frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

https://www.tomshardware.com/video-games/console-gaming/microsofts-unhackable-xbox-one-has-been-h...
180•crtasm•2h ago•83 comments

Kagi Small Web

https://kagi.com/smallweb/
562•trueduke•8h ago•151 comments

Node.js needs a virtual file system

https://blog.platformatic.dev/why-nodejs-needs-a-virtual-file-system
96•voctor•3h ago•86 comments

OpenSUSE Kalpa

https://kalpadesktop.org/
80•ogogmad•4h ago•42 comments

Finding a CPU Design Bug in the Xbox 360 (2018)

https://randomascii.wordpress.com/2018/01/07/finding-a-cpu-design-bug-in-the-xbox-360/
111•mariuz•4d ago•26 comments

FFmpeg 8.1

https://ffmpeg.org/index.html#pr8.1
193•gyan•3h ago•32 comments

Show HN: Antfly: Distributed, Multimodal Search and Memory and Graphs in Go

https://github.com/antflydb/antfly
39•kingcauchy•2h ago•16 comments

Spice Data (YC S19) Is Hiring a Product Specialist

https://www.ycombinator.com/companies/spice-data/jobs/P0e9MKz-product-specialist-new-grad
1•richard_pepper•54m ago

'The Secret Agent': Exploring a Vibrant, yet Violent Brazil (2025)

https://theasc.com/articles/the-secret-agent-cinematography
14•tambourine_man•1h ago•1 comments

Show HN: March Madness Bracket Challenge for AI Agents Only

https://www.Bracketmadness.ai
32•bwade818•4h ago•6 comments

Toward automated verification of unreviewed AI-generated code

https://peterlavigne.com/writing/verifying-ai-generated-code
14•peterlavigne•1d ago•3 comments

Give Django your time and money, not your tokens

https://www.better-simple.com/django/2026/03/16/give-django-your-time-and-money/
308•dcreager•1d ago•113 comments

Show HN: Crust – A CLI framework for TypeScript and Bun

https://github.com/chenxin-yan/crust
14•jellyotsiro•13h ago•5 comments

Building a Shell

https://healeycodes.com/building-a-shell
126•ingve•8h ago•28 comments

Efficient sparse computations using linear algebra aware compilers (2025)

https://www.osti.gov/biblio/3013883
45•matt_d•4d ago•5 comments

Leanstral: Open-source agent for trustworthy coding and formal proof engineering

https://mistral.ai/news/leanstral
695•Poudlardo•20h ago•162 comments

Heart, Head, Life, Fate

https://www.lrb.co.uk/the-paper/v48/n05/steven-shapin/heart-head-life-fate
4•Petiver•4d ago•0 comments

Font Smuggler – Copy hidden brand fonts into Google Docs

https://brianmoore.com/fontsmuggler/
113•lanewinfield•4d ago•60 comments

The unlikely story of Teardown Multiplayer

https://blog.voxagon.se/2026/03/13/teardown-multiplayer.html
192•lairv•4d ago•52 comments

Reverse-engineering Viktor and making it Open Source

https://matijacniacki.com/blog/openviktor
107•zggf•9h ago•50 comments

What I Learned When I Started a Design Studio (2011)

https://www.subtraction.com/2011/12/12/when-i-started-a-design-studio/
13•colinprince•3d ago•0 comments

Kagi Translate now supports LinkedIn Speak as an output language

https://translate.kagi.com/?from=en&to=LinkedIn+speak
1209•smitec•13h ago•278 comments

Sci-Fi Short Film “There Is No Antimemetics Division” [video]

https://www.youtube.com/watch?v=3v8AsTHfAG0
244•Anon84•4d ago•77 comments

GPT‑5.4 Mini and Nano

https://openai.com/index/introducing-gpt-5-4-mini-and-nano
32•meetpateltech•48m ago•12 comments

Meta’s renewed commitment to jemalloc

https://engineering.fb.com/2026/03/02/data-infrastructure/investing-in-infrastructure-metas-renew...
490•hahahacorn•23h ago•221 comments

The American Healthcare Conundrum

https://github.com/rexrodeo/american-healthcare-conundrum
481•rexroad•1d ago•532 comments

