooth Beacon on aliexpress for
| EUR4 and flash it with firmware that pretends to be 50
| different airtags, rotating every 10 minutes, and
| therefore bypassing all tracker detections.
| sabas123 wrote:
| > It's an entirely new class of vulnerability, as far as I
| can tell.
|
| It is know as voltage glitching. If you're interested our
| research group applies to Intel CPUs.
| https://download.vusec.net/papers/microspark_uasc26.pdf
| ActorNightly wrote:
| Basically if someone has physical access to device, its game
| over.
|
| You can do things like efuses that basically brick devices if
| something gets accessed, but that becomes a matter of whether
| the attacker falls for the trap.
| beachy wrote:
| Only if they leave a door open, which they did here.
|
| If your argument is that you can't hope to close every
| door, then AI will make it easier to close all the doors in
| the future.
| robotnikman wrote:
| >then AI will make it easier to close all the doors in
| the future.
|
| AI could also make it easier to open the doors too.
| tverbeure wrote:
| > Basically if someone has physical access to device, its
| game over.
|
| It took more than a decade to exploit this vulnerability
| and even then there are fairly trivial countermeasures that
| could have been used to prevent it (and that are
| implemented in other platforms.)
|
| Nothing is unhackable, but it requires a very peculiar
| definition of "game over".
|
| (And as others have pointed out: only early versions of
| this Xbos One where vulnerable to this attack.)
| selectively wrote:
| This hasn't been true for the time a typical American high
| school senior has been alive. Please stop repeating things
| people said years ago.
| _kidlike wrote:
| not a new vulnerability class.
|
| Extremely impressive feat nonetheless!
| bri3d wrote:
| It's not new - fault injection as a vulnerability class has
| existed since the beginning of computing, as a security
| bypass mechanism (clock glitching) since at least the 1990s,
| and crowbar voltage glitching like this has been widespread
| since at least the early 2000s. It's extraordinarily hard to
| defend against but mitigations are also improving rapidly;
| for example this attack only works on early Xbox One
| revisions where more advanced glitch protection wasn't
| enabled (although the author speculates that since the glitch
| protection can be disabled via software / a fuse state, one
| could glitch out the glitch protection).
| thebruce87m wrote:
| The microcontrollers I worked on 15 years ago had low voltage
| detection:
|
| https://en.wikipedia.org/wiki/Low-voltage_detect
| mox1 wrote:
| Just so you know, hardware hackers have been doing this for
| 20+ years. Hacking satellite TV (google smart card glitching)
| was done the same way.
|
| Its more that its really hard to do security when the
| attacker has unlimited physical access.
| braunshedd wrote:
| The Xbox 360 was hacked in a simpler but nearly identical way
| [1]! Amazing that despite the various mitigations, the same
| process was enough to crack the Xbox One.
|
| [1] https://consolemods.org/wiki/Xbox_360:RGH/RGH3
| Retr0id wrote:
| No? It _is_ crowbar voltage glitching, but you 're
| significantly underselling it here. The glitching does not
| affect key comparisons.
|
| It's a double-glitch. The second glitch takes control of PC
| during a memcpy. The first glitch effectively disables the MMU
| by skipping initialization (allowing the second glitch to gain
| shellcode exec). (I am also skipping a lot of details here, the
| whole talk is worth a watch)
| tetrisgm wrote:
| This is great news. Hopefully this opens the floodgates towards
| emulation and homebrew. Not that there are really any exclusives,
| but it would be interesting.
| whalesalad wrote:
| I'm just excited at the opportunity to re-purpose my old launch
| day XBone as some kind of little homelab linux box.
| jamesgeck0 wrote:
| Xbox One homebrew has effectively always been supported. Anyone
| can register a development account and boot the system into dev
| mode. IIRC in a talk about console security, a Microsoft
| developer noted that this was an intentional deterrent against
| hacking. An effort to split the community so that pirates and
| homebrew enthusiasts wouldn't have a reason to collaborate.
| protimewaster wrote:
| They did dumb things like limit memory availability in dev
| mode, though. Also they require a government ID to enable dev
| mode (but at least the quit charging $100 for it!). And they
| made it so you can't enable dev mode on consoles that are
| banned from Xbox services.
|
| I understand it's still more than most console makers do,
| having dev mode at all, but it's maddening to me that
| Microsoft made dev mode so annoying and limited. I'd honestly
| just rather a hack be available so we have the option of
| using the entire memory or repurposing banned consoles.
| qingcharles wrote:
| Very few exclusives. Couple of Forzas? Halo 5? Practically
| everything else available elsewhere in similar quality.
