Developer Abandons 'PS5 Linux' Project After Sony Patches AI-Discovered Exploit (itsfoss.com) 51
"In April this year, we saw Andy Nguyen turning the PS5 into a Linux-powered gaming PC,"
writes the blog It's FOSS.
It ran Steam games and emulators using the PS5's on-board hardware. But this week Andy announced he's "stopping all my work on PS5 Linux" and "stepping away from the PS5 scene." stopping work on porting the project to the PS5 Pro, which would've shipped sometime in 2027. Andy Nguyen: After pouring my heart and months of my life into it, including plans to finish PS5 Pro support and release in 2027, it's all down the sink.
The scene used to be a group of highly talented researchers, but now it is just a bunch of noobs using LLMs and writing hacks they don't even understand. Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony. I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy Linux. They agreed to wait, but not a day passed and they decided to waste it instead.
Or, as It's FOSS tells it: Running Linux on a PlayStation console is possible because the PS5 Linux project was able to find a way past the hypervisor using exploits Sony had already patched, covering firmware 3.00 through 7.61. ..
[The bug's discoverer writes it was] found with what he calls his "trusty ai clanker machine" and no help from anyone else. He had even agreed to Andy's request to not disclose the findings. Unexpectedly, a third person, still unnamed, found the same bug using AI a few hours later. Anticipating that there would be more people finding the same bug, [he] decided to post the flaw on HackerOne.
The project's GitHub page and all the related repositories are still there. Nothing has been archived as of today, and if you wanted to, you could start contributing to the PS5 Linux project by taking over any pending work or cooking up new improvements... The PS5 Pro support Andy was building never reached the repository, so you would have to start from scratch... While Andy's departure is a blow to the plan for supporting newer PS5 firmware and the PS5 Pro, other contributors have shown that they can deliver work on the loader without him, and I am hopeful more will follow.
It ran Steam games and emulators using the PS5's on-board hardware. But this week Andy announced he's "stopping all my work on PS5 Linux" and "stepping away from the PS5 scene." stopping work on porting the project to the PS5 Pro, which would've shipped sometime in 2027. Andy Nguyen: After pouring my heart and months of my life into it, including plans to finish PS5 Pro support and release in 2027, it's all down the sink.
The scene used to be a group of highly talented researchers, but now it is just a bunch of noobs using LLMs and writing hacks they don't even understand. Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony. I asked them to at least wait for GTA 6 to come out so that people would have the opportunity to legally purchase the game and also enjoy Linux. They agreed to wait, but not a day passed and they decided to waste it instead.
Or, as It's FOSS tells it: Running Linux on a PlayStation console is possible because the PS5 Linux project was able to find a way past the hypervisor using exploits Sony had already patched, covering firmware 3.00 through 7.61. ..
[The bug's discoverer writes it was] found with what he calls his "trusty ai clanker machine" and no help from anyone else. He had even agreed to Andy's request to not disclose the findings. Unexpectedly, a third person, still unnamed, found the same bug using AI a few hours later. Anticipating that there would be more people finding the same bug, [he] decided to post the flaw on HackerOne.
The project's GitHub page and all the related repositories are still there. Nothing has been archived as of today, and if you wanted to, you could start contributing to the PS5 Linux project by taking over any pending work or cooking up new improvements... The PS5 Pro support Andy was building never reached the repository, so you would have to start from scratch... While Andy's departure is a blow to the plan for supporting newer PS5 firmware and the PS5 Pro, other contributors have shown that they can deliver work on the loader without him, and I am hopeful more will follow.
kudos (Score:2, Troll)
for this guy, that was a good challenge, but i never understood the wider motivation in this sort of stuff. ps, wine, linux on macs ... what's the point? if a platform/device desperately wants to be proprietary and exclusive then just let it. you can talk with your wallet and ignore it, and anycase focus your energy on contributing to open platforms. what a waste.
Re:kudos (Score:5, Insightful)
The point is to be able to use your hardware in the manner you deem appropriate, and to ensure it is not doing sneaky shit behind your back.
If, instead of a Playstation, we were talking about rooting LG televisions to run custom Linux builds stripped of pervasive privacy-violating code and "apps," I suspect your opinion might be rather different. (And no, when the entire industry has turned to the Dark Side, voting with your wallet doesn't work.)
Re: (Score:3)
It wasn't inevitable for the bug to get reported to Sony and fixed before the release of GTA6. At that point, Flow would have reported it to Sony himself, and everyone (except Sony and Rockstar) would be happy.
Also, hypervisor access is needed just to dump new games from a console. This likely also prevents piracy of GTA6 on Playstation for the foreseeable future, which is what many of the folks jailbreaking Playstations really wanted. Any sort of Pirate GTA6 is unlikely before PC release.
