Hi Mathieulh, could you give us your curriculum vitae to light up ours members?I reserve my curriculum vitae for business. However, I can tell you that skills are there.
We saw you participating to PSP and PS3 Scenes, two consoles from Sony, do you have some reason (affinity…)? Have you another favorite platform (like the Galaxy S2 with Android…)?
I’ve just been seduced by these two platforms, especially the fact that just a few details were revealed, particularly on the technic side, which raises challenge. I’m more interested in understanding the system architecture of the platform than playing, even if I’m a gamer.
Concerning the Galaxy S2, I’m also really interested on it, but more for fun than to develop or reverse engineer.
According to you, what kind of tools should be in hacker’s tool kits… except a brain (hardware / software)?
A computer of course, a disassembler (e.g. IDA), a logic analyzer, if you’re interested in hardware, good knowledge in development and reverse engineering (assembly…), don’t be afraid to take risks with your equipment, if possible, have the resources to debug the code that you analyze/reverse. Maybe more if you want http://www.ps3hax.net/wp-includes/im.../icon_razz.gif You seemed detached from bad comments which gone the rounds concerning what you told in the past and that didn’t result in a release, and it does you credit ! But aren’t you tempted to shut their mouth by publishing a “legal” release?
Not really, I posted or participated to enough releases in my life (Custom Firmwares M33, Pandora, PSGroove (open source version of PSJailbreak’s exploit + full documentation), Documentation about .self/update packages cryptography, appldr + lv2ldr keys, Documentation and games packages keys, QA flag (even if this release was a leak, it was my work), use of SPE8, Kirk keys to sign applications to PSP… and many others that I’ve forgotten), as well in PSP, as in PS3 Scene to get a deep respect from my peers.I’ve little esteem for ungrateful users who ask more than what they’re graciously provided and who have some chronic amnesia when it comes to remember what developers have done for them. More people claim results, insult me when these don’t match with what they expect… Less I’m disposed to provide my hard work to the public. I don’t develop to fame, money or any other reason like these, I develop by curiosity to understand how the system of a platform was elaborated, and also to challenge, like to find glitches on theses platforms, consoles correspond very well to it as their system are designed with a military level, especially PlayStation 3 and Xbox 360. Apart sharing, I haven’t any interest to publish my work to the public, so when the public abuse of my work or my kindness, I feel no remorse to suspend my releases. I believe this is also the case of many other developers who haven’t any interest to run backups or any other thing on any platform.
This is one of the reasons that pushed me to stop releasing, another good one is to avoid a possible lawsuit from Sony.
You still are active on Gitbrew IRC channel, Twitter, and also reactive to some news, why did you left the Scene?
Despite having stopped public releases, it doesn’t prevent me from continuing my work for personal and educational goals, to be an acute observer, and to help other developers who need it.
This is what’s happening, I attend some developers in their work without asking any credits in return (particularly via IRC or MSN) and post comments on my Twitter when opportunity arises.
Could you tell us more about one of your last [URL="http://twitter.com/#!/Mathieulh/status/120551707720691713"]tweets[/URL]:
@playstation #didyouknow that your self format is uber fail ? #morethanjustmy2cents xD |
It concerns a vulnerability I recently discover in Sony’s SELF format.
Have you been able to exploit the vulnerability (lack of verification to the size of the header of an SCE SELF when copying it from the Local Shared Storage to the Local Isolated Storage) unveiled by yourself a while ago?
This vulnerability is really difficult to implement, and only works with some loaders when we have a direct control on the arguments which are send to them. However, other flaws exist and never have been published.
Rumors say that you’ve got the keys to decrypt 3.60 / 3.65 / 3.66 / 3.70 games. Could you confirm?
I prefer to don’t answer to this issue, and let your interpretation answer to it. Public doesn’t need those keys, you can downgrade to 3.55 (via hardware) almost all PlayStation 3 out now (about 40 million consoles are vulnerable), and it’s possible to run Linux (via OtherOS++) or homebrews on them. I think it’s quite enough to make the PlayStation 3 one of the most open consoles in the market.
What’s your opinion concerning DemonHades’ theory to find them?
It’s a (really) bad sum up of the tweets I posted 6 months ago. Many elements are missing, and I doubt DemonHades has capacities to recover the keys.
With all information available to hackers and without 3.6+ keys, is it possible to sign an application that could be functional on 3.70? If so, do you think it would lead to piracy again?
It’s impossible to obtain the private key from keysets used by Firmwares 3.56+, and so to sign applications to those, however it’s possible to launch SELFs on 3.56+ with old keysets (below 0x0D) if we know how. Therefore, it’s possible to sign a Custom Firmware 3.60+ and install it over Fimware 3.55, if we have 3.60+ keys.
Many people are ungrateful and always want more things, and faster. Do you think this conduct penalizes the Scene and drives away its actors? We recently saw ColdBird leaving PSP Scene.
Indeed, I think this behavior scares many developers, including myself.
Do you think PS3 Scene is still able to progress? Has it got the “good” sceners and public to evolve peacefully?
Good sceners, maybe, even if a lot have gone, I though to fail0verflow, or myself. Good public, I don’t think.
What are your motivations to this Scene? What kind of projects would you like to see?
I appreciate the challenge and the fact that we always find new things, especially items hidden by Sony that are part of PlayStation 3′s system.
Are you working on some projects, like the dead Utopia or other, to PS3?
Currently, I haven’t such project to PS3.
Do you believe Firmwares above the 3.55 could be “jailbreaken”? If so, do you think a release could revive dongles?
I don’t think Firmwares 3.56+ could be jailbreaken with an USB dongle.
What’s your opinion regarding modchips and their future?
I think they’ll allow people to easily downgrade to Firmware 3.55, but their future is lukewarm, at least until 3.60+ keys become public.
People are dissatisfied by the Scene because 3.6x+ keys weren’t found/disclosed, what do you think of these people ? Do you think it’s good to be responsive to their expectations?
I think if they’re unhappy, nothing prevents them to work and retrieve these keys by themselves. I’ve published more than one method to recover them.
A last question, slightly HS if we ignore old rumors, but… As an ex member of M33 Team, do you have some news about Dark_AleX?
I don’t want to reveal too much without his consent, however, I can tell you he goes well, and I’m regularly in touch with him.
Thank you for this interview Mathieulh, maybe we’ll see you again on December 17th?
Hum… I may be busy to that date, I’m not sure to be able to go to CCC, it mainly depends on my availability.
If you want more details about Mathieulh’s works on PS3, you can read the [URL="http://www.ps3devwiki.com/index.php?title=Main_Page"]Wiki[/URL] dedicated to research or go to his own website, [URL="http://lan.st/index.php"]LAN.ST[/URL].