Thanks for FATXplorer BTW, it is very useful.
Thanks for FATXplorer BTW, it is very useful.
[1] https://www.platformsecuritysummit.com/2019/speaker/chen/
More awareness needs to be made of how this will have a devestating impact on end-user freedom. They're attacking the PC, one of the last holdouts of general-purpose computing freedom. Remote attestation will make it so you "can" technically run your own hardware and software (and that's what the FUD-spreaders will always say), but you'll be denied access to lots of, increasingly online, services.
Edit: nice, downvotes. Hello corpo-authoritarians, we know what's up :-)
Linux and Open Source may be one of the last remaining barriers to this becoming widespread. It's one of the main reasons I whole-heartedly support Valve and their Steam Deck ambitions, and encourage everyone to do the same. Money trumps everything else, so as long as the money to be made from supporting SteamOS > money thought to be saved from piracy, I believe we can still thwart this.
On Intel clients, this is done via the Management Engine, bypassing both the CPU and operating system, as the ME can control display output.
If you knew the codec used originally you could even try to (near) perfectly reconstruct the original bitstream. Especially if you know various codec parameters and some side-channel data (such as which video data is contained in which encrypted blocks) it may be possible to relatively efficiently search for the bitstream that decompresses to the data that you are seeing.
It's good to raise awareness of the centralization risks of remote attestation. One pro-security, pro-freedom alternative is local attestation, e.g. to a USB security key running OSS firmware under user control. Widespread use of user-controlled attestations would make it harder for cloud services to impose unilateral requirements, requiring negotiation among competing objectives.
One remote attestation scenario could be disaggregation of critical apps into dedicated on-device VMs which look like cloud lambdas/functions/unikernels. Remote attestation could be done for a special-purpose VM (e.g. banking), leaving other general purpose OS VMs unrestricted. This is possible today with Windows Hyper-V on secured-core x86/Arm hardware, Android 13 with the pKVM hypervisor on Pixel 6/7 hardware, and the HP/Bromium AX hypervisor.
MS/Pluton thread, https://twitter.com/dwizzzlemsft/status/1511440279462563842
> what are they going to say when it's supported in Linux and we open source it ... the Pluton team also uses Linux daily, builds TWO Microsoft Linux distros, and upstreams Linux kernel features.
On servers, a forward-looking approach is being taken with OCP Caliptra, an open root of trust that will precede booting of the main SoC (including Pluton) and mandates open firmware that must be dual-signed by both the OEM and the datacenter owner. It is an early attempt to forestall ME/PSP/BMC Groundhog Day. If it succeeds on OCP servers (where datacenter owners have power to negotiate with OEM/ODMs), perhaps more transparency and owner control/veto can be brought to client devices, https://twitter.com/platformsec/status/1533398356088737793.
What's the point? That's about as useful as running your own CA. The fact is, those pushing remote attestation want remote centralised control and they're going to care that you have your own attestation infrastructure as much as they'll care that you have your own CA, i.e. they're not going to be satisfied because they're trusting their own, and not yours.
the Pluton team also uses Linux daily, builds TWO Microsoft Linux distros, and upstreams Linux kernel features.
That's even scarier. If the only form of "supported" Linux becomes Microsoft Linux (with its own unique brand of spyware and other crap forced on you due to RA), don't say we never saw it coming: Embrace, Extend, Extinguish... or perhaps that last E should now be Enslave.
If it succeeds on OCP servers (where datacenter owners have power to negotiate with OEM/ODMs), perhaps more transparency and owner control/veto can be brought to client devices,
We already had "owner control" until they started trying to take that away from us. We don't need nor want attestation at all. No means NO!
This cuts in both directions. Unlike signing certificates, attestation is not a zero-sum fight over a single monolithic measurement attribute that can only be A or B, it can support a goal of having A and B, e.g. as disaggregated VMs. If a cloud wants subset B, then the user/owner/enterprise local attestation can insist that the client must also have subset A, otherwise it can reject subset-B-without-A. Also applies to multiple clouds with conflicting requirements.
Enterprise clients connected to centralized clouds are not the same as consumption-oriented DRM, where the decision is grant/deny. Enterprise client devices generate business data that is sent to the cloud, and they consume data/compute/apps from the cloud. If businesses stop sending data to the cloud, the hybrid workflow breaks down. It's not as one-sided as Netflix DRM.
> We already had "owner control" until they started trying to take that away from us.
With the exception of IBM POWER / Talos servers that have open firmware including the BMC, most servers depend on many blobs, so there has been little transparency for owners, never mind control. One has to start somewhere, and Caliptra starts at the beginning, with an open silicon+firmware RoT that can potentially evaluate some of the myriad blobs and processors and devices needed to bring a server online.
E.g. DMTF SPDM can be used for local PCI (or virtualized I/O like NVMe-over-TCP) device attestation of firmware integrity to the server, before the device is authorized for use in the server, https://www.dmtf.org/standards/SPDM & https://www.platformsecuritysummit.com/2019/speaker/plank
Running your own CA IS useful.
This situation reminds me of the fuss around Palladium, a solution which seemed to be abandoned by Microsoft on its merits:
https://en.wikipedia.org/wiki/Next-Generation_Secure_Computi...
> Edit: nice, downvotes. Hello corpo-authoritarians, we know what's up :-)
This also reminds me of the fuss around Palladium:
Arm, including the quirky RPi, is not comparable in openness to x86 general purpose desktops, which were a happy confluence of accidents, determined individuals and scrappy businesses. That is still worth defending, if only to slow the slide backwards.
M1 Macs have a unique take on hardware security that can co-exist with general-purpose computing for open-source Linux, and Apple's vertical integration. https://archive.fosdem.org/2022/schedule/speaker/xeno_kovah/. Hopefully Asahi Linux will succeed in creating a relatively maintainable port for multiple generations of Apple Silicon.
Leaving aside the debatable nature of how open and free a RPi is, what's the point of "general-purpose computing" when it can't actually be used? When/if you need a locked-down machine controlled by some central authority to do what you can still do today with a free and open one, i.e. create and consume media, interact with services, communicate with others, etc., how much value does a truly libre computer have? It's almost like the "just build your own platform" argument when it comes to censorship.
> these tiny parts usually run with high privileges and dramatically impact the overall system. In such cases, MTE/CHERI play pretty nicely - they help ensure that whatever bugs we have in these areas are killed at their root cause (probabilistically/deterministically). This is exactly why MSR, MSRC and Azure Silicon pushed for this AMAZING project of CheriIoT ... scaling CHERI down to RISC-V32E, the smallest core RISC-V specification. I’m very excited about this project, and I hope once we will open-source the ISA and the prototype, more folks across the industry could join.
That is a direction that would benefit everyone: open silicon and open firmware for the most security sensitive components. It is technically possible and at least some humans in big companies understand the importance to future would-be-digital civilizations.
https://kakaroto.ca/2019/11/exploiting-intels-management-eng...
Not even the HN-audience cares enough to turn down something shiny.
https://www.platformsecuritysummit.com/2019/speaker/seay/ (click Hardware tag to seek video to the Pluton section)
IEEE paper (2021, paywall) on Pluton, https://ieeexplore.ieee.org/document/9512305
I think “optimize the UX a bit” is what they did, and it falls very woefully short of what they need. Especially when it arguably has a far bigger and better library of titles.
I hope Valve doesn’t throw in the towel after the first round. The Steam Deck idea can be a killer one. It just needs a lot more UX polish and marketing.
Since Valve doesn't share actual numbers, or at least has not done so yet, it's really hard to judge, but I think you're painting a picture that is at least a bit too pessimistic. I don't know if Valve actually expected to outsell stalwart console vendors, but I would actually guess they DID outsell the PS Vita's first year. That's really not too bad for a foray into a saturated market with a somewhat niche and admittedly even somewhat immature product.
Steam Deck probably has a bright future, but I'm most interested to hear if they had any success breaking into the market in Asia, as it seemed like that was a big push for them and probably generally one of the hardest markets for Valve/Steam, for a variety of different reasons. I have to guess the sales numbers in North America are pretty good based on how quickly we went through the preorders.
