<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>The BFC Computing Weblog: XBox 360 - Pretty Dang Secure</title>
    <link>http://blog.bfccomputing.com/articles/2007/03/06/xbox-360-pretty-dang-secure</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description>My God, It's Full of Source!</description>
    <item>
      <title>XBox 360 - Pretty Dang Secure</title>
      <description>&lt;p&gt;Microsoft has billed the XBox 360 as &lt;a href="http://news.bbc.co.uk/1/hi/technology/4218670.stm"&gt;Hack-Proof&lt;/a&gt; since its inception, and for reasonable definitions of that hyperbole, they&amp;#8217;ve succeeded.  A &lt;a href="http://www.securityfocus.com/archive/1/461489/30/0/threaded"&gt;vulnerability&lt;/a&gt; was discovered in the &lt;a href="http://wiki.free60.org/Hypervisor"&gt;XBox 360 Hypervisor&lt;/a&gt; (looks more like a microkernel from the diagrams, but, um, &lt;a href="http://developer.apple.com/documentation/Darwin/Conceptual/KernelProgramming/Mach/chapter_6_section_1.html"&gt;R&amp;amp;D South&lt;/a&gt; already uses that term) which allows arbitrary code execution.  Microsoft patched and deployed a fix for this problem within 6 days.  This leads to many interesting lines of inquiry:  &lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Why can&amp;#8217;t Microsoft patch Windows that fast?  Is it because it&amp;#8217;s too complex? 
&lt;ul&gt;
&lt;li&gt;Not enough data to discern capability vs. motivation&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Is it because the vulnerability could potentially allow copied games to play and they make a cut on each game sold?
&lt;ul&gt;
&lt;li&gt;This seems likely.&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Is it because they care about the Whole Widget experience?
&lt;ul&gt;
&lt;li&gt;could be.  Tight control of hardware and software has some advantages.&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Maybe because it would allow Linux or BSD to run &lt;a href="http://www.engadget.com/2007/02/27/xbox-360-vulnerability-found-homebrew-could-be-just-around-the/"&gt;on XBox 360 hardware?&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;supposedly  Microsoft isn&amp;#8217;t losing money on each unit sold anymore, but an &lt;a href="http://sourceforge.net/projects/xbmc"&gt;XBox Media Center&lt;/a&gt; is a Windows Media Center not sold.&lt;/li&gt;
&lt;li&gt;you have to imagine chairs would get thrown in Redmond if Linux on the Microsoft hardware patform became popular&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;li&gt;Does the XBox 360 architecture represent a modern computing platform that shows off the skill of some Microsofties who are otherwise saddled by 30 years of legacy cruft that keeps them from implementing good security in Windows?
&lt;ul&gt;
&lt;li&gt;Objection! Leading the witness.&lt;/li&gt;
&lt;/ul&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;There&amp;#8217;s one more possibility: this is the way Microsoft wants it.  Have you heard Windows Defender isn&amp;#8217;t that good, as if Microsoft couldn&amp;#8217;t write a good AV product for Windows?  How about the usability of &lt;a href="http://movies.apple.com/movies/us/apple/getamac/apple-getamac-security_480x376.mov"&gt;User Account Control&lt;/a&gt; in Vista (you just want to figure out how to disable it)?  Did you notice Microsoft has been telling us for a year or more that Office is going &lt;a href="http://news.com.com/Gates+Were+entering+live+era+of+software/2100-1016_3-5926237.html"&gt;Live&lt;/a&gt;?  Did anybody notice Vista was 5 years late and under-delivered?  Did you notice that Vista has &lt;a href="http://technology.timesonline.co.uk/tol/news/tech_and_web/personal_tech/article1290451.ece"&gt;features&lt;/a&gt; that force folks into new HDMI/HDCP displays, which ought to work fine with an XBox?&lt;/p&gt;

&lt;p&gt;Wouldn&amp;#8217;t it be great if we could just have a computer that&amp;#8217;s secure, wired, and runs the Microsoft Apps we all love and need instead of dealing with this Windows on Dell mess?  Have just one vendor to buy our hardware and software from, all conveniently online?&lt;/p&gt;

&lt;p&gt;Who says Microsoft doesn&amp;#8217;t &amp;#8216;get&amp;#8217; the Internet?&lt;/p&gt;</description>
      <pubDate>Tue, 06 Mar 2007 11:09:00 -0500</pubDate>
      <guid isPermaLink="false">urn:uuid:02d5d2de-7b75-40a9-94a9-0b91a99cf84c</guid>
      <author>Bill McGonigle</author>
      <link>http://blog.bfccomputing.com/articles/2007/03/06/xbox-360-pretty-dang-secure</link>
      <category>Windows</category>
      <category>Hardware</category>
      <category>Internet</category>
      <category>Linux</category>
      <category>Security</category>
      <category>microsoft</category>
      <category>xbox</category>
      <category>xbmc</category>
      <trackback:ping>http://blog.bfccomputing.com/articles/trackback/2210</trackback:ping>
    </item>
    <item>
      <title>"XBox 360 - Pretty Dang Secure" by Ted Roche</title>
      <description>&lt;p&gt;"Wouldn&#8217;t it be great if we could just have a computer that&#8217;s secure, wired, and runs the Microsoft Apps we all love and need instead of dealing with this Windows on Dell mess? Have just one vendor to buy our hardware and software from, all conveniently online?"&lt;/p&gt;

&lt;p&gt;I thought that was the Apple Inc business model.&lt;/p&gt;</description>
      <pubDate>Mon, 26 Mar 2007 10:37:32 -0400</pubDate>
      <guid isPermaLink="false">urn:uuid:0bbb378a-2481-4e57-98f4-f074c4904966</guid>
      <link>http://blog.bfccomputing.com/articles/2007/03/06/xbox-360-pretty-dang-secure#comment-6</link>
    </item>
  </channel>
</rss>
