Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"#define rand() 4"

Pure genius -- fool the hackers by making your "random" number static, they'll never guess! Now that PSN users are actually seeing money ciphered from their debit accounts, it's only a matter of minutes until the class action lawyers are all over this.



From the context, this appears to be a joke (see http://xkcd.com/221/), not a serious accusation.


It's also a reference to when the PS3 was first cracked, which was possible because they weren't really using random numbers to generate keys.

So yes, it is a serious accusation that points out their consistently lax programming techniques when it comes to security.


No.

The problem was that one of the parameters they used in their ECDSA signatures, k, was the same at least once. This allowed the key to be computed with simple math, but the generation of the key itself was not the issue.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: