Hacker Newsnew | past | comments | ask | show | jobs | submit | 15155's commentslogin

> attach malicious devices to the PCI bus to DMA sensitive data

How do you do this in modern system with TPMs and IOMMU enabled?


Sadly not all Windows machines are able to use kernel DMA protection, so for those machines nothing will stop you.

The obvious next step is to disallow those elderly machines once a critical mass of users have modern-enough equipment. We're almost there.

You pretend to be a device with a driver not compatible with IOMMU

This is a good move, but why isn't the anti-cheat software just refusing to operate on systems with these devices attached?

Because banning players from playing your game leads to refunds and bad publicity

Flash custom firmware emulating some benign "donor card".

> Whatever Microsoft ships would have more holes than swiss cheese

The current execution environment with IOMMU and TPM requirements is changing this rapidly.

Try disabling Windows Defender - good luck.


This is done for the benefit of Hollywood.

Audience matters. Something intended to stop legitimate business consumers in a non tech industry requires substantially less sophistication than something built to withstand professional reverse engineers.


Locks are there to keep honest people honest.

To expand on the saying, they're not there to be insurmountable. Just to be hard enough to make it easier to do things the right way.


And often they’re there so no one can plausibly say they didn’t know what they were doing or stumbled into it accidentally. You can’t “accidentally” go through a door with a padlock on it.

I’d guess it’s something similar with this dongle. You can’t “accidentally” run the software without the dongle.


Copy protection was also generally less robust for educational software, since it sold to generally law-abiding folks (parents, educators, etc.). Never saw Rapidlok or V-MAX! used for educational software on the Commodore 64, for example.


These days there would be an Aliexpress listing selling fake dongles within a month making it easy for the business customers too.


> cellular radio via USB provides far less isolation

Really? Does the radio somehow become the USB Host in this equation and magically start driving the conversation? How?


With a couple of GPS-synchronized receivers stationed in an area, child's play. LoRA airtime is extraordinarily long for common spreading factors.



Buy and keep it elsewhere? Buy futures?


The law covers "monetized bullion" - bars and coins -https://dor.wa.gov/education/industry-guides/jewelry-stores/...


Face ID doesn't work with eyes closed, the warrant wasn't clear whether or not A Clockwork Orange-style setup would be allowed.



Puya is a major flash manufacturer who ventured into ARM chips.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: