PSX-SCENE Forum Discussion for Sony PlayStation/PsOne/PS2/PS3/PSP/PS VITA
  • KaKaRoTo Speaks of ECDSA Algorithm - CFW Impossible

    I have always wanted an explanation of the ECDSA algorithm due to it's mathematical complexity. Anyone who knows anything about PS3 encryption and the hidden keys used to calculate the ECDSA know that it isn't an easy feat. PlayStation 3 developer KaKaRoTo has tried to simplify the subject for us in order to gain some knowledge on the subject. Below is an extract, you can read the full article linked at the source below.


    To Quote:
    To popular demand, I have decided to try and explain how the ECDSA algorithm works. I’ve been struggling a bit to understand it properly and while I found a lot of documentation about it, I haven’t really found any “ECDSA for newbies” anywhere. So I thought it would be good to explain in simple terms how it works so others can learn from my research. I have found some websites that explain the basic principles but nowhere near enough to actually understand it, others that explains things without any basics, making it incomprehensible, and others that go way too deep into the the mathematics behind it.
    Please continue to read the bottom of his article if you are feeling to lazy to read.

    Source: kakaroto.homelinux.net

    Proudly brought to you by psx-scene's Tranced.

    Have news? Post it in the Member News SubmissionsThread
    SupDor likes this.
    Comments 64 Comments
    1. tthousand's Avatar
      tthousand -
      That is what I am thinking. There are probably many doors that have yet to be opened.
    1. Mathematician's Avatar
      Mathematician -
      As finishing my undergrad in nearly pure mathematics and working on my Ph.D. in applied statistics, I will say that nothing is purely random. Unfortunately I believe the hash algorithms are 1-1 so it's impossible to have two different files with the same hash value but then I'm not a computer expert.

      However, do we really want CFW? I think with enough skill, 3.56+ libraries and features should be able to be implemented in 3.55 firmware if you have means to access 3.56+ firmware guts. If you can figure out how K is generated (trust me, it is not being randomly generated and I doubt it is using a time stamp either) you may be able to predict K and thus having higher probability of completing what you need.
    1. Darkman-PSG's Avatar
      Darkman-PSG -
      Games are encrypted with those keys to make it work idk y people cant seem to understand that. If you cant access the private keys there is NO way of making a game work how about this if True Blue can make Final Fantasy XIII-2 work then there is some hope in the scene but like it or not True Blue is all this scene has left.
    1. ridesideways's Avatar
      ridesideways -
      ECDSA systems have been cracked before, and will be cracked again. You just need to understand that the cracking is not done on the EC mathematics (which is indeed *very* secure), instead the cracking is done on the "implementation". This is how the original PS3 keys were cracked, Sony forgot to generate a random number when signing a file (a flaw in Sony's ECDSA implementation), and then the whole ECDSA system for PS3 fell like a house of cards.

      There are numerous other exploits/cracks that can bring an ECDSA system down:
      1. The private keys get leaked from Sony
      2. Hack the piece of code that verifies signatures so that non-authentic signatures are reported as authentic (I don't know enough about the PS3 architecture to say if this is feasible or not)
      3. etc. etc.

      There is no such thing as a completely secure system. The PS3 is a bunch of chips and code that runs on those chips. Code on any chip can be compromised. With enough research any system can be cracked. It's just a matter of how much resources will it take. It's probably that the PS3 contains another weak point (similar to the random-number fail) and it's just a matter of discovering it.
    1. uZer's Avatar
      uZer -
      Like Cartman used to say: "Screw you guys - I'm going home" - I'll just buy xbox if no new games arrive in nearest future...
    1. Mathematician's Avatar
      Mathematician -
      "Games are encrypted with those keys to make it work idk y people cant seem to understand that. If you cant access the private keys there is NO way of making a game work how about this if True Blue can make Final Fantasy XIII-2 work then there is some hope in the scene but like it or not True Blue is all this scene has left."

      You are wrong, you only need the public keys =P

      "it work idk y people cant seem to understand that." (you couldn't have said it better)
    1. Darkman-PSG's Avatar
      Darkman-PSG -
      @Ridesideways
      http://www.youtube.com/watch?v=R2SS0gZ_kKI

