Earlier quoted context omitted.
If the whole project is about signing code packages to prevent the platform being hacked, you would've thought the key generation would be considered a critical part of the application code, rather than a detail of the build process. Even if the code necessarily exists in the build script. The build script is the project in this case. If a developer has ever even thought about generating a list of 1000 random numbers…
I was suggesting a one time list. You need to keep a list of past random numbers anyway so you can verify no repeats. But sadly, I have to agree, this is epic fail.
Root keys for Sony’s PlayStation 3 go public
61–70 of 79 posts
Re: Root keys for Sony’s PlayStation 3 go public
#62"if you want your next console to be secure, get in touch with me. any of you 3." I would take the mans word and hire him. I'd even through Apple into his list, he did after all release jailbreaks for the iPhone too.
Clearly brilliant, but he also faked a photo of a jailbroken iPhone 4, which (apparently) motivated his partial withdraw from the scene. Though talk about a comeback... This is a much better online "hire me" than the ones that were popular on HN several months ago.
This is not unlike his behavior that got him rejected in the iPhone scene. I am actually a bit surprised that there are so many comments here praising him.
Hiring the fail0verflow guys, on the other hand, would be a good move.
There is a reason that he never releases technical details and just comes out of nowhere.
Re: Root keys for Sony’s PlayStation 3 go public
#63Earlier quoted context omitted.
> On the same token, I wonder if that could mean better performance... I found that running Yellow Dog Linux on it was awfully slow. The hypervisor is minimal in terms of overhead. The biggest impact comes from the fact that the PPC core in the PS3 doesn't do out-of-order execution. You'd be downright amazed how huge a difference this makes.
No kidding? I remember someone from GDC in 2005(the one, I believe from Maxis, who created a storm on Gamasutra after bashing the Wii two years later) that putting out-of-order execution on gaming consoles was going to cripple their capabilities... but the PS3 certainly doesn't seem to suffer from it as far as games are concerned. I don't know enough about the topic at this point so I'd have to read some more.
My understanding is that for the prevalent workloads presented by most games, out-of-order execution's benefits don't outweigh its costs in chip complexity/size/power consumption/heat/etc.
Re: Root keys for Sony’s PlayStation 3 go public
#64Earlier quoted context omitted.
Surely, someone has to hire this guy. Forget Apple. Intel? Nokia? IBM?
The US Government?
It's the phone manufacturers that have to use cryptography to prevent you from actually enjoying a device you just paid them $600 for, since they can't legally kill you if you do something they don't like.
Re: Root keys for Sony’s PlayStation 3 go public
#65Re: Root keys for Sony’s PlayStation 3 go public
#66"if you want your next console to be secure, get in touch with me. any of you 3." I would take the mans word and hire him. I'd even through Apple into his list, he did after all release jailbreaks for the iPhone too.
Re: Root keys for Sony’s PlayStation 3 go public
#67Earlier quoted context omitted.
Clearly brilliant, but he also faked a photo of a jailbroken iPhone 4, which (apparently) motivated his partial withdraw from the scene. Though talk about a comeback... This is a much better online "hire me" than the ones that were popular on HN several months ago.
Really not that brilliant. It appears that the fail0verflow guys did all of the work here. He just beat them to the punch after taking the fruits of their labor, and dropped the key using their exploit. This is not unlike his behavior that got him rejected in the iPhone scene. I am actually a bit surprised that there are so many comments here praising him. Hiring the fail0verflow guys, on the other hand, would be a g…
Re: Root keys for Sony’s PlayStation 3 go public
#68From the mathematician on stage: "and for some reason, Sony uses the same random number all the time!" - classic!
I'm not sure if that was hyperbole or not. As I understand it, all that was required was for them to use the same random number /twice/. Let's say you're Sony and you sign a patch, release it, realise there is a minor fix, and release within 2hours... maybe in your rush you failed to regenerate the random seed? Or, my initial thoughts, someone inside Sony did this maliciously?
Re: Root keys for Sony’s PlayStation 3 go public
#69Wow. How did this happen? Was the root key stored in the PS3? Or was it brute forced?
Part 1 - http://www.youtube.com/watch?v=c77Qnk_CMF8 Part 2 - http://www.youtube.com/watch?v=ovy2kPFOu0E Part 3 - http://www.youtube.com/watch?v=Y23LUiBRcOg That talk was at the 2010 Chaos Communication Congress which just concluded a few days ago.
Re: Root keys for Sony’s PlayStation 3 go public
#70So what are the implications of this ? Homebrew software ? Pirated games ?
Homebrew first and foremost, and reclaiming back the ability to run Linux on the consoles (and run it on the PS3 Slim as well). It's possible to pirate games with this knowledge, but from my understanding a lot of the Blu-ray security has not been broken at this point in time so these keys are by no means all you need to get up and start ripping those discs.