5 ms·
From the mathematician on stage: "and for some reason, Sony uses the same random number all the time!" - classic!
by sybreon 16y ago
From the mathematician on stage: "and for some reason, Sony uses the same random number all the time!" - classic!
- nkassis 16y agoCan you provide a time index for that in the videos?
- eirikref 16y agoHave a look at http://www.youtube.com/watch?feature=player_detailpage&v=hcbaeKA2moE#t=2227s http://www.youtube.com/watch?feature=player_detailpage&v... and watch for a few minutes. The whole video is really interesting, but that part is the really embarrassing one.
- deleted 16y ago[deleted]
- Swannie 16y agoI'm not sure if that was hyperbole or not. As I understand it, all that was required was for them to use the same random number /twice/. Let's say you're Sony and you sign a patch, release it, realise there is a minor fix, and release within 2hours... maybe in your rush you failed to regenerate the random seed? Or, my initial thoughts, someone inside Sony did this maliciously?
- gnaffle 16y agoNo, it was parabole. :) From what I understand, they use the same number every single time without exception.
- Swannie 16y agoThat's really quite astounding. Thanks.
- JonnieCache 16y agoIf your build process requires you to manually generate a random number and copy and paste it in, you need to try harder. If you work for a bank handling payments, you should be fired and never allowed to work in software again. EDIT: that last bit about banks is OT, sorry about that, I've been watching the chip and pin hacking talk from CCC and got confused.
- uxp 16y agoPersonally, I don't think the domain matters. If a developer is required to provide security, either to protect a secret, maintain personal or company profits, or protect customer finances, and that developer fails by "int rand() {return 4;}", that developer should never work with technology again.
- Swannie 16y agoI agree. It is unlikely that the release manager would have been expected to generate a random number. I'd have expected, possibly, a pre-generated list of random numbers, maybe 1000 or so, so a duplicate is not unlikely, and cannot happen maliciously. I find it most likely that the build process code was flawed. This sort of code is, in my experience, not written by your most talented developer (unless one of your top developers has a build fetish). All too often you only find deficiencies in the build/release process the month of release, when you have the least time to fix them.
- JonnieCache 16y agoIf the whole project is about signing code packages to prevent the platform being hacked, you would've thought the key generation would be considered a critical part of the application code, rather than a detail of the build process. Even if the code necessarily exists in the build script. The build script is the project in this case. If a developer has ever even thought about generating a list of 1000 random numbers to pick from at a later date, then they shouldn't be developing production code.
- Swannie 16y ago
- stcredzero 16y agomaybe in your rush you failed to regenerate the random seed? Or, my initial thoughts, someone inside Sony did this maliciously? As always, the human factor is the real weakness. (Key management by users and coders.) There are similar problems with RSA signatures on related numbers or selecting keys for IDEA block cipher and RC4 stream cipher, just to name a few. If you use crypto tools incorrectly, you actually put yourself in a somewhat weaker position than if you hadn't even tried. What you've essentially done is create "security theater" for the bad guys to dupe the unsuspecting with.
- Omega191 16y agoNo, it works on any two binaries.
- JonnieCache 16y agohttp://dilbert.com/strips/comic/2001-10-25/ http://dilbert.com/strips/comic/2001-10-25/ (Bonus points if you get the reference: https://secure.wikimedia.org/wikipedia/en/wiki/Feynman_point https://secure.wikimedia.org/wikipedia/en/wiki/Feynman_point)