Technological discussion on PS3 security and crack.*

The link says:

Update: We originally reported that this would be free to current PSJailbreak owners. However, conflicting information has appeared on the PS-Downgrade.com (unofficial) website, where prices have popped up. It seems, at least on this site, the downgrade will sell for $40 on top of the cost of PSJailbreak. This may just be someone trying to make a buck on the update. It may also be evidence that the downgrade will cost additional money, the truth remains to be seen. Below are the prices pulled from http://www.ps-downgrade.com/checkout.htm

PS Jailbreak + PS Downgrade $125.00
PS Jailbreak $100.00
PS Downgrade (Requires a PS Jailbreak) $40.00

HolidayCarts has now informed us of the suggested retail pricing on PS Downgrade. He has confirmed that PS Downgrade is NOT free, and will need to be purchased.

Suggested Retail Pricing
1PC 40.00$ USD
2PC 38.00$ USD
5PC 35.00$ USD
10PC 33.00$ USD
50PC 30.00$ USD
100PC 27.00$ USD
 
So far every game "requiring" 3.50 has been busted easily including black ops. Of course, there's GT5 as probably the first game compiled with 3.50, but the way things are going I wouldn't expect it to hold out either.

If you look back at this thread a lot of people have been calling "fake" at every stage, and keep getting proved wrong.

Unless i am mistaking Black Ops was actually unplayable, it was because of a update to the game that it was possible to "patch it".

Which is a good thing since that helped Sony prepare GT5 better...
 
From Dashkaks

PS Downgrade Real – Confirmed Working 100%

I can personally tell you that PS Downgrade is the real deal. I’ll attempt a video later — just know I successfully downgraded my PS3 Slim running 3.50 to 3.41 a few moments ago. And so we’re clear: ps-downgrade.com is not a scam; they’re the real deal — and very helpful too. I bought my PS Downgrade update for $40 and although it took more than 48 hours, they still delivered; I understand that to be PS Jailbreak’s problem but lets not get into he said she said. After all the PS Jailbreak team did it again!

We have for you the modified 3.41 PUP, both Lv2diag.self files, and the PS Updater app (to update your PS Jailbreak with PS Downgrade). Instructions on all that below. I believe the FLA file (the PS Downgrade software) is specific to each PS Jailbreak device. But I’ve included mine anyway. Maybe someone can do something with it.

How to Downgrade your PS3 with PS Downgrade

1. Insert PS Jailbreak device that has been reprogrammed as PS Downgrade into your console
2. Turn on the console using the same boot method as PS Jailbreak: Press power then immediately press eject. Your console will turn on and PS Jailbreak will light up with red/green LEDs followed by green only, then the PS3 will turn off.
3. Turn on console to make sure you are in factory service mode. You will see a huge red box on the screen saying Factory Service Mode. Once confirmed please turn off console and remove PS Downgrade Dongle.
4. Program any blank USB mass storage device with 2 files:
1. the modified 3.41 PUP
2. Lv2Diag.self (rename Lv2diag.self.1).

These must be the only files on the USB key and must be placed in the main (root) directory.
5. Insert this USB mass storage device into the USB port to the right — the first USB port in from the right side if you’re facing the console. Turn the PS3 on and you will see black screen but the PS3 HDD light will flash.
6. Wait 3 minutes for the system to install the old firmware. Towards the end the power button on the console will start flashing green and then your console will power off.
7. Remove the USB key and turn on the console, you will still be in factory service mode. Please verify you have downgraded successfully to version 3.41.
8. (Optional) – If you wish to downgrade to any older firmware you can follow step 4, 5, 6 using any regular firmware PUP. (You do not need to use modified custom firmware now that you are on 3.41).
9. Insert USB key back into your PC, remove the PUP and Lv2Diag.self file, and copy only the other LV2Diag.self (rename Lv2diag.self.2) to the USB key.
10. Power on your console, after 10 seconds it will power off
11. Turn on your console again with no USB inserted and you will be out of factory service mode and back in retail mode with your chosen firmware version installed.

With this you’re able to downgrade any PS3 running firmware 3.42 or 3.50 and “beyond” … I wonder if Sony has any plans on revising their hardware soon. I suspect this is similar to Pandora’s battery for the PSP, which ultimately forced Sony to release the TA088v3 closing off that backdoor.

If you just can’t wait and you already own a PS Jailbreak, or if you want to buy a PS Jailbreak too, then you do that and you downgrade your PS3; you can buy the standalone update or both PS Jailbreak and software at ps-downgrade.com. Otherwise sit patient because you know this’ll be open sourced real soon.