      Listen to what you are saying Sony made an error that they fixed meaning there is noway it can be cracked now.
    1. CS67700's Avatar
      CS67700 -
      Lets face it, and now i think it's pretty sure to say it : this scene is dead.
      What's coming next ? 10059 versions of multiman, 98623 versions of Showtime, 26895 more 3.55 with different themes and plugins (wouhou, cool) and nothing more.
    1. kada's Avatar
      kada -
      Quote Originally Posted by xtrem3x View Post
      Just because ECDSA can't be cracked does not mean someone can't find a different exploit in the PS3 & take advantage of it.
      I think same way. When PSP TA 088v3 boards came, CFW stopped. Then founded a way to hack PSP TA088v3 via tiff exploit. Maybe PS3 gives a big open that we can run unsigned apps and patches system calls. Who knows. I dont know about programming and is it possible but maybe plugins(like on PSP) will be adapted to 3.55 CFW. Ok PS3 has great security(over a year passed till 3.55 CFW) but every system has openings...
    1. CS67700's Avatar
      CS67700 -
      Quote Originally Posted by kada View Post
      I think same way. When PSP TA 088v3 boards came, CFW stopped. Then founded a way to hack PSP TA088v3 via tiff exploit. Maybe PS3 gives a big open that we can run unsigned apps and patches system calls. Who knows. I dont know about programming and is it possible but maybe plugins(like on PSP) will be adapted to 3.55 CFW. Ok PS3 has great security(over a year passed till 3.55 CFW) but every system has openings...
      No one has interest in hacking this console, that's all.
      The PS3 (despite the ECDSA fail from Sony) was hacked after 4 years (and not one year) because Geohot took his balls and revenged from Sony taking away the other OS function.

      Since then, nada, niet, nothing. No one was talented/smart enough to find another way in, and i believe it's not gonna happen tomorrow.

      PS: the TB thing is gonna end soon, this piece of crap isn't gonna make 4.00+ games work. It's just some tweaking.
    1. soulreaver's Avatar
      soulreaver -
      The Key is Patience guys.....and have some Faith....!!there are so many playable games already in 3.55 CFW....so Enjoy Playing....and STOP the Crying like "Women"...!!!
    1. uZer's Avatar
      uZer -
      Quote Originally Posted by soulreaver View Post
      The Key is Patience guys.....and have some Faith....!!there are so many playable games already in 3.55 CFW....so Enjoy Playing....and STOP the Crying like "Women"...!!!
      Yeah - there are 2 options:
      1. Be a gayf@g and believe in fairytales that "someday, somewhere a dev on white pony will deliver to us new hack"...
      or
      2. Be a man and face that fact that scene is dead and just move on...

      This scene is sooooo pathetic... So many DRAMA queens and no devs at all...
    1. xdslx's Avatar
      xdslx -
      how come the old signed games works on new OFW ?
    1. yes159's Avatar
      yes159 -
      Quote Originally Posted by xdslx View Post
      how come the old signed games works on new OFW ?
      The new OFW have both the old and new decryption keys.
    1. defyboy's Avatar
      defyboy -
      Misleading title. While KaKaRoTo does state that it is impossible to obtain the private key (Not technically true, it is not 'impossible' but extremely improbable - about as close as you will get to an impossibility). He did not say anything about the impossibility of a new CFW.

      It is entirely possible to create a new CFW even though we don't have the private key to sign the firmware. If we get the LV0 private and public key (or a proper lv0 dump), we have the public key to decrypt the entire firmware chain, allowing us to re-sign it with older keys (or patching all key checks out) - Not an easy task, but entirely possible.
    1. dualshock1992's Avatar
      dualshock1992 -
      Quote Originally Posted by jman123 View Post
      Good luck with waiting for that.
      Smartass, you just had to say something, didn't you, eh ?
    1. cyto's Avatar
      cyto -
      Quote Originally Posted by xtrem3x View Post
      Just because ECDSA can't be cracked does not mean someone can't find a different exploit in the PS3 & take advantage of it.
      Exactly! There is more than one way to hack the PS3, obviously since TB is using eboot/sprx files from higher firmwares now as it is. Kakaroto is just probably not the person for the job. Geohot said that it was very unlikely we would ever get the private keys when he began looking into the PS3 but that it did not matter because there are many other exploits that can be used. He said that they didn't have the private keys to iPhone/iPad either and look how they have all been hacked to run unsigned code.

      Where there is a will, there is a way. I just don't see much else going on lately with this scene. There was the anonymous guy that was going to be dumping keys from a dual setup, but we haven't heard anything for months on that. Geohot is put on ice and Math has left the scene. Is there anyone else working on this that has the talent to succeed where so many others have failed?
    1. mathisgod's Avatar
      mathisgod -
      I still remember when everyone and their mothers said that Sony couldn't fix the PS3 without a hardware revision because of the original key leaks? lol

      Idiot sheeps.

      Stop being a bunch of cheap bitches and update the ps3 if you really want to play newer games.
    1. ahou's Avatar
      ahou -
      Quote Originally Posted by Shrek View Post
      CFW Impossible ? Anything is possible, I'd edit that, as you run the risk of looking foolish.
      That's not true.

