Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

One should never call something "unhackable" ...


Given that it held up against 13 years of dedicated efforts by people with physical access to the device, many years after its successor was launched, it seems merited in this case.

This talk about some of what went into it is fascinating: https://youtu.be/quLa6kzzra0


"Extremely hard to hack" or "Hackable only after it's retired" don't exactly roll off the tongue, but they are not synonymous with "Unhackable".

In many cases the truth is simply that its not worth the time/effort to hack it, so only the most dedicated perverts(with a positive connotation) keep trying.


It literally got hacked, that's what the article is about. It is NOT unhackable.


Microsoft stopped manufacturing in 2020. It was not hacked in its lifetime.


I agree, but also find it funny that by that standard the DRM in the original Google video streaming product was not hacked before the service was shutdown, after about 2 years :)


And to think that sometimes people doubt the wisdom of Google’s product-lifecycle decisions!


It was unhackable while it mattered. It was hacked 5 years after it no longer mattered. And all but the effectively beta release remain unhacked even now.


To the community it was unhackable, until very recently. It's security measures held up so long that it appeared to be unshakable. There were no obvious flaws. In hindsight it was hackable, but keep in mind how long it took. This console has long been obsoleted.


I wish people would take statements in relative terms along with the whole context before attempting to refute them with a quick gotcha in absolute terms.

Obviously nothing is ever unhackable, not even Fort Knox, given infinite time and resources, and Microsoft never made such claims, this is just media editorializing for clicks and HN eating the bait, but Xbox One was definitely the most unhackable console of its generation. Case in point, it took 13 years of constant community effort to hack a 499$ consumer device from 2013. PS4 and iPhones of 2013 have also been jailbroken long ago.

Therefore, even the click-bait statement with context in relative terms is 100% correct, it truly was unhackable during the time it was sold and relative to its peers of the time.


> Case in point, it took 13 years of constant community effort to hack it.

Can you attempt to quantify this effort in comparison to other game consoles? I'm not very familiar with the Xbox scene, but I would assume that there was a lot less drive to achieve this given that Xbox has never really had many big exclusive titles and remains the least popular major console (with an abysmally tiny market presence outside of the US).

As an aside, I wonder if Microsoft's extra effort into securing the platform comes from their tighter partnership with media distributors/streaming platforms and their off-and-on demonstrated desire to position the Xbox as a home media center more than just a gaming console.


> Can you attempt to quantify this effort in comparison to other game consoles?

The person who hacked the original Xbox wrote a book on the topic, which they've since made free: https://bunniefoo.com/nostarch/HackingTheXbox_Free.pdf


Oh that’s the best source I could ask for, thank you!


>and remains the least popular major console (with an abysmally tiny market presence outside of the US).

TF are you on about? The xbox one of 2013(competitor of the PS4 who got hacked long before) had a ~46% market share in the US and ~35% globally. Hardly insignificant. And any Microsoft Product, even those with much lower market share, attracts significant attention from hackers since it's worth a lot in street-cred, plus the case of reusing cheap consoles as general PCs for compute since HW used to be subsidized. And of course for piracy, game preservation and homebrew reasons.

I again tap the sign of my previous comment, of uring people to stop jumping the gun to talk out of their ass, without knowing and considering the full context.


Can you provide a source for those statistics? They don’t match up with any numbers I’ve seen, and in fact look ludicrously unrealistic.


>Can you provide a source for those statistics?

Google Gemini

> They don’t match up with any numbers I’ve seen, and in fact look ludicrously unrealistic.

Well can you post your numbers and sources, or are we supposed to read your mind?


> I asked a machine to make it up for me.

I don't come here to argue with an LLM. Use your brain and ability to research if you want to argue with me.


I too forget sometimes that Wii U existed.


I forgot that my Wii U existed until I remembered, hooked it up, and the NAND had gone bad.

So I replaced the NAND by soldering in an SD card, got it working again, and put it back in its box until I decide I need to play Wind Waker again.


Wow. I really did forget it existed. I was still thinking of the Wii.


This goes against information theory as a whole, and the point of words. How are you going to convey all this extra context to people who don't follow the space, and what word(s) do we use for something that is actually unhackable?

Literally unhackable? XD


Firstly, who made the claim that it was guaranteed to be "unhackable"? Was it Microsoft themselves when they sold it, or slop journalists looking to create false contrarianism in order to legitimize their own PoV and drive traffic to their articles? If it's the latter the we're just wasting our breath ehre over made up BS.

Secondly, this is HN, not some generic town corner shop newspaper. It's assumed the readers who come here often and comment with no green profiles, have at least some basic technical know-how that nothing is ever unbackable, least of all a console from 2103, and therefore process information through that context lens, instead of feigning complete ignorance and arguing from the false pretext they gobbled up from editorialized titles created by slop journalists.


In the very strict interpretation probably nothing is unhackable, just not hacked yet. But one should also be pragmatic about what "unhackable" means in context. Without the power of hindsight, a consumer device that stayed unhacked for ~13 years can be reasonably called unhackable during this time.


We don't need to contribute to word inflation. There's "really hard," there's "nearly impossible," there's even "impossible – as far as we know." I don't think it shows a lack of pragmatism to assume a technological claim, made by a technology company, should't be taken at face value. On the contrary, I'd advise more pragmatism to anyone failing to disregard an "unhackable" claim made by Microsoft specially even after fixnum years without known exploits.


I think it's like calling a ship "unsinkable". Yes, you engineered it to not sink, in accordance with strict maritime standards no doubt, but just don't call it unsinkable. If you call it unsinkable you're just begging for a century of snickering at your hubris.


It has no relation to hubris whatsoever if the "unhackable" label is not something self-proclaimed at launch but something descriptively applied by other people who were unable to hack it. Nobody would have snickered if the Titanic were described as unsinkable by people who had been trying to sink it for 10 years.


> Nobody would have snickered if the Titanic were described as unsinkable by people who had been trying to sink it for 10 years.

Pedantic: I'm sure somebody would have snickered about "unsinkable" if the Titanic sank after 10 years. Pragmatic: if the "unsinkable" Titanic lasted 10 years (or at least to profitability) before being sunk by people intending to sink it, that might certainly count as being "unsinkable" for the time it hadn't sunk.

Hubris: Titanic was claimed to be unsinkable before it was launched.


And they believed their own bullshit.


[flagged]


People should use their smarts and common sense to qualify statements. LLMs need a page of context, explanation and disclaimers so they maybe understand the meaning and intention.

> calling a safe uncrackable because nobody showed up with the right tools

The tools used for the hack (like voltage glitching) were there since before the first Xbox but nobody had the skills to apply them in a way that defeated the protections. There was a lot of interest in doing it but everyone who tried even just for the fame failed. I wouldn't fault anyone for calling it uncrackable, same as if a safe stayed impossible to open for decades or more.

If you want the "strictest interpretation", the useless one if you ask me, then only universal laws are immovable (maybe?), everything else is a matter of cost, time, etc. An entire category of words and expressions would have to be wiped from the vocabulary unless their meaning can be proven all the way to the heat death of the universe.

The pragmatism is that when someone calls a console unhackable, they mean it today, within a reasonable timeframe, for all intents and purposes. I don't think anyone realistically expects the "unhackable" console to stay so forever, only in the reasonable proximity of when it was said.

> Most hacks are about cost, not possibility

What about the other hacks which are about possibility? How would you go about proving something is hackable without hacking it? Is something "hackable" if you haven't proved it?


[flagged]


> What changed here is less the existence of the technique and more the instrumentation and persistence.

The instrumentation from 13 years ago is perfectly capable of pulling this off technically. I won't go into the proof that "human persistence" existed prior to 2026 aplenty.

But the discussion wasn't why the Xbox got hacked today, as much as the semantics of whether you are allowed to call something "unhackable" just because at the time of the statement nobody managed despite a lot of time and effort. I wouldn't mind the "linguistic absolutism" if it came from people who never used this kind of expression - one that is interpreted in the strictest sense no matter what. Instead this logic mostly comes from people who want to sound smart correcting without adding to the conversation or understanding the context. Think of all those parroting the "what an idiot to say 640K should be fine for everyone" meme.

> The underlying weakness was probably always there

Probably? You championed precise language. What's the alternative, that the silicon vulnerability developed in time?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: