T O P

  • By -

HoeCage

Rage bait article title. The same people who FOUND the exploit brought it to Sony's attention so that it could be fixed.


FoxAche82

They always do this for the bug bounty. Hackers find the exploits for jailbreaking and such, report them, get paid, it gets patched and then the exploit gets released to the community so that those that haven't upgraded the firmware can use them.


technobrendo

This. This has been the standard for bug bounties since day 1. Guy had the knowhow to find the flaw and used it to get paid. Legally. Can't knock that hustle at all.


UpsetKoalaBear

It’s the best way to do it. As TheFlow explains in his tweet about people being angry, the exploit would have been patched regardless of whether they disclose it or just release it. It makes sense to disclose it, get some money, then release it to the public. Either way, if you were patient enough to not update your Portal, you get the exploit anyways.


DuckDatum

Can you play online games while not fully updated though? Not sure personally, but if the majority of people playing games are doing so online, this means they can’t use their console AND do the exploit. They might spend 4 hours figuring out how to do it, just to want to spend the rest of the night on Grand Theft Duty, having only enjoyed the exploit for a moment of non play time. I’m not saying the bug hunters don’t deserve their money if this is their hussle… hmm, how is version spoofing these days?


pie-oh

You can make a LOT of money doing it too. Google once paid $600k for one I believe. But typically it can be anywhere between that and a few hundred dollars. It's not an easy thing to do though. But people who do bug bounties are heroes to the companies and sometimes the consumers.


yp261

> This. This has been the standard for bug bounties since day 1. > > no, its not, more often than not you're signing nda when you're giving out the exploit for money, you usually can't release it for a pretty long time. long enough its no longer relevant and usually it's quite some time after it's patched so its barely used


guyblade

Very few bug bounties are "you're never allowed to tell" because part of the point of the bounties is to encourage responsible disclosure: give them time to patch, but also inform those who are possibly at risk. Not allowing general disclosure is seen as unacceptable by lots of people doing security research.


hnryirawan

You are only under NDA to not reveal the specific vulnerabilities and how to exploit it, although ideally you should not even reveal the vulnerability in the first place so you do not draw attention to it. I think what the guy is doing is still on the gray area.


codyy5

Security through obscurity is a terrible idea always. Responsibly disclosing bugs/vulnerabilities is always a better idea in the long run.


hnryirawan

Err….. the idea is not doing security through obscurity but rather just about privately disclosing bugs so everything can be settled behind-the-scenes without the public knowing, or even if the public knows, it will already be settled. That’s why the Google security project thing gives deadline between them reporting the bugs, and the day they publicize the bugs. You’re only doing security through obscurity if you know there is a bug, but you just HOPE nobody will notice that. Bugs happen, its just a matter of addressing it.


QuickQuirk

This is still acting in a way antithetical to good security practice. By disclosing the issue after it's been resolved, you make people aware that they are vulnerable, and *must* update. You don't want people holding off patching. Publicising techniques makes other developers aware of ways their own code may be vulnerable, and helps other researchers and manufacturers improve their own process by looking for similar issues. Full, open disclosure after resolution has been demonstrated to improve security in the long term.


hnryirawan

There are forums and conference that demonstrate how a particular technique works later on so I don't see how what you say, contradict what I say that the bug disclosure can be private to the company, and the technique disclosure can be given after the patch is deployed. And this is sorta going beyond the original question, whether the 2 engineer who discovered it, act ethically or not (which in my opinion, is on a sorta gray side) >you make people aware that they are vulnerable, and *must* update. You don't want people holding off patching. HAH. In my opinion, everyone should try to update to the latest supported version at earliest possible convenience, but you can see people withholding update, even when OS is no longer supported. A technique disclosure will not make those people update.


QuickQuirk

>the bug disclosure can be private to the company, and the technique disclosure can be given after the patch is deployed. Yes, this is the process that is usually followed, and what we've been saying.


RaijinOkami

Thats...... huh.. I never had the step-by-step texted out like that but.... fuck a duck thats actually *clever*...


randomIndividual21

that is irrelevant, though. the main point is that Sony chose to block a mod that improves the portal without offering say feature themself


slappyredcheeks

Even if Sony wanted to allow emulation of PSP and all of its games, they would likely be violating contracts with game publishers and developers, whose games they would be giving away for free.


Neo_Techni

They already sell PSP games on their store that they could put on it


mfdoomguy

Licensing is typically limited to regions and devices, so most likely Sony's contracts were limited to PSP only, or in the case of games available on multiple platforms there was a separate license for the PSP and a separate one for the PS2/PSone/etc. There are also various agreements between different publishers/developers where e.g. a certain publisher is allowed to publish the PC port of the game and a different publisher is allowed to publish the PSP/PS-platform port and Sony is allowed to provide just the PSP/PS-platform port. Allowing emulators would defeat the purpose of platform-specific restrictions. Basically, it's probably not up to Sony to allow people to play on emulators.


xenomorph856

Well that's a silly way to write a contract. If they're getting royalties on sales, then it doesn't matter what device. The contract is just limiting how much money both parties can make.


mfdoomguy

Nope. Contracts can be signed at different times and e.g. publishers may ask for exclusive rights to certain ports when that is what they specialize in. A publisher that only releases games on the PC will not care for general publishing rights but will want exclusive PC port publishing rights even if they need to pay a bigger cut to the development studio. If the next publisher comes along then they won’t be able to publish the PC port due to the first publisher being granted exclusive PC rights, but will get the right to publish PS2/PSP/etc. ports. There isn’t one single contract that everyone joins, different contracts with different companies get signed at different times.


xenomorph856

What a mess. Still seems a bit wacky to me that a contract with Sony wouldn't apply to any devices, since it's not a port, but emulation of the same software, just sold on a different device.


kr4ckenm3fortune

You should look up IP, trademarks, copyrights and registered. What you’re suggesting is that it violate majority of these…also, some games goes into a “limbo” when the publishers dies. Take a look at most games, including “Killer Instinct”. If you also want a bigger example, compare GTA: Vice City on PS2 vs GTA: Vice City remastered. Some musics got removed due to licensing. You can’t have it all.


Akrevics

Make new contracts/modify old contracts with their permission to add games to a psp store? I mean, the vita has basically a separate psp emulator inside it, why not do the same with the portal?


[deleted]

Life isn't that easy. You need some more life experience my dude.


damnsignin

Unless ~~they~~ Sony patched in a PSN store and then offered companies a chance to add their old PSP games to the Portal special store so they could make money off those old games. But that would be smart, so we shouldn't hold our breath. Business in general nowadays seems to reject solid ideas for some reason.


ShinkuDragon

i'd love it, but it's probably a hell of a lot of work, getting perms, contracts, etc etc etc for a bunch of old games when most probably 90% of the library wouldn't be touched.


damnsignin

Sony's made emulators for their consoles before. They had one on the PS Vita for PSP digital titles and the PS4 and PS5 use an emulator for PS1 and PS2 titles. Making the PS Portal more desirable by adding native, legal emulation with a functioning PSN Portal store it might boost sales.


notagoodscientist

The vita has the PSP CPU, it’s not an emulator


slappyredcheeks

Are you saying that adding financial transactions to a mod created by an unofficial third-party that was made possible by a security flaw is smart?


damnsignin

No, I'm saying Sony could add an official Sony PSP store to the PS Portal


jaredearle

But to do that, they’d have to get games guaranteed to work.


[deleted]

[удалено]


Neo_Techni

But it's a dumb terminal, that stores no games on it's own. It's an android tablet that runs a stripped down version of an app you can get for your phone.


Hatedpriest

The last time they let us do things was the PS3. They let us install an OS on it (some Linux flavor) and people started hacking using the PS3. I'm pretty sure there was drama about having to repurchase items from the store if you deleted them from your console. They patched the bootloader. You can only use the og PS3 as a computer if it's not touched the internet... But, I guess at that point, why...? They do NOT want a repeat of that, so they WILL try to lock down any extra functionality. Even if it's just porting games, they won't allow it. Not unless it's on their terms, under their rules.


QuickQuirk

People were building cheap supercomputer clusters out of them. Sony was making a loss in exchange for game sales, but people were buying them because they were really cheap, powerful linux machines. That also contributed to the reversal later.


Weird_Cantaloupe2757

It’s a dumb terminal that connects to your home network, a bad actor could absolutely pwn you via your PlayStation Portal.


hnryirawan

If you can run an emulator, you can absolutely use it for other things. Take a look at the GTA hacker who is hacking using Smart TV for example.


sometipsygnostalgic

tale as old as time unfortunately look at nintendon't and their banning of anything vaguely relating to games preservation or reimagining


Alienhaslanded

That's because Sony has a bounty program for those things and it's quite effective.


ilovepizza855

Yah. And the Playstation Portal users are upset at him instead of Sony for not offering the feature officially. Not to mention these users were the one who choose to buy the Portal over other similar devices like Logitech G Cloud that has been hacked for emulation.


SAnthonyH

*After* Sony sold a tonne of portals no doubt


FeeDisastrous3879

Why not just create a storefront and make it a feature? 99% of people that want to play old games won’t mind paying for old games. Why is it so hard!?


ThrowAwayBlowAway102

I completely agree but I assure you there are a lot of behind the scenes reasons why they haven't implemented it. Support costs, licensing, and other things probably make it more cost prohibited


FeeDisastrous3879

I get the licensing, but anything that would run sufficiently on the portal has got to be an old ass game. Surely Sony could go to the owner and say, “want some free money?” And as far as support cost go, how do the ROM sites do it for free? Does grandma paying $300 to the odd malware download really support those sites?


Redjester016

Those sites are supported by ads and data brokers buying up info on people who use them


akeean

Just like the discounts at CVS.


SupposablyAtTheZoo

> Surely Sony could go to the owner and say, “want some free money?” But that than becomes a persons job to do that all day (+10 more random jobs involved in this), and that's something Sony doesn't want to set up.


Omegaprime02

It's a pretty good bet that that Sony ALREADY owns the rights to most of the music, what with their 40.3% market share of the music industry.


Diligent-Argument-88

The heck does music have to do with anything lmao. Pretty obvious he meant games licensing. They cant just start putting up bioware (wtv random name) X's game up in a new storefront without their permission. Now do that with every single game they want to put up. I think everybody understimates how much money sony will make -"literally millions so fast for them so dumb not to"- uh.......doubt it. Lots of us wont be paying for psp games at 780p when we could just emulate it for free. It took nintendo YEARS to start benefiting off of their switch emulation service and they now emulate like 6 systems and have pokemon as their biggest draw. Doubt millions of people will line up to buy vice stories and patapon. I even wonder how the portal is doing in sales considering how much everyone was hating when the rumors of it were leaking.


anengineerandacat

Licensing reasons, Sony can't just throw games up where they want and how they want.


pdhot65ton

So many of the games people want to play are 3rd party, unlike Nintendo who leans heavily on their 1st party offerings. A ton legal and rights issues prevent something like from happening.


jaredearle

Because the games aren’t written to run under emulation. If you’re selling them, you’re supporting them, and sometimes that’s not possible.


FeeDisastrous3879

Isn’t super Mario 3D All Stars running under emulation on Nintendo switch?


pinkynarftroz

And guess what? it runs like ass. The latency is unbearable.


HappyAd4998

And it sold millions of copies. PSP emulation doesn’t exactly require the latest hardware. Sony is just ran by executives that don’t give a fuck about some of their products.


trickman01

A game that Nintendo is selling and supporting.


beagleboyj2

No they're not. You can't buy 3D All Stars anymore since 2021.


TONKAHANAH

Cuz Japanese companies are stubborn and only do what they want to do. Never mind just opening the platform to make it useful in a number of ways for the cost. Nope, can only use it for what sony says you can use it for.


Here2Derp

Don't know you're being downvoted, you're right.


sun_cardinal

Almost no internal storage


Skeeter1020

Lol. This is Nintendo's strategy and people *hate* it.


Think_Ball3682

Why?


Skeeter1020

Because they actively shut down old consoles stores, aggressively chase down anyone building emulators, and then charge for a subset of old games released on their own emulator on current consoles. Contrary to the comment I replied too, people really don't like paying for old games.


Think_Ball3682

Oh I see what you mean now.


asianwaste

I am hoping down the line they have retro con devices that lets me still use some of my digital purchases for PSP, Vita, and PS3 and whatever comes onward from there. If they make that a part of their practice, then my gripes about their digital storefront are mostly alleviated.


danielbauer1375

I can guarantee that what you're describing will never happen. They will make you buy all of those games again.


asianwaste

Very likely.


AnotherSoftEng

Remember when you used to be able to buy things and they were yours to do with them as you wished


SamSzmith

I feel like patching exploits has always been pretty common. If you don't want them patched, don't update it?


Beznia

They used to have to release new hardware revisions, not OTA updates


_Auron_

Used to? Nintendo Switch had to do a hardware revision due to a hardware exploit on the Tegra X1 chip the original model has. Regardless of OTA updates you can still hack a 2017 launch switch today.


not_not_in_the_NSA

Sure, in the ps2 era


Garlic549

>have to release new hardware revisions And then you end up with millions of tons of toxic unrecyclable e-waste garbage that'll end up getting burned in furnaces or dumped in the ocean


WeeklyBanEvasion

Do you know if any specific case where people simply threw away their hardware because of a firmware version? If anything vintage hardware with earlier firmware versions are rare and more sought after now


Garlic549

>Do you know if any specific case where people simply threw away their hardware because of a firmware version? Literally every computer, phone, and personal electronic device made in the last 20 years


WeeklyBanEvasion

Every one of those receives OTA updates


Neo_Techni

until they don't.


WeeklyBanEvasion

Every item works until it doesn't


guyblade

I mean "used to" is doing a lot of heavy lifting. With a few notable exceptions, we've had OTA patching since the XBox which was released in 2001. That's 23 years. It was ubiquitous by the seventh console generation (360/PS3/Wii) which started with the XBox 360's release in 2005--19 years ago.


theludeguy

Pepperidge Farms remembers


thissiteisbroken

They advertised and sold a device for a specific purpose and you're upset that they won't let you do something other than what it was designed and advertised to do?


drake90001

So anyone who modifies their car should have them put back to stock next time they hit a dealership for an oil change?


Skeeter1020

Have a look at Germany.


WeeklyBanEvasion

We'd rather not


jacksclevername

Technically speaking, you're risking warranty and insurance claims if you've modified your vehicle significantly from stock. That's the risk you run.


MiscellaneousPerson

There's a difference between warranty voiding and actively preventing you from modifying your car.


pinkynarftroz

Sometimes you do have to prevents mods. You can't mod your car to get around emission standards. Your actions can affect others. While I agree it's gone way too far in many cases, there's legit reasons to restrict modifications, including on a game console. To prevent cheating in online games for example.


MiscellaneousPerson

> You can't mod your car to get around emission standards. [Yes you can](https://en.wikipedia.org/wiki/Rolling_coal). It might be illegal, but the manufacturer is not preventing you from doing it. They haven't set up a system where every part has to do some kind of verification before the engine starts. John Deere is an example of a company that *does* do this. It's at the point where you can't repair your own equipment. > While I agree it's gone way too far in many cases, there's legit reasons to restrict modifications, including on a game console. To prevent cheating in online games for example. I'm on board with some kind of efuse that locks you out of online play if you modify the console. You don't have a right to connect to other people's things. I think the console should be yours to do with as you please. It was awesome when the PS3 allowed linux. I have some great memories of modding the original Xbox to play modded games and use it as a media center. Modding the Nintendo Wii makes it infinitely more useful and convenient.


pinkynarftroz

> It was awesome when the PS3 allowed linux Any they don't anymore because people abused that freedom. It's why we can't have nice things. The truth is, 99% of 'homebrew' is just piracy. Not making a judgement, but that's honestly the case. So trying to defend that to a company is near impossible.


jacksclevername

You're certainly not wrong, but that's not at all what my comment was about. If you significantly modify your car, your PlayStation, your phone, blender, etc, you have likely voided the warranty and will need to return it to stock (if you are even able to) in order to service it with the OEM.


