Post: Regarding CFW installation on 3.60+
10-28-2012, 09:21 PM #1
(adsbygoogle = window.adsbygoogle || []).push({}); Trying to keep this as short and understandable as possible. I discuss why installing a modified PUP (CFW) on a OFW of 3.60+ will not happen anytime soon, so don't get your hopes up.

In 3.56 Sony fixed the metldr exploit (hardware) by wrapping its security around bootldr (hardware)
In 3.60 Sony fixed the ECDSA Algorithm, making the variable which was supposed to be randomly generated work as intended

What does this mean?

The ability to sign files (PUP, PKG, etc...) is lost because of the change of private key (not hardcoded) and the fix of ECDSA prevents us form getting the key again.

TO CLARIFY:

The recent exploit of bootldr (lv0) (hardware, Sony's Final Defense) allow the ability to modify PUPs 3.56+ which is why we are getting 4.21, 4.25, 4.30

BUT since the private key used in the OFW has been changed and is unknown, 3.60+ IS NOT POSSIBLE (Rogero 4.21 and E3 4.30 are still using 3.55 private key which is why you need 3.55)

ECDSA WILL NOT BE CRACKED. If it is, GLOBAL security will be compromised, as many other databases, websites, etc. are using ECDSA




If you need proof or further reading, google ECDSA.
(adsbygoogle = window.adsbygoogle || []).push({});

The following 25 users say thank you to ericmeltz for this useful post:

AMNE, Brentdevent, Cien, CodJumper:, DEREKTROTTER, ILovePie24!!, johncov1, Kush Friendly, Machiavelli_23, MxModz1, ohTrashy, PounDJo0DoGz0r, primetime43, Pseudo_Soldier, Pulsar877, sithxnew, spudeeelad, Swampman, Swifter, Terrorize 420, tunde1992, Vampytwistッ, Wesley_Pipes540, riggstq, xShadow

The following user groaned ericmeltz for this awful post:

kingpukka
10-28-2012, 09:23 PM #2
DEREKTROTTER
You're Goddamn Right
this should be stickied, would maybe stop the same questions been asked everyday Happy

The following 5 users say thank you to DEREKTROTTER for this useful post:

Kush Friendly, MxModz1, Pseudo_Soldier, Wesley_Pipes540
10-28-2012, 09:29 PM #3
Xx--AIDAN--xX
One Man Army
there is a way to dump your bootldr cfw is not impossible but sony are fucked as of now and soon they will be fucked again when a new cfw/jb comes in
10-28-2012, 09:31 PM #4
Originally posted by DEREKTROTTER View Post
this should be stickied, would maybe stop the same questions been asked everyday Happy


YES! I'm tired of reading non-sensical "theories" on how this or that might work. People just don't seem to get it.
10-28-2012, 09:33 PM #5
GE90
< ^ > < ^ >
Originally posted by ericmeltz View Post
YES! I'm tired of reading non-sensical "theories" on how this or that might work. People just don't seem to get it.

ive heard it takes like 330 million years to crack ecdsa encryption

The following 2 users groaned at GE90 for this awful post:

sciz0r, Super Vegito
10-28-2012, 09:37 PM #6
Originally posted by GE90 View Post
ive heard it takes like 330 million years to crack ecdsa encryption


LOL I don't know about that. But yes, even bruteforce would basically be ineffective
10-28-2012, 09:40 PM #7
MxModz1
Little One
Originally posted by ericmeltz View Post
Trying to keep this as short and understandable as possible. I discuss why installing a modified PUP (CFW) on a OFW of 3.60+ will not happen anytime soon, so don't get your hopes up.

In 3.56 Sony fixed the metldr exploit (hardware) by wrapping its security around bootldr (hardware)
In 3.60 Sony fixed the ECDSA Algorithm, making the variable which was supposed to be randomly generated work as intended

What does this mean?

The ability to sign files (PUP, PKG, etc...) is lost because of the change of private key (not hardcoded) and the fix of ECDSA prevents us form getting the key again.

TO CLARIFY:

The recent exploit of bootldr (lv0) (hardware, Sony's Final Defense) allow the ability to modify PUPs 3.56+ which is why we are getting 4.21, 4.25, 4.30

BUT since the private key used in the OFW has been changed and is unknown, 3.60+ IS NOT POSSIBLE (Rogero 4.21 and E3 4.30 are still using 3.55 private key which is why you need 3.55)

ECDSA WILL NOT BE CRACKED. If it is, GLOBAL security will be compromised, as many other databases, websites, etc. are using ECDSA




If you need proof or further reading, google ECDSA.


Originally posted by DEREKTROTTER View Post
this should be stickied, would maybe stop the same questions been asked everyday Happy

Exactly :y: But im sure they will still ask the same question again xD
3.55 PS3 is getting rare, thats good Needa
10-28-2012, 10:11 PM #8
RealTimeEditz
I defeated!
Originally posted by MxModz1 View Post
Exactly :y: But im sure they will still ask the same question again xD
3.55 PS3 is getting rare, thats good Needa
im Glad i got two 3.55 PS3
10-28-2012, 10:57 PM #9
Sticky it NOW!!! Great job on explaining it in a noobie fashion.
10-28-2012, 11:02 PM #10
primetime43
Knowledge is power Tiphat
Originally posted by ericmeltz View Post
Trying to keep this as short and understandable as possible. I discuss why installing a modified PUP (CFW) on a OFW of 3.60+ will not happen anytime soon, so don't get your hopes up.

In 3.56 Sony fixed the metldr exploit (hardware) by wrapping its security around bootldr (hardware)
In 3.60 Sony fixed the ECDSA Algorithm, making the variable which was supposed to be randomly generated work as intended

What does this mean?

The ability to sign files (PUP, PKG, etc...) is lost because of the change of private key (not hardcoded) and the fix of ECDSA prevents us form getting the key again.

TO CLARIFY:

The recent exploit of bootldr (lv0) (hardware, Sony's Final Defense) allow the ability to modify PUPs 3.56+ which is why we are getting 4.21, 4.25, 4.30

BUT since the private key used in the OFW has been changed and is unknown, 3.60+ IS NOT POSSIBLE (Rogero 4.21 and E3 4.30 are still using 3.55 private key which is why you need 3.55)

ECDSA WILL NOT BE CRACKED. If it is, GLOBAL security will be compromised, as many other databases, websites, etc. are using ECDSA




If you need proof or further reading, google ECDSA.


So most likely we will never get the private key again?

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo