By using this site, you agree to our Privacy Policy and our Terms of Use. Close

Forums - Sony - MUST READ: Call of Privacy: Modern Spyware by PlayStation Network

Prologue


Due our objective research of the SONY PlayStation Network, we decrypted nearly 100% of the traffic transferred over
proxies, http and https to and from the PSN. Just out of curiosity, not to harm anyone or anything and not like SONY may want people to see it.

As SONY calls the scene hackers "evil", we surely do not address pirates and skiddies, we wondered how SONY is treating the users' privacy and rights (remember the Music CD/DVD and USB stick rootkits). After we noticed a few badass functions they have built into the PSN/PS3 functionality, we just call it the "Call of Privacy: Modern Spyware" case.

Below we list and explain a few of the shady PSN functions and data mining stuff. And remember: EVERYONE has a right to know about YOUR OWN PRIVATE data being transferred over the networks !

Sensitive data


Even if a connection is SSL encrypted, companies are aware of the big risk behind custom CA files and it's possibilities.
SONY seems not to care about those known vulnerabilities. It is a big company and a HUGE network. With huge we mean a magnitude of hundreds and even thousands: the PSN utilizes thousands of servers, handled by a very small group of administrators and quality assurance people. The IP ranges and domains of these servers are retrievable by anyone, cause this is how the Internet works ! It is all public data and information !

An example is the credit card information and the login authentification itself. Take a look at the traffic:


creditCard.paymentMethodId=CC_COMPANY&
creditCard.holderName=EXAMPLENAME&
creditCard.cardNumber=1234567890123456&
creditCard.expireYear=2012&creditCard.expireMonth=2&
creditCard.securityCode=123&
creditCard.address.address1=EXAMPLESTREET 24 &creditCard.address.city=EXAMPLECITY &
creditCard.address.province=EXAMPLEREGION &
creditCard.address.postalCode=12345
The credit card information should ALWAYS be encrypted. In ANY case. At least the security code. SONY is only relying on it's https connection. With all those CFWs spreading around, this is not secure anymore.
Same goes for the user details:
serviceid=IV0001-NPXS01001_00&
loginid=example@mail.com&
password=examplepassword&
first=true&
consoleid=EXAMPLEID123


Such sensitive data can now be captured by anyone who builds his own custom firmware with custom certificates. There are enough n00b-friendly tools by now. Means, little scriptkiddies can spread their little CFWs and phish user data. As many of these people are using a third party DNS, they are a potential victim of phishing. At the beginning of the PS3 launch, this user data was even transferred over http !

Information gathering


The PlayStation Network agreement states that SONY is allowed to collect nearly any data that is connected with your
privacy.It is clear, that SONY won't tell you WHAT they are collecting in the TOS etc., as many people would never accept that TOS.

A few month ago we noticed the TOS silently beeing updated without a new user agreement request. It was about that you have the right to contact a "Data Protection Offier" at SCEE, who can can give you details about what data is collected. So we phoned SCEE. Beeing forwarded to many people, it turned out that there is no so called "Data Protection Officer". Funny right? Shortly after this call, the clause was removed from the TOS.


SONY itself told us, that they do not know, what we are talking about regarding this Officer. They told us, that there was never such a position inside SONY, neither a phone number. Even the address was non existing !
Still it is an impudence what huge amounts of data they are collecting. One example is an information list which is transfered everytime you login the PSN as well as at some random time. A few short quotes:


<info category="76">TFT-TV</info><info category="77">


This is a string sent to SONY which includes your TV model. The list is long and contains a lot more like information about attached USB devices, your home network, your playtime behaviour, installed games, apps, homebrews or their so called "circumvention devices" and so on. Details about your Home network, statistics etc.
Modern user tracking we guess They try to make every PSN user transparent like a glass figurine. It seems that not only the governments are going for such plans.

The BANHammer

Now SONY is swinging the "mighty" banhammer. Some users are banned, some are only warned. But who warns SONY? Their semi-legal tactics against the enduser are a joke. We again remember their rootkits on Audio Media and USB Sticks. Just for your interest, we quote a guy from SONY: Thomas Hesse, President of Sony's Global Digital Business, literally says: "Most people, I think, don't even know what a rootkit is, so why should they care about it?"

This is not an urban legend -> http://www.techdirt.com/articles/20051108/0117239_F.shtml

So we could take this for an example and say: "Most people inside SONY don't even know what security is, so why should they care about it?" If SONY cares about their customers, why are they treating them like totally douchebags ? Of course the quote does not reflect the view of the company itself, but HELL, this was not from a Jon Doe inside SONY, it was from a Department's President !


