Slashdot Mirror


Free60 Project Aims for Linux on Xbox 360

BlueMoon writes "The Free60 Project wiki and developers mailinglist has been launched. The project aims to port open source operating systems like GNU/Linux and Darwin to the Microsoft Xbox 360 gaming console. The site already contains some interesting details about the Xbox 360 security: per-box key stored on CPU, boot ROM will be on CPU too and a hypervisor verifies the running state of the kernel."

24 of 511 comments (clear)

  1. Re:Easier option... by KDR_11k · · Score: 3, Insightful

    Because the XBox 360 could run a virtual Mac Mini and still have enough CPU left to play Quake 3?

    --
    Justice is the sheep getting arrested while an impartial judge declares the vote void.
  2. Sounds like a good warm up by koan · · Score: 5, Insightful

    To cracking the Trusted Computing hardware.

    --
    "If any question why we died, Tell them because our fathers lied."
  3. Geeks don't need a "why." by MP3Chuck · · Score: 4, Insightful

    I mean seriously ... why not put Linux on the XBox? If there are some hackers out there that get their rocks off porting Linux to everything from new architectures to dead badgers, then more power to them if they want to tackle the X360, too. And IMO it'd be pretty damn cool to have 1) the power and 2) the form-factor in a general-purpose box.

  4. this is good for microsoft by Anonymous Coward · · Score: 4, Insightful

    microsoft don't care if you run linux on the xbox. they wont loose that much money. (i know that currently they loose a bit on each xbox they sell, but the more they sell, the more they can push manufacturing costs down).

    when 360.0 is cracked, they'll learn how it was done, and make 360.1 more secure. same when people crack 360.1 etc. all the xbox linux code will be open source so they can have a good look at the methods used.

    this is all good practice for them so that oneday they'll be able to make a computer that will only run windows and signed code. then they'll claim that anyone not using their secure platform must be a hacker or software/music pirate. then they lobby the .gov. then they have no competitors.

  5. Re:Source by bbrack · · Score: 4, Insightful

    Electrically programmable fuses make this very simple - when the part is tested at wafer/multiprobe, you simply blow in the ID when you are blowing in all your repair solutions - I can guarantee IBM is blowing an ID into the parts anyway for general yield/return tracking purposes.

    This ID can probably be accessed through the JTAG port, or accessed internally - the data is going to be in a certain format (Lot #, wafer #, x coord, y coord, or something similar) that would be easy to verify...

    You could also make it so reading the id from one place and writing it to another was part of the reset sequence on the chip...

    WRT getting the serialid out of the processor, you should be able to read it out through a simple JTAG instruction

  6. Re:Well, in regards to piracy... by Turmio · · Score: 3, Insightful

    The Xbox360 HD is basically a standard SATA laptop HD covered with a fancy casing. If a modchip for the system is eventually developed, I'm pretty damn sure that compared to that feat, it's a piece of cake to build an adapter that lets you use any hard disk with a SATA connector with Xbox360. Sure you can't fit a 500GB 3.5" drive inside the case but who cares if it must sit next to the case if it works?

  7. Re:Erm why? by oneiron · · Score: 5, Insightful

    I think it's a worthy cause to have an open source operating system working on every piece of equipment that is capable of it. Plenty of reasons it might come in handy some day (post-apocolyptic being the most entertaining one to think about)... Of course, the 360 also happens to have a fair amount of horsepower for the price (for now)...

  8. Re:Odd Timing by ergo98 · · Score: 3, Insightful

    Just as apple drops the PPC, Microsoft starts using it?

    Mobile computing is critical to Apple's strategy (indeed - mobile PCs are going to seriously erode the desktop market), where the PowerPC had few viable options. Mobile computing doesn't really matter much to the gaming console market.

  9. Re:Consoles are not general computing platforms by Geoffreyerffoeg · · Score: 3, Insightful

    special-purpose hardware

    To quote A Canticle for Leibowitz, "How did that heresy get into the world after all these years?" Anything with a standard CPU inside it is general purpose. The Xbox 360 is a Turing machine...with great graphics and an overheating problem, but that doesn't affect its Turing-completeness. Your Linksys router, your graphing calculator, probably your digital clock, are all general-purpose too, if you can find how to reprogram them. This world has very few special-purpose devices left in it. The point of things being Turing-complete is so that they're not special-purpose.

    Remember that anything with a microcontroller can have that chip reprogrammed. The only special-purpose chips left are probably in heavily-embedded systems like the chip inside your optical mouse or something. For most applications it's cheaper to program a general-purpose microchip in software, instead of making your own logic circuits.