| tetrisgm wrote:
| They are on PC afaik?
| qingcharles wrote:
| Forza Motorsport 5 & 6 and Halo 5: Guardians all Xbox One
| exclusives, I think.
| mike_hearn wrote:
| Seems unlikely. Someone would have to turn this into a modchip,
| set up physical distribution networks (all very illegal under
| the DMCA), and it'd only work on the 2013 machines - Chen's
| team clearly anticipated this type of attack and were already
| working on mitigations around the time the Phat released. So as
| he says at the end, later silicon already has more glitch
| mitigations built in and has done for a long time. Current gen
| Xbox isn't even investigated but we can assume it's even
| harder. They were clearly paying for red teaming. Remember:
| ZERO software bugs in the boot rom.
| cortesoft wrote:
| I had a friend who ran a side business installing mod chips
| on the original Xbox in the early 2000s. There was a robust
| community around it, and you could buy chips easily.
|
| This was all after the DMCA was in effect. I don't think that
| will stop this sort of activity.
| charcircuit wrote:
| It wasn't unhackable and decrypted versions of games already have
| been dumped. There was even a public exploit published years ago.
|
| https://github.com/exploits-forsale/collateral-damage
|
| What's new here is that this compromises the entire system
| security giving access to the highest privilege level.
| landr0id wrote:
| Thanks for the mention! I helped with the collateral damage
| exploit (wrote the PE loader).
|
| I didn't ask but Emma -- who wrote the kernel-mode exploit --
| and I would probably agree that Collat is not really what we
| would consider a proper hack of the console since it didn't
| compromise HostOS. Neither of us really expected game plaintext
| to be accessible from SRA mode though.
| landr0id wrote:
| And the plaintext stuff by the way was a great effort by some
| other folks running https://xboxoneresearch.github.io/
|
| I think it was tuxuser, Torus, and Billy(?) who accomplished
| that. Hopefully not forgetting anyone critical.
| hnaccounttw99 wrote:
| It's worth noting that the person responding to you - landr0id
| - is a former criminal hacker who only narrowly avoided going
| to prison for his attacks on Microsoft/game developers during
| the life span of the Xbox 360, which is more than I can say for
| many of his friends - they were less fortunate. His behavior
| included hacking into developers networks to steal unreleased
| games and source code as well as attacks on the Xbox Live
| service, which he oddly (and proudly) writes about on his blog.
| He was involved in attacks on the 360 platform security, but
| the goal was always piracy - not furthering security. He was
| around things that were much more impactful - like the entire
| Dylan Wheeler saga - the two of them knew each other and
| traveled in the same circles. So Lander's behavior was really
| bad, but his friends did much worse, so they were the ones who
| went down.
|
| People in the know find it pretty offensive for Lander to
| continue to attack these systems or do so much as speak to
| anyone who is. They should work on remorse and seek forgiveness
| rather than repeating a variant of the same behavior that
| defined their past. Maybe learn from the other person involved
| who avoided 'issues' and went to the other side of this exact
| security equation.
|
| I guess harassing War Thunder players is not compatible with
| that more respectable lifestyle or something.
|
| I also enjoy their earlier HN posts. Especially the one about
| how the initial system compromise happened, where they pretend
| to speculate about how the HV dump happened/how it could have
| happened/how important it was when they know full well
| _exactly_ who obtained and sold the internal prototype hardware
| that was used to extract that plain text.
|
| They aren't responsible for that, they weren't involved in
| that, but they _know_.
| tencentshill wrote:
| Note this only affects the very first original 2013 "VCR"
| hardware. Newer revisions and variants are still unaffected.
| dlcarrier wrote:
| They're pretty common and cheap on the used market, though. I
| bought mine from a thrifts store for $30, and the console
| itself regularly goes for ~$50 on eBay.
| lionkor wrote:
| Is there any better format article or writeup? I couldn't find
| anything.
| au8er wrote:
| This just again shows that given enough time skill, and
| resources, any security is pointless if the attacker has physical
| access to the device.
| wat10000 wrote:
| I'm pretty skeptical of that lesson. This took 13 years and
| it's cheap mass-market hardware.
| recursive wrote:
| This seems like an unqualified win for the security measure.
| The future value of Xbox One DRM is probably close to zero.
| They already got what they wanted out of it.
| leoc wrote:
| At this point the blip of free media coverage possibly makes
| this a net positive for XBox.