The “small web” is bigger than you might think

https://kevinboone.me/small_web_is_big.html
507•speckx•1d ago•208 comments

Gummy Geometry

https://newkrok.github.io/nape-js/examples.html?open=soft-body&mode=3d&outline=0
54•memalign•3d ago•8 comments

A proposal to classify happiness as a psychiatric disorder (1992)

https://pmc.ncbi.nlm.nih.gov/articles/PMC1376114/
132•wjSgoWPm5bWAhXB•4h ago•82 comments

Every layer of review makes you 10x slower

https://apenwarr.ca/log/20260316
449•greyface-•14h ago•267 comments
Open in hackernews

Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'

https://www.tomshardware.com/video-games/console-gaming/microsofts-unhackable-xbox-one-has-been-hacked-by-bliss-the-2013-console-finally-fell-to-voltage-glitching-allowing-the-loading-of-unsigned-code-at-every-level
172•crtasm•2h ago

Comments

Simulacra•1h ago
One should never call something "unhackable" ...
Arainach•1h ago
Given that it held up against 13 years of dedicated efforts by people with physical access to the device, many years after its successor was launched, it seems merited in this case.

This talk about some of what went into it is fascinating: https://youtu.be/quLa6kzzra0

WJW•1h ago
It literally got hacked, that's what the article is about. It is NOT unhackable.
ralfd•1h ago
Microsoft stopped manufacturing in 2020. It was not hacked in its lifetime.
lokar•1h ago
I agree, but also find it funny that by that standard the DRM in the original Google video streaming product was not hacked before the service was shutdown, after about 2 years :)
leoc•20m ago
And to think that sometimes people doubt the wisdom of Google’s product-lifecycle decisions!
max-m•1h ago
To the community it was unhackable, until very recently. It's security measures held up so long that it appeared to be unshakable. There were no obvious flaws. In hindsight it was hackable, but keep in mind how long it took. This console has long been obsoleted.
Brian_K_White•1h ago
It was unhackable while it mattered. It was hacked 5 years after it no longer mattered. And all but the effectively beta release remain unhacked even now.
devmor•1h ago
"Extremely hard to hack" or "Hackable only after it's retired" don't exactly roll off the tongue, but they are not synonymous with "Unhackable".

In many cases the truth is simply that its not worth the time/effort to hack it, so only the most dedicated perverts(with a positive connotation) keep trying.

joe_mamba•1h ago
I wish people would take statements in relative terms along with the whole context before attempting to refute them with a quick gotcha in absolute terms.

Obviously nothing is ever unhackable, not even Fort Knox, given infinite time and resources, and Microsoft never made such claims, this is just media editorializing for clicks and HN eating the bait, but Xbox One was definitely the most unhackable console of its generation. Case in point, it took 13 years of constant community effort to hack a 499$ consumer device from 2013. PS4 and iPhones of 2013 have also been jailbroken long ago.

Therefore, even the click-bait statement with context in relative terms is 100% correct, it truly was unhackable during the time it was sold and relative to its peers of the time.

devmor•1h ago
> Case in point, it took 13 years of constant community effort to hack it.

Can you attempt to quantify this effort in comparison to other game consoles? I'm not very familiar with the Xbox scene, but I would assume that there was a lot less drive to achieve this given that Xbox has never really had many big exclusive titles and remains the least popular major console (with an abysmally tiny market presence outside of the US).

As an aside, I wonder if Microsoft's extra effort into securing the platform comes from their tighter partnership with media distributors/streaming platforms and their off-and-on demonstrated desire to position the Xbox as a home media center more than just a gaming console.

joe_mamba•1h ago
>and remains the least popular major console (with an abysmally tiny market presence outside of the US).

TF are you on about? The xbox one of 2013(competitor of the PS4 who got hacked long before) had a ~46% market share in the US and ~35% globally. Hardly insignificant. And any Microsoft Product, even those with much lower market share, attracts significant attention from hackers since it's worth a lot in street-cred, plus the case of reusing cheap consoles as general PCs for compute since HW used to be subsidized. And of course for piracy, game preservation and homebrew reasons.