The PSN is a core feature of the PlayStation3, like OtherOS was. So why do they ban the PSN of users who LEGALLY run  homebrew (not backups!) on their consoles? Just because they do not like it? It is a fact that reversing a system is legal in most countries all over the world, and if someone who really only wants to run his own code (no, not backups!), which he legally signed and coded without any SONY libraries or documentation, would sue SONY, they would may lose. Reverse engineering is also allowed for analysing purposes. E.g. is a software/hardware implementing/running, rootkits, spyware, malicious code, security flaws, transferring privacy data and so on. Imagine if this wouldn't be legal, any antivirus software would brake the law ! The companies of antivurus software are reverse engineering virus code, that is NOT copyrighted by them !

So why are those companies allowed to RE and even PUBLISH their findings to the public but not people like fail0verflowetc. ? By studying the PSN since it's launch we know it's vulnerabilities pretty good right now and unbanning consoles might be as easy as banning consoles. It is an infinite circle of "who-is-better".

Sony just can not, or just don't want to, make a clear distinction between pirates&skiddies and hackers, who only want to OWN and UTILISE what they OWN and PAID for. Hackers are responsible for creating stuff like the PC, Unix, Windows, Macs, the Internet, the WWW, AAA games etc. Guess what IBM is calling their Cell/Hypervisor docs ?


This document is intended for programmers who wish to discuss the code of the Research Hypervisor Project. It also
attempts to introduce the hopes and dreams of the maintainers of the code that, hopefully, will make those dreams a reality.
http://www.research.ibm.com/hypervisor/HackersGuide.shtml

One last thing: Our research is based on PUBLIC information, Hardware/Software we OWN and PAID for and the right for our PRIVACY to be PROTECTED !

http://ps3crunch.com/wp-content/uploads/2011/02/psn.pdf

Sorry about the formatting, its from a PDF



Around the Network

if you care for anyone to read this i suggest you format the text asap.



You do realize that no1 can get on psn with custom firmware so your credit card numbers are safe, until atleast one confirmed report of someone getting a credit card number off psn I think it's pretty much a non-issue as for the spyware everyone does it, you don't want to know what spyware is on your PC as for the whole banning legit homebrew from psn, how is Sony suppossed to tell a homebrew game from a program designed to steal peoples credit cards? If someone wants to do whatever they want with something they bought they run the risk of losing all support from the manufacturer and thats the case here, it's no surprize 



I just can't believe they request for the tv you use!



Sony be puttin they software on they hardware? Oh, hell no! /angryheadwobble



Around the Network

only parts that worry me is the uncrypted nature of information being passed back to Sony and what exact details about my home wireless network and what it contains is being transmitted.

i.e. Do they take my network id/pw? files on my shared computers? etc.



sully1311 said:

I just can't believe they request for the tv you use!

Why wouldn't they, they are in the tv business 



superchunk said:

only parts that worry me is the uncrypted nature of information being passed back to Sony and what exact details about my home wireless network and what it contains is being transmitted.

i.e. Do they take my network id/pw? files on my shared computers? etc.


Ya, thats a bit worrying. And they call piracy an issue. The fact at the beginning all this went to a server with an http address let alone now an https address is horrifyingly horrid security measures to say the least. I'd basically recommend anyone who owns a PS3 trade their crap in for a 360 or Wii knowing this information or remove all important data like CC details and all that off the PSN at minimum.



PC gaming is better than console gaming. Always.     We are Anonymous, We are Legion    Kick-ass interview   Great Flash Series Here    Anime Ratings     Make and Play Please
Amazing discussion about being wrong
Official VGChartz Folding@Home Team #109453
 
Demonslayersoultaker said:
sully1311 said:

I just can't believe they request for the tv you use!

Why wouldn't they, they are in the tv business 


what does it matter? are the going to start banning users for using anything other then a Sony TV? It's information that does not pertain to anything Sony is doing in the Networked Devices Division of Sony.



PC gaming is better than console gaming. Always.     We are Anonymous, We are Legion    Kick-ass interview   Great Flash Series Here    Anime Ratings     Make and Play Please
Amazing discussion about being wrong
Official VGChartz Folding@Home Team #109453
 
KylieDog said:

"Such sensitive data can now be captured by anyone who builds his own custom firmware with custom certificates. There are enough n00b-friendly tools by now. Means, little scriptkiddies can spread their little CFWs and phish user data. As many of these people are using a third party DNS, they are a potential victim of phishing."

 

So CFW people get scammed?   Terrible....

 

Sony must really worry about that.

My thoughts exactly.

Wooo, distinct between homebrew hackers and pirates who run BACKUPS! What freakin homebrew? There is none yet, everyone is too busy hacking online modes and copying games (ah, and creating new CFW's so that they can continue doing the aforementioned duo).

From the get-go, the PS3 doesn't need that any of that damn *cough* "homebrew". You have a good array of games, right? It's region free, right? You have PS3 media server for all your media needs, right? What else do you need? Emulators? Get them on PC, they are a 1000 times superior to any console emulator (ALL OF THEM). Homebrew games? Don't make me laugh.

Make no distinction, they all deserve their console banned. Got CFW? Face the risks.