  10. Re:Why? by anagama · · Score: 4, Insightful
    Maybe a usable Linux desktop? A hacked XBOX - yeah that ought to have about 100 users.
    Completely wrong. Hacking the 360 is important ... vital. If it isn't done, then when streaming video or the like starts to take off, content providers will require you to have MS hardware and your only option will be to accept that or give up. Hacking the 360 ensures choice in the marketplace in the future. Here's a quote from an article I ended up at by following some links during my RTFA session:
    Why does it matter? Bear in mind, Microsoft has big plans for the home -- plans that include media center PCs, family entertainment centers, TV set-top boxes, portable media players, mobile phones, and, of course, gaming devices. Considering that the Xbox 360 represents a powerful new computing platform that will be finding its way into tens of millions of homes, it seems likely that Microsoft will attempt to leverage the device to extend its reach throughout the home, offering a wide range of capabilities and services.
    http://www.windowsfordevices.com/news/NS3988467635 .html


    That's doubletalk for "you must use MS ______ to view this content".
    --
    What changed under Obama? Nothing Good
  11. Ooo! Ooo! And a cure for cancer too! by Valdrax · · Score: 5, Insightful

    It would be pretty cool if Linux worked on a 360 but please remind me again why people are trying to make it so? Aren't there enough projects crying out for some decent developer input already? Maybe I am just getting old and grumpy but this seems like a terrible waste of time that could be used to great benefit.

    I consider this the logical equivalent of the question, "Couldn't they be working on a cure for cancer instead?" I cannot abide this sort of arrogant stupidity.

    1) All programmers/scientists/etc. are not equivalent. Life is not some computer strategy game. You can't just wave your mouse around, pull a person off one project, put them on another, and expect the same level of productivity. Maybe the Xbox 360 project will attract people with good hardware hacking skills that aren't really applicable on anything you care about.

    2) What interests you may or may not interest people of technical aptitude. Sure, a cure for cancer would be really great, but not everyone is interested in whatever field of research will finally result in it. Some people might be more interested in entomology than oncology, and some people might be more interested in getting a cheap, powerful Linux home entertainment computer than whatever makes you happy. Your desires are not everyone else's desires.

    3) What doesn't interest you isn't necessarily useless. An Xbox is a very powerful multi-processor system perfect for hooking up to a home entertainment system and well suited for light distributed processing tasks. It's also fantastically cheap for what it's capable of. There are numerous potential uses for it.

    4) Not everything has to be useful to be worth doing. Surprise, surprise -- the people working on this might be doing it for fun! Even if it didn't have a lot of utility, that doesn't mean it isn't worth doing if it brings someone enjoyment to do it.

    In short, stuff it. You're not the dictator of the world, so quit discouraging people from pursuing interests that you don't share.

    </frothing at the mouth>

    --
    If it's for-profit but free, you're not the customer -- you're the product (e.g., the Slashdot Beta's "audience").
  12. Re:Nice try by ultranova · · Score: 5, Insightful

    The OP made a claim, without posting a shred of evidence, and I asked him/her to back it up. I'm genuinely interested to hear where he (or anyone else) thinks flaws might be in the 360's security model.

    There is no absolutely unhackable security model. Even if there is absolutely no bugs in XBOXs software (which I find highly unlikely - this is Microsoft we're talking here), you can always modify the hardware until the code you want to pass passes. Simply replace every single part if nothing else helps.

    The real questions are: is there a hack that requires so little effort from the part of the user that it is worth the trouble, and if so, how long until it is discovered ?

    --

    Forget magic. Any technology distinguishable from divine power is insufficiently advanced.

  13. Re:Source by Helvick · · Score: 5, Insightful

    You're missing the point here - this is supposedly a Trusted Computing architecture. The locks on this are not something as trivial as a serial number that is hard to track down. The core has a cryptographic component that provides for hardware based key management and secure crypto functions. That module will never export its unique private key(s) because the hardware design doesn't provide any instructions that allow that to happen. Good luck attacking it that way, it might be possible if they stuffed up the design but I doubt it.
    Furthermore if it follows the MS TC model then the CPU's crypto store will also have MS X-Box boot and app signing Root certs. All code, especially the boot process will have to be signed by something that will pass a check against those Root Certs. At a guess I'd say they have more than one of each type and they can be revoked via firmware (ie over XBox live, or via code distributed in games) just in case their primary leaks. Finding buffer overflows or figuring out how to code the instructions for an alternative boot firmware wont help unless you can figure out how to sign the code you feed into CPU. If the hardware design is properly secure then that will require breaking a strong crypto system equivalent to that used in X.509 certs in order to compromise those MS owned signing keys. This is a much much harder problem than compromising the original X-Box (which only used software based crypto so it could be subverted by replacing the boot code) or the PSP (which seems to rely on no secure execution model at all). MS certainly know how this should be done, the question is did they actually try to do it and if so did they succeed. That is the main reason I'm interested in this X-Box 360 hacking attempt, it's success will show how serious MS actually are about extreme DRM.
    My guess on that is that the answer is very interested indeed, if they can successfully implement a popular consumer device with a hard TC architecture then there are a lot of people out there who will want them to share it with them - the Cellular Telco's in particular love this stuff and will happily get into bed with MS if they can sell them a proven TC architecture that is resistant to attack.

