PS4 hack: Fail0verflow demonstrate Linux and Steam running on Firmware 4.05
wololo.net
wololo.net
[1] https://marcan.st/2009/06/enabling-intel-vt-on-the-aspire-89...
Ha! Wow, I remember this too. I had a similar model (a 5760 I think?) which was my main "work" laptop at the time. I remember running this in the vague hope that it would work knowing full well that I could have a brick on my hands and it did work, flawlessly. Amazing how these things pop up again years down the line.
So assuming there is no economic impact, what is it that makes us want to lock down consoles (similarly cell phones) when we do not do the same to the personal computer we hold so dearly? It is a fascinating story that I suspect is due to timing and when devices hit markets but curious what others think about this.
Due to the economics and competition, consoles are almost always sold at a hardware loss early in the generation, and only begin to become profitable at some much later point.
Ergo, if someone buys a console and buys no games, Sony/MS/Nintendo (maybe not the last) loses money.
http://phys.org/news/2010-12-air-playstation-3s-supercompute...
Also means it was in Sony's interest to sell many more games/accessories/licences/however else they make money with the PlayStation ecosystem than consoles.
That is incorrect: http://www.theverge.com/2012/10/25/3552686/nintendo-wii-u-lo...
This is an interesting thought I hadn't considered until now.
You have to rent your dev kit and you pay per update. This ensures the hardware is "below cost"
Sure, the hypothetical pirater now has access to device drivers and an open OS environment, but why wouldn't something like SecureBoot work to ensure that if you want to connect to the multiplayer / social network then you have to have loaded an unmodified OS as verified by the TPM.
No one said SecureBoot was a terrible idea technically, only that MS (and ARM/Android) were telling half-lies about a strong commitment to customers being able to make another OS choice, if they so choose.
It was an attack vector and it allowed the initial hypervisor dump[1], which led to the PS3 getting hacked.
1. https://en.wikipedia.org/wiki/George_Hotz#PlayStation_3_secu...
Yes, the additional attack surface available when loading a user-controlled OS is helpful in writing exploits. But Sony bungling the PS3's PRNG for code signing would have still been broken even without Other OS.
[1] https://fail0verflow.com/blog/2016/console-hacking-2016-post...
Not quite. "Security through obscurity" refers to obscurity being the only layer of security. PS3 still had encryption and in ideal world, if the software was completely exploit free then it would not be an issue. However, all real software has bugs, which could be exploited. Not making it easy for an attacker to find these bugs is the Security 101.
Do you open file system on your servers for read to everyone? Do you enable guest accounts on your systems? If you don't you are also practicing "security through obscurity".
>As fail0verflow continually notes in their blogs [1], piracy is the least interesting use case of exploits for them.
A search for e.g. "CFW PS3" will reveal a lot of people who are quite of opposite opinion.
Like most of HN, I'm familiar with the definition.
As to the group's feelings, I'll quote them, "On the PS3, we tried releasing the exploits and letting others sort out the community. The result was that, for all practical purposes, the only users were those interested in piracy." https://fail0verflow.com/blog/2015/console-hacking-2015-line...
The PS3 piracy script kiddies you highlight are exactly my point. Peek in on any of those communities and you'll be hard-pressed to find the caliber of technical skill required to engineer actual exploits. Hell, if it's not in (1) click this, (2) copy exactly this text, (3) ... form then you still see people bricking their hardware.
Remove the necessity of an exploit for running the interesting use cases (even an "Hardware will be opened up after 1 year of sales" promise as suggested), and suddenly the actually talented people are doing more interesting things than trying to assault your security model.
> Peek in on any of those communities and you'll be hard-pressed to find the caliber of technical skill required to engineer actual exploits.
I am curious: so who, in your opinion, has been making all the CFWs for Xbox, Xbox 360, PS3, PSP, Vita, 3DS etc? Who made modchips, dongles and flashcarts for other systems? Who cracks PC releases? Space aliens? People eager to run Linux inside Call of Duty? People who need to run their website off a 3DS?
Most piracy users are dumb kids but it does not mean all people in the scene are. You only need one person to exploit the system and then the whole world can just copy the method.
>Remove the necessity of an exploit for running the interesting use cases (even an "Hardware will be opened up after 1 year of sales" promise as suggested), and suddenly the actually talented people are doing more interesting things than trying to assault your security model.
Why should anyone believe this? Do you have anything to support this claim? Here is an idea: if you are really running systems with enabled guest accounts as you implied - tell the board where they could be found. I am sure nothing bad is going to happen :)
I told you I felt like a properly implemented OS validation/segregation model on custom hardware wasn't analogous to a guest account in terms of STO. You evidently feel differently, but haven't offered your reasoning. I'd be interested to hear it if you disagree that strongly.