| jamesgeck0 wrote:
| One of the DRM circumvention methods for the Xbox 360 involved
| precision drilling a specific depth into one of the chips on
| the board. Microsoft was very aware of the nature of physical
| access while designing this, haha.
| echelon_musk wrote:
| I had many Xbox 360s with flashed DVD drive firmware back in
| the day. But as I never owned a slim console I had no idea
| the drill/Kamikaze hack was a thing until now.
| dist-epoch wrote:
| You do have a credit card, right?
| Waterluvian wrote:
| I think this might be a good example of the fundamental
| misunderstanding of what "security" even is. It is _never_ a
| binary state. Never was. And I think a lot of people don 't
| really grok that and think that if a security block can be
| overcome in _some manner_ then the thing is _not secure_.
|
| Eventually Fort Knox will succumb to the unrelenting arrow of
| time and some future visitors will simply step over the
| crumbling wall and into the supposedly "secure" area.
| tosti wrote:
| I see security as a stopgap measure when there's no peace.
| The best "security" is not to need any in the first place.
| cocoto wrote:
| I can give you a piece of paper with a one time pad encoded
| secret, where the one time is physically destroyed. You can
| take all the time you want but you will not crack anything...
| TobTobXX wrote:
| You don't need to attack the math, if you can attack the
| sender or thr receiver ['s hardware].
| cocoto wrote:
| Good luck If I burnt the one time pad.
| john_strinlai wrote:
| i find this statement is often used as an excuse to not think
| about security at all. which is probably not what you intended
| here (i hope, although you did say "pointless"...), but some
| people parrot it for that purpose.
|
| a) this was a security win. millions and millions of people had
| physical access to the device for over a decade
|
| b) as others have said, security is not all-or-nothing. the
| xbox one is _extremely_ secure, despite not being _perfectly_
| secure.
|
| c) just because something eventually gets hacked does not mean
| security was pointless. _delaying access_ is a perfectly
| reasonable security goal. delaying access until the product is
| retired and the successor is already out on the market is a
| huge win.
| babypuncher wrote:
| 'pointless' is doing a lot of heavy lifting there.
|
| This console went completely unhacked for 12 years, with this
| coming a solid 4 years after the hardware was discontinued.
| They kept piracy off the console for its whole lifespan, which
| was the entire point of these security measures. This is a
| massive success for the Xbox security team.
| jamesnorden wrote:
| Better stop locking your doors, then.
| rangestransform wrote:
| In the talk that the security guy gave, he said it just had to
| cost more than 10 games for a user to enable piracy
| Cthulhu_ wrote:
| I suppose, but I'd argue it's effective security if it took ten
| years.
| autoexec wrote:
| > Whether PC users, our core readership, will be interested in
| actually emulating Xbox One, looks unlikely. The 2013 system's
| game library is largely overlapped in better quality on the PC
| platform.
|
| And this explains why it's stayed unhacked so long. There was
| very little incentive to hack the system when the games are all
| playable on a PC. Pirates, cheaters, archivists, and hackers
| could just go there. Microsoft's best security measure was making
| something nobody cared enough about to hack in the first place
| bombcar wrote:
| There was a time when it would have been a hot target, but
| everything the original modded Xbox could do could be done
| easier elsewhere.
| chocochunks wrote:
| Most of what was done on an original modded Xbox can be done
| on a retail stock Xbox One/Xbox Series with the exception of
| pirated Xbox games. Kodi (formerly known as XBMC) is just in
| the Xbox store, emulators and homebrew can be setup through
| dev mode with a little effort and $20. It's really just
| pirated versions of Halo 5 and a few others missing.
| jerf wrote:
| I know that's been dropping my level of interest for hacking
| consoles farther and farther. Why hack a console when it has
| almost no exclusives, even fewer of which I personally care
| about, and having a real computer hooked to a TV is no longer
| weird or difficult? I could fight to put an emulator on some
| locked down console or I can just install an emulator for
| almost everything ever made in like 10 minutes on my Steam
| Deck, so the choice is pretty obvious.
| giobox wrote:
| The other major incentive for hacking the console Microsoft
| removed was for the first time on a modern mainstream home
| console to allow side loading of homebrew code/emulators etc.
| The console supported a developer mode that allowed side
| loading of third party applications, so folks could get
| emulators and other traditionally "banned" content on the
| console through an officially supported route.
|
| There's a great presentation by Tony Chen on the Xbox One's
| security features:
|
| > https://www.platformsecuritysummit.com/2019/speaker/chen/
|
| Examples of the kinda software you can put on the Xbox One in
| developer mode:
|
| > https://xboxdevstore.github.io/
| philistine wrote:
| You are 100% correct but they started clamping down on people
| using Dev mode strictly for emulators and homebrew. So here
| we are.
