frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Sony PS5 ROM keys leaked – jailbreaking could be made easier with BootROM codes

https://www.tomshardware.com/video-games/playstation/playstation-5-rom-keys-leaked-jailbreaking-could-be-made-easier-with-bootrom-codes
118•gloxkiqcza•2h ago

Comments

MuffinFlavored•1h ago
As in, you can now craft your own "update" and sign the bootloader/entire package and it will flash?

edit:

> You still won't get a jailbroken PlayStation 5 with this leak, but it will make it easier for hackers to compromise the console's bootloader.

nope?

peddling-brink•1h ago
> Now that the ROM keys have been leaked (and assuming they are valid), a hacker could then decrypt and study the official bootloader and potentially use that as a starting point to understand how the PS5’s boot system works.

This would just allow further study.

hypeatei•1h ago
How did the keys get leaked and where are they sourcing this from? Did Sony get compromised, disgruntled employee, what?

If there was a breach, I'd expect keys for the PS4 to be leaked as well which would be quite handy. There are soft jailbreaks you can do currently on the PS4, but they're not full on CFW (custom firmware) and don't persist reboots.

gruez•1h ago
Based on the other comments it looks like it's the decryption keys for the bootrom, which obviously have to be available somehow to every PS5 for it to be able to boot. That means they probably compromised the processor or something, but no need to invoke "Sony get compromised" or "disgruntled employee".
m00dy•1h ago
https://news.ycombinator.com/item?id=46445107
naoru•1h ago
The article says:

> According to The Cybersec Guru, this is an unpatchable problem for Sony, because these keys cannot be changed and are burned directly in the APU.

I'm just speculating at this point, but what could prevent Sony from anticipating this exact situation and burning several keys in the APU? I mean, eFuse is not exactly a new technology. That way, once a key is leaked, Sony could push a firmware update switching the APU to a new key which hasn't been leaked yet.

ghshephard•1h ago
Would that not break every other firmware release that relied on that older key?
toast0•57m ago
Yes, but console vendors generally prefer not to allow downgrades.

So if v1 is signed by key A, v2 is signed by key B and invalidates key A; a console that installs v2 wouldn't be able to install v1 after, but that's not a problem for Sony.

But, I'm not sure how many companies would be able to manage their keys properly to ensure that someone with access to key A doesn't have access to key B.

If these are assymetric key pairs and the device side key was extracted from the device... Switching keys wouldn't help, and it's not a huge deal by itself --- having the device side key doesn't allow you to make a firmware image the device would accept.

wincy•51m ago
Fun fact, the Nintendo Switch blows fuses [0] when they do a patch that’s for security/jailbreaking. If I recall there’s something like 12 or 16 fuses they can employ over the life of the product to ensure you can’t rollback updates that prevent piracy. Nvidia builds these fuses into the board.

So if you’ve blown 4 fuses you can’t do a patch that requires only 2 fuses to have blown, it’s a pretty wild solution.

Edit: it’s actually 22 fuses

[0] https://switchbrew.org/wiki/Fuses

jtbayly•46m ago
I’m not following. Why would it be helpful to check how many fuses had been blown? And how could you have more blown fuses than you’re supposed to?
toast0•43m ago
Firmware v1 requires a switch with zero fuses blown.

Firmware v2 requires a switch with no more than one fuse blown and blows the first fuse.

If you install v2, you can't install v1.

Nintendo can make 22 firmware releases that disallow rollback.

j45•21m ago
Even if trivial it could be manufacturing savings.
sagacity•1h ago
This is probably based on the research outlined in this ccc presentation: https://youtu.be/cVJZYT8kYsI

This also goes into a bit more detail regarding how these keys are used.

embedding-shape•1h ago
> This isn’t the first time that Sony has had to deal with a security crisis with the popular PlayStation family. The PlayStation 3 was previously hit with a vulnerability when the company made a mistake with their cryptography on the console, allowing users to install homebrew software and allow piracy and cheating on popular titles.

Probably could have been avoided if Sony kept the Linux version of the Playstation still alive. Imagine what the (console) world would have looked like, if it was still alive. I never got the chance to even try it myself before it was gone, but I'm sure a lot of the homebrew community's energy could have been redirected towards it instead, hitting two flies with one swath.

Sesse__•34m ago
> Probably could have been avoided if Sony kept the Linux version of the Playstation still alive.

The causality here is backwards; Sony removed Other OS support precisely because the first jailbreak (a glitching attack) relied on it.

mschuster91•12m ago
It only ever was present because Sony wanted to cheat EU import tariffs - by allowing other operating systems, it could be imported under the lower general-purpose computer rate.

IMHO, removal of this feature should have triggered Sony having to pay back the amount of taxes cheated.

xav_authentique•19m ago
If anyone is interested in the cryptography mistake that Sony made I recommend watching the Console Hacking talk at 27c3 by the fail0verflow team: https://youtu.be/DUGGJpn2_zY?t=2096
Thaxll•1h ago
I guess this is similar to TPM / secure boot on a pc?
OptionOfT•1h ago
> https://thecybersecguru.com/news/ps5-rom-keys-leaked/#:~:tex...

Nasty filler to add that to the page.

