Go Back  
Reply
 
Thread Tools
Old 01-19-2013   #11
mckenziesdaddy
Member
 
Join Date: Sep 2011
Location: York,PA USA
Posts: 528
Likes: 12
Liked 96 Times in 63 Posts
Mentioned: 33 Post(s)
Tagged: 0 Thread(s)
Originally Posted by NF7 View Post
That is not true. The lv0.2 would be hacked. The 3K and 4K models still would not be able to install CFW on it. Because the Software Update process on newer FW's blocked the 3.55 PRIVATE KEYS, which are the last Private keys known to us, so the 3.55 signed lv0.2 would be rejected during System Update. Well, maybe you are right, but that is how I understand PS3 FW's.
I never knew that about blocked CFW updates. You learn something new everyday.
mckenziesdaddy is online now   Reply With Quote
Old 01-19-2013   #12
NF7
Member
 
Join Date: Sep 2010
Posts: 192
Likes: 1
Liked 37 Times in 30 Posts
Mentioned: 12 Post(s)
Tagged: 0 Thread(s)
Originally Posted by mckenziesdaddy View Post
I never knew that about blocked CFW updates. You learn something new everyday.
Newer FW have new Updater that checks the integrity of the PUP, and the Keys that were used to sign it. That is why, we have the LV0 fully opened, hacked Bootldr, but we still cannot install 4.30CFW from 4.30 OFW, but only from 3.55CFW ... for which we have te Private keys...
NF7 is offline   Reply With Quote
Old 01-20-2013   #13
FaxiY
Member
 
FaxiY's Avatar
 
Join Date: Dec 2012
Location: Germany
Posts: 360
Likes: 4
Liked 43 Times in 39 Posts
Mentioned: 20 Post(s)
Tagged: 0 Thread(s)
Send a message via Skype™ to FaxiY
Originally Posted by NF7 View Post
Newer FW have new Updater that checks the integrity of the PUP, and the Keys that were used to sign it. That is why, we have the LV0 fully opened, hacked Bootldr, but we still cannot install 4.30CFW from 4.30 OFW, but only from 3.55CFW ... for which we have te Private keys...
well but the private keys must be somewhere saved in the PS3?
even if its encrypted it must be able to decrypt it how is the ps3 able to read it without decrypting?

i somewhere read(not sure if its a joke) that you have to rob sony offices to get the keys
__________________
FaxiY is offline   Reply With Quote
Old 01-20-2013   #14
DEFAULTDNB
 
DEFAULTDNB's Avatar
 
Join Date: Mar 2012
Posts: 8,975
Likes: 6,275
Liked 3,862 Times in 2,511 Posts
Mentioned: 954 Post(s)
Tagged: 0 Thread(s)
Originally Posted by FaxiY View Post
well but the private keys must be somewhere saved in the PS3?
even if its encrypted it must be able to decrypt it how is the ps3 able to read it without decrypting?

i somewhere read(not sure if its a joke) that you have to rob sony offices to get the keys
The private keys are not in the PS3.

@NF7 HMAC keys are the ones used in updater IIRC.
__________________
DEFAULTDNB is offline   Reply With Quote
Old 01-20-2013   #15
FaxiY
Member
 
FaxiY's Avatar
 
Join Date: Dec 2012
Location: Germany
Posts: 360
Likes: 4
Liked 43 Times in 39 Posts
Mentioned: 20 Post(s)
Tagged: 0 Thread(s)
Send a message via Skype™ to FaxiY
Originally Posted by DEFAULTDNB View Post
The private keys are not in the PS3.

@NF7 HMAC keys are the ones used in updater IIRC.
how is it possible that the PS3 checks a FW before updating without the private keys? it must be somewhere saved the console has to compare the keys with the FW-update?

FWs are signed with private keys and the PS3 has to compare it with something in the PS3 itself to check if its official or not
__________________
FaxiY is offline   Reply With Quote
Old 01-20-2013   #16
donkey-punch
Senior Member
 
Join Date: Jul 2012
Posts: 1,057
Likes: 71
Liked 255 Times in 204 Posts
Mentioned: 45 Post(s)
Tagged: 1 Thread(s)
Originally Posted by FaxiY View Post
well but the private keys must be somewhere saved in the PS3?
even if its encrypted it must be able to decrypt it how is the ps3 able to read it without decrypting?