  14. Let's get hacking. by Aqws · · Score: 5, Insightful

    I don't see why there isn't a lot more enthusiasm behind this project, only 100 posts so far, and hald of them saying why hacking the X-box 360 isn't that important. I thought this site is for nerds, the type of people who would love to get there hands dirty with this type of stuff. How can there be so much exitment about the x-boxs release, not as much exitment about greatly expanding what you can do with your X-box. First off, this allows gamers a much, much larger variety of games... I might end up playing Frespace to this thing. Anything you would be able to do with a PC you could do with an X-box 360 if linux is ported to it. I intend for my next PC to be an X-box 360, microsoft gets the hardware at a reduced cost, and that reduced cost is not only carried over onto you, but is improved upon, microsoft loses $130 for each xbox sold. This is no minimalistic PC, it's much better than my current one. When the security is cracked for linux, it won't be long until mac os X or any of the BSDs are ported to. Plus, it only runs $300 for a base unit. Alright anough dealing with these non-nerds, why aren't you linux experts hacking away at this thing? Think of the boon in linux developers when all these computer users get a taste of linux, because it will so vastly improves there console. Whos' going to care about the X-box when the PS3 comes? The faster it is ported, the more people who will be exposed to Linux, and end up developing it and making it better. Plus, the sooner I get my PC. How can you turn down this challenge? I wish they would have another one of those contests, were that guy got $100,000 for getting linux on the first x-box without a hardware change.

  15. Speaking of crashes... by kyashan · · Score: 4, Insightful

    Those that have a system with the HD and intend to keep it standing vertically, may want to think twice about that.
    It was very easy for me to kill a devkit as it fell laterally while the console was on.
    I can't imagine the retail system being less sensitive to that, as it's only normal for an HD to get damaged that way.
    The problem is that the thing is meant to stand up, but it's light and it doesn't have a wide base.

    Watch out.

    --
    "La presi e te la pagai (480.000 Lire)"
  16. Nitpick by Quiet_Desperation · · Score: 3, Insightful
    You're not the dictator of the world, so quit discouraging people from pursuing interests that you don't share.

    Well, a theoretical dictator of the world not have to "discourage" people. He'd just send in the shock troops and put an end to whatever the rablle was doing. :)

    And the OP's attitude wasn't *that* horrible. Things should have their value questioned at all times. The lack of questioning things leads to most of the messes we have in the world today. Watch a politician give an interview thse days. I don't think "follow up question" is even in the cirriculum of journalism schools these days.

    And, yes, "doing it for fun" is a perfectly valid answer, but there's no need to Bakersfield chimp on the OP. ;-)

  17. Security isn't about perfection by cgenman · · Score: 5, Insightful

    Parent poster implies a very important point. No security model needs to be perfect. It just needs to be good enough that it isn't worth screwing up whatever the security model is there to protect.

    If it takes 50 solder points and a week of effort, 99.9% of your users won't modify their consoles and your software sales won't be negatively impacted. If it takes a complete code re-write then finding a hash collision to get a modified console online, nobody will do it. Heck, Nintendo found that adding 2 little plastic tabs to the SNES was sufficient to greatly reduce the scope of the import market.

    Security is about dissuading people from doing things, not preventing them.

    1. Re:Security isn't about perfection by interiot · · Score: 4, Insightful
      Security is about dissuading people from doing things, not preventing them. That's true to some extent. Theoretically, many government sites are vulnerable to nuclear attack. However, the difficulty (politically and physically) of constructing one, and the likelyhood of counterattacks, mean that it's exceedingly unlikely to happen, despite the technical possibility. If it takes 50 solder points and a week of effort, 99.9% of your users won't modify their consoles and your software sales won't be negatively impacted.

      If it takes 50 solder points, somebody in China will figure out a way to make the work go quickly, and people will import them from Lik-sang. And we're nowhere near the 50-solder-point mark yet. And granted, if it got to the point where modifying it took more than $50-100 of work, people would just buy the nearest-priced open media portal device instead.

      Ultimately, technical security is completely different from physical security. Developers can do things in their home that's not detectable anywhere, and once things are broken once, they can easily be broken everywhere.

  18. Re:Nice try by ArbitraryConstant · · Score: 5, Insightful

    As long as these things play games online the possibility exists of a buffer overflow there as well.

    I know games programmers, and while many are competent, they rarely care/have time to audit their code for security bugs.

    --
    I rarely criticize things I don't care about.
  19. Enough! by UncleRage · · Score: 3, Insightful
    Yeah, I know this is /. and it's so very 7331 to device really ubercool ways of taking down the evil Redmond giant....

