Live data from Hacker News

Root keys for Sony’s PlayStation 3 go public

geohot.com

21–30 of 79 posts

Re: Root keys for Sony’s PlayStation 3 go public

#22
post #20
post #3

Earlier quoted context omitted.

Part 1 - http://www.youtube.com/watch?v=c77Qnk_CMF8 Part 2 - http://www.youtube.com/watch?v=ovy2kPFOu0E Part 3 - http://www.youtube.com/watch?v=Y23LUiBRcOg That talk was at the 2010 Chaos Communication Congress which just concluded a few days ago.

I always assumed the PS3 has top notch security given how long they had managed to avoid exploits. Seems from watching the videos that they could go a long way on a future console to prevent hacks just by plugging these issues. The hypervisor happily allocating/ running anything and everything seems like a good place to start. Obviously other ways would probably eventually be found but as these guys say, just providi…

I always assumed the PS3 has top notch security given how long they had managed to avoid exploits.

Sometimes absence of evidence really is evidence of absence. Sometimes it's just that nobody was really looking that hard.

Their presentation makes a good case that real hackers really do just want to run their own code and that the 'piracy' bugaboo is something else entirely.

When I was little, I thought Sony was the coolest company ever. They made high-quality reasonably priced HiFi gear. Now my small children have made Sony the laughing stock of the household. Between this Linux debacle and the Windows rootkit, Sony has shown itself to have a habit of shooting its customers in the foot my opinion. No other company has fallen so low in my view.

Seems from watching the videos that they could go a long way on a future console to prevent hacks just by plugging these issues.

Naah. Every major security layer they had in place was broken or ineffective. That's usually a sign of deeper problems in the development process.

IBM probably wrote the hypervisor layer for them. IBM discontinued development on the Cell processor a few years back. It's likely nobody really understands that system at this point better than the hackers.

Re: Root keys for Sony’s PlayStation 3 go public

#24
post #5

"if you want your next console to be secure, get in touch with me. any of you 3." I would take the mans word and hire him. I'd even through Apple into his list, he did after all release jailbreaks for the iPhone too.

I'm not so sure I'd want to take a job having just made my new chain of command look like incompetent idiots, they'd probably find a way to repay the favor. They'd just make him to sign a bunch of long-term NDAs and fire him 6 months later. If this guy had much experience in the workplace he'd know that development like this usually happens when an organization has systematically driven out the detail-oriented security-minded people. They tend to be on the low end of the "net reduction in buglist items per salary dollar" scale.

On the other hand, there are any number of independent security assessment/pen testing firms that would love to have this guy's skills. He might even end up working on consoles. That's probably the way he should approach it.

Re: Root keys for Sony’s PlayStation 3 go public

#25
post #9

From the mathematician on stage: "and for some reason, Sony uses the same random number all the time!" - classic!

http://dilbert.com/strips/comic/2001-10-25/

(Bonus points if you get the reference: https://secure.wikimedia.org/wikipedia/en/wiki/Feynman_point)

Re: Root keys for Sony’s PlayStation 3 go public

#26
post #15
post #9

From the mathematician on stage: "and for some reason, Sony uses the same random number all the time!" - classic!

I'm not sure if that was hyperbole or not. As I understand it, all that was required was for them to use the same random number /twice/. Let's say you're Sony and you sign a patch, release it, realise there is a minor fix, and release within 2hours... maybe in your rush you failed to regenerate the random seed? Or, my initial thoughts, someone inside Sony did this maliciously?

If your build process requires you to manually generate a random number and copy and paste it in, you need to try harder. If you work for a bank handling payments, you should be fired and never allowed to work in software again.

EDIT: that last bit about banks is OT, sorry about that, I've been watching the chip and pin hacking talk from CCC and got confused.

Re: Root keys for Sony’s PlayStation 3 go public

#27
post #23

So what are the implications of this ? Homebrew software ? Pirated games ?

Homebrew first and foremost, and reclaiming back the ability to run Linux on the consoles (and run it on the PS3 Slim as well). It's possible to pirate games with this knowledge, but from my understanding a lot of the Blu-ray security has not been broken at this point in time so these keys are by no means all you need to get up and start ripping those discs.

Re: Root keys for Sony’s PlayStation 3 go public

#28
post #15
post #9

From the mathematician on stage: "and for some reason, Sony uses the same random number all the time!" - classic!

I'm not sure if that was hyperbole or not. As I understand it, all that was required was for them to use the same random number /twice/. Let's say you're Sony and you sign a patch, release it, realise there is a minor fix, and release within 2hours... maybe in your rush you failed to regenerate the random seed? Or, my initial thoughts, someone inside Sony did this maliciously?

maybe in your rush you failed to regenerate the random seed?

Or, my initial thoughts, someone inside Sony did this maliciously?

As always, the human factor is the real weakness. (Key management by users and coders.) There are similar problems with RSA signatures on related numbers or selecting keys for IDEA block cipher and RC4 stream cipher, just to name a few. If you use crypto tools incorrectly, you actually put yourself in a somewhat weaker position than if you hadn't even tried. What you've essentially done is create "security theater" for the bad guys to dupe the unsuspecting with.

Re: Root keys for Sony’s PlayStation 3 go public

#29
post #5

"if you want your next console to be secure, get in touch with me. any of you 3." I would take the mans word and hire him. I'd even through Apple into his list, he did after all release jailbreaks for the iPhone too.

I'm not so sure I'd want to take a job having just made my new chain of command look like incompetent idiots, they'd probably find a way to repay the favor. They'd just make him to sign a bunch of long-term NDAs and fire him 6 months later. If this guy had much experience in the workplace he'd know that development like this usually happens when an organization has systematically driven out the detail-oriented securi…

I'm not so sure I'd want to take a job having just made my new chain of command look like incompetent idiots

A chain of command that's savvy enough to really want him despite that is one you'd actually want to be in, though. An organization that focused on results would be all edge like the fictional Maas Neotek from Gibson's Neuromancer.

Re: Root keys for Sony’s PlayStation 3 go public

#30
post #20

Earlier quoted context omitted.

I always assumed the PS3 has top notch security given how long they had managed to avoid exploits. Seems from watching the videos that they could go a long way on a future console to prevent hacks just by plugging these issues. The hypervisor happily allocating/ running anything and everything seems like a good place to start. Obviously other ways would probably eventually be found but as these guys say, just providi…

I always assumed the PS3 has top notch security given how long they had managed to avoid exploits. Sometimes absence of evidence really is evidence of absence. Sometimes it's just that nobody was really looking that hard. Their presentation makes a good case that real hackers really do just want to run their own code and that the 'piracy' bugaboo is something else entirely. When I was little, I thought Sony was the c…

Naah. Every major security layer they had in place was broken or ineffective. That's usually a sign of deeper problems in the development process.

That, plus the serious problems they had at the launch of the PS3 Fat might indicate that a lot of know-how has leaked out of their organization and moved onto better things.

Post reply on HN