Sony PS3 rootkit rumours rubbished

  • Thread starter Thread starter Nujui
  • Start date Start date
  • Views Views 3,396
  • Replies Replies 21

Nujui

I need something to do.
Member
Joined
Aug 12, 2010
Messages
3,933
Reaction score
147
Trophies
0
Age
29
Location
Dreamland.
XP
851
Country
United States

Suggestions that Sony has added a rootkit with the latest firmware update to its PS3 console have been denounced as bunkum by a leading gaming security expert, Chis Boyd, a security researcher at GFI Security who has studied the security of online games for several years, points out the development is not new since Sony wrote the ability for it to do remote updates into its terms and conditions since at least 2006.

"It's been known for a while that a networked PS3 will contact Sony servers at start up (whether it has an active PlayStation network account on it or not), which performs various tasks related to error logs, updates and other activities," Boyd (aka Paperghost) told El Reg.
[/p]
Source
I wish I could link to the ps3hax one, but appearently I can't get on there for some reason.
 
This guy has TOTALLY missed the point.

Error 1:
QUOTE said:
But Chris Boyd, a security researcher at GFI Security who has studied the security of online games for several years, points out the development is not new since Sony wrote the ability for it to do remote updates into its terms and conditions since at least 2006.
People aren't complaining about updates, but about remote code execution, which no producer should ever be able to do, since the product has been bought, and it's not their right to do something without the owner's will.

Error 2:
QUOTE said:
"It's been known for a while that a networked PS3 will contact Sony servers at start up (whether it has an active PlayStation network account on it or not), which performs various tasks related to error logs, updates and other activities," Boyd (aka Paperghost) told El Reg.
STILL missing the point.

Error 3:
QUOTE said:
"This is only really a concern if you're interested in modding - otherwise I'm not convinced there's a 'threat' as such," Boyd told El Reg. "I'm still waiting for someone to explain how this 'PS3 rootkit' could be used to run unsigned malicious code on a non-jailbroken box," he added.
Malicious code? WTF is he talking about? We're not worried of hackers, we're worried of Sony itself!
rofl2.gif


Error 4:
QUOTE
Boyd, who has been vocal in criticising the lawsuits against the PS3 hackers such as geohot, nonetheless argues that gamers need to get a grip. "People will happily download homebrew from Basement Bob which could steal logins/credit card details, but code from the console maker is evil?"
Yes, because you're _arbitrarily_ deciding to run that code. If a console maker shoves it inside your throat, well, then that's a completely different thing.
 
raulpica said:
Malicious code? WTF is he talking about? We're not worried of hackers, we're worried of Sony itself!
rofl2.gif
Actually that's only partially true. A rootkit is a backdoor and if Sony really integrated one, this would mean that hackers could use it, too.
What if someone decides to prove how dangerous the rootkit is and starts to randomly brick consoles?
 
QUOTE said:
Error 1:
QUOTE said:
But Chris Boyd, a security researcher at GFI Security who has studied the security of online games for several years, points out the development is not new since Sony wrote the ability for it to do remote updates into its terms and conditions since at least 2006.
People aren't complaining about updates, but about remote code execution, which no producer should ever be able to do, since the product has been bought, and it's not their right to do something without the owner's will.

Especially when the updates are known to break the system and Sony says tough crap, pay us to fix it.
 
M[u said:
ddy]
raulpica said:
Malicious code? WTF is he talking about? We're not worried of hackers, we're worried of Sony itself!
rofl2.gif
Actually that's only partially true. A rootkit is a backdoor and if Sony really integrated one, this would mean that hackers could use it, too.
What if someone decides to prove how dangerous the rootkit is and starts to randomly brick consoles?
Sure, but then that would be Sony's fault for introducing the hole in the first place.
And I at least expect them to do that function decently, maybe doing it server-side, just to be safe.

And most console hackers luckily aren't interested in bricking others' consoles
wink.gif
 
The problem is everybody using the word "rootkit" when it does NOT apply to this situation AT ALL.

This security expert is going off the idea that everything thinks it's a rootkit, and unlike everybody else he's using the actual definition of what a rootkit is and does.

I don't know why people used the word rootkit in the first place.
 
Remember Super Nintendo and Nintendo 64? Remember when that had a bunch of security issues because of online gaming? Remember when we worried that Nintendo is going to force an update for the 64 that required the expansion pack?.... Oh... wait.
 