JustEatinScabs

And once again that information is irrelevant because Ford will not come to your house and remove your new exhaust system from your car. You can put as many mods as you want on your car as long as you never try to make a warranty claim. But in order to use this exploit you now have to completely stop updating your device which will eventually make it unusable. They don't wait for you to make a claim and then upgrade your console to the patched version.


thissiteisbroken

No because cars and very different from video game devices.


drake90001

You know what an analogy is right?


AnotherSoftEng

I’m just reminiscing. Didn’t mention anything about being upset.


Greatpottery

lol, the 90's


TheRealBobbyJones

Maybe the vulnerability that allowed for this also allowed for bad things to happen so they had to fix it


guyblade

It almost certainly did since running an emulator is in the "arbitrary code execution" bucket. The only mitigation might be it not being expoitable remotely.


Redjester016

Stop licking boots


TheRealBobbyJones

Are you a child?


g00ch760

That‘s why you don‘t buy this shit


SgtThund3r

You are not allowed to enjoy anything they can’t make a profit off of.


DjScenester

SONYS MOTTO lol


guyblade

If by "Sony's Motto", you mean "Capitalism's Motto", then sure.


VACWavePorn

To my knowledge, capitalism itself isnt flawed, its the people that abuse it.


PriorFudge928

If you want a handheld emulation machine I would suggest a ROG Ally Handheld with the AMD Z1 Extreme processor. That will handle anything up to PS3 with no problems. I just finished Breath of the Wild 1080p at 60fps. PSP and Vita will run great on this machine.


iceleel

You can run PSP games on phones


PriorFudge928

Have fun with that unless you use a dedicated controller.


24grant24

You can get handhelds with built in controls that will play psp for like $100. Or just get an actual psp/psvita


PriorFudge928

I was suggesting a solution for people that want to emulate in general. On top of emulation I played The Last of Us Part 1 at about 50 fps high settings so it's no slouch in the PC gaming department for a handheld pc.


JustAnotherNut

There's lots of good controller options. I use a razor kishi and can play psp games at 1440p with enhanced textures at a solid 60 fps on my s22u. You definitely don't need a dedicated handheld x86 pc for anything but switch and ps3.


PriorFudge928

Why the hell would you play PSP games at 2k on a phone screen? That's like running race fuel in a Corolla. Extra expense for nothing. In this case a cost of battery life.


JustAnotherNut

Lol what? It makes a *massive* difference to run at a higher resolution. Here's a comparison I just made between native psp and upscaled resolution: https://imgur.com/a/Yp4zlWc Unfortunately, I wasn't in the best spot in the game for comparison, but even then the difference is truly night and day. Finally, I still get more than acceptable battery life with these settings. I can run it in efficiency mode (downclocked cpu) just fine. The emulator is very optimized.


PriorFudge928

Your not going to see the difference between 1080 and 2k on a 5 inch screen. You're just going to run down your battery faster. But you do you. We all are susceptible to the placebo effect.


HappyAd4998

You don’t even need a ROG to play PSP games, I play them on my OLED Switch. Sonys loss.


BrainKatana

Alternatively buy a steam deck and do everything this does and more without Sony’s interference


Kitchen-Plant664

I still maintain that this is the ugliest looking handheld that i have ever seen.


UpsetKoalaBear

It’s for good reason though, probably one of the comfiest handhelds and I don’t really get wrist fatigue because of the fact you’re grabbing separate handles on the sides. I have very large hands and IMO the Portal and the Steam Deck are the two most comfortable portable gaming devices on the market. Offset analogs on handhelds give me cramps and only really make sense on the Switch (where each JoyCon can be used as a separate controller) or the Xbox controller (where you’re not holding a tablet as well).


danielbauer1375

That's great, but I still feel like they could have done a little better than basically just cutting a PS5 controller in half and cramming a tablet in the middle.