| pjmlp wrote:
| This is what killed Linux support on PS as well, Sony was
| disappointed with what was being done with PS2Linux,
| instead of indie titles.
|
| Hence why PS3 Other OS no longer did hardware acceleration.
| beAbU wrote:
| The PS3 was incredible value dollar-to-flop, given that
| it was sold at a loss. This resulted in universities and
| other research institutes buying them en masse to create
| supercomputer clusters. Naturally buying thousands of
| consoles but not a single game puts sony in a difficult
| position. Although I think it's sad the hardware got
| locked down in later revisions, I fully understand why
| they did it.
| mschild wrote:
| The US Department of Defense went quite a bit further.
| They created the Condor Cluster in 2010 which was
| comprised of 1760 PS3s. At the time it was placed 33rd
| worldwide for a supercomputer.
|
| https://phys.org/news/2010-12-air-
| playstation-3s-supercomput...
| AlphaAndOmega0 wrote:
| I would be curious to know more precise numbers. My
| intuition suggests that when Sony sells millions of them,
| the number diverted for non-gaming purposes is maybe
| thousands or tens of thousands.
| mr_toad wrote:
| Nearly 90 million units by the time it was discontinued,
| but I'm not sure how many were sold at the point they
| removed Linux support.
| monocasa wrote:
| The marketing win of being able to say "these are so
| poweful, the military literally uses them in
| supercomputers" certainly more than makes up for a
| hundredth of a percent of consoles having a zero attach
| rate.
| Keyframe wrote:
| Linux on playstation was a play by Sony not to have
| customs like on a toy but as a more favorable computer
| merchandise. They didn't care.
| pjmlp wrote:
| Nope, that was with YA BASIC.
| monocasa wrote:
| There were different customs for different countries
| targetted with different tactics.
|
| Ya basic was only one front in that war.
| pjmlp wrote:
| Sure, if we disregard that PS2 Linux came almost two
| years later, was only sold via Internet, added an extra
| 500 euros on top, although it got discounted into 300
| euros at the end of PS2 lifetime.
|
| I own one such kit.
| philistine wrote:
| Linux on Playstation was the final hubris of Ken Kutaragi
| to have his insane CPU design take over computing.
| Kutaragi envisaged the PS3 becoming a standard hardware
| platform similar to the PC but fully controlled by Sony.
| That was their goal with the PS3, they said so themselves
| time and time again. The second Kutarago was removed from
| power over at Playstation, they closed the Other OS
| function.
|
| It was the last time that a Japanese company made a
| fundamentally Japanese move.
| rustyhancock wrote:
| In their defense, they clamped down following lobbying (and
| pressure) from Nintendo IIRC.
|
| Part of me also thinks that Microsoft were so forward with
| offering what was basically a test kit because they were
| confident in their security.
| gjsman-1000 wrote:
| I've seen this argument, but I strongly suspect that it's a
| cope argument. "We couldn't get in... because... we didn't
| care to! Even though we've hacked literally every other
| object on the planet just because."
|
| The proof in the pudding of this will be when the Nintendo
| Switch 2 reaches 2035 with no cracks. That's my prophecy;
| that this time around the cat actually will catch the mouse.
| Between NVIDIA's heavily revised glitch-resistant RISC-V
| security architecture and Nintendo's impeccable microkernel,
| there's nowhere left to hide. DRM may turn out to have been a
| very slow long battle to "victory," not a "this will always
| be defeated."
| mikepurvis wrote:
| Well, and these systems are also designed with ratchet-type
| measures in place from the get-go, where holes are plugged,
| fuses are burned, and newly released titles will only
| decrypt/run on the latest OS.
|
| So even if Switch 2 doesn't make it all the way to 2035
| with _zero_ cracks, there 's a strong likelihood that any
| exploits found will be short-lived.
| joseda-hg wrote:
| Which incentivizes people to hold on to exploits for as
| long as possible, ideally past the console life cycle,
| just to make sure it can be used, which already is a
| thing
| selectively wrote:
| I have my doubts. I suspect that Nvidia have made mistakes.
|
| Anyway, situations like the one you describe are one to be
| solved by legislation requiring certain devices be sold as
| open devices that put power in the hands of the owner.
| Forgeties79 wrote:
| Also getting a dev account and loading up RetroArch/emulators
| in general is trivial. Best use of an Xbox one for sure. Well
| documented and exploited at this point.
