PS3 hacked for good this time

Discuss any wonders of the modern age, as well as wonders of the old age...but mostly the modern age.

Moderator: amsroks

PS3 hacked for good this time

Postby eoinzy » Sat Jan 08, 2011 12:51 am

Finally, the PS3 has been hacked! And what an epic fail on the part of Sony for allowing this to happen!

http://www.bbc.co.uk/news/technology-12116051 wrote:The PlayStation 3's security has been broken by hackers, potentially allowing anyone to run any software - including pirated games - on the console.

A collective of hackers recently showed off a method that could force the system to reveal secret keys used to load software on to the machine.

"The complete console is compromised - there is no recovery from this," said pytey, a member of the fail0verflow group of hackers, who revealed the initial exploit at the Chaos Communication Congress in Berlin in December.

"This is as bad as it gets - someone is getting into serious trouble at Sony right now." :lol:

The group, which has previously hacked Nintendo's Wii and says it is vehemently against games piracy, said that it had developed the hack so that it could install other operating systems and community-written software - known as homebrew - on the powerful machine.

Following the presentation, US hacker George Hotz, who has previously hacked parts of the console, used a similar technique to extract the master key. He has now published it on his blog.

This formerly secret number is used to "sign" all games and software that run on the system, to authenticate that it is genuine and approved by Sony.

However, once the key is known it can be used to sign any software - including unofficial software and games - on the PS3 and PSP.

In the end, the flaw that allowed them to crack the system was a basic cryptographic error that allowed them to compute the private key, held by Sony, he said.

"Sony uses a private key, usually stored in a vault at the company's HQ, to mark firmware as valid and unmodified, and the PS3 only needs a public key to verify that the signature came from Sony.

"Applied correctly, it would take billions of years to derive the private key from the public key, or to make a signature without knowing the private key, even when you have all the computational power in the world at your disposal."

"The signing recipe requires that a random number be used as part of the calculation, with the caveat that that number must be truly random and not predictable in any way," the team said.

"However, Sony wrote their own signing software, which used a constant number for each signature."

This allowed the team to use "simple algebra" to uncover Sony's secret key, without access to it.

"This is supposed to be the most secret of secret of secrets - it's the Crown jewels," said pytey.



In case you're wondering where the vulnerability was, I'll quickly explain.
Every games console can play its official games, but if you try to play copied games, it just wont load them. Thats because the official discs come with a "signature". This "signature" is a huge long number that just cant be cracked. So its kinda like a password. You need this password to make the games console run the game officially.
Typically, hacks are found that bypass the need to put in this password, for example, on the wii you need the homebrew channel to install games, but you still cant load games from the official disc channel. On the XBOX, you have to modify the hardware and install a chip to bypass it.
With this key for the PS3 applied to your copied disc, you won't need to do any of that because, as far as the console is concerned, these discs come directly from Sony and are official PS3 games.

The only way for Sony to fix this now, is to release a new console! This key was generated back in their HQ and has been applied to all previous games. Changing it will stop all the old games from working, which they simply cant do! So looks like its cracked for good! Someone is definately getting in trouble in Sony now!

For a bit of a basic technical explanation, theres a video I found on Youtube. Basically, where the coders were meant to get a random number to create this key. I'm not sure if they were just taking the piss, or this was actual Sony code (I hope not), but they just used the number 4 instead of a random number, so it can easily be predicted, hence how they got the key. To be honest, looks like someone was gonna make it random but for the time being just used this, and forgot to go back and finish it!! :lol:

See video:
PS3 Public Key hacked
User avatar
eoinzy
Site Admin
 
Posts: 2140
Joined: Mon Dec 01, 2008 8:19 am
Location: Dublin, Ireland

Re: PS3 hacked for good this time

Postby pimptastic » Mon Jan 10, 2011 8:41 am

Awesome i just bought a PS3 for myself for xmas. Give it 2 months and there will be a burning application to copy any game. I guess I will just need a blueray burner now.
User avatar
pimptastic
 
Posts: 500
Joined: Wed Jul 01, 2009 6:56 pm

Re: PS3 hacked for good this time

Postby dingo » Mon Jan 10, 2011 8:22 pm

Or an external hard drive, like I have for my Wii!
User avatar
dingo
Site Admin
 
Posts: 785
Joined: Sat Nov 29, 2008 9:56 pm
Location: Australia

Re: PS3 hacked for good this time

Postby pimptastic » Tue Jan 11, 2011 11:46 am

I've got an internal 160gb Hdd unlike your Wii :P
User avatar
pimptastic
 
Posts: 500
Joined: Wed Jul 01, 2009 6:56 pm

Re: PS3 hacked for good this time

Postby eoinzy » Wed Jan 12, 2011 1:05 am

ah ye, but each PS3 game is about 17 gigs!