I again tap the sign of my previous comment, of uring people to stop jumping the gun to talk out of their ass, without knowing and considering the full context.

debugnik•1h ago
I too forget sometimes that Wii U existed.
deadbeef7f•1h ago
> Can you attempt to quantify this effort in comparison to other game consoles?

The person who hacked the original Xbox wrote a book on the topic, which they've since made free: https://bunniefoo.com/nostarch/HackingTheXbox_Free.pdf

scottyah•56m ago
This goes against information theory as a whole, and the point of words. How are you going to convey all this extra context to people who don't follow the space, and what word(s) do we use for something that is actually unhackable?

Literally unhackable? XD

joe_mamba•10m ago
Firstly, Who made the claim that it was guaranteed to be "unhackable"? Was it Microsoft themselves or slop journalists looking to create false contrarianism in order to legitimize their own PoV and drive traffic to their articles?

Secondly, this is HN, not some generic town corner shop newspaper. It' assumed the readers here have some technical know-how that nothing is ever unbackable and therefore process information through that lens.

close04•1h ago
In the very strict interpretation probably nothing is unhackable, just not hacked yet. But one should also be pragmatic about what "unhackable" means in context. Without the power of hindsight, a consumer device that stayed unhacked for ~13 years can be reasonably called unhackable during this time.
mikkupikku•1h ago
I think it's like calling a ship "unsinkable". Yes, you engineered it to not sink, in accordance with strict maritime standards no doubt, but just don't call it unsinkable. If you call it unsinkable you're just begging for a century of snickering at your hubris.
applfanboysbgon•1h ago
It has no relation to hubris whatsoever if the "unhackable" label is not something self-proclaimed at launch but something descriptively applied by other people who were unable to hack it. Nobody would have snickered if the Titanic were described as unsinkable by people who had been trying to sink it for 10 years.
inetknght•1h ago
> Nobody would have snickered if the Titanic were described as unsinkable by people who had been trying to sink it for 10 years.

Pedantic: I'm sure somebody would have snickered about "unsinkable" if the Titanic sank after 10 years. Pragmatic: if the "unsinkable" Titanic lasted 10 years (or at least to profitability) before being sunk by people intending to sink it, that might certainly count as being "unsinkable" for the time it hadn't sunk.

Hubris: Titanic was claimed to be unsinkable before it was launched.

replooda•1h ago
We don't need to contribute to word inflation. There's "really hard," there's "nearly impossible," there's even "impossible – as far as we know." I don't think it shows a lack of pragmatism to assume a technological claim, made by a technology company, should't be taken at face value. On the contrary, I'd advise more pragmatism to anyone failing to disregard an "unhackable" claim made by Microsoft specially even after fixnum years without known exploits.
stinmpy•1h ago
Marcus used to work for Microsoft, in the MSRC. I wonder if he used insider knowledge for this hack.
Scaevolus•1h ago
Microsoft released a video that covers effectively all of the Xbox One security system, and it's referred to extensively in the talk. The specific methods of glitching don't require any insider knowledge.
ZiiS•34m ago
They also told everyone they added more anti glitching to later hardware revisions; which by the process of elimination tells everyone they thought this was possible. The whole initiative was a success when it gave them a year; an unqualified triumph when it gave them the whole generation; they really are not going to be to sad after 12 years.
mike_hearn•17m ago
Right, as Markus says - even gods can bleed. And he's right: Tony Chen's team did god-level work with the Xbox One security system, so what must have followed in the Xbox Series S is truly unknowable. I don't think there's even a tech talk on it. This talk is probably the most elite hacking talk I've ever watched. Everyone who worked on this stuff at MS can and obviously should be very proud of what it took - especially as this probably won't have any commercial impact on Xbox game devs or multiplayers.
nxc18•1h ago
I think it counts as effectively unhackable since it remained unhacked until five and a half years after its successor went on the market.