i somewhere read(not sure if its a joke) that you have to rob sony offices to get the keys
The keys are not in the ps3 hence you have to hold trusted Sony employees at knife point to obtain them. But if you can break an ecdsa signature you can avoid the threats with the knife. IMO an exploit is the likely solution, and you have to remember kakarotoks tried in vein to find an exploit (miss guided by the bool shyt merchant math) and found nothing. Most likely their wil be some way to exploit something that was coded by a human, but finding somebody with the talent and enough spare time on their hands and desire to work on it is as likely as you finding the exploit. Just my tuppence worth.
donkey-punch is offline   Reply With Quote
Likes: (1)
Old 01-20-2013   #17
FaxiY
Member
 
FaxiY's Avatar
 
Join Date: Dec 2012
Location: Germany
Posts: 360
Likes: 4
Liked 43 Times in 39 Posts
Mentioned: 20 Post(s)
Tagged: 0 Thread(s)
Send a message via Skype™ to FaxiY
Originally Posted by donkey-punch View Post
The keys are not in the ps3 hence you have to hold trusted Sony employees at knife point to obtain them. But if you can break an ecdsa signature you can avoid the threats with the knife. IMO an exploit is the likely solution, and you have to remember kakarotoks tried in vein to find an exploit (miss guided by the bool shyt merchant math) and found nothing. Most likely their wil be some way to exploit something that was coded by a human, but finding somebody with the talent and enough spare time on their hands and desire to work on it is as likely as you finding the exploit. Just my tuppence worth.
but how is the PS3 checking if the FW update is official or not?
__________________
FaxiY is offline   Reply With Quote
Old 01-20-2013   #18
donkey-punch
Senior Member
 
Join Date: Jul 2012
Posts: 1,057
Likes: 71
Liked 255 Times in 204 Posts
Mentioned: 45 Post(s)
Tagged: 1 Thread(s)
Originally Posted by FaxiY View Post
but how is the PS3 checking if the FW update is official or not?
Because it is signed with private key. Private being the operative word. Sony's private key is protected by an ecdsa signature. It is the most dominant key so to speak. If the ecdsa signed private key says the pup is good to go then the console will swallow the information provided. The priv that was generated by failoverflow is listed as fake so to speak (or generated) therefore visible to Sony security and black listed. I'm half drunk now and could be wrong but pretty sure I'm not.
donkey-punch is offline   Reply With Quote
Old 01-20-2013   #19
FaxiY
Member
 
FaxiY's Avatar
 
Join Date: Dec 2012
Location: Germany
Posts: 360
Likes: 4
Liked 43 Times in 39 Posts
Mentioned: 20 Post(s)
Tagged: 0 Thread(s)
Send a message via Skype™ to FaxiY
Originally Posted by donkey-punch View Post
Because it is signed with private key. Private being the operative word. Sony's private key is protected by an ecdsa signature. It is the most dominant key so to speak. If the ecdsa signed private key says the pup is good to go then the console will swallow the information provided. The priv that was generated by failoverflow is listed as fake so to speak (or generated) therefore visible to Sony security and black listed. I'm half drunk now and could be wrong but pretty sure I'm not.
hmm okay i somehow understand a bit how ECDSA works

http://kakaroto.homelinux.net/2012/0...gorithm-works/

to guess the private key isnt possible because it has 49 digits :D
__________________
FaxiY is offline   Reply With Quote
Old 01-20-2013   #20
digiprog
Member
 
digiprog's Avatar
 
Join Date: Nov 2012
Location: tripoli, lebanon
Posts: 208
Likes: 59
Liked 33 Times in 27 Posts
Mentioned: 8 Post(s)
Tagged: 0 Thread(s)
Originally Posted by FaxiY View Post
hmm okay i somehow understand a bit how ECDSA works

http://kakaroto.homelinux.net/2012/0...gorithm-works/

to guess the private key isnt possible because it has 49 digits :D
haha 49 ?? damn that means about 680bit !!!
************* [ - Post Merged - ] *************
i've found this http://en.wikipedia.org/wiki/Elliptic_Curve_DSA
__________________
NOR Downgrade service in Tripoli, Lebanon: Here
My facebook account: Here
digiprog is offline   Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



PS3Hax.net is Copyright © 2010-2013.
Use of this site is governed by our Terms of Use and Privacy Policy. All Trademarks and images are owned by their respected owners.
Posts and links are subject to each author on this forum and are no way affiliated with the operations and/or opinions of ps3hax.net
All times are GMT -5. The time now is 08:19 PM.