4 ms·
The bounty is nothing but a PR stunt - they might as well offer $50k, it's very unlikely anyone will ever claim it. The XBOX 360 and their official(ly licensed)
by trotsky 16y ago
The bounty is nothing but a PR stunt - they might as well offer $50k, it's very unlikely anyone will ever claim it. The XBOX 360 and their official(ly licensed) peripherals are protected by TPM style infineon chips that do cryptographically secure mutual authentication and protocol encryption (as needed). These chips are very tamper resistant, requiring a state sponsored level of sophistication to physically remove private keys that are never exposed outside of the chip dye. Or an exposure of the original microsoft signing keys for the xbox project which are undoubtedly closely controlled and are never required to be exposed to 3rd party developers (except, perhaps, infineon).
The exposure of such keys or a process to avoid the use of them would be of significantly more value to software bootleggers, unlicensed peripheral manufacturers and homebrew folks than any amount of money this open source group is likely to offer. And they'd be requiring a fully functional driver for a set of complex hardware with no documentation on top of the cryptographic attack. Nobody on earth would do all that work to claim that bounty. Not to mention, defeating the protections would surely fall under the DMCA circumvention rules, meaning revealing the coders identity would open them up to significant legal risk.
While it's fun blame microsoft for their behavior, it should be noted that this kind of peripheral protection is becoming significantly more common. Among others, I'm under the impression that this style of on chip cryptographic protections drives the new class of "made for iPhone" officially licensed bluetooth enabled gadgets and certain other "made for iPhone" hardware. I'm unsure if they use as tamper proof a solution, but the intent is the same.