I wonder if, assuming they continue making Xbox, they find a way to mitigate this in the next generation.

fredoralive•1h ago
The presentation notes that this hack currently only works with the first revision of silicon. Later variants have more protections, like some anti-glitching tech that wasn’t quite debugged for the early units being enabled for later runs, and further changes with the security / reset subsystems being split into two separate cores with revised consoles like the the One X. So these would be more of a challenge, even if there’s now an angle of attack to investigate.
darknavi•57m ago
> assuming they continue making Xbox

It sounds like that's the plan:

https://news.xbox.com/en-us/2026/03/11/project-helix-buildin...

babypuncher•23m ago
The new Xbox is going to be a specialized PC running Windows with full access to third party game stores (Steam, Epic, etc). It won't need to be "hacked" because anyone will already be able to run any software they want on it.
SteveNuts•19m ago
What is the point of a device like this if the only difference is form factor? Why wouldn't someone just buy a pre-configured gaming PC?
delecti•11m ago
I mean, at that point it is a pre-configured gaming PC. Hardware that's uniform across millions of units provides advantages, both for developers and users. IMO that's a big part of why the Steam Deck outsells more powerful competitors: there are so many of them that it gets targeted by developers, so more people buy them, in a virtuous cycle.
mitkebes•6m ago
The main goal is money, an Xbox branded windows PC has potential to drive sales.

Microsoft can also hopefully target a smoother user experience than a typical windows PC provides. They want this to be a valid console competitor, but just slapping xbox brand on a windows PC isn't enough to do that.

Having a first party hardware device to target for PC games can also help devs with having a clear performance target for PCs, similar to how the Steam Deck is currently a minimum spec performance target for a lot of games.

Jerrrrrrrry•1h ago
Created a voltage drop that exactly occurred to be timed to the key comparison, then a spike at the continuation.

Irl noop and forced execution control flow to effectively return true.

B e a utiful

hedora•1h ago
The earliest example I know of for this is CLKSCREW, but security hardware (like for holding root CA private keys) was hardened against this stuff way before that attack.

Has anyone heard of notable earlier examples?

btown•44m ago
It's fascinating - how does one defend against an attacker or red-team who controls the CPU voltage rails with enough precision to bypass any instruction one writes? It's an entirely new class of vulnerability, as far as I can tell.

This talk https://www.youtube.com/watch?v=BBXKhrHi2eY indicates that others have had success doing this on Intel microcode as well - only in the past few months. Going to be some really exciting exploits coming out here!

phantom784•39m ago
Could a chip detect this and reset?
johncolanduoni•22m ago
Yes, and the Xbox One has mechanisms to do just that. But they turned out to not be fully sufficient.
jolan•17m ago
This attack is on the early models that didn't have those protections enabled. The researcher surmised that later models do indeed have anti-glitching mechanisms enabled.
mkipper•7m ago
I'm not at all familiar with the Xbox One, but this is a feature that's generally available if you're designing "closed" hardware like a console. Most SoC these days have some sort of security processor that runs in its own little sandbox and can monitor different things that suggest tampering (e.g. temperatures, rail voltages, discrete tamper I/O) and take a corrective action. That might be as simple as resetting the chip, but often you can do more dramatic things like wiping security keys.

But this exploit shows that it's still almost impossible to protect yourself from motivated attackers with local access. All of that security stuff needs to get initialized by code that the SoC vendor puts in ROM, and if there's an exploit in that, you're hooped.

msla•36m ago
You can't. Console makers have these locked-down little systems with all the security they can economically justify... embedded in an arbitrarily-hostile environment created by people who have no need to economically justify anything. It's completely asymmetrical and the individual hackers hold most of the cards. There's no "this exploit is too bizarre" for people whose hobby is breaking consoles, and if even one of those bizarre exploits wins it's game over.

And if you predict the next dozen bizarre things someone might try, you both miss the thirteenth thing that's going to work and you make a console so over-engineered Sony can kick your ass just by mentioning the purchase price of their next console. ("$299", the number that echoed across E3.)

PUSH_AX•33m ago
> how does one defend against an attacker or red-team who controls the CPU voltage rails

The xbox does have defences against this, the talk explicitly mentions rail monitoring defences intended to detect that kind of attack. It had a lot of them, and he had to build around them. The exploit succeeds because he found two glitch points that bypassed the timing randomisation and containment model.

sabas123•25m ago
> It's an entirely new class of vulnerability, as far as I can tell.

