This was my initial thought and a sentiment I've seen expressed elsewhere, but I think I'm missing something about how they'd implement this.
Sure, Rockstar can enforce a minimum software revision to launch the game, but couldn't some homebrew software just (a) lie about the software revision to any running game, or (b) apply any relevant software updates minus patching the kernel vuln?
That's not how attestation infrastructures work. Obviously they thought of all that.
Modern hardware attestation is - if implemented correctly - not beatable unless you decap chips and start trying to extract hardware keys. But the silicon itself is often heavily obfuscated and such a feat has not been demonstrated for modern hardware.
All breaks of modern console security rely on finding bugs or mistakes in the implementation. If the PS5 has got serious exploits then either:
1. They will patch it and revoke old firmwares, as the infrastructure lets them do. Then you have to try and find a new exploit in the firmware that GTA6 was released for.
2. It won't be released for PS5 until later. Xbox security has been undefeated for a long time now, so Microsoft might have an advantage there.
The way downloading games works on PS5 is your console asks PSN for a ticket using hardware attestation and account tokens, PSN checks if you own the game and gives you the keys. It's not doing attestation on every game start because that would make offline play impossible, and it wouldn't be effective against jailbreaks anyway.
If someone manages to download and decrypt the game on 1 single hacked console then it's out forever. Even if Sony decides to only allow unhacked firmware it's only a matter of time (months not years) before that version gets a jailbreak too because no complex system can be totally secure.
The only way to prevent this is making the game online only. That would be an extreme sales and reputation hit because it's the type of thing people expect from EA games where single player is a side mode. Not Rockstar famous for their incredible story modes that have always been offline.
Then you can see from projects like ReSkate that to successfully pull it off you would need to make the game effectively a thin client, because if you leave any logic on the console it will get reversed even if parts of it are server only.
And running a full game engine millions of times on your servers gets expensive real fast. Take Two can't afford it, and even if they could, the hit to their profits would be way more than what they can lose from the game getting cracked day 1.
So it's not feasible to fiddle with incoming firmware
updates, even with the level of access Relapse gives? I couldn't imagine how such a thing would be implemented. A hypervisor?
Yes all modern console RA systems have a verified boot rooted in hardware that chains to a hypervisor. They also encrypt all code and network traffic, use revokable per-CPU hardware keys, and can tie game releases or updates to revokable firmware versions.
The underlying architectures are quite complex but there are some good tech talks about them online. One of the best is by Tony Chen, which covers Xbox One security. It's many years obsolete now, but even that security system wasn't cracked until long after obsolescence. Microsoft have proven you can build an effectively unbeatable security system for general computing devices even though they only use it for games and multiplayer anti-cheat. It seems Sony might have not reached Microsoft's level.
Maybe AI will speed things up by making it easier to find obscure bugs, but design wise the architectures are sound and can work well.
You need to get the game in the first place, which requires a console that’s authorized to download games from PSN.
I don’t know how Sonys attestation works, and how resistant it is; but presumably it’s a bit harder than “lie to the game about what firmware you’re running”.
(GTA VI will famously not have a physical release, so you can’t rip data off the disk.)
A trivial scheme would be to distribute some shared secret key in a new update, and require it to be supplied back on connections to Sony's servers. In order to extract that key in order to replay it from an older firmware, you'd need to have root on the new firmware.
I'm not sure I understand the "minimal"/"small core" branding Pi is using. It's 450,000 SLOC and has at least a dozen direct dependencies, which I'm sure explodes into hundreds of indirect ones. It also depends on NodeJS/NPM.
Minimal to Pi isn't lines of code, it's everything else. Pi comes with four basic tools (read, write, edit, bash) and the ability to read its source and build more. So when other harnesses were building TUIs with window analogs and integrating MCPs (which I read yesterday that Pi is changing it's opinion on), or LSPs, or subagents, or web browsers, etc, Pi comes with none of that, and you add what you need. It's much lighter weight in that way.
Although if you want to compare sloc, a quick Google returns that OpenCode is ~670k sloc, so it's smaller there, too. But the real advantage is the prior one.
Half a million loc to do the basics feels like highly inefficient. Pi 1.0 also turn on the “fullscreen” tui by default… it’s becoming more and more like opencode.
not as complete as Pi yet but ive been working on https://wingman.actor, a different take on a lot of this stuff, written in Go, minimal dependencies, etc...
That's this internet. Nothing precludes you from dropping big tech and solely engaging with the "indie web"[0][1] if you so choose. You're free to build your own website with its own RSS feed, join webrings[2] of like-minded people, and engage organically.
[0] One of many similar initiatives, I'm sure. Not an endorsement.
Exactly. Plus, many people don't seem to understand the word "avoid" (it's come up in my own bubble recently). It doesn't mean "never." For example, a vegan would not say "I avoid eating meat." Furthermore, because someone successfully avoids now doesn't mean they went through a period of being unable to in order to earn the privilege to do so regularly.
Your exemple says much more: a short definition of veganism may use "never" and not "avoid", but a more complete, thoughtful definition encompass catches it:
> [...] which seeks to exclude—as far as is possible and practicable [...]
Ha, fair! It was an example off the top of my head and used based on my experience of how vegans talk, but yes, it's not a perfect example. But then if we're going down the rabbit hole then nothing is really absolute when it comes to what we should and shouldn't do. An actual software example would have been better:
"Avoid strong coupling between modules" v. "Never upload raw keys to a git server."
archive.is / archive.ph haven't loaded for me for a while, but since people are sharing fresh links it must be working somewhere. Am I experiencing a DNS block?
Edit: I did a web search and it seems to go even further back. There are discussions online about archive.is blocking Finland already 10 years ago. But the block was definitely off between then when it was put back on earlier this year.
That feels a little cynical. I think partly up to perception: "Target" would be a badass name for a weapons company, but we all know they actually sell clothes, so it's not particularly interesting.
In tandem, we're less familiar with them, which gives them that alure. Think of Rheinmetall and you think vaguely of a hulking corporate giant encompassing metalworkers manging molten metal to men in suits pitching fully automatic anti-aircraft turrets to entire nations; think of Missouri Metalworks and you just imagine a dingy suburban factory your mate reckons he worked at once. And no doubt that's how Germans would think of Rheinmetall too.
I think companies like Tesla, IBM, Lockheed, GE, etc. have the potential to sound "cool" like Rheinmetall were they not so ingrained in Anglophone culture. We just know them all too well, so they've become boring.
Last time I tried creating a Twitter account, I couldn't even complete the sign-up flow before getting automatically banned pending giving them my phone number. After that, I went to like and follow things. My account was then banned again for suspicious activity.
reply