01.01.2021
Results 1 to 4 of 4

Thread: iPhone hacker publishes secret Sony PlayStation 3 key

  1. #1
    Savant Undiluted Karma's Avatar
    Join Date
    Aug 2009
    Location
    UK/Yuggoth
    Posts
    3,358
    Rep Power
    31

    Default iPhone hacker publishes secret Sony PlayStation 3 key

    BBC NEWS


    The PlayStation 3's security has been broken by hackers, potentially allowing anyone to run any software - including pirated games - on the console

    A collective of hackers recently showed off a method that could force the system to reveal secret keys used to load software on to the machine.

    A US hacker, who gained notoriety for unlocking Apple's iPhone, has now used a similar method to extract the PS3's master key and publish it online.

    Sony declined to comment on the hack.

    "The complete console is compromised - there is no recovery from this," said pytey, a member of the fail0verflow group of hackers, who revealed the initial exploit at the Chaos Communication Congress in Berlin in December.

    "This is as bad as it gets - someone is getting into serious trouble at Sony right now."

    The group, which has previously hacked Nintendo's Wii and says it is vehemently against games piracy, said that it had developed the hack so that it could install other operating systems and community-written software - known as homebrew - on the powerful machine.

    "The details we provided and information and techniques we disclosed would have been enough to install Linux," he said. "We have no interest in piracy."

    Following the presentation, US hacker George Hotz, who has previously hacked parts of the console, used a similar technique to extract the master key. He has now published it on his blog.


    This formerly secret number is used to "sign" all games and software that run on the system, to authenticate that it is genuine and approved by Sony.

    However, once the key is known it can be used to sign any software - including unofficial software and games.

    "I hate that it enables piracy," said Mr Hotz. "The publication of the key is more academic than anything else."

    The number also works for Sony's handheld console the PlayStation Portable, said Mr Hotz.

    Developers have already started releasing tools to develop new software for the PS3 using the hacks.

    'Valid target'
    The PS3 - once regarded as the most secure of the game's consoles, and the only one not to have been permanently cracked - has in the last 12 months come under increasingly scrutiny from hackers



    In January 2010, Mr Hotz claimed to have cracked the console.

    Following his initial announcement, Sony released an update disabling a function, called OtherOS, that allowed gamers to install a version of Linux on their machines, thought to have been exploited by Mr Hotz.

    Many saw it as a pre-emptive strike to guard against games piracy.

    Mr Hotz never released the exploit and publicly said that he had stopped work on the console.

    But Sony's removal of OtherOS prompted other hackers to begin to look at the system more closely.

    "It became a valid target," pytey told BBC News. "That was the motivation for us to hack it."

    He said the team had spent "months" trying to find their way into the system.

    "It was not trivial to do this," he said.

    In the end, the flaw that allowed them to crack the system was a basic cryptographic error that allowed them to compute the private key, held by Sony, he said.

    "Sony uses a private key, usually stored in a vault at the company's HQ, to mark firmware as valid and unmodified, and the PS3 only needs a public key to verify that the signature came from Sony.

    "Applied correctly, it would take billions of years to derive the private key from the public key, or to make a signature without knowing the private key, even when you have all the computational power in the world at your disposal."


    But the team found that Sony had made a "critical mistake" in how it implemented the security.

    "The signing recipe requires that a random number be used as part of the calculation, with the caveat that that number must be truly random and not predictable in any way," the team said.

    "However, Sony wrote their own signing software, which used a constant number for each signature."

    This allowed the team to use "simple algebra" to uncover Sony's secret key, without access to it.

    "This is supposed to be the most secret of secret of secrets - it's the Crown jewels," said pytey.

    The team decided to publish its method but not the keys.

    After the team revealed their hack, Mr Hotz said that he was prompted to renew his work on the system.

    "What fun is a race if no-one else is running," he said. "fail0verflow did great work - they took it up a level."

    Using a similar technique he was able to extract the entire master key for the system, which he subsequently publish online along with a demonstration of it in action.

    However, he has not released the method he used to extract the key.

    "There is no reason to," he said.

    However, he said that he may release a piece of software that will allow people to easily sign their own pieces of software and homemade games - also known as homebrew - on to the console.

    "I have a program running but am thinking of a good way to release it," he said.

    Like fail0verflow, he said that he does not condone games piracy.

    "I do not want it to be able to sign official Sony programs. I'd like it just to be able to sign homebrew."

    fail0verflow said it "disagrees" with Mr Hotz's decision to release the key, saying that it expects them "to make piracy easier without accomplishing intrinsically useful".