Rydian said:
The problem is everybody using the word "rootkit" when it does NOT apply to this situation AT ALL.

This security expert is going off the idea that everything thinks it's a rootkit, and unlike everybody else he's using the actual definition of what a rootkit is and does.

I don't know why people used the word rootkit in the first place.
The guy used it, so the guy's wrong in using it
smileipb2.png
 
Rydian said:
The problem is everybody using the word "rootkit" when it does NOT apply to this situation AT ALL.It kind of does...

http://en.wikipedia.org/wiki/RootkitQUOTEA rootkit is software that enables continued privileged access to a computer while actively hiding its presence from administrators by subverting standard operating system functionality or other applications. The term rootkit is a concatenation of "root" (the traditional name of the privileged account on Unix operating systems) and the word "kit" (which refers to the software components that implement the tool). The term "rootkit" has negative connotations through its association with malware.[1]
Essentially you, the user, would be the administrator. By having it update without notification or indication it is hiding it's presence and subverting standard functionality (which would be asking to update).


And Sony is no stranger to Rootkits:
http://en.wikipedia.org/wiki/Sony_BMG_copy...rootkit_scandal
 
raulpica said:
Sheaperd121 said:
raulpica said:
This guy has TOTALLY missed the point.
I know right? He missed it completly.
Kinda expanded on my views by editing the previous post
wink.gif
Sorry, the computer I was on didn't show all of what you said(Laptops suck somtimes.)
 
shakirmoledina said:
is this not against the law? privately sending info about the userIt's in the TOS, when you agree you give Sony permission to do this. In addition it's not info that can be used to personally-identify the user. I mean look at the trouble they had trying to prove if geohot had an account or not...

QUOTE(shakirmoledina @ Feb 4 2011, 03:01 PM) and possibly making the ps3 for a user vulnerable?
No. That's what people feared by the of the word "rootkit", but it's not the correct usage.
 
ShadowSoldier said:
Remember Super Nintendo and Nintendo 64? Remember when that had a bunch of security issues because of online gaming? Remember when we worried that Nintendo is going to force an update for the 64 that required the expansion pack?.... Oh... wait.
not sure why you are comparing systems from 20 & 14 years ago...

unless you are just trolling >_>
 
ShadowSoldier said:
Remember Super Nintendo and Nintendo 64? Remember when that had a bunch of security issues because of online gaming? Remember when we worried that Nintendo is going to force an update for the 64 that required the expansion pack?.... Oh... wait.
I don't get it...


Anyway. The Rootkit thing. Its a way for Sony to ban consoles (y'know like Microsoft can on the 360) so why its such a big deal I don't know. They're protecting their platform or putting on a show that they are so Devs won't be scared away by threat of rampant piracy. I really hope they encrypted that backdoor properly otherwise some nasty could start a PS3 virus chain.
 
Joe88 said:
ShadowSoldier said:
Remember Super Nintendo and Nintendo 64? Remember when that had a bunch of security issues because of online gaming? Remember when we worried that Nintendo is going to force an update for the 64 that required the expansion pack?.... Oh... wait.
not sure why you are comparing systems from 20 & 14 years ago...

unless you are just trolling >_>



Jamstruth said:
QUOTE(ShadowSoldier @ Feb 4 2011, 05:58 PM)
Remember Super Nintendo and Nintendo 64? Remember when that had a bunch of security issues because of online gaming? Remember when we worried that Nintendo is going to force an update for the 64 that required the expansion pack?.... Oh... wait.
I don't get it...


Anyway. The Rootkit thing. Its a way for Sony to ban consoles (y'know like Microsoft can on the 360) so why its such a big deal I don't know. They're protecting their platform or putting on a show that they are so Devs won't be scared away by threat of rampant piracy. I really hope they encrypted that backdoor properly otherwise some nasty could start a PS3 virus chain.

I'm talking about the whole online thing and problems people have with it with these generations of consoles, and how with the N64/Playstation or the SNES, didn't have any worries or anything like this to worry about.
 
Rydian said:
shakirmoledina said:
is this not against the law? privately sending info about the user
It's in the TOS, when you agree you give Sony permission to do this. In addition it's not info that can be used to personally-identify the user. I mean look at the trouble they had trying to prove if geohot had an account or not...

This is the thing, I haven't agreed to any TOS and the system sends the data you agree to when you accept the TOS if you have or not.
 

Site & Scene News

Popular threads in this forum