Interesting to see that one of the most impactful exploits is in an open source library.
Interesting to see that one of the most impactful exploits is in an open source library.
> With these vulnerabilities, it is possible to ship pirated games on bluray discs. That is possible even without a kernel exploit as we have JIT capabilities.
So this person basically saved them from loosing tons of money (if you accept these companies claim that pirating games actually make them lose money in the first place) and they only awarded them $20K.
Good way to ensure others who find similar exploits to sell them to highest bidder on darkmarkets instead as they'll be able to get way more than that.
You can be very sure that if a piracy case went to court, Sony would claim to suffer billions in damages.
https://torrentfreak.com/gary-bowser-agrees-to-pay-10-millio...
IANAL, but I think you have to keep the scope of the damages in consideration.
It is not like PS5 owners are going to be upset for having a straightforward way to run games -- e.g. make their own Blu-ray copies etc.
Edit: To clarify: that this is valued for/by Sony at only 20k is beyond me. But absolutely that valuation should be admissible in court in my opinion. On the other hand, this number tells me to never submit a bug bounty for the money -- at least to some companies. It is simply not worth most of the time/most of the contexts. Write a paper/publication of some short and use it to get a good job that pays you salaried for more -- if you have already one just publish them immediately with a ping to the sec team. If they want to fix these fine, otherwise... they can pre-pay you to report them to them under contract for a good amount of money.
I don’t understand why there isn’t an industry of selling pirate copies of official games. What I mean is buying an official copy of the game, “image” the disc, and press 1:1 copies for cost + a couple dollars.
Why didn’t that happen? Are there technical issues preventing this from working? I can’t think it’s a matter of cost, BRD can’t cost that much to make at scale.
You don’t have to do research on any given platform. If you don’t like the terms of their bounty, find something else to play with. If you are skilled enough to find something like this you will have no problem finding very highly paid jobs.
1 in 5 have different variations of devils horns on the characters heads. 3 in 5 look like they've been cropped from communist murals around my city. Almost all of the characters look angry and criminal.
Browse these avatars and in your mind compare them to Nintendos. The vast majority of users are interacting with each other and seeing these creepy avatars as they're friends virtual faces. What effect is this having on young kids?
An example, if you find a bag of cash, typical finders fee is 10%. Insurance companies, others, often offer this.
Meanwhile, Sony is kicking maybe .01% "cash saved" for this vulnerability.
Wrong website.
It’s selling bugs in customer hardware that can used to reduce control of the manufacturer of it and allow users to run pirated stuff (and homebrew likely as a result). It’s totally in the best interest of the manufacturer to always be the highest bidder.
I don’t have any moral issues with people selling those issues on the black market, if manufacturer isn’t interested in rewarding researcher properly.
I understand that nobody has to do the research of any sort but my point is that these skills and effort involved are being commoditised very quickly and become comparable to gig economy. Bounty programmes are very very cheap to large corps, compared to the returns involved. Building a substantial infosec division that could match the crowdsourced model is way more expensive.
Try not to regard things in such an all-or-nothing perspective. At worst it indicates a psychological disorder, at best—a high conflict personality. Either way, it wont benefit you or the people that interact with you.
I also disagree that it ‘completely’ lacks morals. If OP is being truthful, then he has a desire to work hard and put in the time necessary to fulfill a virtuous (albeit under-compensated) calling.
However, OP is also cognizant of a hypothetical (albeit realistic) temptation that will most likely confront him, should he carry out these pursuits: ethical conflicts which would force him to choose between large financial gains (selling exploits to bad actors), or the less lucrative (and often thankless) white hat approach of reporting it in good faith, and expecting (but not necessarily receiving) equal measures of good faith from corporations (like Sony in this case).
Having an awareness of one’s own weaknesses or susceptibilities to temptation isn’t a weakness to be admonished from atop a digital soap box. Instead, recognize and reinforce OPs desire to do good—it costs little more energy to encourage the good in people, rather than shaming them for not having an unshakable moral fortitude. Have a Happy Father’s Day.
One of note: the "criminals" in this context are, at best, homebrew developers and users who'd like to unlock the full potential of the hardware they bought. At worst, they're "pirates" (the industry term, not mine) and game cheats. Nobody likes a cheater in a video game, but I don't know if I'd go as far as to make ethical prescriptions about it.
Sony feels comfortable paying a pittance for these vulnerabilities because the market for them is relatively soft. But that doesn't mean that the underlying asset actually lacks value; it means that Sony has successfully criminalized applications of the asset, artificially lowering their salability.
Your position affords you a unique opportunity to have some perspective here.
It's not that straightforward (even if I wish it was).
First, it requires a judge and jury who understand "interoperability" to include "connecting to a server you don't own and sending it payloads that it isn't expecting."