Each Wii game is only about 3 gigs!

So with my 300gb external hdd, i can store about 100 games,with your PS3, you can only store about 8, at most!
Actually, some Wii games are smaller ,coz i've about 40 or so games and its nowhere near half full!
User avatar
eoinzy
Site Admin
 
Posts: 2140
Joined: Mon Dec 01, 2008 8:19 am
Location: Dublin, Ireland

PS3 Hacker Must Turn Over Hard Drives to Sony, Judge Says

Postby pimptastic » Mon Feb 14, 2011 8:54 am

PlayStation 3 hacker George Hotz must hand over his computers to Sony lawyers as part of a temporary restraining order issued last month, a federal judge ruled Thursday.

Hotz had objected to the stipulation, arguing that Sony would be able to go through its contents, but U.S. District Judge Susan Illston was not convinced: "That's the breaks," she said, according to a report from Wired.

In late January, Illston granted Sony's request for a temporary restraining order against Hotz, who hacked the Sony PS3 and posted his circumvention technique on his Web site, as well as links for others to do the same. As part of the TRO, Hotz was banned from posting or distributing those links or information about his hacking techniques. He was also required to turn over computers, hard drives, CD-roms, DVDs, USB sticks, or any other storage devices on which the circumvention devices are stored.

Hotz objected to that last part, but Judge Illston was not having it. "Here, I find probable cause that your client has got these things on his computer," she said, according to Wired. "It's a problem when more than one thing is kept on the computer. I'll make sure the order is and will be that Sony is only entitled to isolate … the information on the computer that relates to the hacking of the PlayStation."

Earlier in January, lawyers representing Hotz argued that he hacked the PS3 to add back a feature that Sony had removed. Hotz, the lawyers claimed, "re-enabled" OtherOS functionality, or the ability to dual-boot the PlayStation 3 using some other OS, such as Linux.

February 11, 2011 02.08pm EST
http://www.pcmag.com/article2/0,2817,2380143,00.asp
User avatar
pimptastic
 
Posts: 500
Joined: Wed Jul 01, 2009 6:56 pm

Re: PS3 hacked for good this time

Postby dingo » Tue Feb 15, 2011 1:28 am

Ye its a loada bollix. I dont know why Sony are still fighting this. They're losing fans by the day, and are acting like spoilt children!

Their keys have a huge gaping hole which cannot be plugged! Just give it up Sony and let the homebrew makers improve your console by adding the features that either should have been included at release, or have been removed with all these so called "updates"!

I might consider buying a PS3 in the next few months now, when theres enough software for it. If it had support for a TV card, like Foxtel IQ, or Sky+, with pause and rewind and recording, it could replace my whole multimedia setup!
User avatar
dingo
Site Admin
 
Posts: 785
Joined: Sat Nov 29, 2008 9:56 pm
Location: Australia

Re: PS3 hacked for good this time

Postby pimptastic » Tue Feb 15, 2011 8:45 am

It does, it's called play tv.

"PlayTV is an HDTV/DVR add on unit for the PlayStation 3 (PS3) video game console. It allows the PS3 to act as an HDTV or DTV receiver as well as a digital video recorder (DVR) for recording television programmes to the hard drive for later viewing. The application will only start up with the DVB-T adaptor connected."

http://en.wikipedia.org/wiki/PlayTV

Also, I run Fuppes media server from my pc. Works fine cabled with Cat 5 but had issues streaming over wireless.

"FUPPES is a free, multiplatform UPnP A/V Media Server."

http://fuppes.ulrich-voelkel.de/
User avatar
pimptastic
 
Posts: 500
Joined: Wed Jul 01, 2009 6:56 pm

Re: PS3 hacked for good this time

Postby qianan » Wed Jun 08, 2011 5:43 pm

pimptastic wrote:Awesome i just bought a PS3 for myself for xmas.Give it 2 months and there will be a burning application to copy any game. I guess I will just need a blueray burner now.





t's a problem when more than one thing is kept on the computer.
qianan
 
Posts: 1
Joined: Wed Jun 08, 2011 5:32 pm


Return to Technology

Who is online

Users browsing this forum: No registered users and 0 guests