 |
forums.ps2dev.org Homebrew PS2, PSP & PS3 Development Discussions
|
| View previous topic :: View next topic |
| Author |
Message |
TyRaNiD
Joined: 18 Jan 2004 Posts: 918
|
Posted: Mon Sep 01, 2008 3:38 pm Post subject: |
|
|
Perhaps you keep forgetting, you don't need the HMAC key, at least for the IPL that can be brute forced in a few days for a single encrypted block which is all you need :) All you need to do is find the method of data encryption/decryption and job done.
It is worth remembering that the encryption itself was probably more about obfuscation than any actual protection mechanism, of course they have probably tweaked something to make it not just decrypt plain using AES on a PC but that is so you couldn't easily break the obfuscation. The history of PSP security measures has been one of security through obscurity, this is just one step in that. They are unlikely to be hiding the algorithms, in fact they could probably say it uses AES and SHA1 HMAC and we would be no closer really to finding anything.
When it comes down to it security of this kind is all about defense in depth and is also assumed to be time limited. If we had never got code to run on the device at all it would be considerably harder to do what has been done. If they hadn't screwed up from day 1 maybe, just maybe, the PSP would still be a "secure" system :) |
|
| Back to top |
|
 |
paulotex
Joined: 20 Jan 2008 Posts: 19
|
|
| Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
Powered by phpBB © 2001, 2005 phpBB Group
|