      ECDSA is impossible to crack within any reasonable amount of time (say, before the earth is gone). And there are other things which are in fact 100% impossible to crack, even given an infinite amount of time, such as, for example, a one time pad.
    1. Mathematician's Avatar
      Mathematician -
      OTP:

      "If the key is truly random, as large as or greater than the plaintext, never reused in whole or part, and kept secret, the ciphertext will be impossible"

      However, nothing is truly random. OTP can be cracked.
  • Daily Digest


    Want to receive the latest PSX info in your email?

    Sign up for our Daily Digest!



    Want to learn more about the team keeping you up to date with the latest scene news?

    Read about them now!

    Check out our Developer bios, too!

  • Recent Threads

    teepo

    PS3 Hard Drive Read?

    Thread Starter: teepo

    I was wondering if there are any ways to view an OFW ps3's hard drive from either linux/windows?

    I've read that the ps3 encrypts the drive

    Last Post By: BahumatLord Today, 02:16 PM Go to last post
    bhek

    Help me install HDD on Sony PlayStation 2 Slim NTSC-J SCPH-70xxx

    Thread Starter: bhek

    Hi I'm just new here and new in ps2 HDD installation, i bought a 2nd Sony PlayStation 2 Slim NTSC-J SCPH-70xxx and i wanted to install hdd. Can someone

    Last Post By: amp2006 Today, 01:28 PM Go to last post
    Rikrik

    Progskeet 1.2

    Thread Starter: Rikrik

    Hi,

    I'm having some trouble with my progskeet 1.2. I'm hoping anyone here has a solution because i can't find much on the internet.

    Last Post By: vampman Today, 11:31 AM Go to last post
    snowkid1995

    PS2 Slim problem.

    Thread Starter: snowkid1995

    Hello guys,

    i have replaced laser unit in my PS2 Slim... everything went fine until i wanted to play game (disk is little bit scratched but

    Last Post By: snowkid1995 Today, 06:27 AM Go to last post
    Lombiz

    ISO Game Multiman

    Thread Starter: Lombiz

    Hello,

    I am sorry to ask this question if it has been answered before several times but cannot find any answer googleing or searching these

    Last Post By: amp2006 Today, 06:12 AM Go to last post
    Koolgus

    Anyone know?

    Thread Starter: Koolgus

    Anyone know what mod menu can change online player ped i really want this to change non modders into people they want besides the default online players.

    Last Post By: creighton Today, 01:52 PM Go to last post
  • Recent Comments

    Mathematician

    Super Pixel Jumper v1.2 by ThatOtherPerson

    I've played this game for the wii port so many times. I remember getting a ridiculous high score.... Go to last post

    Mathematician Today 01:01 PM
    STLcardsWS

    Super Pixel Jumper v1.2 by ThatOtherPerson

    How to place a Vote



    http://img716.imageshack.us/img716/9273/psxscenecontesttute.gif Go to last post

    STLcardsWS Today 12:45 PM
    JOshISPoser

    CFW 4.40 MiralaTijera - Update 4: System Manager 1.1 & 3.2.0 Integrated Core + qaflag

    oh man, i hope that feature alone gets put in other firmwares. it took me a long ass time to figure... Go to last post

    JOshISPoser Today 11:20 AM
    exofreak

    {Update #1} Rogero's CFW 4.40 v1.02 Released

    hi all. i have been on this fourm for a while now so i am no guest.
    anyways, i wanted to ask some... Go to last post

    exofreak Today 09:41 AM
    Tranced

    CFW 4.40 MiralaTijera - Update 4: System Manager 1.1 & 3.2.0 Integrated Core + qaflag

    I'm really liking the no sleep implementation. Some games will not run on my 2TB external. Go to last post

    Tranced Today 09:04 AM
    ppr2012

    BwE NOR Validator 1.28 -- Final Version?

    pls can any1 help!! i used this app to validate my 2dumps when taken on k3.55 with mm before... Go to last post

    ppr2012 Today 08:54 AM
    Raggamuffin

    UPDATE: Remarry Blu Ray Drive 3.15 / 3.50 / 3.55 Guide - No Need to Downgrade

    What if you dont own a bluray movie disk. can this still work ?
    i dont watch bluray movies so it... Go to last post

    Raggamuffin Today 08:13 AM
    negodosul

    CFW 4.40 MiralaTijera - Update 4: System Manager 1.1 & 3.2.0 Integrated Core + qaflag

    I think it is too much trouble to install this cfw. Go to last post

    negodosul Today 07:56 AM
    szczuru

    Bite h&e v1.5.1 -- Addition of 3 PC emulators.

    Added to PSP2PS3 dorpbox :) Go to last post

    szczuru Today 07:26 AM
    aldostools

    Fan Control Utility v1.7 Relased CFW 4.41 Supported!!

    Ok, here is the official answer from Estwald about the sudden shutdown exiting from this app.
    ... Go to last post

    aldostools Today 07:10 AM