Download: PS Downgrader
(modified 3.41 firmware PUP, Lv2diag.self, PS Updater, etc.)
 
Otherwise sit patient because you know this’ll be open sourced real soon.

The team that did the open source break has clearly stated they don´t intend to create a firmware downgrader and that they knew how to make one before the jailbreak team created theirs.

I am getting the sense that the original hack was way more serious than originally imagined and the "box" may actually have been opened. But those that really know ain´t talking.
 
The team that did the open source break has clearly stated they don´t intend to create a firmware downgrader and that they knew how to make one before the jailbreak team created theirs.

I am getting the sense that the original hack was way more serious than originally imagined and the "box" may actually have been opened. But those that really know ain´t talking.

Original hack=the Geohot hack?
 
Original hack=the Geohot hack?

No, the USB jailbreak. From reading between the lines, more is possible than was first expected. The firmware thingy was kind a mentioned before the release. Apparently there is a good knowledge about the encryption techniques used, and how to reverse engineer them. And other stuff that kind a hangs in the air.

I hope that the 3.50 update and the new keys shut the door and those that wants to "play" with homebrew can do all that they want with 3.41. However the FW downgrade is a open door to hack the console, and just upgrade when you want to use 3.50 features or games. And apparently PSN is accessibly from 3.41 incl games. Which brings one of the primary reasons why i absolutely HATE this stuff to the table, the clear risk of people cheating in online games...
 
Its my understanding that they already have a working patch for 3.50and we will see it before the end of the year. they are just waiting to test it on gt
 
This morning was the big unveil at the Chaos Communication Congress in Berlin, and it did not disappoint. Here is a brief synopsis for those that missed it.

The first few minutes of the conference were spent explaining the state of security on other consoles (Wii, 360, etc). Following this, the group went on to explain the current state of affairs on the PS3. First, explaining Geohot's memory line glitching exploit from earlier this year. The team then went on to explain the current PS3 security bypasses, such as jailbreaking and service mode/downgrading.

Approximately a half hour in, the team revealed their new PS3 secrets, the moment we all were waiting for. One of the major highlights here was, dongle-less jailbreaking by overflowing the bootup NOR flash, giving complete control over the system. The other major feat, was calculating the public private keys (due to botched security), giving users the ability to sign their own SELFs Following this, the team declared Sony's security to be EPIC FAIL!

The recent advent of these new exploits means current firmware is vulnerable, v3.55 and possibly beyond. It will be very difficult for Sony to fix the described exploits.

The team then displayed the website http://fail0verflow.com/ were we assume will host examples of the new exploits and further details. They stated that easy to use tools would be coming next month.

Stay tuned to this article and PSGroove.com we will be updating it as more info is availble. Also for those that missed the stream we will be posting links for you to download the entire stream.

http://psgroove.com/content.php?581-Sony-s-PS3-Security-is-Epic-Fail#ixzz19WMUJZAE
 
Wow, a huge hole !

# our goal is to have linux running on all existing PS3 consoles, whatever their firmware versions. less than 20 seconds ago via web in reply to KushanTheCat

# Our current PS3 goal: AsbestOS.pup 2 minutes ago via web

It looks like we don't have to wait for Sony to improve XMB anymore.
 
wow, seems like someone really messed up if you can recreate the signing keys.

On the bright side I will likely update my PS3 soon, now that I dont have the nagging thoughts about locking out OtherOs forever
 
So, finally mkv support then? I guess the only way for Sony to fix this is via hardware revision.
They said they don't have the keys for apploader, what does that mean?
 
So, finally mkv support then? I guess the only way for Sony to fix this is via hardware revision.
Not even that, the only way would be to invalidate keys - which means alot of existing software wouldnt work anymore.
In some cases it could be downloaded again from PSN, Im not sure what kinda software would be affected - retail games seem to use a different key (but apparently the signing key could be calculated too)
 
Terribly embarrassing for Sony. The failure to use Elliptic Curve properly, thereby revealing their signing keys (and making it possible for the hackers to sign their own firmware, indistinguishable from Sony's) is about as bad as it could get for PS3 from Sony's perspective.

I know PSP has been on the market for years with similar (?) issues, so I presume Sony will just bluff it out this generation. At least fail0verflow did a nice job at the start reviewing all the security measures across systems this generation to help Sony with their job next time.

Maybe Sony could even hire these guys next time around. I'd hate to be responsible for designing something to stand up to them. :oops:
 
Back
Top