As for piracy, the majority of the dongles, modchips, flashcarts, etc I've seen tend to be "take an existing POC exploit, package it up, put a logo and snazzy name on it, and try to make a quick buck off of someone else's work." See: https://m.youtube.com/watch?v=C4lJEOEd-_g&t=1m42s .
That seems like a biased presentation, but statistically speaking I feel like "most of those who can technically originate hacks have better things to do with their time than enable game piracy" is a pretty strong statement. Sure some will focus on that, and kudos to them for pursuing their dream. But if you enable interesting use cases by default then there are that many fewer people trying to break the security system to do something that could have been allowed in the first place.
Admittedly, I could be off base, so I'd be interested in any numbers or links you can offer in terms of piracy-first groups pioneering console hacks.
As for piracy, I don't get your point. While I agree that most pirates do not discover exploits themselves, somebody had to do it first. You cannot copy something that does not exists. And, seeing how most CFWs do not run Linux, I ask again, who in your opinion developed the original exploits? I get it that most people copy them. Who wrote the original ones?
>That seems like a biased presentation, but statistically speaking I feel like "most of those who can technically originate hacks have better things to do with their time than enable game piracy" is a pretty strong statement.
I agree that most people capable of cracking a game console do not care about it in the first place. However, most people in console scene only care about piracy. Take a look on http://psx-scene.com/ for example. See many Linux enthusiasts swapping tips on configuring their distros? People do not spend years cracking consoles because they desperately need to run Linux but have no hardware available.
The fact that there exists other, less or more secure, operating system is not a question here. It's just the relationship between, say, EA FIFA 17 legal team and Microsoft game distribution team.
With current generation consoles, piracy has so far been impossible. Perhaps in the future this won't be the case, but currently every purchase is legit. I can't see any scenario where going from 0 piracy to who knows how much piracy would be rational
Its also rational if it allows them to move away from custom designs entirely, and save a truckload of money, more than they lose to the nebulous spectre of "piracy".
People usually cite narrow cases where an AAA game succeeds in spite of lacking DRM as if piracy helped, or games that didn't spend anything on marketing and get big through marketing, which is an exceedingly rare lottery to win.
No one ever cites games like Crysis 3 which had been pirated more times than it ever sold days before release
The major boost in sales was improving the sales process (Steam and similar stores) and dropping prices, not attacking legitimate users with DRM rootkits. People keep repeating this DRM suppor mantra when up until now there STILL hasn't been any good proof that it does any good. If anything, it only damaged sales due to people not buying games that randomly stop working when internet fails.
Piracy will obviously cause some non-zero number of people not to buy games because it turns a games cost from a price, to a suggested donation.
"I'll pay if I like it" isn't the profit model a publisher who puts out a multimillion dollar game wants to support.
Not to mention, paying for something can be a great motivator. It's a lot easier to dismiss a a game saying "I wouldn't have wanted to pay for this" at the slightest flaw when you haven't paid for it.
But today, you can do it with a few clicks, so if someone really wants to play a game because it looks cool/interesting/whatever, I'd say a lot of people will just pay for it if they can't find the crack.
1) Developing a second SKU is expensive.
2) It seems that much of the PS4 hacking has been enabled by the minimal "open" surface provided by simply having a browser available on the PS4. The protections of an "open" SKU would likely be a roadbump.
3) Piracy is not the only problem. Hacking undermines multiplayer competition, the value of leaderboards, achievements, ...
Frankly, the cheapest option to solve all these problems would be to simply bundle an extra PC to make your "open variant". But of the question is: Why would they? What's the profit in it?
They're just locked behind the dev kit licensing costs and NDAs.
But yes, theoretically, "anyone" can buy a devkit and have access to the full architecture of PS4/X1 is they want to.
At the time, PS4's tooling seemed much more polished/complete/reliable - I only needed to resort to the command line interfaces for integrating with our existing custom tooling, and CI processes, exactly as you'd hope. The APIs were mostly solid, retro, C style APIs - with sane error handling, few edge cases, and no callback hell.
I'm sure the XB1 has caught up somewhat in the tooling department at this point. Also, you may already support D3D11, and get to reuse a lot of code there. Not so much reuse with other WinRT APIs (for Win8/10 apps) although the APIs feel very similar.
Manmal seemed to be positing some kind of mass access semi-open SKU that didn't completely defeat the purpose of having a closed SKU in the first place. I'd argue that mass access to devkits would defeat the purpose of having a closed SKU in the first place.
I suppose you could argue I should've said "developing a third SKU is expensive", though.
At the very least, it makes it possible to not lose sales at launch, which is when most of the money is made iirc.
Pretty interesting.
Are you saying piracy has an impact that isn't economic in nature? If so can you clarify?
Manufacturers who enable both in some form see less hacking done on their consoles. Of course, hacking with piracy as the main goal always gets done, but at a much slower rate.
