• Home
  • Downloads
  • EBOOT Fixes
  • Forums
  • New Posts
  • Register
    • Welcome, Register Now! 
    • Premium VIP Membership
    • PS3 Sticky
      • PS3 CFW & MFW
      • PS3 Debug Firmware
      • PS3 Decrypted PSN Links for CFW
      • PS3 Downloads
      • PS3 EBOOT.BIN Original File Links
      • PS3 Firmware
      • PS3 Game Releases List
      • PS3 Guides & Tutorials
      • PS3 Hacking Guides and Tutorials
      • PS3 Hacks & JailBreak
      • PS3 Help & Support
      • PS3 JailBreak Game Compatibility List
      • PS3 JB2 / True Blue (TB) Game Links
      • PS3 multiMAN Updates
      • PS3 Resources
      • PS3 Reviews
      • PS3 Save Files Repository
      • PS3 Themes
      • PS3 Trophies List
      • PS3 Videos
      • PS Vita Trophies List
    • Quick Links
      • Affiliates
      • Contact Us
      • FAQ
      • Post News
      • Site Rules
      • Tag Cloud
 

Video: PS Vita Content Manager and Security Concerns of Wololo

Category: PSP & PS Vita News  By: smokyyuwe - (wololo.net)
Tags: video ps vita content manager ps vita security concerns ps vita hax ps vita hacks wololo

73w ago - Following up on the PS Vita HBL Demo, today PlayStation Vita hacker wololo has shared details on the PS Vita Content Manager and the related security concerns as outlined below.

To quote: A few days ago I posted my concerns about the “Content Manager” tool, a tool that is compulsory to install and use if you want to copy files from and to your vita. Some people said I was paranoid (see my answer to that at the end of the article), and others shared my concerns and started digging. Interestingly enough, that article gathered almost as much attention as my much more spectacular (in my opinion) video of a Megadrive emulator running on the vita.

Some sites took my words out of context and said that I had proof Sony is spying on us when we copy files. This is not true, I don’t have any proof, just lots of concerns. Because of that I decided to call Sony’s customer service in order to get more information. Read along.

First of all, a piece of relatively good news: some users on French site psvitagen mentioned that it is possible to copy Movies and Music without being connected to the internet, through the dedicated “Music” and “Movie” sections of the vita.

I confirmed this is true, so movies, music and pictures can still be copied to the vita even without an internet connection. The internet connection is however, as far as I can tell, required to copy anything else, which, given the limited possibilities of the vita, basically means PSP/Vita games and/or savedata.

In theory and from what I saw so far, the internet connection is probably used for two things: check for new versions of the firmware (an update was enforced on me if I wanted to keep using the content manager 2 days ago), and possibly do some DRM verifications. That’s the theory, and is somewhat confirmed by some early investigations of the binary by dev Hykem.

So, when you copy it to your vita, Sony checks that your Vita game or your Sony-purchased movie is actually “ok” to play on your vita, to make sure you didn’t steal it or copied it from a friend’s computer. Fair enough (although I would question why this check needs to be done there, rather than directly on the vita). But what happens for content that does not require any Sony drm check is my concern.

Even though it’s possible to copy them without an internet connection, does Sony gather any information on my music, my pictures, or my movies (and how about my games savedata, which do require the internet connection while being transferred) ? Do they collect filenames, id3 tag, or exif information? Probably not, but more transparency on the subject would definitely be welcome. This is not about hacking here, this is about sending private information to a company that has proven regularly that they cannot be trusted with our data.

So, full of concerns, I decided to call Sony’s customer service today (actually my wife did it for me...). The person we talked to, as expected, wasn’t a technical person and therefore had close to no information on this. She was aware that an internet connection is required, and mentioned to us that this is written on the manual.

We explained that we knew that, and that we have an Internet connection (it usually takes time when calling a customer service to explain that you don’t have a technical problem using the software, but an ethical one) , but we’d like to disconnect it when it is not necessary, because we don’t see the point in being connected to Sony’s server when we transfer files between two pieces of hardware we own (at which point my wife added: “especially given what happened to your company recently, we’re a bit concerned about our private information“. Hehe, that’s why I love her ).

Understanding our concern the person at the customer service contacted somebody more technical to get more information on the subject. She then came back to us and told us this was in place to make sure that the computer running the content manager is correctly “associated” to the Vita. She didn’t have any technical details to share about the firmware upgrade or the DRM verifications, but she guaranteed us that no personal data was being transferred. She also gave us her name (which I won’t share here) in case we have more questions on the subject (but don’t ask me to call them more, first it’s not a free call, and second I already felt super bad to have my wife spend 30 boring minutes on the phone for me because of my new toy)

(one thing I’d like to say is that every time I contacted Sony’s customer service, their answers were fairly fast and accurate. They usually give me bad news, but they’re doing their best to help. The only time they were completely wrong was when my PSP 1000 stopped accepting connecting to Media Go. They told me it was because the PSP was a Japanese PSP, and I was trying to connect to the European store. I knew this wasn’t true since I had no problem doing the exact same thing with two other PSPs. The real cause was probably that Sony had banned my console for some reason. Anwyays overall thumbs up for the efficiency of the customer service)

So, that’s the official answer, but I’m sure some of us will pass the PC parts of the Content Manager through their microscopes to confirm if this is true. But at least now I have some official information from Sony, which is, in a way, positive. Nevertheless, it does not statisfy my curiosity on some of the files found by Hykem, (such as Mp3Promoter.suprx, png_promoter.suprx, etc… so I’m sure many people will want to learn more about this thing.

Oh, Before I go...

Note: don’t read the section below if you don’t like me when I rant, I know some of you don’t like me when I do that (Spare me the “why do you buy Sony products in the first place?” types of comments if possible, as that’s not the point)

A personal note about why I’m doing all of this, and a message to haters. There’s something interesting about fanboys, no matter how much you show them the truth and give them verifiable proof about it, they’ll always find excuses to justify the illegal behavior of their favorite company. A few days ago I started investigating the insides of the PS Vita. I got HBL to run on it, and was able to run PSP homebrews on the vita. Fanboys told me I would kill the vita because of piracy.

I also raised privacy concerns about the vita “content manager”, a tool that is compulsory to use if you want to transfer some files from and to your vita, and requires you to be constantly connected to the internet while doing so. Again, Sony fanboys told me Sony would never spy on their users, or went Eric Shmidt on me, telling me that Sony probably has good reasons to spy on me in the first place.

Well guess what, champions: my work on the PSP was never used in any way to pirate Sony’s content, because it is not technically doable to do such a thing with HBL. And telling me that Sony would never do something illegal to their users is completely forgetting that they intentionally did so a few years ago with their infamous rootkit.

There’s no historical record of me being a bad guy, I was never sued or sent to jail in my life, while Sony has proven several times to engage in illegal or barely legal activities (see the rootkit case, or the Sony VS Universal studios case), but yet in Sony fanboys’ heads, I am the one with a suspicious behavior. Next time you comment on my work, just get your facts straight, not all hackers are promoting piracy, and my work (HBL) cannot be used to pirate games.

I won’t pretend I’m a fighter of freedom or anything, I do this mostly for fun, but I take extra care to do things that are legal, or at least not ethically questionable. The same cannot be said for Sony, so it is perfectly legit to have doubts about the tools they make me install on my machine, even if in the end the suspicions were wrong.

Sony lost their “presumption of innocence” rights years ago, I’d rather assume they’re guilty first, than feel sorry for myself later when the contents of my hard drives get leaked from Sony’s servers by some black hat hacker.









Stay tuned for more PS3 Hacks and PS3 CFW news, follow us on Twitter and be sure to drop by the PS3 Hacks and PS3 Custom Firmware Forums for the latest PlayStation 3 scene updates and homebrew releases!

Comments 188 Comments - Go to Forum Thread »

Errors

The following errors occurred with your submission

Okay

Quick Reply Quick Reply

  • Decrease Size
    Increase Size
  • Wrap [QUOTE] tags around selected text
Posting Quick Reply - Please Wait Posting Quick Reply - Please Wait
Prince Valiant's Avatar
#148 - Prince Valiant - 69w ago
Reply
Indeed, at least he didn't reveal them specifically. I hope the launch firmware isn't very high for the US.

ModderFokker's Avatar
#147 - ModderFokker - 69w ago
Reply
I hope a couple of exploits are kept secret until we actually can buy the damn thing.

(Not talking about import ....)

PS3 News's Avatar
#146 - PS3 News - 69w ago
Reply
Since reporting on his last flaw uncovered, PlayStation Vita hacker SKFU has found a few new vulnerabilities in Sony's PS Vita handheld gaming system.

To quote via http://wololo.net/wagic/2012/01/20/vita-hack-skfu-finds-new-vulnerabilities/#more-3890: Few hours ago, developer SKFU (known for his work on the PS3, but also recently for some investigations on the Vita security) posted a screenshot of his Vita showing some HTML in what is supposed to usually show official messages from Sony’s updates or packages.

Knowing SKFU's passion for everything network-related, I'm assuming he's doing some tests using some local DNS changes... or maybe he managed to put some of his own files in an official package? That would be exciting.

In previous tweets this week, he mentioned he found 2 potentially usable vulnerabilities on the Vita

VITA is back to life, since last tweet found 2 new possibile vulnerabilities. If it runs good, news in blog this evening!

That was, however, 2 days ago, and his blog wasn’t updated since then, so I’m assuming he ran into a few issues. (the “back to life” comment refers to the official 1.52 firmware which bricked his Vita…or appeared to do so... which turned out to be that the battery had to charge for almost 24 hours before the Vita accepting to turn on, for some reason)

Obviously lots of this experimentation will probably not lead to anything, but for now, every bit on info on the internals of the Vita is interesting. Let’s keep digging

Also from SKFU (linked above) is an update on the recent PlayStation Vita 1.52 Firmware status below, as follows:

Ok guys we tested the possibilities on firmware 1.52 for a few days now. What I can confirm is the following:

• Tech4's exploit still works
• Wololo's HBL still works
• Everything I research atm didn't change from 1.50 to 1.52

If that is fine for you, there's no reason not to update. Anyways, I have to mention that this can change without a firmware upgrade!

