Hijacking the PS5's RTMP Stream

(yashgarg.dev)

89 points | by ibobev 3 hours ago

6 comments

  • PaulHoule 10 minutes ago
    Vote with your $ and get a gaming PC. Don’t let people who remember the 1990s tell you it will be a sweaty experience, install Steam and it won’t be. There are like 15 exclusive games for the PS5, what’s the point?
    • tantalor 5 minutes ago
      I'd rather eat poison than use Windows.
      • zamalek 0 minutes ago
        Depending on what you play, you don't have to. But if you play draconian anti-cheat games then fair point.
      • freshpaint 0 minutes ago
        Don’t use Windows. Try CachyOS or Bazzite.
  • Muromec 1 hour ago
    Don't mind me, I'm just sitting here with my HDMI-RX port on rk3588 being happy that is works and I didn't brick the board when doing uboot update to uncurse it.
  • mixdup 2 hours ago
    Maybe I'm missing something but there seems to be a gap between "figure out the REAL hostname" and "we no longer have to worry about the stream never showing up on YouTube"
    • Sebb767 1 hour ago
      The live-video.net domain belongs to Twitch. So, from what I can gather, apparently the OP switched back to Twitch streaming and the last-hop RTMP server does not use certificates.
    • Aissen 2 hours ago
      Me too. YouTube was given up, and what the op did was to use Twitch streaming and redirect it before the forward to a TLS-verifed server, bypassing verification:

      > redirects the actual stream to the Mac without any certificate issues.

  • tamimio 1 hour ago
    You can combine the last two steps the nginx and mpv with obs and gstreamer, or just gstreamer really.
  • charcircuit 1 hour ago
    Another crypto mistake by Sony this time leaving traffic completely unencrypted.
    • rf15 55 minutes ago
      is it truly a security issue here? Especially relative to the machine's effort to encrypt the stream.
  • tvbusy 1 hour ago
    PS5 uses DNS to resolve where to send RTMP stream. The author found out that they cannot spoof the main server since that server uses TLS and it's not possible to make the PS5 trust self made certificate. The author then runs a real Twitch stream and monitors DNS requests and finds DNS of the server that receives the RTMP stream and spoofs only that final server. It's more of a problem with RTMP protocol/Twitch security rather than the PS5.