A big and weird part of this is simply because Valve is different. Still a corporation, still flawed, but certainly, if nothing else, definitely different. They have an appeal almost reminiscent of how people once regarded Google a long time ago. They've gotten a solid reputation for playing the long game with respect to building their ecosystem, and in that regard, Deck feels like a product many years in the making: the Steam client and games library, Proton and DXVK, the overlay and other middleware libraries, the multiple iterations of SteamOS, and many more endeavors all came into the product that the Deck is today.
Meanwhile, PS Vita did not have the luxury of the depth of consumer goodwill that Valve has, even if Sony has many times the breadth of consumer goodwill; worse, it needed to bootstrap it's ecosystem, whereas Valve has committed to bringing it's entire existing ecosystem to Deck instead. Valve also had the luxury of not being a traditional video game console vendor, and thus I don't think it elicited as strong of a reaction in the "console wars" either: I do not think that people view it the same. And hell, I don't think Valve does either. It has an aggressive starting price, and thus definitely can compete, but it seems probably still profitable. At the higher end, it's priced more like a gaming laptop, and thus the enthusiast gear that you would expect. I think they landed themselves a nearly unloseable situation with Deck. Because it's basically just an extension of their existing Steam ecosystem, it's essentially a value-add at worst. I would bet it acts more complimentary to other consoles, and there are probably few Deck owners without at least one other game console.
As a competitor to Nintendo's gaming handhelds and as a successor to the PSP, it seems like consumers largely rejected the PS Vita. Maybe in an alternate universe where Sony took an entirely different approach to the ecosystem and marketing of the PS Vita, things could've gone very differently.
Though I could buy the Steam Deck now, I am eagerly waiting for Steam Deck 2 just to see if there are lessons-learned-improvements from the first iteration.
Just wait for the Steam Deck 3, where they'll solve all the problems that don't even exist yet on the Steam Deck 2. Or better yet, might just wait for the Steam Deck 5 just to make sure they've finally ironed out all the kinks.
I'm just saying, if it's something you want, it fits your needs today, and you've got the budget for it, just buy it. Don't wait for the "what if the next generation is better?", Because of course the next generation will probably be better, if it comes out. But this fits your needs well enough today, and it's something you want, and there will always be something newer supplanting whatever you buy in the future as well.
So if you're thinking you'll wait for the 2 because it'll be better than the original, why get the 2? Won't the 3 be better? And of course, the 4 will be better than the 3, so maybe you shouldn't buy the 3 but instead wait for the 4. But what if there's a 5th generation...
Why would I buy the iPhone of today, won't the one next year be faster? And the one the year after that be faster than next year? Why would I buy the one this year when there will probably be a better one available eventually?
I just never got this line of reasoning. Could you share why you'd wait for the 2, but not the 3?
Cheers!
I'm very surprised that you don't seem to be aware of this, and treat it purely as n versus n+1.
On the other hand, it's plausible that the Steam Deck could hit within 50% of Vita, the Wii U or Gamecube, which is amazing for Valve's second push into the console market, and immensely profitable, given Valve owns pretty much the only avenue with which people will be buying games for it and gets a 30% cut, on top of the Deck being significantly more expensive than any comparable console, now or historically.
I just picked the closest analog: a modern handheld that can be plugged into a TV.
When the Game Cube "fails" as a product, all the worlds Game Cubes become just cubes that you can't do anything interesting with.
If Steam Deck "fails", it becomes merely a funky form factor PC. Plug it into a monitor via USB-C and it's a full desktop computer. With a surprisingly okay price for that, too!
The funny thing about security is it's about the weakest links they find.
So you can harden link A as much as you want if link B is a dud all the extra work on A was wasted energy.
What's most impressive is Xbox realised this and added in Dev mode.
What's shocking is Sony knew this from the PS2 era and gave it up!
TBH the Xbox 360 console was like a refresh of XBMC. One of the greatest things about the 360 out of the box was it played popular video codecs directly from USB storage - unmodded!
