Breaking the console: a brief history of video game security
sergioprado.blog
sergioprado.blog
So, yeah. The "article" is incorrect from nearly the get-go about the "wild west" Atari age.
No, it is not AI generated. It was based on my research.
I think there is a mix-up here between Atari home consoles and Atari home computers.
In that section I was talking about early console platforms such as the Atari 2600, where the cartridge interface itself had no lockout/authentication mechanism comparable to what Nintendo later did with the 10NES. That is why third-party cartridges could exist and Atari’s main response was legal rather than technical.
What you describe for the Atari 800 is real, but it belongs to a different context: the Atari 8-bit computer line, especially floppy-disk software, where copy-protection tricks such as intentional bad sectors and timing-based checks were indeed common.
So I agree that Atari computer software often used copy protection, but that does not contradict the point I was making about the early console era.
I'm a former Xbox hacker, then former Microsoft employee, and (long after) leaving Microsoft helped with the Collateral Damage post-exploitation payload.
The design of the Xbox One security predates me, but Microsoft has always known that SystemOS would be a weak link that would almost guaranteed to be compromised and shoved most of their attack surface that can be trivially attacked in there. The system shell, 3rd-party apps, guide, etc. all run in SystemOS.
The key things they focused on though were:
1. Extremely strong defense-in-depth
2. Making full or partial exploitation not economical
3rd party apps and the web browser were seen as being obviously untrusted _and_ needed JIT because they'd mostly be based on .NET or the JS VM. But practically speaking there should be nothing interesting in that VM: its compromise shouldn't enable piracy/cheating and ideally shouldn't leak game plaintext.
What some others found though was that for some reason plaintext was actually visible to SystemOS, but didn't enable piracy on console. You can take those games though and run them on PC using XWine1: https://github.com/xwine1
Technically speaking there's no reason why Collateral Damage couldn't have happened waayyyyy earlier in the Xbox One's lifecycle except for motivation. Even still you could probably take some Hyper-V N-day and compromise HostOS through.
Over there years there have been other "exploits" too: some folks have managed to tamper with gamesaves via cloud connected storage and other shenanigans, XSS in the system shell (some of these apps are JS), etc., but most of this was relatively benign and easily patchable. And there has been a very, very small group of people with similar but less capable exploits to Collat.
Collat allowed compromise of plaintext.
Bliss breaks everything :)
If you're referring to Windows, this is not very walled at all. You barely need a computer to write and release windows apps, let alone money.
Office, perhaps? Or a variety of other products.
However, Windows also has many, many, walled garden things bolted onto it. You aren't distributing your own drivers without Microsoft's approval. You aren't running Microsoft Office on Wine. You aren't connecting to Active Directory without Microsoft's blessing. You aren't making group policies that work on Linux for MDM. You aren't manufacturing Windows devices, at all, unless they meet Microsoft's system requirements and mandates (e.g. a Windows icon on the keyboard). Your BIOS must follow strict rules about where the activation key is fused. Etc.
In that respect, Windows is only open from an end user perspective. In all other respects, it is closed, and it is closed tightly.
Only kernel drivers.
> You aren't connecting to Active Directory without Microsoft's blessing.
I think you're talking about EntraID. That is true enough. You can just spin up Windows Server and create a domain controller, no problem. You don't need Microsoft for domain services, though - you can use other domain controller types. (You don't get GPO and other things - that's not a 'walled garden' thing, that's a feature set which other systems don't have)
> In that respect, Windows is only open from an end user perspective. In all other respects, it is closed, and it is closed tightly.
Not so tight as you seem to think. And anyways, I was specifically referring to building windows apps - which you did not disagree with. You absolutely can pull down various free tools, build an app, package it up as a .zip or .msi and distribute it from a variety of places. The Windows app store is a walled garden, but you don't have to use it.
(it was an NV GPU)
My dad would never cheat or do anything illegal even though he was an EE who could’ve done the mod himself. Today he might do it but there was a strict no stealing policy even for digital things. Like the time he freaked out because I was grabbing stuff from The Scene and wrote down a bunch of terms to research, he saw the word Warez and freaked out.
https://www.youtube.com/watch?v=U7VwtOrwceo
I like this video too, Tony Chen explains the overview of Xbox security system.