Second, it requires a lenient interpretation of EULAs under the DMCA: the DMCA promotes otherwise legal reverse engineering activities into illegal activities by allowing companies to establish "acceptable use," which can include prohibiting reverse engineering activities that circumvent restrictions on copyrighted or other controlled material. A bank may plausibly (in the eyes of attorneys) claim that third-party uses of its APIs compromise the bank's ability to comply with federal regulations, since no law requires that compliance and operation be integral operations.
ianal etc.
Reverse engineering would also be a copyright infringement issue, which does have a carve out for reverse engineering.
Its literally only the corporation beneficiaries of having their own product fixed that are paying the wrong amount. Inching up the payout amounts ever so slowly.
Anything that makes those corporations pay out better is also a moral outcome, and doing things that supports this status quo lacks ethics as well.
(We actually agree that selling to some bidders, and some actions, lack ethics)
But what hasn't worked and will continue to not work is using social moral condemnation. I think we all find "you wouldn't download a car" funny, right? Worse for this situation is the context of the growing economic divide worldwide in 2022. Under that lens I wouldn't be surprised to see this happening more. The more oligarchies show individuals that they don't care, why should individuals show they care about the oligarchies?
That Sony is not the criminal here is a reflection of our inadequate laws, not morals, and selling vulnerabilities to them is just as bad.
If I find a high tier vuln and the company isn't giving reasonable bounties, it's going straight onto Zerodium or similar platforms and I won't lose a second of sleep over it.
Nah, copyright is immoral, bypassing it is the morally right thing to do.
When I worked with someone who was a point of contact for outside security researchers it seemed for many were just happy to get their name in the release notes.
And I’m not sure if you’re selling that you’re a white hat researcher anymore…
>Good way to ensure others who find similar exploits to sell them to highest bidder on darkmarkets instead as they'll be able to get way more than that.
Sure, sell it for how much? twice? thrice? as much
instead using it for your own branding, cv, to negotiate salary which will pay you way more over years
> With these vulnerabilities, it is possible to ship pirated games on bluray discs
This is illegal AFAIK.
This isn't always the case. On the Switch for example you can very easily bypass system version checks.
Compare this to the DS and DSI where piracy carts were sold at retail stores and had zero downsides and were widely popular.
It's also worth mentioning that vulnerable consoles were sold for a relatively small window of the console's lifetime, and while patched units are still hackable to some extent its much more inconvenient. For the DS all you needed was a flash cart, regardless of anything else.
I’m not saying that’s what should have happened, but $20k for something this severe is practically asking for that to happen.
If that was a chain of 5 vulnerabilities for say the iPhone or Android, that would be worth over $1 million.
But what we got here is a way to pirate video games.
Weaponizing this vulnerability means someone can play bootleg video games. And to profit from bootlegging video games, you'd have to create manufacturing and distribution channels. Then you'd have to find people who want to buy games. That's a lot of work, and when you inevitably get caught you'll like face stiff fines (if not prison).
Is this vulnerability worth more than $20k to Sony? Yes. Is it worth more than $20k to the person who found the vulnerability? Only if they can monetize it, which would require breaking various and sundry laws.
I mean, doesn't the same restriction apply to mobile exploits? You'd be breaking some kind of law by selling the exploit off, no?
In my opinion, game piracy for latest gen consoles would be very easily monetizable. The challenge is figuring out how to make money without revealing your identity and/or basing your operations out of a more piracy-tolerant jurisdiction. Or you could sell the exploit off to someone who is willing to deal with all of this.
This is especially true with PS5 thanks to the ongoing console shortage.
I do think that the bounty is underpaid but not by that much it should probably be closer to 100k.
Especially when so many people work on sensitive work in their homes due to COVID, huge chunks of the federal government are having conversations next to hot mics as they do Tinder and the like on their "personal" devices.
What's the market for this exploit, though? Who is going to pay never mind $20k but more or less anything for it?
Possibly but who is going to pay you $20k to realize these theoretical profits? They essentially mean un-networking your console, never updating it, only using physical media, likely losing your PSN account. There's a huge leap from step 1. 'an exploit exists', step N 'lots of hacked consoles and people buying pirated discs for them' and whatever step 'PROFIT' appears in. A latent market for free or cheap stuff is not the same thing as a market for this exploit.
Everything you list there is a plus in non-wealthy countries were internet access is slow and expensive. I suspect the total sales of bootleg PS2 games greatly exceeded Sony's legit sales in the global south due to the widespread availability of "chipped" PS2 consoles.
I’m not sure many people could afford a PS5 in places such as this. And in most ‘second world’ where people have a but more money internet is generally cheap and fast especially compared so countries like US or Canada.
Why does it have to be "many"? Bootleg games have extremely high margins for the bootleggers.
That said, the PS5 is cheaper than an iPhone, and there are plenty of those. If you're bored, look up instagram pictures geolocated in the poorest cities you can think of, then count the number of recent iPhones that at least worth a new PS5. The number may surprise you.
WebKit is infested with vulnerabilities and it is a hackers paradise for exploitation. Probably the most exploited and targeted software component out there.