Unheard of at the time.
I had an early model PSX console in high school and bought the plug and play mod chip online in 2000 or so. Rented a lot of games and bought a lot of verbatim blue bottoms
Later a USB plus 1 wire mod chip for the PS2 that let me play backups and homebrew
According to sources, a modified original Xbox running the latest XBMC was put on the center podium, was shown off, and the executives had ordered the engineers to "make the new xbox do this"...and it was.
I was blown away when half way through the setup of my 360 my desktop running Vista helpfully chimed in saying it found the 360 and offered to let me stream all my MP3's right to it while playing games
XBox vs PS2: XBox was faster, but PS2 launched earlier, was cheaper, and had more games, so won the generation.
XBox 360 vs PS3: Sony reacts to Microsoft by making the PS3 more powerful than the 360 and more expensive. Microsoft reacts by getting more games and really doubling down on Halo (the biggest draw to XBox back then). XBox wins the generation.
Note: this is from memory, didn't check sources!
If you remove the SPE's from the equation (which many developers did) the PS3 has a much slower 2 Ghz Dual Core PPC64 CPU, while the Xbox has a 3.2Ghz Triple Core (6 thread) PPC64
The extra threads aren't directly as useful as games back then were almost entirely single-threaded, a trend that has only begun to really change course in the last decade or so (partially due to the Xbone and PS4 having anemic Bulldozer derived CPU's that had weak single-thread performance)
IIRC it's not even a dual core but a single core with two threads.
Sony really dropped the ball with the PS3 chip.
It's a shame they invested hundreds of millions or even billions in this new, hot, complicated to use chip, only for it to be completely surpassed by off the shelf x86 parts.
Sony though the chip would be so good they could sell it to be used in super computers for years to come, but by the time it was out, x86 had basically caught up and no customers cared about buying their cell processor.
The winner of 7th generation was clearly Nintendo with their Wii: over 100 million units.
And the funny thing is 2nd place: PS3! Just at the end of the generation it managed to outnumber X360.
Piling onto that with "we're getting rid of game sharing or the resell market" and "our new console is going to be your entertainment hub, i.e. it's going to be jammed full of shit most gamers don't want!" and the launch was just... ugh.
I think the trouble is that people kept finding ways back from arbitrary code execution in a limited environment to running pirated games and cheating in online games, and Sony continually failed to actually manage that.
Security is about reducing the frequency of events, and the impact of those events- Not making things philosophically impossible.
It was! I was a pre-teen then but I remember modded controllers and getting into modded lobbies. The only modding I did was USB modding my avatar and gamerscore, only to login a month or so later to the prompt that my account was banned forever.
dude. The irony. They bricked our machines and joked about it. They had a fellowship with the FBI.
They (MS and EA) threw OP, the author of this fkn submission, in jail.
Their own Terms of Service and Policy Enforcement page still brags about "pwning the pwnrs" - to this day.
Make no mistake, MS and Xbox still hate us. It's just from a capitalist perspective, its hard to compete with losing PC audience.
Their only selling point is itself, an unhackable console.
They did have restraint. There is a list of console ID's hardcoded in every NAND because originally a few souls had reversed the NAND enough to RSA-sign CON files - they were just gonna ban everyone who had made modified content, but didnt... because of Halo3's File Share incidentally preserving personal RSA keys, making it difficult to reconcile modified content, once spread.
Regarding hacked DVD drives....they did the math and banned millions when it was profitable, ironically.
> Make no mistake, MS and Xbox still hate us.
I should point out that I was not suggesting there was a good relationship between console hackers and Microsoft. Quote from me again:
> respect towards the ingenuity of console hackers
I did not say they had respect for the people, or that what they were doing was good, or anything like that. I'm claiming that from a security standpoint, they took the threat very seriously.
Microsoft legally bullying people is bad, but it's nothing new from Microsoft. Hell, it's nothing new from the console industry either. I actually was not aware of Microsoft putting anyone in jail over the Xbox homebrew/modding scene, but it does not surprise me. I remember what happened with Sony and Geohotz.