    Legal worry
    Sony takes a dim view of people hacking its system.

    Last year, a team released a USB dongle called PSjailbreak that contained software that allowed gamers to play homemade and pirated games on the PlayStation 3.

    Sony updated its consoles to block the software and took legal action against distributors in many countries.

    However, according to pytey, it may not be so easy to fix the problem this time.

    "The only way to fix this is to issue new hardware," he said. "Sony will have to accept this."

    He said that he thought his group was on safe legal ground with its work.

    "I haven't stolen anything," he said. "It's my own hardware, I can run whatever I like on it.

    Mr Hotz also defends his actions, although admits he is "scared of being hit with a lawsuit".

    "I am confident I would win since what I released was just a number obtained by running software on the PS3 I purchased".

  2. #2
    Terry Cloth Rudolph Joint Sky Blue Bally Kid's Avatar
    Join Date
    Dec 2003
    Posts
    6,515
    Rep Power
    74

    Default

    Could be good news in a way for Sony as people will buy the console just so they can play pirated games, also the modding community will buy it to modify it.

    Don't think the film industry will be too pleased though.

    Sony say they'll fix this but I'm sceptical.

    When I'm writing in my room







    It's like a child that's fighting in the womb


    - KP -

  3. #3
    SiferBorn BornPower's Avatar
    Join Date
    May 2006
    Location
    Souf CHIolin
    Age
    42
    Posts
    1,247
    Rep Power
    25

    Default

    Quote Originally Posted by Bloodspitta View Post
    Could be good news in a way for Sony as people will buy the console just so they can play pirated games, also the modding community will buy it to modify it.

    Don't think the film industry will be too pleased though.

    Sony say they'll fix this but I'm sceptical.
    according to the article, the only way for Sony to fix this would be for them to distribute new hardware. I am interested to see how they will sucker the public into buying another console @300 a pop when they can keep the old ones and use it for more...common things (like bootleg movies!)
    weep for lost babylon,
    the bleeding god, the forgotten sheep slaughtered in a forest of evil fog
    bordered by a sea of faults,
    fleeing mobs turn to see the holocaust and become kings and queens of salt
    screaming shots, police and chalk,
    wingless fallen demons walking among us as people...

    -.5Kut

  4. #4
    Veteran Member shaolinsword's Avatar
    Join Date
    Aug 2006
    Location
    Basildon, Essex
    Posts
    2,677
    Rep Power
    24

    Default

    Quote Originally Posted by Bloodspitta View Post
    Could be good news in a way for Sony as people will buy the console just so they can play pirated games, also the modding community will buy it to modify it.

    Don't think the film industry will be too pleased though.

    Sony say they'll fix this but I'm sceptical.
    The only thing Sony can do now is brick the consoles that use the hack which is apparently possible even if you don't sign in.

    Looks like Sony got a bit annoyed

    It seems that Sony might be the one who will win the piracy issue with the PlayStation 3. Sony has addressed GeoHot, the hacker that got everything started on the PlayStation 3 stating that failoverflow and GeoHot will be getting sued.

    The ironic thing is, has Microsoft sued anyone over hacking the Xbox 360? Frankly, no, Microsoft just bans the console that is convicted of piracy. Sony knows how to stop it period while Microsoft is just letting it go out in the dust.

    I do not hate Microsoft on this because Microsoft was too late to the party to be honest for the Xbox 360 when piracy to start to rise on the console but I do give them credit for at least attempting to get rid of it.

    GeoHot and the failoverflow crew seems to be in a ton of trouble after just skimming over the legal documents. A restraining order was put on GeoHot, now that is pretty big.

    List of charges:

    18 U.S.C. § 1030(a)(2)(C) – Confidential Information On Computer

    18 U.S.C. § 1030(a)(4) – Intent To Defraud And Obtain Value

    18 U.S.C. § 1030(a)(5)(A) – Knowing Transmission of Code

    18 U.S.C. § 1030(a)(5)(B) and (C) – Intentional and Reckless Damage And Loss

    18 U.S.C. § 1030(a)(6)(A) – Trafficking in Password

    18 U.S.C. § 1030(a)(7)(B) – Intent to Extort

    Here are the papers that were sent to GeoHot: (Will not be hosted on E4G due to the site not wanting to go into a legal issue of it's own, the PDF files take a while to load)
    http://www.everythingforgamers.com/a...soft-does-not/
    Last edited by shaolinsword; 01-12-2011 at 04:57 AM.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •