3 ms·
The articles says that the security sector is RSA-signed using a private key only Microsoft possesses, what if you also change the public key used for verificat
by imadr 4y ago
The articles says that the security sector is RSA-signed using a private key only Microsoft possesses, what if you also change the public key used for verification that is stored in the console?
- fredoralive 4y agoYou’d need Microsoft’s private key to sign the system firmware with a changed HDD verification public key in it (or an exploit undermining the general security chain of the system).
- imadr 4y agoIf everything is verified locally couldn't you also change the firmeware verification key, and whatever verifies the firmware verification..etc ? Isn't it turtles all the way down?
- izacus 4y agoThe Xbox 360 security is a lot of turtles and the last turtle is actually baked into the SoC itself so it's impossible to modify. That firmware verifies the next stage and establishes the chain of verification that's very hard to break. It did get broken eventually (after years of trying!) by figuring out that the CPU stops being reliable at very low clocks, but it was not even remotely easy.
- AceJohnny2 4y agoAt that level you're already hacking the console firmware. Easier then to just patch out the check as they've done.
- EatonZ 4y agoThe key is inside of the hypervisor. Not changeable if you want to retain your unmodded status.