Also, these days the 'reusing hardware' part is not as important as it used to be. It used to be a big deal to repurpose a cheapo device for some other function because it was the only way to do it for cheap. However, these days everyone has access to very cheap and quite open platforms in both portable (Android cellphones) and home (Raspberry Pi) format.
So the main angle for homebrew functions these days seem to be adding multimedia/internet functionality to devices that have those limited in some way. One example is that everyone wants Kodi on their consoles for ease of use, so much that people resort to plugging ARM HDMI sticks that run Kodi into their XboxONE's hdmi-in port for ease of switching into the media player app.
So, all a producer needs to do to significantly lower the number of people motivated to hack their console is 1) have Kodi installed on it 2) have a decent browser installed on it 3) not needlessly inconvenience people who want to play a game from a different country 4) have some way of running simple homebrew in sandboxed environment.
And without a locked down client, these things run rampant, and can very frequently ruin a game.
Keeping the system locked and having it balk at every modification makes it much easier to control that.
I was not much of a gamer in 1983 but I believe on-line gaming and cheating was not a significant issue at the time. Nintendo first moved to lock its system and take control over the content due to quality concerns.
And while I do love my PC for gaming, it definitely feels more and more like an afterthought these past couple of years.
Whenever people complain that the UI for AAA games like, for example, Skyrim, is designed with a controller in mind and not a keyboard & mouse, I just point out that Skyrim sold 10 times more copies for console than it did for PC.
If you want "PC master race" games, you gotta start selling games on that platform. Right now, it's a tiny fraction. (With a few exceptions, like Civilization games.)
http://www.pcr-online.biz/news/read/pc-games-have-surpassed-...
Grand Theft Auto for PC at 4K, while requiring a helluva graphics card, blows away consoles. To be honest any game I've played on a PC has been a better experience (with the exception of racing games and some side scrollers which benefit from an input device not being a keyboard or mouse).
Admittedly, on PC, there's probably hundreds of great games for each bad port, but it seems to happen more and more. Maybe I'm conflating it with the rise of botched releases in general.
And yes, GTA4 is one heck of a PC port.
Would you consider a PC as an 'open' console for this context? If not, what would differ?
It didn't work out well for them.
It's true that it might have been due to other issues, but right now, the console industry have a very public, well covered by the press console, that has tried to be open from the start and that failed in a spectacular manner and is now a joke.
Open consoles aren't doomed just because they're open. OUYA was just a super underpowered system bundled with a crappy homebrewed controller.
They could have made a tiny Android board bundled with a PS4 controller. They could've shipped it in a no-frills box. They could've used some of that Kickstarter money to start a development fund, to help kickstart games on their console.
Instead, you get a crappy controller in a fancy box, and there are basically no interesting games you can play with your new device.
Try installing Windows 7 or Linux on a newer HP laptop with UEFI. Those pricks also encrypt their BIOSes, make them non-downgradeable, and disable features for no real reason (locking RAM speed to 1333 MHz on Sandy Bridge comes to mind).
I love Amigas, but they're not exactly a stellar endorsement of that model.
PS4s just have a regular old AMD x86/64 chip in them ... plus all that other garbage he described in the talk. With all the hacks it takes to get Linux to even boot, I'm pretty sure it's not worth the cost compared to just buying a real x86/64 PC based server.
So what's more insane, the PS4 or the hacked together manufacture kernels and binary blobs on Android phones?
arm soc southbridge also not a surprise, xbox one has something similar. enables the console's rest mode to be "smart"
I know the xBox one hard drives are removable. Are PS4s the same way? (I haven't owned either; more a PC gamer). Maybe with their device hacks, USB was easier to plug-n-play than SATA?
Sony even gives out instructions on how to do it: https://support.us.playstation.com/articles/en_US/KC_Article...
1) There's only one SATA port on the southbridge.
2) USB-SATA chips are cheaper than SATA port multiplier chips.
3) They needed a USB hub anyway for other stuff.
Many ARM kernels from Android manufactures are so terribly put together than when they do eventually release the source, they're so full of holes they would never be accepted upstream.
On the bright side, the Air Force made a really nice PS3 cluster.
http://phys.org/news/2010-12-air-playstation-3s-supercompute...
Integration and Development of the 500 TFLOPS Heterogeneous Cluster (Condor) [0]
Another release article that includes more information: http://www.zdnet.com/article/what-the-dods-playstation-power...
Did Sony/IBM every actually release viable/affordable Cell hardware outside of the PS3, or is Cell pretty much dead now?
ARM chips took the many-independent-cores end of the market, GPUs took the wide-SIMD end, and may history show that the Cell approach was a failure.
So now I have this awesome machine that should be running something actually interesting. I could care less about pirating games.
My understanding is the BSDs have a reputation for being more secure than Linux. Is this not the case?
Slow clap