Root keys for Sony’s PlayStation 3 go public
geohot.com
geohot.com
I would take the mans word and hire him. I'd even through Apple into his list, he did after all release jailbreaks for the iPhone too.
It's the phone manufacturers that have to use cryptography to prevent you from actually enjoying a device you just paid them $600 for, since they can't legally kill you if you do something they don't like.
On the other hand, there are any number of independent security assessment/pen testing firms that would love to have this guy's skills. He might even end up working on consoles. That's probably the way he should approach it.
A chain of command that's savvy enough to really want him despite that is one you'd actually want to be in, though. An organization that focused on results would be all edge like the fictional Maas Neotek from Gibson's Neuromancer.
Absolutely. But if they were the savvy type, would they have been pwned at nearly every security layer like that? If you haven't seen it, the video says it better than I can.
So probably if he were hired, it would be with mixed feelings of some of his uppers. At best, he probably "wouldn't fit in with the team" as they say. Someone like him would need to be either in charge of the whole freaking platform direction, or not there at all. (now there's an idea) Seriously, IMHO Sony's best move would be to fire the guy responsible for reneging on Linux and hire someone with a clue instead. Microsoft would have the guts do something like that.
It's ridiculous. I bought a PS3 (by coincidence) the other day. Guess what?! It doesn't play PS2 games! PS2 plays PS1 games (so I thought). Our Wii plays GameCube games. Xbox360 plays Xbox games. What is a PS3 if not a PlayStation? I didn't have my heart set on it anyway, but the kids tracked down some PS2 games they wanted. They specifically wanted the older PS2 versions because they didn't like the PS3 versions!
In fairness, Gran Turismo 5 and Little Big Planet are beautiful and fun games and they have only crashed a few times.
Congrats Sony, you thought you'd force your customers to repurchase their favorite games didn't you? Instead you made enemies of an upcoming generation of gamers.
If only they could have heard the tears of the small children on Christmas morning upon finding out that they would not, in fact, be able to use the dance pad and the older Dance Dance Revolution which had the actual anime songs that they had saved their allowance to buy and they would only be able to dance to Lady Gaga instead...
(that's only slightly an exaggeration)
If you really want to play PS2 games, buy a used PS2 on Craigslist for a fraction of the cost of a PS3. Heck, you can still get them new.
Then they ought to stop selling it as a "PlayStation 3" once it no longer performs the functions of a "PlayStation 3". Call it a "Playstation 3--" or something.
Product model names invoke the very definition of what the product is and does, particularly when the name includes a number. They aren't just attractive words to be chosen by Marketing, even when it was the same company that made the initial definition of the feature set in the first place.
Like I said, it wasn't particularly frustrating or surprising to me to find this out after I bought it, but only because my expectations of a Sony product were so low to begin with. I would have been shocked if this had been Google though.
True. If I were him, I'd try working at Apple. Also, "they" are not monolithic. It's quite possible that the parties they beat would not be in his chain of command. One would have to do some diligent research before taking that job. It might well be worth it, however.
Getting to the point, the PS3's with the PS2 core were dropped not long after release due to their high cost. I understand your frustration, but it's becoming increasingly important to do research and understand each system's capabilities before putting your dollars down... the 360 is no exception here either.
I am happy for you. I think you have not worked anywhere really bad. Look at what what you are missing out on: http://www.google.com/search?q=vindictive+employer
Actually, I didn't think this was about GeoHot, but one of the guys presenting at CCC.
Though talk about a comeback... This is a much better online "hire me" than the ones that were popular on HN several months ago.
This is not unlike his behavior that got him rejected in the iPhone scene. I am actually a bit surprised that there are so many comments here praising him.
Hiring the fail0verflow guys, on the other hand, would be a good move.
There is a reason that he never releases technical details and just comes out of nowhere.
The only reason that he was able to do anything with his dump was because of all of fail0verflow's work. See the twitter feed of marcan42 for clarification.
Actually, since the beginning, geohot's ps3 trick was just him copying what fail0verflow had done on the wii (glitching the address bus). He didn't give them credit for that either.
I will agree though that what geohot did and the what Team Twiizers (as they were calle back in the day) are quite similar.
As I understand it, all that was required was for them to use the same random number /twice/. Let's say you're Sony and you sign a patch, release it, realise there is a minor fix, and release within 2hours... maybe in your rush you failed to regenerate the random seed?
Or, my initial thoughts, someone inside Sony did this maliciously?
From what I understand, they use the same number every single time without exception.
EDIT: that last bit about banks is OT, sorry about that, I've been watching the chip and pin hacking talk from CCC and got confused.
I find it most likely that the build process code was flawed. This sort of code is, in my experience, not written by your most talented developer (unless one of your top developers has a build fetish). All too often you only find deficiencies in the build/release process the month of release, when you have the least time to fix them.
If a developer has ever even thought about generating a list of 1000 random numbers to pick from at a later date, then they shouldn't be developing production code.