If you are online with your PS VITA, it can download and install silent updates for any application which runs in usermode and has nothing to do with system critical modules.

The good is, those updates are removed once the system is restored to the current firmware, so it would not be a major problem to remove a fix.

- SKFU


More PlayStation 3 News...

GrandpaHomer's Avatar
#145 - GrandpaHomer - 70w ago
Reply
Originally Posted by Nabnab View Post
Quote I announced this update a week or 2 weeks ago (don't remember)


Wasn't it actually 1.51 as it was released around that time?

Nabnab's Avatar
#144 - Nabnab - 70w ago
Reply
Sony will keep everything secret about the security things or other stuff that the people don't need to know

Page 9 of 38 «‹123456789›LAST »

Related PS3 News and PS3 CFW Hacks or JailBreak Articles

• Grab Killzone: Mercenary a Week Early, Pre-order Bonuses Detailed
• Video: Jacob Jones and the Bigfoot Mystery Camps Out on PS Vita
• Coconut Dodge Revitalised is Coming Soon to PlayStation Vita
• Video: Soul Sacrifice PS Vita: A Sacrificial Q&A With Keiji Inafune
• Video: Muramasa Rebirth: Seek the Demon Blade on PlayStation Vita
• Video: Media Molecule Reveals Tearaway PS Vita Pre-Order Extras
Affiliates  NewsNow  Privacy  PS3 CFW & MFW  PS3 Hacks & JailBreak  PS3 Reviews  PS3 Videos  © 2013 PlayStation 3 News

PlayStation 3 Links

• Contact Us E-Mail
• PS3 Affiliates
• PS3 CFW & MFW
• PS3 Debug Firmware
• PS3 Decrypted PSN Links for CFW
• PS3 Downloads
• PS3 EBOOT.BIN Original File Links
• PS3 Firmware
• PS3 Game Releases List
• PS3 Guides & Tutorials
• PS3 Hacking Guides and Tutorials
• PS3 Hacks & JailBreak
• PS3 Help & Support
• PS3 JailBreak Game Compatibility List
• PS3 JB2 / True Blue (TB) Game Links
• PS3 multiMAN Updates
• PS3 News Forums
• PS3 News Site FAQ
• PS3 News Site Advertising FAQ
• PS3 News Site Posting FAQ
• PS3 News Site Privacy FAQ
• PS3 News Site Rules
• PS3 News Site Tag Cloud
• PS3 News Site Terms
• PS3 Resources
• PS3 Reviews
• PS3 Save Files Repository
• PS3 Themes
• PS3 Trophies List
• PS3 Videos
• PS Vita Trophies List

PlayStation 3 News Discussions
PSN Games Decrypted for PS3 Custom Firmware 3.55 by DUPLEX! - 7m ago

xchris5's Avatar
Quote thanks salam maleikum...
By xchris5 with
 8161 Comments »
PSN Games Decrypted for PS3 Custom Firmware 3.55 by DUPLEX! - 30m ago

AdilAliraqe's Avatar
Quote http://www.gulfup.com/?Oe5qkI...
By AdilAliraqe with
 8161 Comments »
does anybody know when does rogero 4.41 come? - 1h ago

panosp's Avatar
Quote i am really sorry for writting about the same issue twice. i dont want to use rebug. is there anybody tha knows exactly when rogero releases his cfw...
By panosp with
 0 Comments »
PSN Games Decrypted for PS3 Custom Firmware 3.55 by DUPLEX! - 2h ago

xchris5's Avatar
Quote BLES01773-(EURO) can you upload the resident evil fix again please because its down thanks...
By xchris5 with
 8161 Comments »

Latest PlayStation 3 Trophies
Call of Juarez: Gunslinger: Keep At It
Call of Juarez: Gunslinger: True Story
Call of Juarez: Gunslinger: Grows In The Telling
Call of Juarez: Gunslinger: Turkey Shoot

Latest PlayStation Vita Trophies
Men's Room Mayhem: Toilet Trouble
Men's Room Mayhem: Mayhem Master
Men's Room Mayhem: Hygiene Award
Men's Room Mayhem: Sand in the Face

Latest PlayStation 3 Releases
Resident Evil Revelations PS3-ANTiDOTE - 05-19-2013
Muvluv Alternative Total Eclipse JPN PS3-HR - 05-17-2013
Skate 2 EUR PS3-Googlecus - 05-16-2013
The Walking Dead A Telltale Games Series PS3-COLLATERAL - 05-15-2013

Latest PlayStation 3 Themes
Wolverine Origins PS3 Theme - 05-19-2013
Heavy Rain (Official) Dynamic PS3 Theme - 05-09-2013
Wipeout HD Fury Dynamic PS3 Theme - 05-06-2013
Batman Arkham City Dynamic PS3 Theme - 05-04-2013
  • Contact Us
  • -
  • PS3 News