games  anime  |  toys
Destructoid is gaming news, community, videos, and sometimes love. Take the tour or jump in with Facebook:

 


200 PS3s used to create an undetectable hack attack photo

A farm of about 200 PlayStation 3s were used to by researchers to launch a nearly undetectable phishing attack, says NetworkWorld. Their goal was to exploit a bug in the Web site security certificates you use daily on the internet. The researchers were able to hack into Verisign's RapidSSL.com certificate authority and create fake digital certificates for any Web site on the Internet.

The PS3 farm spits out fake certificates that would be trusted by any browser. NetworkWorld says that the PS3's Cell Processor is popular with code breakers for its ability to perform cryptographic functions well.

The group plans to present their findings at the Chaos Communication Congress hacker conference, to held in Berlin on Tuesday.

Naturally, Verisign was pissed, and it looks like they were the last to know: 

"I can't express how disappointed I am that bloggers and journalists are being briefed on this but we're not, considering that we're the people who have to actually respond," said Tim Callan, vice president of product marketing with Verisign.


Continue: More top stories stories





prev next

30 comments | showing # 1 to 30

007's Avatar
007 at 12/30/2008 16:35
Err... what? You're not going to give your thoughts on this?


OK then.....
mix's Avatar
mix at 12/30/2008 16:37
At least the farm would have been toasty inside from the heat these thigns throw out!

Okay? Go!
Xiofire's Avatar
Xiofire at 12/30/2008 16:46
Still don't know how this would be done. Not through Linux because that doesn't give the user full access to the Processor or any of its power. And I don't think the XMB has a hacking option. :P

Still interesting, makes me see the PS3 not just as a gaming machine or a media center, but more as a Tech Demo of the Cell Processor and Blu Ray.
RonBurgandy2010's Avatar
RonBurgandy2010 at 12/30/2008 16:48
BOW BEFORE THE PS3 ARMY!!! BOW I SAY!!!
Cartman's Avatar
Cartman at 12/30/2008 16:48
Forgive me, but what would this ultimately allow them to do?
GrayFox's Avatar
GrayFox at 12/30/2008 16:49
They tried to do this with the Xbox 360 but they all got 3 red lights indicating hardware failure!! LOL!
linuxguy's Avatar
linuxguy at 12/30/2008 16:49
@Xiofire: under linux you get access to 6 out of 7 SPEs which is not too shabby
Jonathan Ross's Avatar
Jonathan Ross at 12/30/2008 16:51
@cartman Basically, it could spoof any website and present a legitimate authorization certificate. Theoretically, someone could create a dummy site of, say, eBay, then have that site present a valid Verisign certificate, and then people enter their login/creditcard/paypal/whatever information and get it stolen. It's like all those spam emails you get from your "bank" saying that you have to reactivate you credit card or whatever, and the link directs you to some obviously fake site.
Cartman's Avatar
Cartman at 12/30/2008 16:55
Thanks for the clarification. But also, since when was there a hackers convention? Lulz.
Niero's Avatar
Niero at 12/30/2008 16:55
@ Cartman - steal your yobs

But can 200 PS3's render Crysis in 1080p flawlessly? Would they blend?
Uther's Avatar
Uther at 12/30/2008 17:10
PS3 is evil! Here is the proof!
CrocBox's Avatar
CrocBox at 12/30/2008 17:10
Hmm... That's bad.
The-Excel's Avatar
The-Excel at 12/30/2008 17:14
I want to go to the C3 but it costs like 80 Euro to get in.
superezekiel's Avatar
superezekiel at 12/30/2008 17:28
the CHAOS COMMUNICATION CONGRESS.

after that, the matter will be taken to the UNHOLY HELLHOUNDS HOUSE OF REPRESENTATIVES.
Holyetheline's Avatar
Holyetheline at 12/30/2008 17:37
Wow this is impressive.
Coldbrand's Avatar
Coldbrand at 12/30/2008 17:53
Maybe if the ps3 had more games they wouldn't have to resort to things like this to fill the void.
Timmeh's Avatar
Timmeh at 12/30/2008 17:58
@Cartman - More common than you might think: Here's what Wikipedia has.