Still, from a sterile, technical point of view, I do think that in 2005 they were way, way ahead of keeping their console "secure" according to their threat model. I am never going to be particularly fond of a threat model where the adversary is the customer, but that's not really the point.
I agree, see my other comment re: KV.bin
They built the x360 with layers, upon layers, like an onion.
Two exploits (JTAG and RGH), and a few forever-unspeakable social engineering incidents aside, they did great work.
Until Mw2 came out in 2011.
I would consider contributing to a third episode with a new generation of stories/correbance/trivia, but with the amount of contribution from the feds to correct the record, I feel it would be unwise.
https://www.euronews.com/next/2022/07/09/could-you-end-up-in...
It's not like they got jailed because of MS's sheer spite to hackers - no, they made good money hacking MS consoles. Essentially, it's one capitalist against the other, and they had to be aware of the rules of the game.
I think you will agree that security in computing is not just "prevent people from getting hacked" or some static goal like that, but rather security is the management of "threats" under a given "threat model".
DRM, for example, is DEFINITELY a form of security software. DRM is an attempt to uphold policies around the access and/or copying of digital data such that access, distribution, etc. is controlled by said policy. Like any security software, it is meaningless if it's trivial to bypass, so it employs techniques to prevent users from modifying it, inspecting it, and otherwise bypassing its security measures.
Similarly, technology that is meant to only allow licensed hardware is largely the same idea. Like SEGA's Trade Mark Security System, although instead of cryptographic signatures, they instead hinged on the threat of a lawsuit. This is still a form of security system, just with a very different model of the threat.
What I am not saying is that these security measures are any good for the consumer. Obviously, these measures are very largely anti-consumer. Arguably there are some potential consumer benefits in limited cases (the most honest answer is probably anti-cheat, because most online games are frustratingly unplayable without some strong approach to dissuade cheating) but that is still not really my point. How is this security? It's simple. It's security against the threat of the end user. It upholds policies that the device vendor would like to impose on the consumer.
A lock is still a security device even if you abuse it to lock somebody in a room against their will.
E.g.: the corporate default settings for MFA show zero additional information. Literally just an “accept” button. The XBox equivalent shows location, etc…
PS3 Linux was about as useless as PS2 Linux, because the PS3 had only 256MB of RAM. I put Ubuntu Server on one and used it as a Squid proxy server to route P2P traffic through to the university’s college of computing since P2P was blocked in the dorms. For some stupid reason I totally got away with it. PS3 running in one of the research labs 24/7 routing traffic all day.
Rephrasing:
> You can sideload apps so it's not a vector for piracy
Most of the piracy scene depends on hackers figuring out how to break security so that they can run [SWEET DEMOS](https://www.youtube.com/watch?v=z8JaG6hQVbA) and homebrew apps on it. By saying "yeah mate here, toggle some settings, pay $90, and we'll even help you break the seal" it completely eliminates the drive that most experienced attackers have to actually attack it.
From what I understand there's an informal bounty among the Xbox and Hyper-V teams that increases on a regular basis for unsigned executables on the Xbox One platform.
That's the point
I won't claim Dev Mode is their solution to hacker, but there seems to be some correlation.
>Most of the piracy scene depends on hackers figuring out how to break security so that they can run [SWEET DEMOS](...) and homebrew apps on it
That's definitely the experience I have with modding scene; piracy is rarely the primary goal. Yes, Dev Mode is a niche feature, but it's a feature appealing to the hacker's niche.
And from what I see, stuff like RetroArch can be run on normal console even without Dev Mode nowadays. Heck, you can play NES games directly in Edge browser without any shenanigans.
More likely they wanted to make it difficult for grey-market vendors of unauthorized disk drives to escape cease and desist orders from Microsoft’s army of lawyers.
Xbox 360 also had XNA, I think you needed a paid membership to actually boot a game on it though. And on the last few Nintendo consoles they've had BASIC programs available letting you write your own software. Obviously there's some limitations there but people have done some neat stuff and it's even possible to do 3D. The original Famicom also had BASIC available.
No, it's because MS gave them the keys right out of the gate with Dev Mode.