PS3 re-secured with Firmware 3.60?
Hacker says "epic fail" security holes now fixed.
A leading PlayStation 3 hacker says that today's firmware 3.60 update re-secures the system from hackers and by extension, should lock out piracy.
Youness Alaoui (hacker alias: KaKaRoToKS) knows what he's talking about. He developed PSFreedom - an open source Jailbreak alternative, and devised the PL3 payload for the USB dongles that attacked the PS3's security system on firmware 3.41 and lower.
According to his swift analysis of the new system update posted on his Twitter feed, Sony has come up with an ingenious method of side-stepping its existing security protocols:
"For now, it looks to me (at first glance) that the PS3 has been re-secured, but it doesn't mean it can't be broken again from scratch," he says, qualifying his findings by adding that he didn't spend more than a couple of minutes looking at the new update.
The PS3's existing security system is based on a "chain of trust" - different layers of the console are protected by individual levels of encryption, one opening up access to the next. This chain of trust was annihilated when Geohot revealed the "mtldr" key, the root decryption cipher that can unlock all of the others.
According to Alaoui's quick analysis, Sony simply doesn't use mtldr any more, opting for a new security system that could possibly require a completely new exploit to be uncovered - something hackers would be unlikely to take on bearing in mind the legal blitzkrieg Sony has unleashed in recent weeks.
"The epic fail was epic," Alaoui says. "It doesn't mean they can't come [up] with an epic save."
You may also like...
-
Gravity Rush Review 48
-
Sony patents method to interrupt your gaming with an ad 107
-
Wii U Aliens: Colonial Marines is best-looking version because of console's "more modern tech" 74
-
Kingdoms of Amalur: Reckoning needed to sell 3 million to break even 65
-
Activision vs. Vince Zampella and Jason West: Inside the game industry trial of the decade 70
-
Skyrim gets mounted combat in new update 53
-
Arma 3 in-engine footage shows off lighting tech 18
-
App of the Day: Go Robo! 2
-
Ghost Recon: Future Soldier Review 132
-
Dirt Showdown Review 89
-
Minecraft overtakes Black Ops on XBL activity chart 25
-
Minecraft total sales hit 9.2 million 8
-
FIFA has a new world champion 8
-
How the Darksiders 2 delay benefits you 9
-
Tony Hawk's Pro Skater HD soundtrack listing revealed 18
Comments (72) Latest comment 1 year ago
Comments for this article are now closed, but please feel free to continue chatting on the forum!
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
No doubt over the next few days/weeks/months stories will crop up on how hackers have re-hacked the system but thats life. I dare say it wont be a simple process either which will shut out all but the more "hardcore" hackers out their.
Regardless id like to applaud sony for the fightback, its been a tough few months but iv liked the way they have conducted the fight against hackers.
Comment below viewing threshold Show
That comment was epic win!
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
What Sony really need is to convincingly win the Geohot court case to make an example of him such that he's bankrupted and/or receives a prohibitive sentence to effectively deter (for as long as is possible) anyone else distributing tools that compromise the console until it's nearing the end of its lifecycle.
Comment below viewing threshold Show
These hackers really are 14 year olds.
Comment below viewing threshold Show
Comment below viewing threshold Show
There was a US pay TV company who's decoder boxes had been hacked so that people could use counterfeit access cards. Over a period of months the company issued updates that made minor changes, each update also contained a small chunk of garbled text as padding, so that the update was always the same size. After a number of these updates, there was one final update that decoded all of the garbled text into executable code that re-secured the decoder. They also programmed it to show a message on screen when a counterfeit card was used - "The free show is over"
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Or to bring in the first analogy (and the only one we'll need here) they changed the lock on the door.
Comment below viewing threshold Show
Comment below viewing threshold Show
Only a bit of fun, but loads of website forums have picked up on this....
Comment below viewing threshold Show
So how are you qualifying that statement? That's right, you're using a Eurogamer article. Furthermore, you're using a comment from a hacker who admittedly spent "a couple of minutes" with the update. Well done.
Comment below viewing threshold Show
Comment below viewing threshold Show
Went to download the Motorstorm demo last night.
I couldn't, PSN down for maintenance.
Remind me again why I have this big black box in the corner of my room.
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
10/03/11 @ 09:38
ignore poster | #19
0
"Great. Another update when I next turn my PS3 on.
Went to download the Motorstorm demo last night.
I couldn't, PSN down for maintenance.
Remind me again why I have this big black box in the corner of my room."
Tbf dude, maintenance happens on live too, so not like u getting away from it , unless u go pc gaming ( not pc gamer so can't verify this) , but surely even then if gme servers go down, and they do, there will be frustration there too.
Comment below viewing threshold Show
Does it sing when you touch its teeth?
Comment below viewing threshold Show
stop whining. do you pay for your PSN service? probably not i think.
if it means that my PS3 is safe from idiots who think it's "fun" to ruin
everyone else's online experience, then i'm more than happy to have
an update every now and then.
Comment below viewing threshold Show
i ve grown tired of wankers claiming victories and using verbal fireworks of their illegal actions.
there may be a key for every lock but not every door should be opened by anyone right?
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
do that and it's game set and match.
Any further hacking work is clearly just for piracy and therefore the whole of the gaming comunity will back sony in further legal battles
And people get to use their PS3's and fully fuctioning media centres in their living room
win F'ing Win !
Comment below viewing threshold Show
You are just so uncool. Bankrupt? WTF.
Comment below viewing threshold Show
Further along they could even implement anti-hacking checks within games themselves so that games require a PSN signon and implement various surreptitious checks that cripple the game or make it fail in non-obvious ways on modded firmware.
Comment below viewing threshold Show
Problem is, a large percentage of PS3 users aren't online. So you need to put the updates on the game discs too. And once you do that, they're accessible.
Comment below viewing threshold Show
..and it's such a shame we have lost another tosser to deal with on PSN.
Comment below viewing threshold Show
The irony is that every time someone mentions zombies/ninjas/pirates I feel the same way!
Comment below viewing threshold Show
I will just stay on 3.55 and carry on using it however i want. Never even accepted the PSN new TOC and can still access it.
Comment below viewing threshold Show
Comment below viewing threshold Show
@randompanda: FAIL
Comment below viewing threshold Show
Comment below viewing threshold Show
But the key thing is, the hackers believe in opening closed systems, which I think is all well and good, but they know full well what the repercussions are, and where the majority of the use of their tools and utilities will be. To claim that the internet means they cannot be stopped doesn't help them, and for them to believe they can act with impunity and that their stand is beyond reproach is frankly naive, particularly in the US where litigation can be dropped on someone in the blink of an eye for trivial things.
If the hackers had found a way to completely replace the PS3 OS, rather than augment it with unauthorised code, then I doubt this case would have any merit and I doubt that Sony would've even bothered about it.
They really should've known that someone would have come after them sooner or later, and be dragging around a cackle of lawyers behind them, when they did so.
Comment below viewing threshold Show
The official forums suggestions list has loads of great ideas for new features, now would be a great time to start implementing some of them.
Comment below viewing threshold Show
"Every time someone uses the term 'epic fail' a little bit of me wishes for a zombie apocalypse just to purge the human race a bit."
As long as I stay alive, that's fine with me
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
edit - sorry 3.60. Arf.
Comment below viewing threshold Show
However, the hacking community has spent years of what now appears to be entirely wasted effort, doing little more than incur the wrath of an enormous litigation-hungry corporation.
If such puerile phrases as "epic fail" must be used at all, they are far more suitably aimed in the direction of the hackers who could've spent all their wasted time and energy actually enjoying consoles for their intended purpose.
Good on you Sony!
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
It worked
Comment below viewing threshold Show
I'm just trying to work out whether to leave this until after midnight when my unlimited download limit kicks in.
Comment below viewing threshold Show
Dunno why
Comment below viewing threshold Show
Are people who use 3.55 and spoofer still able to go on mw2 and use hacks like previously??
Does this basically only really affect new consoles and those who update by choice??
Sorry for being thick lol
Comment below viewing threshold Show
So I guess the already open consoles won't update and find a way round it and stay open, by all means this stops it going mass market as such.
Edit:
Seriously who marked me down, thought it was a decent point.
Comment below viewing threshold Show
Comment below viewing threshold Show
so hacker fest still going to be going down in mw2 etc I'm guessing then.??
Comment below viewing threshold Show
I don't see the point in cheating on games online, where is the fun?
Comment below viewing threshold Show
in i understandcorrect the way the mw2 hack work, this OFW update wont fix it.
the MW2 hack already done <strong>before</strong> the advent of CFW
Comment below viewing threshold Show
May as well not play the game.
Comment below viewing threshold Show
Given Sony's near-negligible profitability per unit sale, I doubt they'll be crying in their sleep.
Developers, however, will be happier. And since they're the people who provide us with our games...
Comment below viewing threshold Show
Epic Fail is not security that took 4+ years to break. (PS3)
Epic Fail IS 3DS security that was broken withing minutes of release.
Get some fucking perspective.
Comment below viewing threshold Show
Comment below viewing threshold Show
how is that anything useful to Sony? people who have already hacked wont ever update anyways?
Comment below viewing threshold Show
Its useful for on reason, currently you buy a console new it starts at 3.30 firmware, i guaranteed that any new console start with minimum 3.56
Also games now are needing 3.56 watch that change also. Sony dont game about the people who have chosen not to update its the potential new buyers who they care about
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
Comment below viewing threshold Show
post 1. No. There still is a difference between hacking and pirating. Even if most people don't want to see it.
post 2. No. These games will be cracked (to use the correct terminology) or misguided by bogus FW and will still be offered on-line.
Comment below viewing threshold Show
On PC I could easily find cracked/pirated software but I dont do it. But my primary reason for NOT doing it is not that its morally wrong. Its that I dont have time to weed out all the crap. And I think that the amount of low-quality software is the major problem behind lack of sales and not so much piracy. I have in a few cases actually downloaded a cracked version of a game i BOUGHT just to avoid the hassle of the piracy-protection they put in. If that isnt a sign that something needs fixing I dont know what is.
Make decent quality games and if they are new IPs back them up with a resonable amount of advertising (and dont waste money advertising for the new FIFAs and NHLs, people are gonna buy them anyway). And maybe consider lowering the price because I am sure there are people that would buy more if they could afford it. Apples App-store seems to be a good example of how many potential customers there are for lower priced games (but I bet the rate-of-crap-to-good-stuff is even worse there so thats another problem).
I think Sony should just stop spending enormous amounts of money making things less accessible and instead "locking" out pirates by charging a fee to use PSN...oh wait they started that already didnt they?
Its a case of "you get what you pay for" but the other important side of it is "you pay for what you feel you get".
Comment below viewing threshold Show
It's good news anyway.
Comment below viewing threshold Show
Comment below viewing threshold Show
[link url=http://psx-scene.com/forums/f6/mathieulh-jailbreaks-3-60-a-83423/
]http://psx-scene.com/forums/f6/mathieulh...[/link]
analysis how what they do?
and how what sony can do to fix it?
Comment below viewing threshold Show
so they will still be able to do what they are doing, so the main problem has not been fixed, only changed for future consoles. if the hackers can spoof fw numbers then the new games will think their consoles are running said newest version and run as normal wont they?
Comment below viewing threshold Show
Comment below viewing threshold Show