General question: (I don't know enough about cryptography)

Are these symmetric keys or asymmetric ones? Both allow you to decrypt, but only the former would allow you to make changes to it, whereas the latter would still require you to find an exploit in the next stage. I think?

nopurpose•1h ago
given that there is no dev mode or ssh server running on a console, how do they even read low level binary code such as boot loader? Do they transplant memory chips?
Retr0id•1h ago
https://xcancel.com/notnotzecoxao/status/2006525981113332025

> news sites are overhyping the release/leak/whatever of the rom keyseeds, saying it could be used to fully unlock the ps5. i've already stated on twitter and i'll state it again. rom and seeds alone are NOT enough to pwn a ps5, you either need fuses and nandgroups to complement it

> ... or alternatively, you need to find bugs in the rom that you can use to exploit the ps5. neither of these are easy and require immense work. also, decapping a ps5 apu to retrieve the fuses optically will prove useless to the end user because those fuses are encrypted/xored/obfuscated

Cameras and Lenses (2020)

https://ciechanow.ski/cameras-and-lenses/
64•sebg•58m ago•5 comments

OpenWorkers: Self-Hosted Cloudflare Workers in Rust

https://openworkers.com/introducing-openworkers
178•max_lt•3h ago•53 comments

iOS allows alternative browser engines in Japan

https://developer.apple.com/support/alternative-browser-engines-jp/
105•eklavya•4h ago•47 comments

Python Numbers Every Programmer Should Know

https://mkennedy.codes/posts/python-numbers-every-programmer-should-know/
77•WoodenChair•3h ago•33 comments

Bluetooth Headphone Jacking: A Key to Your Phone [video]

https://media.ccc.de/v/39c3-bluetooth-headphone-jacking-a-key-to-your-phone
306•AndrewDucker•6h ago•96 comments

Implementing HNSW (Hierarchical Navigable Small World) Vector Search in PHP

https://centamori.com/index.php?slug=hierarchical-navigable-small-world-hnsw-php&lang=en
41•centamiv•2h ago•11 comments

Common Lisp SDK for the Datastar Hypermedia Framework

https://github.com/fsmunoz/datastar-cl
29•fsmunoz•2h ago•7 comments

Sony PS5 ROM keys leaked – jailbreaking could be made easier with BootROM codes

https://www.tomshardware.com/video-games/playstation/playstation-5-rom-keys-leaked-jailbreaking-c...
119•gloxkiqcza•2h ago•21 comments

Build a Deep Learning Library

https://zekcrates.quarto.pub/deep-learning-library/
31•butanyways•3h ago•3 comments

Heap Overflow in FFmpeg EXIF

https://bugs.pwno.io/0014
43•retr0reg•2h ago•6 comments

2025 Letter

https://danwang.co/2025-letter/
120•Amorymeltzer•3h ago•64 comments

Memory Subsystem Optimizations

https://johnnysswlab.com/memory-subsystem-optimizations/
3•mfiguiere•23m ago•0 comments

2025: The Year in LLMs

https://simonwillison.net/2025/Dec/31/the-year-in-llms/
772•simonw•18h ago•399 comments

Ultra-Wide Band: A Transformational Technology for the Internet of Things

https://www.eetimes.com/ultra-wide-band-a-transformational-technology-for-the-internet-of-things/
9•fzliu•1w ago•4 comments

Rust--: Rust without the borrow checker

https://github.com/buyukakyuz/rustmm
77•ravenical•7h ago•111 comments

Meta made scam ads harder to find instead of removing them

https://sherwood.news/tech/rather-than-fully-cracking-down-on-scam-ads-meta-worked-to-make-them-h...
188•wtcactus•5h ago•49 comments

ACM Is Now Open Access

https://www.acm.org/articles/bulletins/2026/january/acm-open-access
251•leglock•2h ago•39 comments

How to recognise a genuine password request

https://eclecticlight.co/2025/12/18/how-to-recognise-a-genuine-password-request/
3•naves•1w ago•0 comments

Easel Turns One One year of building my own IDE in Clojure

https://blog.phronemophobic.com/easel-one-year.html
136•todsacerdoti•5d ago•10 comments

A font with built-in TeX syntax highlighting

https://rajeeshknambiar.wordpress.com/2025/12/27/a-font-with-built-in-tex-syntax-highlighting/
29•LorenDB•5d ago•3 comments

European Space Agency hit again as cybercriminals claim 200 GB data up for sale

https://www.theregister.com/2025/12/31/european_space_agency_hacked/
26•smurda•1h ago•8 comments

I canceled my book deal

https://austinhenley.com/blog/canceledbookdeal.html
571•azhenley•23h ago•317 comments

BYD Sells 4.6M Vehicles in 2025, Meets Revised Sales Goal

https://www.bloomberg.com/news/articles/2026-01-01/byd-sells-4-6-million-vehicles-in-2025-meets-r...
73•toomuchtodo•2h ago•62 comments

Pokémon Team Optimization

https://nchagnet.pages.dev/blog/pokemon-team-optimization/
149•nchagnet•5d ago•55 comments

Beyond the Nat: Cgnat, Bandwidth, and Practical Tunneling

https://blog.rastrian.dev/post/beyond-the-nat-cgnat-bandwidth-and-practical-tunneling
15•rastrian•5d ago•6 comments

Show HN: I created a tool to design and create foamcore inserts for boardgames

https://boxinsertdesigner.com/
39•Rabidgremlin•4d ago•10 comments

I rebooted my social life

https://takes.jamesomalley.co.uk/p/this-might-be-oversharing
233•edent•7h ago•161 comments

A Christmas Present to Myself – Vector Network Analyzer (2014)

https://axotron.se/blog/vector-network-analyzer-a-christmas-present-to-myself/
33•joebig•1w ago•3 comments

Tell HN: Happy New Year

401•schappim•1d ago•193 comments

Web Browsers have stopped blocking pop-ups

https://www.smokingonabike.com/2025/12/31/web-browsers-have-stopped-blocking-pop-ups/
336•coldpie•1d ago•368 comments