• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Anonymous hackers detail PSN privacy concerns (when using CFW)

Status
Not open for further replies.

N.A

Banned
Anonymous hackers have posted a PDF detailing some PSN privacy concerns.

Full PDF: http://demo.ovh.com/download/e1ae850ae75b5410ab7967a9d005ee20/psn.pdf


Prologue
Due our objective research of the SONY PlayStation Network, we decrypted nearly 100% of the traf?c transferred over
proxies, http and https to and from the PSN. Just out of curiosity, not to harm anyone or anything and not like SONY may
want people to see it.
As SONY calls the scene hackers "evil", we surely do not address pirates and skiddies, we wondered how SONY is treating
the users' privacy and rights (remember the Music CD/DVD and USB stick rootkits). After we noticed a few badass functions
they have built into the PSN/PS3 functionality, we just call it the "Call of Privacy: Modern Spyware" case.
Below we list and explain a few of the shady PSN functions and data mining stuff. And remember: EVERYONE has a right to
know about YOUR OWN PRIVATE data being transferred over the networks !


Sensitive data
Even if a connection is SSL encrypted, companies are aware of the big risk behind custom CA files and it's possibilities.
SONY seems not to care about those known vulnerabilities. It is a big company and a HUGE network. With huge we mean a
magnitude of hundreds and even thousands: the PSN utilizes thousands of servers, handled by a very small group of
administrators and quality assurance people. The IP ranges and domains of these servers are retrievable by anyone, cause
this is how the Internet works ! It is all public data and information !

An example is the credit card information and the login authentification itself. Take a look at the traffic:
creditCard.paymentMethodId=CC_COMPANY&
creditCard.holderName=EXAMPLENAME&
creditCard.cardNumber=1234567890123456&
creditCard.expireYear=2012&creditCard.expireMonth=2&
creditCard.securityCode=123&
creditCard.address.address1=EXAMPLESTREET%2024%20&creditCard.address.city=EXAMPLECITY%20&
creditCard.address.province=EXAMPLEREGION%20&
creditCard.address.postalCode=12345%20

The credit card information should ALWAYS be encrypted. In ANY case. At least the security code. SONY is only relying on
it's https connection. With all those CFWs spreading around, this is not secure anymore.
Same goes for the user details:
serviceid=IV0001-NPXS01001_00&
loginid=example@mail.com&
password=examplepassword&
first=true&
consoleid=EXAMPLEID123

Such sensitive data can now be captured by anyone who builds his own custom firmware with custom certificates. There
are enough n00b-friendly tools by now. Means, little scriptkiddies can spread their little CFWs and phish user data.
 
Yeah..I need to remove mine. I never used it but it's on there. Damnit.

Edit: If I remove it is it gone for good? I can remove it right?

Edit 2: Removed.
 

Hanmik

Member
wtf..? when all this CFW started I was worried about my Credit Card being on PSN.. you all laughed at me and told me not to worry... but now this..?
 
sajj316 said:
wtf?????

seriously Sony ... do you even have a security department!

They're too busy suing and threatening people to actually fix this stuff.

Not buying a damn thing from PSN until this issue is resolved. Already removed my CC.
 

MThanded

I Was There! Official L Receiver 2/12/2016
This can be tested easily at home with wireshark. I would like some verification to see if this is actually true. With my current network setup I cannot do it.
 

Plinko

Wildcard berths that can't beat teams without a winning record should have homefield advantage
If this is true this could be grounds for a massive class-action lawsuit, could it not?
 

Massa

Member
Such sensitive data can now be captured by anyone who builds his own custom firmware with custom certificates. There
are enough n00b-friendly tools by now. Means, little scriptkiddies can spread their little CFWs and phish user data.

This is only a problem for people who install CFW, and from unknown sources even.

The connection between your PS3 and Sony is encrypted. Kevin Butler will file this under "Not an issue".
 

MThanded

I Was There! Official L Receiver 2/12/2016
this thread title is incorrect!!!
this thread title is incorrect!!!
this thread title is incorrect!!!




They still use https to transmit the data. The issue is if you have a CFW you can be snooped and your info can be stolen. Unless someone man in the middles your https handshake you are fine. Someone should fix the title.
 

panda21

Member
i'm confused, https isn't plain text, it is encrypted. they are saying that when you decrypt the https, it is plain text? well no shit
 

ElFly

Member
This is amazing.

Doesn't Visa or any of the other credit card houses check for this kind of shit on their end? I mean, they could trivially demand ssl connections for all transactions.

e:eek:h, it goes through https? never mind then.
 

androvsky

Member
Plinko said:
If this is true this could be grounds for a massive class-action lawsuit, could it not?

It's encrypted, via https. Looks like it's only a problem if you install a cfw designed to farm credit card numbers.
 

V_Ben

Banned
panda21 said:
i'm confused, https isn't plain text, it is encrypted. they are saying that when you decrypt the https, it is plain text? well no shit

Heh. I think we're done here.
 

entremet

Member
Not even SSL encryption? Oh, Sony. They really need to get the software side of stuff, including security leveled up. I know they're primarily a hardware company, but Sony's software inexperience as really been showing of late.
 