|
| Not the same as emulating its titles, but a lot of interest in
| the Xbone/series line (outside of actual console users) is the
| dev accounts. So I imagine a lot more effort went there first.
| genthree wrote:
| How is this the first I'm hearing of it? Looks like I finally
| have a reason to own an x-box, aside from the best version of
| Perfect Dark (the HD release of the original with modern
| controls, I mean) being on the 360.
| Forgeties79 wrote:
| They used to charge too but now it's free. I got mine set
| up after about 30min of work a few weeks ago just need to
| actually load it up now. It's tedious and you have to share
| your personal ID but it's not difficult.
| mrandish wrote:
| I was vaguely aware this is possible although the "sign-up
| for a dev account and boot it in dev mode all the time", even
| if free, was still enough of a barrier that I haven't done
| yet. I'm hoping this hack eventually leads to a simpler "one-
| click" way to run emulation, home brew and mods while still
| maintaining full original game and media playing
| functionality.
|
| Then I'll finally hook up the XBOne I have again and put it
| to some use on the downstairs TV. I already have a 'retired'
| PS4 filling similar role on the upstairs TV (although it must
| stay offline to remain 'liberated').
| Retr0id wrote:
| This is true, but it is also true that the Xbox One's security
| architecture and mitigations were ahead of its time. It
| would've taken a while to hack even with stronger incentives to
| hack it.
| autoexec wrote:
| True, I'm not trying to diminish this guy's efforts to defeat
| all the obstacles MS put in his way.
| glenstein wrote:
| >The 2013 system's game library is largely overlapped in better
| quality on the PC platform.
|
| I get what this essentially means, but for those of us with a
| certain amount of love of language (or pedantry), it's
| fascinating to try and parse this literally because I don't
| quite think it works as intended.
|
| Clearly the intended meaning is something like eclipsed in
| quality. And it may be overlapped in the sense that the same
| games are separately available on PC. But overlap isn't a
| relation of quality; quality is generally better or worse when
| it's comparative. So it's like a smushed together way
| simultaneously saying the selection of games on Xbone overlaps
| with what's available on PC and is also better quality on PC.
| inertiatic wrote:
| It's clear it means that there's a large overlap in titles
| and they are available in better quality on the PC platform?
| glenstein wrote:
| I already acknowledged that part several times?
| Philpax wrote:
| Yes, but the grandparent poster and I would agree that
| the parse is not that ambiguous/the meaning is easily
| inferred. The sentence states that the library is
| overlapped _and_ that overlap is available in better
| quality: it may seem contrived, but it reads as a rather
| natural collapse of an implicit conjunction to me.
| autoexec wrote:
| I think they could have used some punctuation.
|
| examples:
|
| The 2013 system's game library is largely overlapped, in
| better quality, on the PC platform.
|
| The 2013 system's game library is largely overlapped (in
| better quality) on the PC platform.
| louhike wrote:
| One thing PC does not have are the Xbox/Xbox 360 updated games.
| Microsoft did a great job of making the old games playable on
| Xbox One with better resolution, performance, etc. It would be
| nice to play the exclusive games of those consoles on PC
| through this.
| pjmlp wrote:
| It might be coming as per GDC news, lets see.
| foobiekr wrote:
| the main value is that it's way easier to make an emulator of a
| console than some point-in-time windows PC.
| zadikian wrote:
| Maybe cheaters want to cheat somewhere nobody else cheats. Idk
| if these games do online cross platform nowadays.
| bor_real wrote:
| The Xbox One has been emulated though (well not emulated, it's
| a compatibility layer like Wine). Before this hack, there was
| Collateral Damage. We were able to dump games with the exploit.
|
| Minecraft: Xbox One Edition (the Legacy version) was of keen
| interest to our community as it would be playing LCE natively
| on a PC if you used a compatibility layer which never happened
| before.
|
| So a few of my LCE cult friends contributed to WinDurango which
| was pretty much dead before they joined, and got Minecraft:
| Xbox One Edition to work.
|
| Of course, you'd ask "why don't you just play Minecraft on PC
| normally?" Legacy Console Edition has so many minute
| differences and details that it's impossible to discuss all of
| them--things as big as the Minigames and as small as the
| mipmaps.
|
| And then LCE source code from 2014 got leaked and that had a
| native PC port. Oh well.
| Thaxll wrote:
| This is not the reason, the reason is that the security is very
| strong. It's explained in the video.
| selectively wrote:
| Yeah, you couldn't be more wrong here. The exact same people
| who thoroughly destroyed the 360 badly wanted to attack this
| system - they were just outgunned.
