3 ms·
No worries. Yep you're spot-on in this case, and as you say the software signing keys hasn't been compromised, though they aren't needed in service mode. Ther
by bennysaurus 16y ago
No worries.
Yep you're spot-on in this case, and as you say the software signing keys hasn't been compromised, though they aren't needed in service mode.
There are definitely ways the dongle keys could have been better protected (and I'm sure a few people are having some very serious talks about why they weren't), but have to give Sony kudos for having a system last 3 years without being compromised, and even now it's only easily broken at ring 2; the gameOS level of the system.
- daeken 16y agoIt's simple to protect the dongle keys better: sign the dongle ID. In this way, only the public key exists on the PS3, and the system is secure (if implemented properly). As it stands, their system is equivalent to having both the public and private key sitting on the PS3. No matter how well you protect this key, the system is still broken in theory.
- bennysaurus 16y agoAgreed with the way it could be done better though they didn't actually have the private key on the system. They really badly implemented their crypto so they might as well have though.
- daeken 16y agoI'm referring purely to the dongle attack. When you use an HMAC in that way, your secret is your "private" key. It also just happens to be the "public" key as well. That's why it's a terrible design.