Forum: Latest News - Get all of the latest legal dev and underground news as it relates to the Sony PlayStation right here on PSX-Scene.

The above video goes away if you are a member and logged in, so log in now!



 
Would you like to get all the new info from
PSX-Scene in your email each day?




Want to learn more about the team keeping you up to date with the latest scene news?

Read about them now!

Check out our Developer bios, too!

 


Thread: Call of Privacy: Modern Spyware By PlayStation Network
  

Page 1 of 9 1 2 3 ... LastLast
Results 1 to 10 of 85
  1. #1 Call of Privacy: Modern Spyware By PlayStation Network 
    The Central Scrutinizer's Avatar
    The Central Scrutinizer is offline PSX-SCENE Admin Bot
    Join Date
    Jul 2002
    Posts
    919
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    512
    On the hells, of the mightly BanHammer being throw around by Sony now, along with tons of Warning emails to millions of PSN account holders, a group of hackers called The Anonymous Data Protection Officers have produced a PDF on Playstation Network that shows it is totally lacking in Security even your Credit Card is transmitted in plain text format over the 'net ever time you use your PS3 console!


    Update:
    A document written by the hackers has clarified what they did and what privacy and security risks they believe the PlayStation 3 poses. The PS3's connection to PSN is protected by SSL. As is common to SSL implementations, the identity of the remote server is verified using a list of certificates stored on each PS3. The credit card and other information is sent over this SSL connection. So far so good; this is all safe, and your web browser depends on the same mechanisms for online purchases.

    The concern raised by the hackers is that custom firmwares could subvert this system. A custom firmware can include custom certificates in its trusted list. It can also use custom DNS servers. This raises the prospect of a malicious entity operating his own proxies to snaffle sensitive data. He would distribute a custom firmware that had a certificate corresponding to his proxy, and that used a DNS server that directed PSN connections to the proxy. His proxy would decrypt the data sent to it, and then re-encrypt it and forward it to the real PSN servers.

    Such a scheme would be transparent to PSN users (except for any potential performance reduction caused by the proxying), and would give the attacker access to all the information that the PS3 sends to Sony. This information is shown to be extensive, but apart from the credit card data, probably not too sensitive or unreasonable.

    As flaws go, the risks here are not substantial. There is no generalized ability for hackers to grab credit cards from PSN users; only those using specially devised custom firmwares would be at risk. Essentially the same risk could be faced by anyone downloading a pirated version of Windows: extra certificates could be added to those normally trusted, along with suitable DNS entries, to allow interception of any traffic destined for, say, amazon.com. In practice, the risk of either of these is slight, and in any case, trivially avoided: don't use custom firmware.
    Original story:
    Sony has officially stated that anyone using hacked firmware or any sort of circumvention technology will have their console banned for life from the PlayStation Network, but how does the company know when such a console logs in? One person claims to have broken into the PlayStation Network, and what he has found is rather shocking. If his findings are accurate, your credit card information is being sent to Sony as an unencrypted text file, and Sony is watching every single thing you do with your system, keeping detailed records all the while.

    "Sony is the biggest spy ever... they collect so much data. All connected devices return values sent to Sony's servers," the hacker said. He claims that Sony knows what controllers you're using, what USB devices are plugged in, what sort of television you're using—everything. Here's another section of the chat log:
    Code:
    •user2: another funny function i found is regarding psn downloads
    •user2: its when a pkg game is requested from the store
    •user2: in the url itself you can define if you get the game free or not. requires some modification in hashes and so on tho
    •user3: ..
    •user2: is like
    •user8: :D
    •user3: my god
    •user2: drm:off
    That's not all: your credit card information is apparently being sent as an unencrypted text file. This is how the code is being sent to Sony:

    Code:
    creditCard.paymentMethodId=VISA&creditCard.holderName=Max&creditCard.cardNumber=45581234567812345678&creditCard.expireYear=2012&creditCard.expireMonth=2&creditCard.securityCode=214&creditCard.address.address1=example street%2024%20&creditCard.address.city=city1%20&creditCard.address.province=abc%20&creditCard.address.postalCode=12345%20
    This information is allegedly being stored online and is updated every time you turn on your system. We've been receiving reports from various sources that e-mails are being sent to those with hacked firmware even before they log back into the PlayStation Network, which is even more evidence that Sony is grabbing information from your system just from being connected to your wireless network.