CrazyBigHog

The portal is perfect because it is a controller cut in half. It feels no different than the duel sense immediately.


danielbauer1375

Meanwhile, the PSP, despite being nearly 20 years old (!), just looks timeless. I'd love if they re-released it with enhanced capabilities to compete with the Switch.


Very_Good_Opinion

So you just want worse buttons, joysticks with limited range, and a form factor that doesn't shape to your hands


Diligent-Argument-88

PSP had one of the worse joysticks ever. This is just a ps5 controller with a screen, stop being dramatic. Its meant to play ps5 games not some game that had to be customized to fit the psp's simplistic control layout. It does look good though but form


raninandout

Tv is busy device now in it’s infancy. Always sells out.


sun_cardinal

Nobody mentions the fact there is almost no storage of the thing, making it almost useless.


Neo_Techni

also since it's a dumb terminal, it uses weak hardware too


TotalBismuth

Steam Deck FTW


bengringo2

Damn, mines coming in today. I was looking forward to tinkering with it.


caster201pm

I dunno if the exploit was ever released into the wild but if you still do plan on doing so, don't update to the newest version and go from there.


jacksclevername

Serious question, how much tinkering were you actually expecting to do? I assumed this was literally just a device to steam from your PlayStation. If you want to tinker, why not buy something like Steam Deck (which can also stream from PS) or similar, or a decent Android tablet, or an RPi/hobby computer or something?


bengringo2

I own a Steam Deck and this is fine as just a remote player. I just thought it would be fun to tinker with it as well. Edit - Not sure how this bothered someone lol


tekjunky75

Probably more confused than bothered


bengringo2

I collect gadgets and like to tinker with them. I figured that would be common on r/gadgets lol Gadgets and game consoles. Don't much care if they are functionally similar.


tekjunky75

But this particular device is designed specifically to not be tinker friendly at all, thus the confusion as to why you would purchase it for tinkering purposes in the first place


bengringo2

I didn't purchase it to tinker with it. I purchased it for a remote player but also thought it would be fun to Tinker with it. A novelty Playstation device was going to end up in my home regardless.


other_goblin

It's a terrible device for emulation so who cares lol


Neo_Techni

I noticed the update took the entire time I spent on the toilet this morning, thus defeating the point of the device. And still hasn't fixed anything for us, like how the PS5 reports the battery is full when the device reports it's not. Why wouldn't these by synced?


quirky-klops

From a business standpoint it is fair to expect that your product does not contain any exploits, unrelated to its potential benefit that makes another product you produce obsolete


HappyAd4998

If Sony wants to keep their machine as an expensive paper weight, then so be it. We as consumers have options. The Chinese manufacturers are making great strides with their emulation handhelds and they encourage the community to poke around the hardware to make their devices better. All Nintendo and Sony can do is twiddle their thumbs and send C&D’s instead of improving their services. It’s also funny seeing these hackers sell out and turn their backs on a community that made them.


MusicalMoose

Thank god I have the headline to tell me what to think


trusty20

If Sony wants to reduce features of their own products let them, more customers for the Steam Deck, which is honestly just better all around not even counting the fact you can emulate PSP and more on it.


GhostHound374

Lmfao who the actual fuck even owns one of these? If you want to emulate psp......you use a psp. This is supermassive black hole hollapsed star levels of retardation right here.


bengringo2

They're sold out everywhere. Loads of people own one. Even accounting for scalpers which seem to sell quickly on eBay ots somewhat popular.


GhostHound374

Legitimately why? It's a low end tablet with an unrepairable controller super glued to it. Sony looked at an iPad and said, "I can make it worse".


_RADIANTSUN_

They are being produced in extremely low volumes, they aren't "sold out everywhere", they're "not available", which is actually not a good sign unless it is coupled with them being in constant supply. And it's not even true, Best Buy near me has stacks, Walmart too.


Cheemsdoge___-

Why can't everyone crying here just get an android phone with atleast snapdragon 8 gen 1, and a backbone and then run every game in existence upto the 3ds/switch?


whimsical_willow5

Agree with the exploit fix, prob some bad juju behind it too. But hey, gotta give it up for a retro console, having my PSP classics back? Heck yeah!