Feeds

'Regular' PS3 gamers who've cancelled credit cards? You FOOLS!

'Network still secure' despite firmware hack and decryption key leak – security expert

Next gen security for virtualised datacentres

The appearance of a Sony PlayStation 3 firmware hack will only affect hardware modders, according to a gaming security expert.

Chinese hacker group BlueDisk-CFW has published a tool that circumvents the console's firmware. This was followed by the release of "LV0 decryption key." The decryption keys allow PS3 firmware packages to be unscrambled on a PC, then re-encrypted with existing firmware 3.55 keys so that they can be run on hacked consoles, as previously reported.

BlueDisk-CFW originally intended to charge for their tool but the release of the decryption key by a separate group called the The Three Musketeers spoiled that plan.

Anyone with a bit of technical skill can get around the restrictions themselves.

Chris Boyd (AKA PaperGhost), senior threat researcher at GFI Software, and an expert in gaming security, said both incidents make little different to regular gamers.

"The only real benefit to this is for those already running custom firmware on hacked machines, who are now able to update their PS3 and go online. While they may be able to play games online until Sony change the PSN passphrase, it's unlikely to cause a wave of in-game cheating and modding."

Boyd added that the firmware hack has no bearing on the security of the Playstation Network itself.

"The Playstation Network itself is still secure and users shouldn't panic. I've already seen one person say they cancelled their credit card as a result of thinking the PSN had been compromised (it hasn't). With the PS4 on the horizon, this may prompt SONY to speed up work on the upcoming console."

The arrival of the firmware hack coincides with a ruling by a US judge that the notorious Sony PlayStation Network hack of May 2011, which left millions unoable to play online games for weeks, provides insufficient grounds for a class action lawsuit. ®

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
prev story

Whitepapers

Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up distributed data
Eliminating the redundant use of bandwidth and storage capacity and application consolidation in the modern data center.
The essential guide to IT transformation
ServiceNow discusses three IT transformations that can help CIOs automate IT services to transform IT and the enterprise
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.