Download the
Tom's Guide App from the AppsStore
News and trends on internet
/ mobile / "sound & picture" / IT
Yes No

Fail0verflow Obtains PS3 Cryptography Key

- By - Source : Engadget

Fail0verflow has discovered the PlayStation 3's private cryptography key.

Wednesday during the 27th annual Chaos Communication Conference, the team behind the Wii's Homebrew Channel-- fail0verflow-- revealed that they figured out the PlayStation 3's private cryptography key. This means hackers could have full access to the console without the need for a USB device or actual software/hardware hacking.

Typically the "magic password" is used by Sony to authorize the execution of code on the gaming console. Now Sony's key is revealed, hackers can develop hack-free apps and games-- literally signing their code--to execute on the PlayStation 3 as if they're licensed developers.

"It's not an exploit, it's an Epic Fail by Sony," the team said during a live demo. "The PS3 is fine. They screwed up in HQ. They gave us their private key basically. They leave their private key mathematically, so we don't have to exploit anything, we just sign things."

According to reports, Sony didn't bother to generate random numbers to secure the key's secrecy. With that said, the fail0verflow team plans to release tools next month that will take advantage of the security flaw. However the tools aren't intended to enable PlayStation 3 piracy. Instead, they'll re-enable the installation of Linux on every unit sold no matter the firmware-- even v3.55 and beyond.

"Yes, we'll release all our tools as soon as we cleaned them up in January or so," the group said via Twitter.

To see the live demo, check out the video pasted below:

PS3 Private Key Exposed

Share:
33
Comments
X

Comments

nevertell 12/31/2010 11:29 PM
Hide
-1+

I watched the whole thing, it was hilarious actually.

Probably due to the way they presented it, though.

Blessedman 12/31/2010 11:34 PM
Hide
-0+

Hmmm can they not be held liable?

hellwig 12/31/2010 11:47 PM
Hide
-1+

Blessedman :
Hmmm can they not be held liable?


With the DMCA, simply possessing the private key can probably be considered tampering or illegal in some way. I wouldn't doubt Sony's lawyers are already working overtime getting the cease-and-desist and lawsuits ready. The same thing happened when someone cracked the DVD master key. The DVD association dried to stop the guy from posting it using all sorts of legal claims, of course, its everywhere now.

Travis Beane 01/01/2011 12:27 PM
Hide
-4+

I only play PC games now, and use my PS3 as a media centre. With Steam summer and winter sales, it's easier to just buy them.
Custom firmware on the other hand, I like. Hopefully with full GPU access.

March on men.

christop 01/01/2011 12:42 PM
Hide
-4+

will some one of Tom's delete this dude with the name dsdfsdfdsf . The Spam is getting old and I am going to have to fire up the LOIC on the linecheckout site.

jj463rd 01/01/2011 12:48 PM
Hide
-2+

christop :
will some one of Tom's delete this dude with the name dsdfsdfdsf . The Spam is getting old and I am going to have to fire up the LOIC on the linecheckout site.


Please do this the spammer websites.

vincenz0 01/01/2011 3:00 AM
Hide
-0+

wow

LordConrad 01/01/2011 4:25 AM
Hide
-0+

Does this mean Linux without Sony's Hypervisor???

servarus 01/01/2011 4:36 AM
Hide
--1+

Sometimes I feel that this stuff is more like excuses to run pirated games. Maybe the developer didn't intend to use it that way, but many others are.

FloKid 01/01/2011 4:46 AM
Hide
-0+

should they not tell sony about this? lol next firmware

slipdisc 01/01/2011 6:01 AM
Hide
-1+

FloKid :
should they not tell sony about this? lol next firmware


Thats not going to work. That would revoke the license of every current and past PS3 title. Sony might be fuct this time.

Darkk 01/01/2011 6:05 AM
Hide
--1+

This is actually good news to give us the linux capability again. However, it won't be long for Sony to update the firmware with a new key that will disable the hacks. If you really want to run linux stuff you're better off doing it on a regular PC and avoid the hassle.

Darkk 01/01/2011 6:07 AM
Hide
-0+

Darkk :
This is actually good news to give us the linux capability again. However, it won't be long for Sony to update the firmware with a new key that will disable the hacks. If you really want to run linux stuff you're better off doing it on a regular PC and avoid the hassle.



Actually this isn't entirely true. If they used the same scheme as DVDs it means they use multiple encryption keys. So if one gets broken other keys will work.