Now, Playstation
Re:kudos (Score:4, Insightful)
The point is to be able to use your hardware in the manner you deem appropriate, and to ensure it is not doing sneaky shit behind your back.
then buy the appropriate hardware?
If, instead of a Playstation, we were talking about rooting LG televisions to run custom Linux builds stripped of pervasive privacy-violating code and "apps," I suspect your opinion might be rather different.
that's not an apt comparison but, in fact, my opinion is the same.
(And no, when the entire industry has turned to the Dark Side, voting with your wallet doesn't work.)
get yourself a regular monitor. they come in many sizes and have none of that crap. or don't, but realize that digital television is a proprietary system by definition. you get what you pay for.
sakrebleu! (Score:2)
regardez un grand revolutionnaire! vive la liberte, avec son ps5 et tele lg pourrie ...
Re: (Score:2)
A monitor the size of a modern 65 inch TV would be prohibitively expensive, if you could even find one. Even so, monitors have limited support for home theatre HDMI features like HDR, ARC, and CEC compared to TVs
choices, (Score:2)
choices, choices ....
Re: (Score:3)
Or just buy the "smart" TV and don't connect it to the internet? I fail to see the issue here.
Re: (Score:1)
I was responding to a parent that said that you should just buy a monitor instead of a smart TV. I was pointing out that monitors and TV fill different use cases and have different pricing scales so they aren't necessarily drop in replacements.
Re: kudos (Score:2)
Re: kudos (Score:5, Informative)
Re:kudos (Score:4, Interesting)
The point is to be able to use your hardware in the manner you deem appropriate
It's sold as a gaming console. At no point does Sony give the impression that you're buying anything buy a gaming console. Additionally, keeping the system secure is typically considered a desirable aspect of a gaming platform, since it's not really all that much fun to play online against people who are using cheats and/or hacked player profiles.
Granted, I do think gaming consoles should be unlocked by the manufacturer once they reach the end of their supported lifespan, as the hardware could then be repurposed for other uses (and wouldn't just end up a useless brick once the servers shut down).
Re: (Score:3)
It's sold as a gaming console. At no point does Sony give the impression that you're buying anything buy a gaming console.
That wasn't the case with the PS2 and the PS3. After they stole my PS3 Linux from me, they deserve to get hit back.
Re: (Score:2)
Re: (Score:2)
Why do you want to root their device to defang it, requiring you to first give money to a bad company?
Wouldn't not buying it be a superior approach?
Re: (Score:2)
Re: (Score:2)
Engineers like to practice engineering to extend their skills. Yes, most people do not get that. But without engineers you would still live in a cave.
eggs (Score:2)
Engineers like to practice engineering to extend their skills.
which was implicit (or maybe even rather explicit) in the first 9 words of my commentm, but for some reason you chose to deliberately missed the point.
Re: (Score:2)
Ah, no. It was not. You first 9 words were a comment specifically for this guy, mine was one about the 10-15M engineers in the world, which would be a "wider" group than just this one person.
Re: (Score:1)
Get more use out of the hardware when they stop supporting it.
eos (Score:2)
that kinda makes sense. but imo it would be smarter not to support such hardware to begin with. if you're going to run linux on it why not buy a pc?
Re: (Score:2)
It's like complaining that Apple doesn't allow people to hack the Mac OS for whatever reason they want.
What are you talking about? You can literally hack Mac OS for whatever reason you want.
Only bug left. (Score:2)
Slop kiddies found the only hypervisor bug left, which I had also found a while ago, and decided to report to Sony.
And he knows this is the "only hypervisor bug left" because...he hasn't been able to find another one yet?
This smells like some dude saying "AI is better than me at my hobby, so I'm taking my ball and going home!"
Re:Only bug left. (Score:5, Interesting)
Not a few days later, not 6 months later, *a few hours* later. If you needed proof that information leaks from one user session to another user session this would be another clue.
TL;DR: everything you say, every idea you painstakingly work out, everything you do in a conversation with an LLM will be copied, trained on, and shared with strangers who also use another instance of the AI company's products. Caveat emptor + enjoy your day!
Re: (Score:3)
LLMs have certainly made people get really into conspiracy theories. *eyeroll*
The LLMs didn't just off on their own decide to look for hypervisor bugs. Users told it to look for hypervisor bugs. The timing means that multiple users did so at roughly the same time - probably in response to some news of some sort.
Re: (Score:2)
We have excellent data on vulnerability research going back decades. Researchers do find the same sets of bugs when they look at the same code with the same motivation. And it never happens within hours of each other. It's a slow diffusive process, that progresses on the scale of weeks and months.
Remember the disclosure embargo arguments we've had not so long ago? The idea that a "responsible" security researcher should quietly tell the company about a bug, and give them time to fix it over a couple of we
Re: (Score:2)
Add that we know the LLM assholes steal everything they can get their hands on.
What is hilarious to me is that there are still mentally defectives that try to defend that crap.