    The ability to enable free downloads is likewise unsurprising, as there may be a way for some users, such as press and developers, to access the PlayStation Network without needing to pay for content. While other console manufacturers may keep free, pre-review content in a separate, closed-off network, it's possible Sony keeps everything in one place, and controls who pays and who doesn't via a simple toggle. That would be unsafe from a security standpoint, but when has that stopped anyone from stupid mistakes in the past?

    It's also very possible this is all fake, but much of what the unnamed hacker is saying links up with what we know from other sources about the behavior of the PlayStation Network. It's worth treating this as a very real threat: use PSN cards instead of credit cards on the PlayStation Network, and make sure you don't share any passwords or login information between your PSN account and other accounts.

    We've contacted Sony for comment, but have not received a reply at time of publication. The hackers joked that the next update will remove the PlayStation Network, just as Sony removed the Other OS feature when it became compromised.
    Attached is original PDF that been making the rounds on the 'net!

    News Source: Report: PSN hacked, custom firmware could pose security risk to users (UPDATED)

    Sorry for delay in posting the news, I had major problems getting into the site via IE, now I fixed the broken attachment also!
    Attached Files
    Last edited by garyopa; 02-17-2011 at 03:29 PM. Reason: Formatted for front page, and fixed broken PDF link!
    Reply With Quote  

  2. #2  
    Noxside's Avatar
    Noxside is offline Retro Gamer
    Join Date
    Nov 2010
    Location
    Norway
    Posts
    68
    Downloads
    0
    Uploads
    0
    Likes Given
    3
    Likes Received
    5
    If this is all true, i god hope people in the US sue the **** out of Sony for this. Glad that i removed my credit card details from PSN when the first jailbreak dongle came out, since i planned to have it jailbroken. In the end PS3 got ****ed and your details is then at risk.
    Reply With Quote  

  3. #3  
    juanmiglesias is offline Registered User
    Join Date
    Nov 2002
    Posts
    4
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    1
    i was surprised at first... then i remember its SONY what we are talking about..LoL big fail...
    __(¯`·._ juan VENEZUELA_.·´¯)_
    Reply With Quote  

  4. #4  
    Peppers's Avatar
    Peppers is offline Hot and Spicy
    Join Date
    Nov 2004
    Posts
    999
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    0
    The lead of this news post is missleading.

    If you continue to read you see that if your ps3 has not been modified specifically for the purpose of stealing your personal information your ok, an unmodified ps3 is not at risk. Your regular computer is far more likely to be a target of such an attack.
    Last edited by Peppers; 02-17-2011 at 03:53 PM.
    My Christmas decorations aren't coming down.
    Reply With Quote  

  5. #5  
    PhaReelDoa is offline Member
    Join Date
    Feb 2011
    Posts
    41
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    0
    you guys do realize the vulnerability lies wthin using cfw right. make sure of your download sources.
    Reply With Quote  

  6. #6  
    braders1986 is offline Banned
    Join Date
    Dec 2010
    Posts
    243
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    0
    Can't believe the cheek of people on here moaning that they got banned lol
    WTF!.... do you actually expect to get away with it.
    You went against there policy now you pay the price


    ****ing deal with it
    Reply With Quote  

  7. #7  
    ModderFokker is offline Member
    Join Date
    Sep 2010
    Posts
    45
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    2
    Why the F would someone use a CC on a modded PS3 ...pmsl
    Reply With Quote  

  8. #8  
    Wutangrza's Avatar
    Wutangrza is offline Member
    Join Date
    Dec 2010
    Posts
    488
    Downloads
    0
    Uploads
    0
    Likes Given
    0
    Likes Received
    12
    Wow, this is such FUD and should be deleted. Are you kidding me?

    Being only protected by SSL and being sent in plaintext aren't even close to the same ****ing thing. The only way this is a vulnerability is if you install malicious software on your PS3. This isn't Sony being evil.

    For example, if I distribute a CFW or a self signed cert and tell you to install it on your PS3, then I also tell you to use my server as a proxy server, yes, I could scrape your details including your CC info, but news flash, installing random software you find on the Internet is a bad idea and as the devs have been saying for MONTHS it's a bad idea to route your traffic through someone's proxy you don't trust.