    But enough already!

    Look, it's reall simple... and I'm going to spell it out for you. Ready?

    Microsoft makes a product (Windows) that, in most of its incarnations, basically blows. We all know that. Every day, I promote Linux to as many of my clients / customers as I can. I sell new and refurb boxes with (k)Ubuntu installed. I build low-mid range servers running Gentoo and occasionally a *BSD. I install Linux on everything I can... because I'm a geek.

    Now, all that being said, the reason I get paid to install Linux on everything is because Microsoft continues to make a product (Windows) that, in most of its incarnations, basically blows.

    However, they also make some other products, and some of them are actually pretty nice: mice, keyboards, and... gaming consoles. So, the question is: Since we hate Windows... we have to hate the Xbox (or mice, or keyboards, etc...)? If the answer is yes, then what about the PSy? Who do we hate more this week? Micro$oft or $ony?

    Because... $ony installs rootkits on our computers... remember?

    But we game (we're hanging in games.slashdot.org... right?)

    So, which side do we choose? Because let's face it... you hate Microsoft and want to put them out of business (No more Xboxes, no more Windows... which means no more desktop games), and you hate Sony and don't want their rootkit installing shite, and if all that happens, then there'll only be Nintendo left and you'll hate them because they're monopolizing the gaming market.

    So, here's my thing... You really hate Microsoft? Hate the part that matters and do something about it! Hate the OS, because it's insecure, because it's buggy, because it stamps out competition, innovation and growth. But do more than hate it... actively participate in offering a choice. Volunteer a little time and energy and package old PII's and PIII's w/ a light Linux and offer to assist an NPO in acclimating to it. Put your burner to good use and start burning Live/Install distros and passing them out to anyone even remotely interested. Simply put... get involved in a real way. Put the $400 you were going to spend on a 360 (to SHUT M$ DOWN, DUDE!) and buy a burning system and get to work!

    But enough with this kind of psuedo-guerilla warfare talk. It's just a bit annoying. Because for every hundred of you that say something like... "Yeah, I'll install Linux on my Xbox 'cause it costs M$ money", one of us have actually done it... because we really are geeks. (And, because in a pinch, an Xbox running Linux makes a damn quick and easy backup server =D ).

    And just to answer the question... yes, I do practice what I preach. My Stellar2 burns an everage of 150-200 discs a month (ranging from Live distros -- usually knoppix or Ubuntu, install discs and other OSS projects like OpenCD). And, if you'll look below, my sig is the truth... My Microsoft Partner rep does not like me... at all. Why? Because every month on the phone I ask her this question: What am I doing to help "win the war"? I'm putting the best OS I can into the hands of my clients. What are you guys doing to make that OS Windows?

    Now, after a long and heated rant... I'll get back on topic with the actuall article and say this... Linux on a 360? Souns interesting... as soon as its possible, I'll try it. It'll be even nicer than Linux on the Xbox for one reason I can think of (outside of muscle & memory, of course): We can hook it up to a monitor this time!!!

    Get to work, Bunny! I'm waiting to follow in your mighty big footsteps!

    --
    #SickNotWeak
    1. Re:Enough! by croddy · · Score: 4, Insightful
      Windows isn't what we should be afraid of. The technology behind Windows has already undergone two significant shifts (from 3.1 to 9x, and then to NT) -- and it will shift again. Windows is nothing to worry about. For all but a few users with specific niche needs, there are numerous other OS options which are ready to use.

      The real danger is that the 360 represents some of the first real shooting in the DRM wars: a large-scale deployment of hard-wired cryptographic restrictions with the sole purpose of locking consumers out of their own property. Running Linux on this hardware is just a fun side effect of the very important and immediate need to defeat trusted computing and digital restrictions technology -- and to defeat it soundly and rapidly.

  20. Re:Nice try by Anonymous Coward · · Score: 3, Insightful

    If you have to mod the processor itself to get it done, it's unhackable. This is what the TCPA/Palladium/NGSCB/whatever effort is trying to get to eventually as well. Not everyone has the ability to manufacture fresh CPUs, especially of a specific design, and the silicon can't be changed afterwards.

  21. Er... say wha? by brunes69 · · Score: 4, Insightful

    Once you get into hardware probably very few people will attempt it. Too risky.

    I don't know what circles you travel in, but I don't know *anyone* who owns an Xbox that is not modded, and that is out of about 20 to 30 Xbox owners.

    The benefits of modding (namely, XBMC and the ability to play backups) are just too great to *not* do it.

    It will be the same for the 360 - a hardware mod chip will be out in a matter of weeks, and everyone and their dog will have one.

  22. Re:Nice try by alerante · · Score: 4, Insightful

    Simply replace every single part if nothing else helps.

    After that, rename your Xbox to "Ship of Theseus".