Re: (Score:2)
It absolutely happens "within hours of each other" when (A) some news comes up on the topic, and (B) all you have to do is type into a box, "Find a vulnerability in this software". This isn't a situation where bug-hunting is a weeks or months-long process that takes all your effort.
I'll repeat: LLMs don't just on their own decide to go off and look for bugs to report.
Re:Only bug left. (Score:4, Insightful)
You're one of those dingbats who still doesn't realize they're going to do all the things their terms of service let them do.
They claim they use the "chats" for training, but you consider it a "conspiracy theory" that they might use them for training.
You're an idiot. There's no conspiracy. They use the user interactions for training, and part of that signal is detecting results that the user had a very positive reaction to, and providing those results to others.
The real "conspiracy theory" is your idea that they leave money on the table for some unknown reason.
Re: (Score:2)
Yes, well said.
Re: (Score:3)
I have had a clear information leak with an LLMs years ago. I had tried an exam question with ChatGPT and it could not answer. Only 6 days later it was able to answer for 23 students asking literally the same question (i.e. all of them). Others made similar experiences.
It was totally clear to me back then that there is zero privacy in LLM sessions and that they probably had humans work on failed queries and use manual additions in a search engine that runs in parallel, because there was not enough time for
Re: (Score:1)
I expect it's more "they found this exploit I'd been using in a matter of hours. I'll have to find a new exploit/exploit chain to continue the project, and anything I do find will likely also be found by someone else in very short order."
who would want to continue working on a project when every avenue to advance it has a useful life measured in hours to days from first git-commit?
Re: (Score:2)
"AI is better than me at my hobby, so I'm taking my ball and going home!"
This sort of drama was fairly prevalent in the iOS jailbreaking scene even before AI. The issue was mostly that whatever exploit you found, it would get patched right away anyway, so it ultimately ended up being less about producing something neat that the average user could play with and more about bragging rights between the folks finding and implementing the exploits.
Boo hoo (Score:5, Insightful)
I respect what he was trying to accomplish, BUT...
Bug was found, bug was reported, bug was patched. This is the way things are supposed to work. He was sitting on a known hypervisor bypass bug so he could exploit it for his plans. His plans may have been noble, but others may have also known about the exploit and had less-than-noble plans for it.
Sony may suck, but fixing bugs is good for all of us. No exploit will ever remain only for the good guys to use.
Re: Boo hoo (Score:2)
Re: (Score:3)
This is the way things are supposed to work.
While I agree in general bugs getting patched is a good thing, I don't think this particular method is the way it's supposed to work. The PS5 hypervisor is a bit of the white whale, something that absolute experts have spent years prodding and poking at. Now we are in a time where not one but 2 random people suddenly discovered the bugs within hours of each other? I bet you one or neither even understood how the bug worked.
The PS5 got off light, but the reality is now we're in the days of AI generated bug r
Re: (Score:2)
You have to wonder why Sony is running the same code, finding these exploits and patching them first.
Exploits like this are never ideal anyway. You need older firmware for them to work, because as soon anything using them is released, Sony will patch them and require the latest firmware to play newer games and use their online services. Most people are going to want to wait for an unpatchable exploit anyway, something that either targets ROM code early in the boot process, or which comes after Sony has aban
Idiots and assholes with LLMs ... (Score:2)
... are still idiots and assholes, just with skills upgraded from "none" to "somewhat there, but not too impressive".
Same in the security space. They will never match an expert, but they can get lowish-medium skills and that is already very dangerous because that LLM does not provide them with the clue needed to use those skills responsibly. Eventually we may have to ass an "LLM user" category for the Darwin Awards.
Re: (Score:2)
... are still idiots and assholes, just with skills upgraded from "none" to "somewhat there, but not too impressive".
The problem, obviously, is not "idiots using LLMs in security space", but instead "motivated, skilled hackers using LLMs". There is a lot of reserach on this topic laltely,
AI is shrinking the time [tomshardware.com] from finding a bug to exploiting it.
Re: (Score:2)
Ah, no. The problem is primarily no-skill attackers with LLMs going after targets that the high-skill attackers would not have bothered with. Sure, drastically reduced time-to-exploit-available is a serious problem, but doing a competent attack is far more than that.
Call me weird but, (Score:2)
maybe don't "pour your soul" into hardware that is controlled by cutt-throat corporations?
What did he expect to happen? Sony thanking him for his work?
How old is he?
Ps5 (Score:2)
Lesson to learn: If your happiness depends on 100% participation from everyone you come into contact with, and 100% of people you -don't- come into contact with, you're going to be unhappy. Just go ahead and do what you're doing anyway.
Also p.s. Slashdot: There's no point putting red text up to say that my adblocker is making a mistake. I trust them a LOT LOT LOT more than I trust you.
Entire project reliant on single point of failure. (Score:2)