ChryZ

Member
MThanded said:
this thread title is incorrect!!!1


They still use https to transmit the data. The issue is if you have a CFW you can be snooped and your info can be stolen. Unless someone man in the middles your https handshake you are fine. Someone should fix the title.
This.
 
MThanded said:
this thread title is incorrect!!!1


They still use https to transmit the data. The issue is if you have a CFW you can be snooped and your info can be stolen. Unless someone man in the middles your https handshake you are fine. Someone should fix the title.
mind speaking in non-moon language, is my shit ok if i dont haz cfw? I take it that's a yes, yes?
 
MThanded said:
this thread title is incorrect!!!
this thread title is incorrect!!!
this thread title is incorrect!!!




They still use https to transmit the data. The issue is if you have a CFW you can be snooped and your info can be stolen. Unless someone man in the middles your https handshake you are fine. Someone should fix the title.

Cannot be quoted enough.
 

MThanded

I Was There! Official L Receiver 2/12/2016
entrement said:
Not even SSL encryption? Oh, Sony. They really need to get the software side of stuff, including security leveled up. I know they're primarily a hardware company, but Sony's software inexperience as really been showing of late.
This is why the title needs to be fixed. It is extremely misleading.
 

Adamm

Member
MThanded said:
this thread title is incorrect!!!
this thread title is incorrect!!!
this thread title is incorrect!!!




They still use https to transmit the data. The issue is if you have a CFW you can be snooped and your info can be stolen. Unless someone man in the middles your https handshake you are fine. Someone should fix the title.
Quoted for great justice!
 

Z_Y

Member
I keep thinking about that one guy in the Genesis games/PSN+ thread who told Sony to "Take his money!!!"

PSN keeps delivering! lol haters.


Edit: wonder if this is why Sony is so nutso about stopping CFW?
 

herod

Member
Stored in plaintext is more worrying.

So your card details are just sitting there waiting to be dumped from the PS3 HDD if your system is stolen?
 

Hanmik

Member
MThanded said:
This is why the title needs to be fixed. It is extremely misleading.

thanks for the clarification.. so us non-cfw PS3 users have NOTHING to worry about..? I really hope so..
 

amar212

Member
MThanded said:
this thread title is incorrect!!!
this thread title is incorrect!!!
this thread title is incorrect!!!




They still use https to transmit the data. The issue is if you have a CFW you can be snooped and your info can be stolen. Unless someone man in the middles your https handshake you are fine. Someone should fix the title.

This /Thread.

OP needs correction.
 

androvsky

Member
MThanded said:
this thread title is incorrect!!!
this thread title is incorrect!!!
this thread title is incorrect!!!




They still use https to transmit the data. The issue is if you have a CFW you can be snooped and your info can be stolen. Unless someone man in the middles your https handshake you are fine. Someone should fix the title.

Nobody with cfw is connecting to PSN to buy anything anyway, so I might as well quote this again just for the hell of it. :)
 

V_Ben

Banned
MThanded said:
this thread title is incorrect!!!
this thread title is incorrect!!!
this thread title is incorrect!!!




They still use https to transmit the data. The issue is if you have a CFW you can be snooped and your info can be stolen. Unless someone man in the middles your https handshake you are fine. Someone should fix the title.

Let's go quoting again.
 
Having the root keys on a computer does not break SSL security.

You have admin access on your laptops and computers but you still can't break SSL.

However, installing custom firmware means you are giving complete control over your computer to whoever made the firmware. That's the real security issue not SSL being broken.
 

Owensboro

Member
MThanded said:
this thread title is incorrect!!!
this thread title is incorrect!!!
this thread title is incorrect!!!




They still use https to transmit the data. The issue is if you have a CFW you can be snooped and your info can be stolen. Unless someone man in the middles your https handshake you are fine. Someone should fix the title.

Just quoted again so no misinformation spreads.
 

LiquidMetal14

hide your water-based mammals
LOL so you use CFW and this happens? Or is this for everyone?

ChryZ said:
"PSN transmits your credit card details in plain text."

FUDtastic thread title.
So true. I expected better.
 

Oni Jazar

Member
MThanded said:
this thread title is incorrect!!!
this thread title is incorrect!!!
this thread title is incorrect!!!




They still use https to transmit the data. The issue is if you have a CFW you can be snooped and your info can be stolen. Unless someone man in the middles your https handshake you are fine. Someone should fix the title.

Everyone aboard the jump to conclusions train. Can't wait for the news to hit Kotaku.
 
Does it only transmit when you buy something and/or are signed into PSN?

If so, it's not really an issue, even for CFW users, considering the new measures Sony have taken to keep people off PSN.
 

Plinko

Wildcard berths that can't beat teams without a winning record should have homefield advantage
Good, glad to hear it's only for CFW. That could have been a huge problem.
 
Status
Not open for further replies.
Top Bottom