    This should be deleted from the frontpage immediately or at least edited to make clear this only poses a risk to someone if they install malicious software on their PS3.

    edit: To clarify, your credit card is never sent in plaintext over the net. It's sent over https and encrypted with SSL. The user in that chat log is simply saying that it's not encrypted twice (ie, encrypted and then also sent over https). The only way this is dangerous is if you install malicious software on your console. Essentially it's like saying, "WARNING IF YOU INSTALL THIS VIRUS YOUR COMPUTER WILL GET MESSED UP, SONY EPIC FAIL LAWL!"
    Last edited by Wutangrza; 02-17-2011 at 03:34 PM.
    Reply With Quote  

  9. #9  
    erexx is offline PS3 Freak
    Join Date
    Oct 2010
    Posts
    82
    Downloads
    0
    Uploads
    0
    Likes Given
    4
    Likes Received
    3
    Many probably didn't think about this when putting their JB consoles online
    but its not necessary to have a credit card to sign up for a PSN account or buy PSN content.
    There is absolutely no need to input your CC information for PSN
    An email address is all you need.
    Last edited by erexx; 02-18-2011 at 11:49 AM.
    Reply With Quote  

  10. #10  
    patmorita is offline Senior L33ch3r
    Join Date
    Sep 2010
    Posts
    161
    Downloads
    0
    Uploads
    0
    Likes Given
    11
    Likes Received
    7
    This is like telling the phisher kids where the candies are and how to get them. I can see in the near future a lot of "CFW" with "stealth" internet access ala fudgepsn...all for free (even scammed for free lol)
    Reply With Quote  

Page 1 of 9 1 2 3 ... LastLast
Posting Permissions
  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

Popular Tags

1tb 3.15 3.41 3.42 3.50 3.55 3.55 cfw 3.56 3.60 3.61 3.70 3.72 3.73 007 80gb agent under fire apps assassins creed atmel backup back up backup games backup manager backups backwards compatible banned batch black blackbox black ops blackrhino black screen blackscreen blu-ray bluray bluray drive boot break brick bricked broken bug burned bypass call of duty card cfw cfw 3.55 cheap cheat cheats cobra cod code codebreaker codes compatibility connection contest controller crash custom custom firmware dead deank debug demo diy dlc dongle downgrade downgrading download drive dvd e3 card reader e3 flasher easy eboot eboot.bin eboot bin elf emulator error esr ethernet exploit external external hdd fat fifa firmware fix flash drive fmcb fmcb 1.8 format free free mcboot freemcboot free mc boot freeze friv ftp fuse gaia gaia manager game games gameshark geohot graf_chokolo gran turismo 5 groove gt5 gta iv guide hack hacking hard hard drive harddrive hdd hdl hdloader help! helpme hermes hex homebrew ide infectus install internal internal hdd iso issue jac jailbreak jailbreak 3.55 jailbreaking jtag kakaroto killzone 3 kmeaw kmeaw 3.55 lan laser leds light linux loader logo mac magic manager matrix matrix infinity maximus mcboot media player memento memor32 memory memory card mfw mod modbo mod chip modchip modded modding mods move multiman mw2 nand need for speed netflix network network adapter newbie new ps3 news noob no sound ntfs ntsc ofw online open manager open ps2 loader open ps2 loader 0.8 openps2loader opl opl problem oplv7 otheros packer pal pandora battery param.sfo patch payload pes 2011 pgen pic pkg playstation playstation 2 playstation 3 playtv port power problem problems progskeet ps1 ps2 ps2 backups ps2 slim ps3 ps3 3.55 ps3 break ps3 break.ps3 yes ps3 game modding ps3 hdd ps3 homebrew ps3 jailbreak ps3 slim ps3break ps3key psfreedom psgroopic psgroove psjailbreak psl1ght psn psn bypass psp psx psx-scene purchase question read rebug recovery region remote play repair restore rock band rogero router save saves scene screen sdk showtime skyrim slim slim ps2 smb sms softmod sony speed spoof stuck swap swap magic swapmagic swap trick system theme themes transfer trick trophies true blue tutorial ubuntu ulaunchelf update updates upgrade usb usbadvance usb flash drive v@ughn video vmc waninkoko winhiip working x3max xmb xploder ylod