| Gigachad wrote:
| The security was way better with the Xbox One, but also no
| one cared about the Xbox one. The 360 was the last successful
| Xbox.
| beAbU wrote:
| There is this general vibe online that the newer generation
| xboxen are either bad, worse than playstation, or a straight up
| failure.
|
| My series x, combined with gamepass, is by a very large margin
| the most at-home-entertainment bang I have gotten for my buck.
|
| Before then I had what could be regarded as a "vintage" gaming
| PC: 1st gen i7 (nehalem?), a gts 450 and some amount of ram. An
| upgrade (read: full replacement) was desperately needed. This
| was in the middle of the crypto gpu boom, so a decent GPU alone
| would've wiped my budget. I settled for an xbox as it was
| cheaper than a ps5.
|
| I've always seen myself as part of the pc master race, and
| thought consoles to be very limited. But man, it just worked,
| the games just worked, and gamepass made it all a total steal.
|
| Even now, when our 3 month old baby is settled for the night,
| me and my wife's preferred entertainment is a session of bg3
| over watching tv.
| kleene_op wrote:
| > Microsoft's best security measure was making something nobody
| cared enough about to hack in the first place
|
| Maybe that's what they're trying to achieve with Windows as
| well.
| JoeAltmaier wrote:
| Physical possession of a machine is pretty hard to make secure.
| It's a different level of secure, an order of magnitude less
| secure than remote attackers. This is expected?
| jolan wrote:
| Tony Chen from Microsoft gave a talk called "Guarding Against
| Physical Attacks: The Xbox One Story" and he explains that they
| want any sort of physical attack to cost at least the price of
| 10 games ($600 at the time).
|
| https://www.youtube.com/watch?v=U7VwtOrwceo&t=715s
| lxgr wrote:
| Depends on the size of the system you need to secure.
|
| If kilobytes of storage and very limited computing power works
| for your use case, you can get very secure (smartcards and
| secure elements remain essentially undefeated at the hardware
| level; all attacks I know happened via weak ciphers).
|
| For an entire current-gen gaming console, you'll have a much
| harder time.
| jvillegasd wrote:
| Don't ever call a thing "unhackable", because every single human
| creation is imperfect
| Cthulhu_ wrote:
| Nobody was calling it that, which is why the title is in
| 'quotes'.
| echelon_musk wrote:
| He is one of us :)
|
| https://news.ycombinator.com/user?id=gaasedelen
| everyone wrote:
| It had those e-fuses in it right? *Seriously* it should be
| illegal to sell anything with those.
| megous wrote:
| E-fuses are just write once memory with limited reads ability
| 10e6-10e7 read cycles after which it becomes unreliable.
|
| Secure boot that can't be controlled by the user should be
| illegal, though. You should get some secret code along with a
| device, that allows you as the buyer to tamper with it. So much
| hardware out there can just serve as something else, or can be
| supported by people on a voluntary basis, sans the completely
| arbitrary lockdown of ability to install your own code to the
| device.
| Gigachad wrote:
| Basically all computers use efuses, otherwise it would be
| possible to rollback the firmware to a previous, insecure
| version.
|
| For something like a game console, that's annoying, for a phone
| or laptop, that's highly desirable if something like a TPM bug
| is fixed, without efuses the system would forever be
| vulnerable.
| mike_hearn wrote:
| Amazing talk. Here's a quick writeup if you don't want to watch
| the full hour or don't have enough hardware knowledge to follow
| what Markus is talking about, as he goes _very_ fast, in some
| cases too fast to even let you read the text on his slides. It 's
| mandatory to use the pause key to understand the full details
| _even if_ you have a deep understanding of _every_ relevant
| technology, of which he explains none.
|
| The Xbox uses a very advanced variant of the same technologies
| that also exist on smartphones, tablets and Secure Boot enabled
| PCs. When fully operational the Xbox security system prevents any
| unsigned code from running, keeps all code encrypted, proves to
| remote servers (Xbox Live) that it's a genuine device running in
| a secure state, and on this base you can build strong anti-piracy
| checks and block cheating.
|
| The Xbox has several processors and what follows applies to the
| Platform Security Processor. When a computer starts up (any
| computer), the CPU begins execution in a state in which basically
| nothing works, including external communication and even RAM.
| Executions starts at a 'reset vector' mapped to a boot ROM i.e.
| the bytes are hard-wired into the silicon itself and can't be
| changed. The boot ROM then executes instructions to progressively
| enable more and more hardware, including things like activating
| RAM. Until that point the whole CPU executes out of its cache
| lines and can't use more memory than exists on-die.
