• Ever wanted an RSS feed of all your favorite gaming news sites? Go check out our new Gaming Headlines feed! Read more about it here.

thankyoumerzbow

Prophet of Truth
Member
Dec 8, 2020
8,392
if hackers get a working ps3 bc app in like less than a week that would be hilarious

i have absolutely no idea about any of this stuff so idk if that's even possible a this stage
 

Madao

One Winged Slayer
Member
Oct 26, 2017
4,678
Panama
great. now we'll have to compete against people that want a second PS5 to hack on top of all the other people trying to buy one.
 

Eiji

Member
Oct 28, 2017
145
if hackers get a working ps3 bc app in like less than a week that would be hilarious

i have absolutely no idea about any of this stuff so idk if that's even possible a this stage

An exploited system should allow Linux to run once all the compatible Linux drivers are in place.

There is already a PS3 emulator for Linux, RPCS3.

It would take more than a week though.
 

squall23

Member
Oct 25, 2017
4,767
I still remember the original PS3 hack where an important random number generator returned a constant. I was a programming student at the time so I showed it to the class and we all laughed.
 

BeI

Member
Dec 9, 2017
5,973
An exploited system should allow Linux to run once all the compatible Linux drivers are in place.

There is already a PS3 emulator for Linux, RPCS3.

It would take more than a week though.

Does it need any specific drivers though? Could it not just run standard Linux or other versions of it like SteamOS?
 

TripaSeca

Member
Oct 27, 2017
2,762
São Paulo
The PS5 is completely busted. Everything will be possible, CFW for sure, and if it's software only, it'll spread very fast. This is PS3/WII/Switch level of exposure.
 

SecondNature

Member
Oct 25, 2017
15,148
The PS5 is completely busted. Everything will be possible, CFW for sure, and if it's software only, it'll spread very fast. This is PS3/WII/Switch level of exposure.
As long as people cant play online, and as long as Sony fixes up the issue and ensures future consoles fix the exploit, would it matter?
 

TeenageFBI

One Winged Slayer
Member
Oct 25, 2017
10,222
As long as people cant play online, and as long as Sony fixes up the issue and ensures future consoles fix the exploit, would it matter?
It matters for people with exploitable hardware. Custom firmware is good times in every system I've hacked.
didn't take long to immediately try and derail the thread with this shit but ok
Did you expect anything else? At least stuff like that is eventually caught by mods.
 

gebler

Member
Oct 27, 2017
1,269
if they're talking about encryption keys it means that they can sign and execute code on the ps5 that has full access to the hardware. The implications here range from custom OS installation to homebrew to full blown piracy.

The PS5 is completely busted. Everything will be possible, CFW for sure, and if it's software only, it'll spread very fast. This is PS3/WII/Switch level of exposure.

Not so fast! Note the "symmetric" qualification in their statement. Digital signatures use asymmetric crypto, which could mitigate the impact of this breach considerably. The dump they show in the screenshot is probably from an encrypted update file, with the clearly readable text proving that they can decrypt it. Assuming asymmetric crypto is used for signatures, being able to read the cleartext of an upgrade file doesn't mean they'll be able to modify it, since its signature would be checked before the PS5 accepts it, and not having the keys for asymmetric encryption would mean that they couldn't produce a valid signature for the modified file. Likewise for other code running on the system. So the impact might be more about gaining insight into how things work, while still not being able to change it (yet).
 
Jun 12, 2018
492
didn't take long to immediately try and derail the thread with this shit but ok
How is it derailing when a security breach involving consoles usually leads to people asking if this will lead to console hacking later down the road? We both know what does through people's minds when they see security breach in a headline.
 

