Hacking the PS Vita(yifan.lu)
yifan.lu
Hacking the PS Vita
https://yifan.lu/2015/06/21/hacking-the-ps-vita/
5 comments
Hello, didn't expect to see this here. I'll be happy to answer any question as I refrained from giving deep technical details in the article. I'm surprised at how secure the Vita is given Sony's track record. I would say that the Vita is the most secure consumer embedded device that's out today.
First off that was a fascinating read. Thanks.
> I would say that the Vita is the most secure consumer embedded device that's out today
It's really disappointing in some ways. The PSP made for a great portable media/emulation platform and the additional power of the Vita would have been welcome for those purposes. But it's buttoned up incredibly tight, so mine just sits as a paperweight because there are very few Vita games that interest me.
> I would say that the Vita is the most secure consumer embedded device that's out today
It's really disappointing in some ways. The PSP made for a great portable media/emulation platform and the additional power of the Vita would have been welcome for those purposes. But it's buttoned up incredibly tight, so mine just sits as a paperweight because there are very few Vita games that interest me.
How does the Vita compare to the 3DS with regards to security and -- from a developer's point of view -- overall system architecture?
How detailed do you want me to get? I've hacked both of them so I can give you as much info as you want. From a broad perspective, Vita has KASLR/ASLR, stack canaries, trustzone, just to name a few standard things that 3ds doesn't have. Overall the 3ds is pretty much "hacked" (only a couple of components are still secured including bootrom and aes engine). Vita is not even hacked at a kernel level yet.
I didn't expect to see this OR you here! I read gbatemp/wololo/hn about every hour most days and it's weird to see both worlds come together (in some small way). Congrats on all your work to date and look forward to seeing more from you in this space!
> I would say that the Vita is the most secure consumer embedded device that's out today
Moreso than the PS4 and XBONE?
Moreso than the PS4 and XBONE?
Or the 3DS.
It's funny, when it's our personal data or credit card numbers, they can't seem to manage the most basic of security procedures. Yet when it's DRM and they want to prevent unauthorized third party code from running (because they can't take their 60% cut), suddenly they're masters at sandboxing.
It's funny, when it's our personal data or credit card numbers, they can't seem to manage the most basic of security procedures. Yet when it's DRM and they want to prevent unauthorized third party code from running (because they can't take their 60% cut), suddenly they're masters at sandboxing.
> suddenly
Ignoring the Gameboy, Gameboy Pocket, Gameboy Color, Gameboy Advanced, Gameboy Advanced SP, Gameboy Micro, all the various combinations of those machines, and then the Nintendo DS and combinations.
They've never been friendly to homebrew, but after DS flash cards it's not surprising they tightened things up.
Ignoring the Gameboy, Gameboy Pocket, Gameboy Color, Gameboy Advanced, Gameboy Advanced SP, Gameboy Micro, all the various combinations of those machines, and then the Nintendo DS and combinations.
They've never been friendly to homebrew, but after DS flash cards it's not surprising they tightened things up.
Suddenly as in compared to securing customer data, not their previous consoles. Suddenly was used to indicate the contrast between their efforts and abilities in securing various segments of their platform.
The difference between a profit center and a cost center, I guess. It costs money to secure a bunch of systems that process credit card data or other stuff; it profits to be able to take that 60% cut.
Typical system behavior. Tax offices are uber fast at cross relating shallow data to spot potential fraud, but coudln't help you fill some form to save their life.
Well I don't consider them embedded, but I would say yes for the PS4. I haven't looked at the xbone yet so I can't say anything for that. PS4 uses FreeBSD9 as its kernel. Plus there is no KASLR. In theory, if you find an exploit in freebsd, you can exploit the ps4. Some people already got some kernel memory leaks to work. Meanwhile, the vita uses a custom os built from the PSP but is vaguely similar to it (I wouldn't be surprise if it was a complete rewrite).
The only thing standing between anyone executing their code on PS4 or Xbox One is a valid signing certificate. If you had it, or if you could trick the system into thinking it doesn't need one, you could just burn your data to a BD disc, or try running it from a USB stick. On the Vita you don't even have an attack vector. It uses propriatery cards for both games and extra storage,with no commercial readers/writers available. I have a Vita Devkit at work and the only way Sony provides for devs to write/read from these cards is through the devkit itself,it has an extra Mini-USB port to connect to PC through special connection. It's super secure from what it looks like.
Well if I can be pedantic for a second, "valid signing certificate" is much harder to find than any software exploit. In fact if you can find it without physically stealing the certificate, you just broke modern cryptography. And on the vita, if you can sign code, I can load it for you over wifi by faking an update package ;)
Yep, of course - but the PSP was originally broken by tricking the firmware into thinking that literally everything has a valid certificate. MS Pro Duo readers were popular, you could easily grab the eboot.pub and modify it yourself. With the Vita, if you haven't got a devkit you don't even know what the file layout on the memory card looks like.
Even if you had a devkit, you still won't know. The devkit is just as sandboxed and there's an additional processor whose sole job is to enforce security on the debugger and PC communications.
Really? My devkit just shows the memory card as another storage device when I plug it in, I can freely copy files to/from it. But granted, I only had to use it a few times, mostly work with PS4/X1 nowadays, so maybe I have missed something.
Does Sony reach out to developers in the scene to employ them to make their next console harder to hack?
No, typically Sony is hostile towards hackers. Being ignored is the best response from them. I think after the bad press for PS3 and psn hacks, Sony hired security consultants to secure the Vita. They did so many things right that frankly it's suprising. Not everything rolled over into the ps4 though so the vita is more secure than the ps4.
They famously sued geohot (and others) for their work on the PS3. [0]
[0] https://en.wikipedia.org/wiki/Sony_Computer_Entertainment_Am...
[0] https://en.wikipedia.org/wiki/Sony_Computer_Entertainment_Am...
Are we some day going to see the same activity in Homebrew on the Vita as we saw it on the PSP?
I hope so. But the cynic in me thinks think there won't be as much work because now most people who would work on homebrew games and emulators are now coding for smartphones and tablets. However, by getting an open sdk started and releasing a public exploit for developers (honestly it's not user friendly enough for everyone), I'm hoping the scene will finally get a jump start.
I only bought a DS when there was homebrew available - or at least the possibility of "Hello World". Is the Vita at that point now? Do I have to search eBay for an old Vita or will the newest ones work?
Don't bother. But to answer somewhat your question: You should look for one with a game on it, which is known to be usable for hacking. Those games are mostly pulled from the store and not available anymore.
In a sense we already literally do: the only working exploits (that I know of, it's been a while since I checked) involve the PSP emulator on the system. So you have the same activity insofar as you can run the exact same homebrew :P
I've noticed a dramatic rolloff in homebrew scene activity since the rise of smartphones and the like, at least in portables. Part of this is due to the (more) open nature and ubiquity of smartphones, but also due to proprietary consoles getting more and more boring.
The Nintendo DS homebrew community was very active, with a well-supported toolchain. The NDS was a neat piece of hardware - the graphics system was inherited from the GBA, which bears many similarities back to the original Gameboy and the NES. It's probably the last console produced with the concept of tilemaps and sprites. You also got a fast CPU, two screens, and a touchscreen, three years before the iPhone.
Now, today, portable game consoles are basically underpowered smartphones. Perhaps the 3DS is a bit unique due to its screen, but better consumer hardware exists even for that. It's even worse for desktop consoles, which are an AMD APU with no particular merits whatsoever.
The Nintendo DS homebrew community was very active, with a well-supported toolchain. The NDS was a neat piece of hardware - the graphics system was inherited from the GBA, which bears many similarities back to the original Gameboy and the NES. It's probably the last console produced with the concept of tilemaps and sprites. You also got a fast CPU, two screens, and a touchscreen, three years before the iPhone.
Now, today, portable game consoles are basically underpowered smartphones. Perhaps the 3DS is a bit unique due to its screen, but better consumer hardware exists even for that. It's even worse for desktop consoles, which are an AMD APU with no particular merits whatsoever.
> Now, today, portable game consoles are basically underpowered smartphones.
With the notable addition of good physical controls
With the notable addition of good physical controls
Having good physical controls is not so hard to get on smartphones [1]. If smartphone manufactures wanted to make their device better for gaming, they'd just need clips for common controllers and make the wired and wireless connection work.
http://buy.thegameklip.com/products/gameklip-casemount
http://buy.thegameklip.com/products/gameklip-casemount
That does kill the portability aspect though.
Yes, you are right, that specific linked gadget kills portability to a large degree. However, there speaks nothing against making a gamepad more specific to this use-case so you have better portability. Of course this approach will not be as good as dedicated controllers on the device itself, but I think it would be enough.
One might argue that good physical controls just don't matter that much for the audience that casually plays a game on the train.
But one might also argue that those weren't the people who were interested in home-brew on a portable game console
Site down, here is cache: https://archive.is/TTR4f
Great to see follow-ups like this.
I was involved in the old PSP homebrew scene; good to see people keeping it alive for more than just playing ripped games.
I was involved in the old PSP homebrew scene; good to see people keeping it alive for more than just playing ripped games.