|
| Getting to the state where the Xbox can achieve all its security
| goals thus requires it to boot through a series of chained steps
| which incrementally bring the hardware online, and each step must
| verify the integrity of the next. The boot ROM is only 19kb of
| code and a few more kb of data, and can't do much beyond just
| activating RAM, the memory mapping unit (called MPU on the Xbox),
| and reading some more code out of writeable flash RAM. The code
| it reads from flash RAM is the second stage bootloader where much
| more work gets done, but from this second stage on it can be
| patched remotely by Microsoft. So if bugs are found there or in
| any later stage, it hardly matters because MS can issue a
| software update and detect remotely on Xbox Live servers if that
| upgrade was applied, so kicking out cheaters and pirates. The
| second stage boot loader in turn loads more code from disk,
| signature checks and decrypts it, sets up lots of software
| security schemes like hypervisors and so on, all the way up to
| the OS and the games.
|
| Therefore to break Xbox security permanently you have to attack
| the boot ROM, because that's the only part that can't be changed
| via a software update. It's the keys to the kingdom and this is
| what Markus attacked. Attacking the boot ROM is very, very hard.
| The Xbox team were highly competent:
|
| * Normally the bringup code would be written by the CPU or BIOS
| vendors but MS wrote it all in house themselves from scratch.
|
| * The code isn't public and has never leaked. To obtain it,
| someone had to decode it visually by looking at the chip under a
| scanning electron microscope and map the atomic pictures to bits
| and then to bytes.
|
| * Having the code barely helps because there are no bugs in it
| whatsoever.
|
| So, the only way to manipulate it is to actually screw with the
| internals of the CPU itself by "glitching", meaning tampering
| with the power supply to the chip at exactly the right moment to
| corrupt the state of the internal electronics. Glitching a
| processor has semi-random effects and you don't control what
| happens exactly, but sometimes you can get lucky and the CPU will
| skip instructions. By creating a device that reboots the machine
| over and over again, glitching each time, you can wait until one
| of those attempts gets lucky and makes a tiny mistake in the
| execution process.
|
| Glitching attacks predate the Xbox and were mostly used on
| smartcards until the Xbox 360, which was successfully attacked
| this way. So Microsoft knew all about them and added many
| mitigations, beyond "just" writing bug free code:
|
| 1. The boot ROM is full of randomized loops that do nothing but
| which are designed to make it hard to know where in the program
| the CPU has got to. Glitching requires near perfect timing and
| this makes it harder.
|
| 2. They hardware-disabled the usual status readouts that can be
| used to know where the program got up to and debug the boot
| process.
|
| 3. They hash-chain execution to catch cases where steps were
| skipped, even though that's impossible according to program
| logic.
|
| 4. They effectively use a little 'kernel' and run parts of the
| boot sequence as 'user mode' programs, so that if sensitive parts
| of the code are glitched they are limited in how badly they can
| tamper with the boot process.
|
| And apparently there are even more mitigations added post-2013.
| Markus managed to bypass these by chaining two glitch attacks
| together, one which skipped past the code that turned on the MMU,
| which made it possible to break out of one of the the usermode
| 'processes' (not really a process) and into the 'kernel', and one
| which then was able to corrupt the CPU state during a memcpy
| operation, allowing him to take control of the CPU as it was
| copying the next stage from flash RAM.
|
| If you can take control of the boot ROM execution then you can
| proceed to decrypt the next stage, skip the signature checks and
| from there do whatever you want in ways that can't be detected
| remotely - however, the fact that you're using a 2013 Phat device
| still can be.
| nerdsniper wrote:
| Thank you, sincerely. My main question now is, what degree of
| repeatability has Markus achieved so far?
| mike_hearn wrote:
| On Phat consoles? You could turn it into a modchip, if for
| some reason you wanted to. It'd be repeatable on every boot
| but might take a while.
|
| The hard work comes after this though. There are lots of
| software level mitigations MS could use to keep the old
| devices usable with Xbox Live if they really wanted to. Just
| because you can boot anything you want doesn't mean you can't
| be detected remotely, it just makes it harder for MS to do so
| reliably. You'd be in a constant game of catch-up.
| Retr0id wrote:
| > It's mandatory to use the pause key to understand the full
| details
|
| I was going to say I disagreed but the rest of your comment
| reminded me that I've accumulated a lot of domain-specific
| knowledge.
| mike_hearn wrote:
| What I meant is that at points he skips past slides so quick
| even very fast readers can't absorb every bullet point. I
| read at ~2-3x the average speed, have lots of domain
| knowledge and couldn't read fast enough to get every word on
| every slide. So the pause key is very useful for that even if
| you know what's coming.