It is know as voltage glitching. If you're interested our research group applies to Intel CPUs. https://download.vusec.net/papers/microspark_uasc26.pdf

ActorNightly•6m ago
Basically if someone has physical access to device, its game over.

You can do things like efuses that basically brick devices if something gets accessed, but that becomes a matter of whether the attacker falls for the trap.

braunshedd•24m ago
The Xbox 360 was hacked in a simpler but nearly identical way [1]! Amazing that despite the various mitigations, the same process was enough to crack the Xbox One.

[1] https://consolemods.org/wiki/Xbox_360:RGH/RGH3

Retr0id•20m ago
No? It is crowbar voltage glitching, but you're significantly underselling it here. The glitching does not affect key comparisons.

It's a double-glitch. The second glitch takes control of PC during a memcpy. The first glitch effectively disables the MMU by skipping initialization (allowing the second glitch to gain shellcode exec).

tetrisgm•1h ago
This is great news. Hopefully this opens the floodgates towards emulation and homebrew. Not that there are really any exclusives, but it would be interesting.
whalesalad•1h ago
I'm just excited at the opportunity to re-purpose my old launch day XBone as some kind of little homelab linux box.
jamesgeck0•1h ago
Xbox One homebrew has effectively always been supported. Anyone can register a development account and boot the system into dev mode. IIRC in a talk about console security, a Microsoft developer noted that this was an intentional deterrent against hacking. An effort to split the community so that pirates and homebrew enthusiasts wouldn't have a reason to collaborate.
protimewaster•22m ago
They did dumb things like limit memory availability in dev mode, though. Also they require a government ID to enable dev mode (but at least the quit charging $100 for it!). And they made it so you can't enable dev mode on consoles that are banned from Xbox services.

I understand it's still more than most console makers do, having dev mode at all, but it's maddening to me that Microsoft made dev mode so annoying and limited. I'd honestly just rather a hack be available so we have the option of using the entire memory or repurposing banned consoles.

qingcharles•33m ago
Very few exclusives. Couple of Forzas? Halo 5? Practically everything else available elsewhere in similar quality.
mike_hearn•18m ago
Seems unlikely. Someone would have to turn this into a modchip, set up physical distribution networks (all very illegal under the DMCA), and it'd only work on the 2013 machines - Chen's team clearly anticipated this type of attack and were already working on mitigations around the time the Phat released. So as he says at the end, later silicon already has more glitch mitigations built in and has done for a long time. Current gen Xbox isn't even investigated but we can assume it's even harder. They were clearly paying for red teaming. Remember: ZERO software bugs in the boot rom.
cortesoft•7m ago
I had a friend who ran a side business installing mod chips on the original Xbox in the early 2000s. There was a robust community around it, and you could buy chips easily.

This was all after the DMCA was in effect. I don’t think that will stop this sort of activity.

charcircuit•1h ago
It wasn't unhackable and decrypted versions of games already have been dumped. There was even a public exploit published years ago.

https://github.com/exploits-forsale/collateral-damage

What's new here is that this compromises the entire system security giving access to the highest privilege level.

landr0id•1h ago
Thanks for the mention! I helped with the collateral damage exploit (wrote the PE loader).

I didn't ask but Emma -- who wrote the kernel-mode exploit -- and I would probably agree that Collat is not really what we would consider a proper hack of the console since it didn't compromise HostOS. Neither of us really expected game plaintext to be accessible from SRA mode though.

tencentshill•1h ago
Note this only affects the very first original 2013 "VCR" hardware. Newer revisions and variants are still unaffected.
dlcarrier•4m ago
They're pretty common and cheap on the used market, though. I bought mine from a thrifts store for $30, and the console itself regularly goes for ~$50 on eBay.
lionkor•1h ago
Is there any better format article or writeup? I couldn't find anything.
au8er•1h ago
This just again shows that given enough time skill, and resources, any security is pointless if the attacker has physical access to the device.
wat10000•1h ago
I’m pretty skeptical of that lesson. This took 13 years and it’s cheap mass-market hardware.
recursive•1h ago
This seems like an unqualified win for the security measure. The future value of Xbox One DRM is probably close to zero. They already got what they wanted out of it.
leoc•22m ago
At this point the blip of free media coverage possibly makes this a net positive for XBox.
jamesgeck0•1h ago
One of the DRM circumvention methods for the Xbox 360 involved precision drilling a specific depth into one of the chips on the board. Microsoft was very aware of the nature of physical access while designing this, haha.
echelon_musk•23m ago
I had many Xbox 360s with flashed DVD drive firmware back in the day. But as I never owned a slim console I had no idea the drill/Kamikaze hack was a thing until now.
dist-epoch•1h ago
You do have a credit card, right?
Waterluvian•59m ago
I think this might be a good example of the fundamental misunderstanding of what "security" even is. It is never a binary state. Never was. And I think a lot of people don't really grok that and think that if a security block can be overcome in some manner then the thing is not secure.