mugurumakensei

Elizabeth, I’m coming to join you!
Member
Oct 25, 2017
11,320
Not so fast! Note the "symmetric" qualification in their statement. Digital signatures use asymmetric crypto, which could mitigate the impact of this breach considerably. The dump they show in the screenshot is probably from an encrypted update file, with the clearly readable text proving that they can decrypt it. Assuming asymmetric crypto is used for signatures, being able to read the cleartext of an upgrade file doesn't mean they'll be able to modify it, since its signature would be checked before the PS5 accepts it, and not having the keys for asymmetric encryption would mean that they couldn't produce a valid signature for the modified file. Likewise for other code running on the system. So the impact might be more about gaining insight into how things work, while still not being able to change it (yet).
Eh you can determine where the keys used for the signing are if you know the original value, the algorithm, and the result as the set of possible keys for signing gets reduced and you just scan for files / locations in memory that have one of your expected values.
 

gebler

Member
Oct 27, 2017
1,269
Eh you can determine where the keys used for the signing are if you know the original value, the algorithm, and the result as the set of possible keys for signing gets reduced and you just scan for files / locations in memory that have one of your expected values.
The keys wouldn't need to be in memory at all, but could be embedded in custom hardware that only performs cryptographic operations using the keys without ever divulging the keys themselves. Pretty standard stuff for high-security embedded systems.
 

asmith906

Member
Oct 27, 2017
27,349
Does this mean we are likely to see hackers in PS5 online games in the near future? Because that would absolutely suck arse.
Doubt it, console would probably get banned with the quickness. And they probably participate in Sony's bounty program so chances the exploit will get patched in an update before it gets released.
 

mugurumakensei

Elizabeth, I’m coming to join you!
Member
Oct 25, 2017
11,320
The keys wouldn't need to be in memory at all, but could be embedded in custom hardware that only performs cryptographic operations using the keys without ever divulging the keys themselves. Pretty standard stuff for high-security embedded systems.
Eh, the key needs to be stored somewhere as I doubt it's fixed, and it needs to be deterministically recalled and needs to consume an arbitrary amount of space which means it's stored somewhere on the SSD and before you go "well maybe the file is encrypted" the symmetric keys have been found.
 

Stoopkid

Member
Oct 27, 2017
4,367
Does this type of stuff even matter anymore when most games and people wanna play online?
 

Aurora

Member
Jul 22, 2018
1,364
Lemuria
So it IS a fundamental hardware exploit akin to unpatched Switches that can only be fixed with a model revision?
 

Gentlemen

Member
Oct 25, 2017
9,503
Not so fast! Note the "symmetric" qualification in their statement. Digital signatures use asymmetric crypto, which could mitigate the impact of this breach considerably. The dump they show in the screenshot is probably from an encrypted update file, with the clearly readable text proving that they can decrypt it. Assuming asymmetric crypto is used for signatures, being able to read the cleartext of an upgrade file doesn't mean they'll be able to modify it, since its signature would be checked before the PS5 accepts it, and not having the keys for asymmetric encryption would mean that they couldn't produce a valid signature for the modified file. Likewise for other code running on the system. So the impact might be more about gaining insight into how things work, while still not being able to change it (yet).
this is a good explanation. thank you.
 

Remark

Member
Oct 27, 2017
3,542
Hmm. Not really from what history has shown. If they crack the console OS wide open, they can certainly spoof any attempts to make sure that it's not a hacked system. It becomes a mouse and cat chase game that never ends.
Doesn't matter at the end of the day because this will likely get patched by the time it makes it out to the public.

Was the same case with all the hacks on the PS4.
 

gebler

Member
Oct 27, 2017
1,269
Eh, the key needs to be stored somewhere as I doubt it's fixed, and it needs to be deterministically recalled and needs to consume an arbitrary amount of space which means it's stored somewhere on the SSD and before you go "well maybe the file is encrypted" the symmetric keys have been found.
I think you underestimate the possibilities opened up by having custom hardware. A HW-based security module having a programmable but non-readable key store using antifuses is very possible, for instance. But more importantly, digital signatures based on asymmetric crypto allows the verification key and the signing key to be kept separately, and as long as the PS5 only needs to verify signatures and not produce them, it would only need access to the verification key. So the asymmetric signing key could be impossible to obtain from the PS5 simply by not being there!
 