| Retr0id wrote:
| I read at Normal speed but I didn't feel that way when
| watching. I believe you though, I was just having an XKCD
| 2501 moment.
|
| https://xkcd.com/2501/
| mysteria wrote:
| Thanks for this writeup as I haven't had time to review the
| video yet :)
|
| _So, the only way to manipulate it is to actually screw with
| the internals of the CPU itself by "glitching", meaning
| tampering with the power supply to the chip at exactly the
| right moment to corrupt the state of the internal electronics.
| Glitching a processor has semi-random effects and you don't
| control what happens exactly, but sometimes you can get lucky
| and the CPU will skip instructions. By creating a device that
| reboots the machine over and over again, glitching each time,
| you can wait until one of those attempts gets lucky and makes a
| tiny mistake in the execution process._
|
| Considering that the PSP is a small ARM processor that
| presumably takes up little die space, would it make sense for
| it to them employ TMR with three units in lockstep to detect
| these glitches? I really doubt that power supply tampering
| would cause the exact same effect in all three processors
| (especially if there are differences in their power circuitry
| to make this harder) and any disrepancies would be caught by
| the system.
| Retr0id wrote:
| The Nintendo switch 2 uses DCLS (Dual-core lockstep) in the
| BPMP and PSC (PSC is PSP-like but RISC-V). So yes, it helps -
| I'm unsure if/where msft uses it on their products.
| mysteria wrote:
| DCLS actually makes sense for this scenario as the fault
| tolerance gained from having three processors isn't needed
| here. The system can halt when there's a mismatch, it
| doesn't have to perform a vote and continue running if 2 of
| 3 are getting the same result.
|
| Also I just thought of this but it should be possible to
| design a chip where the second processor runs a couple
| cycles behind the first one, with all the inputs and
| outputs stashed in fifos. This would basically make any
| power glitches affect the two CPUs differently and any
| disrepancies would be easily detected.
| aservus wrote:
| xbox is always trying to limit the users, when a person buys
| something, he clearly gets the ownership of the thing yet
| companies nowadays are trying really hard to sell some
| subscription while giving the illusion that the owner of the
| product is in control all the while keeping him in control. is
| there anyone else who feels the same way?
| gradientsrneat wrote:
| Could this technique be used to reverse-engineer end-of-life
| Nvidia GPUs to improve Noveau on them?
| natas wrote:
| I wonder... if microsoft can't secure a gaming console which they
| have full control on, from top to bottom, how do they secure
| "Azure Government"?
| physicles wrote:
| When your hardware is in the physical custody of the attacker,
| the threat model changes significantly. Designing a console
| that takes years for attackers to crack is an impressive feat
| of engineering.
| Lammy wrote:
| The point of the gaming console _is to get hacked_ , because
| that's how they develop the security techniques that
| metastasize over to strangle general-purpose computing, which
| is the real goal. Device attestation is a perfect example of
| this.
| int0x29 wrote:
| That game console isn't in a data center with CCTV coverage,
| mandatory access control, guards, and employees with background
| checks. If somone is soldering wires to your server and doing
| fault injection something has gone very wrong. Azure Government
| customers also don't have to worry about the NSA demanding
| access.
| Cthulhu_ wrote:
| I don't believe servers actually have this level of hardware
| protection to be honest. Physical protection, as someone else
| pointed out, on the other hand.
|
| If hacking the xbox goes wrong, the hacker will short out the
| console. If hacking Azure goes wrong, the hacker will get shot.
| missing_cipher wrote:
| Good think MS had a fallback to the RSA encryption if that ever
| failed, lol
| MichelleM2030 wrote:
| This is great news. I've actually been spending my weekends
| learning how to modify my old 360 and play great games to relive
| some of those younger days, while my Series X gathers dust.
| deepriverfish wrote:
| has there ever been a modern game console post 90s, that's really
| unhackable?
| selectively wrote:
| Where are the slides at?
| coretx wrote:
| Can someone answer yes/no to the question ; is this the cheap
| steam box now ?
| michaelbrave wrote:
| I would like to try running linux on an xbox series-x (but
| thought it wasn't in the cards), it might make for a decent
| openclaw setup.
| client4 wrote:
| The RE//verse conference has very high signal to nosie for
| reverse engineering content and attendees. I'd highly recommend
| it if it's an area you're interested in.
___________________________________________________________________
(page generated 2026-03-17 23:00 UTC)