Not all 'hacking' is done with the goal of 'stickin' it to the man' or stealing your mother's credit card details, the computer security industry actually learns a lot by working with hackers at events like these.
Mushman's Avatar
Mushman at 12/30/2008 18:14
Wow, impessive
Mabui's Avatar
Mabui at 12/30/2008 18:35
This could be good news for Sony - with the sale of 200 PS3's to every hacker, thief, or Otaku's.
sleepingagain's Avatar
sleepingagain at 12/30/2008 18:39
that is fucking epic....
Crackpot360's Avatar
Crackpot360 at 12/30/2008 18:51
Make it 300 PS3's and tonight we will all dine in hell.
The-Excel's Avatar
The-Excel at 12/30/2008 18:55
@Crackpot360:
If such a cluster of PS3s were to exist (heaven forbid), that may actually be a reality.
CharleyTony's Avatar
CharleyTony at 12/30/2008 19:03
this hacking feature should have been removed instead of the ps2 BC
Crumpet Lips's Avatar
Crumpet Lips at 12/30/2008 19:12
That is really really bad. Hopefully that exploit is patched up sooner than later. I can't begin to imagine how much havoc that would wreak over the internet from people/organizations that can afford 200 PS3's and build an array like that.
teach4food's Avatar
teach4food at 12/30/2008 19:43
So that was what my PS3 was doing when I first hooked it up. Making Sony more money by creating Phishing sites. It does explain the constant delays and redundant menu commands.
brainderailment's Avatar
brainderailment at 12/30/2008 20:29
20111904 Skynet
carpwrist's Avatar
carpwrist at 12/31/2008 08:51
@MotoRobo, oh yea, I remember that. There was an article about the PS2 before it came out in EGM that said the PS2 had the capability of launching missiles.
Israel thought it was the Hamas the whole time, we should have been keeping an eye on Sony since 9-11...
Drach's Avatar
Drach at 12/31/2008 10:36
The PS3 is not EVIL. The people who own those particular PS3's are showing us what Evil they could be made to do. Know the difference.

Kneel Before the almighty PlayStation Army! All your Credit card information and private log in information are BELONG TO US.
liqideos's Avatar
liqideos at 12/31/2008 22:26
Imagine the possibilities if it just had a regular influx of compelling software.
Roryzilla's Avatar
Roryzilla at 01/01/2009 18:15
Haha. Take that Verisign, you're entire setup is a joke.
prev next

Comment with Facebook





Click connect and comment instantly!

Comment with Dtoid





New? SIGN UP - it takes 5 seconds

Comments policy

Destructoid is an open discussion community. You don't need to "audition" to post a comment - just speak your mind. We respect differing opinions on the site, so have at it. Be smart, funny, insightful, clueless, or cute -- but back it up with substance. Keep your cool, keep it fun. We only ask that you act respectfully and above all: don't be a troll and ruin it for everyone else. Don't bring down gamers or we'll, you know, gently shoot you in the face and stuff you into a flaming mailbox. Each comment is your opportuntity to make this community awesomer. Is that even a word?

Avoiding the banhammer only requires common sense: spamming, trolling, racism, NSFW stuff, and other forms of sucking will not be tolerated. If anyone is griefing please report abuse. Be good. Don't suck!

 
New on Destructoid.TV play all videos

Loading
Loading Destructoid Videos




    Win this!
    Reminder: We're giving away six copies of Magnacarta 2!



    Dtoid Twitter    Got news?   tips@destructoid.com

    Reviews & Previews
    Mahjongg Artifacts 2 review
    Dragon Age: Origins review
    Lost Winds: The Winter of the Melodias review
    Osmos review
    Space Invaders Extreme 2 review
    Half-Minute Hero review
    JU-ON: The Grudge review
    Kenka Bancho: Badass Rumble review
    Thexder Neo review
    Domino Rally review
    more reviews
    PS3's 256-player MAG
    Rooms The Main Building
    Skate 3
    Hudson's bringing back the Bonk
    James Cameron's Avatar
    Bomberman Battlefest
    Calling
    Bad Company 2's multiplayer
    Partying like it's 1959 in BioShock 2's multiplayer
    BioShock 2 through the eyes of Big Daddy
    more previews


    - The Dtoid Army is 49607 strong -

    Showing Cblogs with 3+ faps   show all

    Call for entries: do the wrong thing

    New to Dtoid? Read the survival guide




     Originals
    Jim Sterling: How to respond to a videogame review





















    More Destructoid Originals




     Popular now more
























    Destructoid's editorial lovefest is:
    Nick Chester
    Editor-in-Chief
    Jim Sterling
    Reviews Editor
    Dale North
    News Editor
    Hamza Aziz
    Community Manager
    Anthony Burch
    Features Editor
    Rey Gutierrez
    Video editor & director
    Niero
    Founder, publisher
    Letters to the editors
    tips@destructoid.com
    Associate Editors
    Ashley Davis Jonathan Holmes
    Brad Nicholson Jonathan Ross
    Brad Rice Jordan Devore
    Chad Concelmo Matthew Razak
    Colette Bennett Tom Fronczak
    Conrad Zimmerman Topher Cantler
    Dyson Samit Sarkar
    Contributors
    Adam Dork
    Ben Perlee
    Daniel Lingen
    Joseph Leray
    Joe Burling
    Mikey
    Will Maddock
    Stella Wong





     

     
      get involved

    register or login
    post a blog
    post a forum
    enter a contest
    contribute a news tip
    suggest a feature
    be a guest editor
    support

    new member's guide
    login assistance
    tech support
    report abuse
    email our editors
    read our dev blog
    nuclear crisis?
    keep in touch

    RSS feed
    Twitter
    Facebook
    Myspace
    Flickr
    Game nights
    Meetup+play online
    seriously

    about Destructoid
    advertising
    terms of use
    privacy policy
    jobs at MM
    buy our crap
    our network

    Tomopop
    Japanator
    Despingation?




    Destructoid is an independently-run publication forged by our love of video games and the gaming community's need of accountable enthusiast press
    living the dream since March 16, 2006