Eventually Fort Knox will succumb to the unrelenting arrow of time and some future visitors will simply step over the crumbling wall and into the supposedly "secure" area.

tosti•13m ago
I see security as a stopgap measure when there's no peace. The best "security" is not to need any in the first place.
cocoto•50m ago
I can give you a piece of paper with a one time pad encoded secret, where the one time is physically destroyed. You can take all the time you want but you will not crack anything…
TobTobXX•31m ago
You don't need to attack the math, if you can attack the sender or thr receiver ['s hardware].
john_strinlai•42m ago
i find this statement is often used as an excuse to not think about security at all. which is probably not what you intended here (i hope, although you did say "pointless"...), but some people parrot it for that purpose.

a) this was a security win. millions and millions of people had physical access to the device for over a decade

b) as others have said, security is not all-or-nothing. the xbox one is extremely secure, despite not being perfectly secure.

c) just because something eventually gets hacked does not mean security was pointless. delaying access is a perfectly reasonable security goal. delaying access until the product is retired and the successor is already out on the market is a huge win.

babypuncher•15m ago
'pointless' is doing a lot of heavy lifting there.

This console went completely unhacked for 12 years, with this coming a solid 4 years after the hardware was discontinued. They kept piracy off the console for its whole lifespan, which was the entire point of these security measures. This is a massive success for the Xbox security team.

jamesnorden•11m ago
Better stop locking your doors, then.
autoexec•26m ago
> Whether PC users, our core readership, will be interested in actually emulating Xbox One, looks unlikely. The 2013 system’s game library is largely overlapped in better quality on the PC platform.

And this explains why it's stayed unhacked so long. There was very little incentive to hack the system when the games are all playable on a PC. Pirates, cheaters, archivists, and hackers could just go there. Microsoft's best security measure was making something nobody cared enough about to hack in the first place

bombcar•17m ago
There was a time when it would have been a hot target, but everything the original modded Xbox could do could be done easier elsewhere.
chocochunks•9m ago
Most of what was done on an original modded Xbox can be done on a retail stock Xbox One/Xbox Series with the exception of pirated Xbox games. Kodi (formerly known as XBMC) is just in the Xbox store, emulators and homebrew can be setup through dev mode with a little effort and $20. It's really just pirated versions of Halo 5 and a few others missing.
giobox•10m ago
The other major incentive for hacking the console Microsoft removed was for the first time on a modern mainstream home console to allow side loading of homebrew code/emulators etc. The console supported a developer mode that allowed side loading of third party applications, so folks could get emulators and other traditionally "banned" content on the console through an officially supported route.

There's a great presentation by Tony Chen on the Xbox One's security features:

> https://www.platformsecuritysummit.com/2019/speaker/chen/

Examples of the kinda software you can put on the Xbox One in developer mode:

> https://xboxdevstore.github.io/

JoeAltmaier•24m ago
Physical possession of a machine is pretty hard to make secure. It's a different level of secure, an order of magnitude less secure than remote attackers. This is expected?
jolan•8m ago
Tony Chen from Microsoft gave a talk called "Guarding Against Physical Attacks: The Xbox One Story" and he explains that they want any sort of physical attack to cost at least the price of 10 games ($600 at the time).

https://www.youtube.com/watch?v=U7VwtOrwceo&t=715s

jvillegasd•9m ago
Don't ever call a thing "unhackable", because every single human creation is imperfect
echelon_musk•8m ago
He is one of us :)

https://news.ycombinator.com/user?id=gaasedelen