rare

Member
Oct 25, 2017
1,421
Are they wrong or something? I don't get why you're angry.
nah not really angry, coulda phrased my post better but saying that 99% of people who are into console hacking are into piracy is incorrect.
I've personally have been into console modding for a really long time now, and while yea piracy is an issue on any platform, a lot of people who bother spending the time with this kind of stuff go beyond piracy or don't touch it at all.
when I was younger, yeah, piracy was something I did. I was a kid, once I had an income things changed and I buy all my games. I still have my ps2 with freemcboot because I backed up all my ps2 games onto my server and stream the games onto my ps2 (which I'm glad I did because the disc reader died), same with my ps3 including running various homebrew and being able to adjust fan speeds to allow for it to be quieter for example. the switch has a ton of incredible homebrew and backup options that make it a no-brainer for me, I even own two separate switches, one strictly online, one to keep as a backup just in case + custom menus, mods, etc.
I know I'm probably an exception, but that's what I see when things are able to be modded or jailbroken, it opens up an entirely new experience of gaming that you don't really get to see unless you put in that time and effort, and I find it worth it to myself every time.

sorry for the essay but I just really don't want people to see consoles hacked and immediately go "damn pirates!!!!!!!!!!!!" because the people who hack the things in the first place don't even do it for piracy, but that is just an unfortunate byproduct of a product being blown wide open.
 

JoJo'sDentCo

Unshakable Resolve
Member
Oct 25, 2017
8,535
nah not really angry, coulda phrased my post better but saying that 99% of people who are into console hacking are into piracy is incorrect.
I've personally have been into console modding for a really long time now, and while yea piracy is an issue on any platform, a lot of people who bother spending the time with this kind of stuff go beyond piracy or don't touch it at all.
when I was younger, yeah, piracy was something I did. I was a kid, once I had an income things changed and I buy all my games. I still have my ps2 with freemcboot because I backed up all my ps2 games onto my server and stream the games onto my ps2 (which I'm glad I did because the disc reader died), same with my ps3 including running various homebrew and being able to adjust fan speeds to allow for it to be quieter for example. the switch has a ton of incredible homebrew and backup options that make it a no-brainer for me, I even own two separate switches, one strictly online, one to keep as a backup just in case + custom menus, mods, etc.
I know I'm probably an exception, but that's what I see when things are able to be modded or jailbroken, it opens up an entirely new experience of gaming that you don't really get to see unless you put in that time and effort, and I find it worth it to myself every time.

sorry for the essay but I just really don't want people to see consoles hacked and immediately go "damn pirates!!!!!!!!!!!!" because the people who hack the things in the first place don't even do it for piracy, but that is just an unfortunate byproduct of a product being blown wide open.
Great post. I get it now! :)
 

mugurumakensei

Elizabeth, I’m coming to join you!
Member
Oct 25, 2017
11,320
I think you underestimate the possibilities opened up by having custom hardware. A HW-based security module having a programmable but non-readable key store using antifuses is very possible, for instance. But more importantly, digital signatures based on asymmetric crypto allows the verification key and the signing key to be kept separately, and as long as the PS5 only needs to verify signatures and not produce them, it would only need access to the verification key. So the asymmetric signing key could be impossible to obtain from the PS5 simply by not being there!
Actually you can see that there's a function that reads asymmetric keys into a page in memory along with hmacKeyGen being the signing function in the dump and we already know PS5 can be pushed into enabling debug mode which means the exploit likely enables signing and executing arbitrary code.
 
Last edited:

Beer Monkey

Banned
Oct 30, 2017
9,308
Yeah I'm deleting my wifi from the system for a couple weeks to avoid stability. I don't give a fuck about piracy or online cheating but I'm into hacks.
 
Oct 27, 2017
3,892
ATL
Yeah I'm deleting my wifi from the system for a couple weeks to avoid stability. I don't give a fuck about piracy or online cheating but I'm into hacks.

I would personally love the possibility of turning the PS5 into a Steam Machine. Would be even more awesome if there was some way to put in a boot loader such that you could boot, Linux, Windows, or the PS5 OS.
 

War95

Banned
Feb 17, 2021
4,463
With the odyssey that it is getting a single PS5 im not risking mine even if im big into CFW. I will wait sadly