Darkk 01/01/2011 6:07 AM
Hide
-0+

Dang it..I quoted the wrong comment. Ah well...where is my edit button!!

Anonymous 01/01/2011 7:23 AM
Hide
-1+

No random number generator, it is static, so it would be trivial to calculate the new keys exactly the same way as they calculated this key. Sony screwed up!

gsxr1181 01/01/2011 8:14 AM
Hide
-2+

Hmm now I might have a reason to buy a PS3. Sweet!

chick0n 01/01/2011 9:51 AM
Hide
-2+

leak key again, its not just Sony, it happens all over the place.

I guess humans can design the most secured lock, but they always just leave the keys under the front carpet with a sign next to it that saids "No spare key underneath"

surfer1337dude 01/01/2011 11:14 AM
Hide
-0+

Im curious to what the key actually is... Also I think it would be hard for sony to just change the key, since by changing it wouldn't all the games that are currently out no longer work? Unless the games/ps3 have multiple codes and you could remove just one and still have it work; but I'm not really sure if it works that way?

This does seem like a plus for the fact that anyone could develop a game for the ps3, on the other hand some people will probably use it to try make some kind of virus... but only time will tell.

lukeeu 01/01/2011 1:50 PM
Hide
-0+

surfer1337dude :
Im curious to what the key actually is... Also I think it would be hard for sony to just change the key, since by changing it wouldn't all the games that are currently out no longer work? Unless the games/ps3 have multiple codes and you could remove just one and still have it work; but I'm not really sure if it works that way?This does seem like a plus for the fact that anyone could develop a game for the ps3, on the other hand some people will probably use it to try make some kind of virus... but only time will tell.


That's right. Changing the key would kill every game out there. However signing stuff with someone's private key is a criminal offense in most of the world so I wouldn't count on any commercial gain from this.

TeKEffect 01/01/2011 6:54 PM
Hide
-1+

Linux with a unlocked gpu. I was bitter when Sony took away Linux support so I guess they deserve this

applegetsmelaid 01/01/2011 7:06 PM
Hide
-0+

Earlier release for PS4?

Simple11 01/01/2011 8:51 PM
Hide
-0+

Not really an EPIC fail on their part. Did pretty well till now.

Anonymous 01/01/2011 10:11 PM
Hide
-2+

I've been wanting to see something as bad as this happen ever since the rootkit DRM scandal many years ago involving Sony BMG and malicious audio CDs. It just proves that treacherous computing just doesn't work.

thillntn 01/02/2011 12:49 PM
Hide
-0+

I cannot wait to see my lil penguin friends again :)

Keklian 01/02/2011 3:30 AM
Hide
-0+

Will you please install an automated spam blocker?

These ads by "sdfdsfds" and "others" (the same guy) are easily scrolled by, but they are somewhat annoying. Not to mention the shame I feel for the sorry son-of-a-b****h who writes those awkward "ads". Get a life.

bv90andy 01/02/2011 4:59 AM
Hide
-0+

What I DON'T GET is why do they still feel like locking the PS3 systems.... as far as I know they are now making a profit with each console sold, they are not losing money when selling a console, so why not just unlock it and make everybody buy one.????

invlem 01/02/2011 7:21 AM
Hide
-0+

The most exciting thing about this is the prospect of the PS3 being able to function like a TRUE media box (one that doesn't require a server to transcode unsupported formats) imagine being able to load an xbmc style interface, capable of using the entire system resources including the rsx, with full codec support for various media files!

I could see this development possibly being a bad thing for Sony, but it might actually end up being a boon to their sales depending on how the community makes use of their new access to the system.

Scott2010au 01/02/2011 9:20 AM
Hide
-0+

Sony employees verbally promised everyone, in recorded media, that Linux would be installable on the PlayStation® 3 console during its release.

In firmware updates, and modern units, they revoked this promise.

Any consumer can lean on this, the videos are on YouTube (and elsewhere). Kept highly duplicated for a reason.

mayankleoboy1 01/02/2011 10:17 AM
Hide
--1+

SONY= EPIC FAIL

BulkZerker 01/03/2011 1:33 AM
Hide
-0+

I supposed if I bitch about the spam the sights recieving we'll get another 20 "new users"...

Sony's little temper tantrum is finally biting them in the ass again. And I for one am happy as hell this is happening again. I WANT this to happen because I would REALLY LIKE to have my PS3 run double duty as a nice gaming system, and a media server.

eddieroolz 01/03/2011 3:42 AM
Hide
-0+

So I suppose this means the PS3 is finally cracked?