‹ BackHN Continuity

Thread

PS5 Relapse Exploit

351 points · 254 comments · therepanic

  1. Muromec · · focus · HN ↗
    If I know anything about those communities, they sit on a bag of zero days and another bag of leads to zero days in the bootloader or whatever everjail they need to break out of.
    1. MBCook · · focus · HN ↗
      I saw a post from someone who worked in the scene recently, seems they were someone famous. I don’t follow things so I’m not sure. Basically they were giving up because new people to the scene were just discovering things with AI and then immediately disclosing them to the world, allowing Sony to patch them before they really got used.

      It sounded like things may have changed.

      1. arprocter · · focus · HN ↗
        Might've been 'PS5 Linux lead quits: "a bunch of noobs using LLMs" that "they don't understand"'

        <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49727627">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49727627

        1. MBCook · · focus · HN ↗
          I didn’t see it here, but I do believe that’s it!
      2. Synthetic7346 · · focus · HN ↗
        Sucks for the hoarder, but that is indeed how bug bounties are supposed to work. The first reporter gets the payout, disincentivizing sitting on valid vulns.
        1. nicce · · focus · HN ↗
          I think the hoarder just wanted to have rooted PS5
        2. alias_neo · · focus · HN ↗
          Unfortunately the goal here wasn&#x27;t to get the bounty, it was to keep it out of the hands of Sony who&#x27;ll patch it.

          The issue, as I understood it in this case was that he wanted it kept quiet until GTA6 launches, because announcing it to the public also announces it to Sony, and they&#x27;ll patch it; normally that&#x27;s fine, everyone just doesn&#x27;t update, but given GTA6 is apparently quite popular, my understanding is that he wanted to let everyone get that one last update that allows GTA6 to run before they&#x27;re stuck on that version.

          1. MBCook · · focus · HN ↗
            That was my sense. It takes time to figure out how to use a bug as an exploit.

            So normally if the community found this stuff I guess they’d work together to make a jailbreak. Maybe they already were working on that with bug X but hadn’t told anyone.

            The JoeClaudeUser posts publicly “Hey everyone I found bug X over here! I’m awesome!”.

            Now it can’t be used because Sony will fix it. If they had already been using it behind closed doors all that work is flushed.

            1. alias_neo · · focus · HN ↗
              That&#x27;s exactly how I understand it, and from further reading, it seems Sony has now patched it already so it&#x27;s game over.
              1. MBCook · · focus · HN ↗
                Makes sense. In their position it would be stupid not to.
                1. mrheosuper · · focus · HN ↗
                  I bet my $5 they already knew about that exploit, but no one made &quot;official&quot; report it, so they can turn the blind eye.

                  &quot;PS5 running Linux&quot; was hot news months ago.

              2. doctorpangloss · · focus · HN ↗
                There&#x27;s no logic to any of it, Sony can run LLMs too!
                1. worthless-trash · · focus · HN ↗
                  Yes. But that is work, time and money.

                  They don&#x27;t want to sacrifice any of that.

          2. cyberrock · · focus · HN ↗
            While he&#x27;s a legend in Vita and PS4, he&#x27;s also reported many PS4&#x2F;PS5 exploits to Sony before [0] [1] so I&#x27;m not really sure what his point is.

            [0] <a href="https:&#x2F;&#x2F;hackerone.com&#x2F;reports&#x2F;826026" rel="nofollow">https:&#x2F;&#x2F;hackerone.com&#x2F;reports&#x2F;826026

            [1] <a href="https:&#x2F;&#x2F;hackerone.com&#x2F;reports&#x2F;1379975" rel="nofollow">https:&#x2F;&#x2F;hackerone.com&#x2F;reports&#x2F;1379975

          3. bsimpson · · focus · HN ↗
            Can you still access Sony&#x27;s servers (e.g. to buy games, collect achievements, etc) on crackable versions of the system software?

            I&#x27;d expect you&#x27;d have to play offline, which might be a nonstarter when the disc drive costs extra, and live service games are popular.

            1. klausa · · focus · HN ↗
              GTA6 will not have a disk release, which is why this is important for some people.
              1. prmoustache · · focus · HN ↗
                And people expect to have a decently working release from day1?

                Not a big player myself, and I mostly play older game I can buy for less than $15 but every single time I have heard about a big game launch in the last decade, the games were released in early beta quality, crippled with bugs according to the tests and news.

                1. klausa · · focus · HN ↗
                  You hear about them _because_ they launched in a poor state; not because _every_ game launches like this.

                  Yes; there have been some pretty high profile cases of games launching in terrible state, and Day 0 patches have become an industry standard, but acting like all (or even most) of big games launch like this is just sampling bias.

        3. kevin_thibedeau · · focus · HN ↗
          Plot twist: They&#x27;re actually TLA staffers who don&#x27;t want their backdoors burned.
          1. MBCook · · focus · HN ↗
            Those highly valuable PS5 exploits for spying on foreign leaders?
            1. kevin_thibedeau · · focus · HN ↗
              Their kids&#x27; console will be on the home network if they don&#x27;t have someone competent managing their security.
      3. ctippett · · focus · HN ↗
        I noticed this exact flavour of frustration in the webOS jailbreak scene. Some newcomer proudly announced a vulnerability they found only to be met with hostility because it was seen as premature and unnecessary given there was already an existing jailbreak available that had yet to be patched.
      4. [deleted] · · focus · HN ↗

        [deleted]

      5. captainmuon · · focus · HN ↗
        Instead of being angry with people who publish exploits, they should be angry with Sony for patching the exploits or for locking down the console in the first place.

        I am the customer, most people are customers, in an ideal world there would be customer protection laws serving us and not the content industry. But that is not how laws work. Realizing this actually radicalized me.

        1. KeplerBoy · · focus · HN ↗
          They should be angry at sony? wtf?

          It&#x27;s literally their job to keep their consoles safe, this is not just about piracy. A vulnerable console could do all kinds of stuff users don&#x27;t want.

          Then also piracy: The game industry is already struggling, good luck explaining that one of the rare non live service offline single player games (after all those are the games most hurt by piracy), which has been in development for years, didn&#x27;t sell because you left a disclosed exploit wide open and now everyone loses their jobs.

          1. Cpoll · · focus · HN ↗
            It is just about piracy. Sony&#x27;s repeatedly demonstrated they don&#x27;t care about their users&#x27; safety (see: numerous high profile data leaks), and these bootloader exploits aren&#x27;t the sort of thing a virus can exploit.
          2. captainmuon · · focus · HN ↗
            Sony is totally in their right to act this way, it makes business sense for them, and I would do the same in their position. Customers do benefit e.g. from working anti-cheat, subsidized consoles, offline play etc.

            But does that mean I have to like it? No, of course not!

            Would I prefer to have root on my own machines to do whatever I want with them, knowing that it conflicts with other people&#x27;s interests? Sure.

            I guess my point is: If you treat the status quo as a fact of nature, non-negotiable, then you direct your anger at your peers. You can&#x27;t change Sony or how society works, but you can yell at people on X. If you realize Sony is also just people and everything is in principle negotiable, then... well it is actually pretty silly that there are some people spending a lot of time building these baroque ultra-secure systems, and other people spending a lot of time cracking them (and bickering with each other) - where they could all just, I don&#x27;t know, not do that.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.