But sadly, I have to agree, this is epic fail.
In any case, this risk is orders of magnitude lower than the risk of someone leaking your list of past numbers, especially when they're this valuable.
That way, you can't even accidentally reuse a seed in development, or leak that list of the previously used seeds. When something compromises the system, and you don't need it any more, it should be destroyed.
Or, my initial thoughts, someone inside Sony did this maliciously?
As always, the human factor is the real weakness. (Key management by users and coders.) There are similar problems with RSA signatures on related numbers or selecting keys for IDEA block cipher and RC4 stream cipher, just to name a few. If you use crypto tools incorrectly, you actually put yourself in a somewhat weaker position than if you hadn't even tried. What you've essentially done is create "security theater" for the bad guys to dupe the unsuspecting with.
(Bonus points if you get the reference: https://secure.wikimedia.org/wikipedia/en/wiki/Feynman_point)
Part 2 - http://www.youtube.com/watch?v=ovy2kPFOu0E
Part 3 - http://www.youtube.com/watch?v=Y23LUiBRcOg
That talk was at the 2010 Chaos Communication Congress which just concluded a few days ago.
The talk covers the motivations of hackers, as well as the vulnerabilities they found.
The new exploit starts toward the bottom, on the slide that just says "ECDSA" in big letters.
It might be worth waiting until the official recording gets released at http://mirror.fem-net.de/CCC/27C3/mp4-h264-HQ/ (named "Console Hacking 2010").
Obviously other ways would probably eventually be found but as these guys say, just providing a way for people to run their own code to begin with takes a lot of effort behind people hacking the system. There will always be an army of people out there wanting to pirate games and an army of people wanting to profit off of it but only a tiny amount of them can really do anything about it.
Sometimes absence of evidence really is evidence of absence. Sometimes it's just that nobody was really looking that hard.
Their presentation makes a good case that real hackers really do just want to run their own code and that the 'piracy' bugaboo is something else entirely.
When I was little, I thought Sony was the coolest company ever. They made high-quality reasonably priced HiFi gear. Now my small children have made Sony the laughing stock of the household. Between this Linux debacle and the Windows rootkit, Sony has shown itself to have a habit of shooting its customers in the foot my opinion. No other company has fallen so low in my view.
Seems from watching the videos that they could go a long way on a future console to prevent hacks just by plugging these issues.
Naah. Every major security layer they had in place was broken or ineffective. That's usually a sign of deeper problems in the development process.
IBM probably wrote the hypervisor layer for them. IBM discontinued development on the Cell processor a few years back. It's likely nobody really understands that system at this point better than the hackers.
That, plus the serious problems they had at the launch of the PS3 Fat might indicate that a lot of know-how has leaked out of their organization and moved onto better things.
The PS3 itself is still not a good example of holding up against piracy until the hackers that wanted to run linux worked on it. It was first broken for the reasons of piracy (PSJailbreak) and was not done by the homebrew scene. Actually, all of their work required and is based on already having code running on the PS3 using the pirate method.
So, what exactly is left to support the opinion that the homebrew people are smart, the piracy people are dumb, and if you do not support linux the homebrew people will make it work with the side effect of allowing piracy? In every instance it is piracy that was first. You can also look to the DVD/HDDVD/BluRay scene and see that the piracy people were ahead of the 'make it play on linux' crowd and quite capable.
And don't put words into the mouth of the PSJailbreak authors. The PSJailbreak allows unsigned code to run, that is why they made it first and foremost (they need unsigned code for piracy), they saw that they can get piracy and went for it. Anything to drive the sales, right? And we still don't know who's behind PSJailbreak, and if they are or aren't in the 'homebrew scene'.
What 'pirate method'?
'DVD/HDDVD/BluRay scene' we're comparing consoles to media now? Get your act together.
The pirate method I was referring to is the USB descriptor buffer overrun.
The technological measures protecting HDDVDs and BluRay are as tough as any used by the gaming consoles. Even still, SlySoft in particular manages to deal with new hurdles faster than the rest of doom9.
PS3: OtherOS allowed unsigned code, way before piracy. Wii: Team Twiizers, who are strongly anti-piracy, were the first to run unsigned code. This was later abused for piracy, but only after Nintendo refused to work with them to fix the issue. Xbox 360: Don't know much about this. You might be right here.
Drivechips aren't "hacking" in any way comparable to what fail0verflow, Team Twiizers, or any other group accomplished.
http://www.eurogamer.net/articles/digitalfoundry-ps3-securit...
The hypervisor is minimal in terms of overhead. The biggest impact comes from the fact that the PPC core in the PS3 doesn't do out-of-order execution. You'd be downright amazed how huge a difference this makes.
However, nothing under OtherOS used the SPEs really, and it had no access to the GPU, so the speed came down to the in-order PPC core.
My understanding is that for the prevalent workloads presented by most games, out-of-order execution's benefits don't outweigh its costs in chip complexity/size/power consumption/heat/etc.