Hacker Geohot denies involvement in PlayStation Network attack, blames Sony’s hubris

One potential suspect behind Sony’s massive PlayStation Network security breach was 21-year old George Hotz, AKA Geohot, who recently settled a lawsuit with the company over hacking into the PlayStation 3’s hardware. But in a blog post today, Hotz denies that he had anything to do with the PSN attack.

Assuming he’s telling the truth (“I’m not crazy, and would prefer to not have the FBI knocking on my door,” he said), that leaves plenty of other suspects for Sony to consider, like the patchwork group of hackers calling themselves “Anonymous,” who have been known to cause distributed denial of service (DDoS) attacks.

Hotz clearly doesn’t have much sympathy for Sony. He says in the blog post that Sony invited the attack by making enemies of hackers: “The fault lies with the executives who declared a war on hackers, laughed at the idea of people penetrating the fortress that once was Sony, whined incessantly about piracy, and kept hiring more lawyers when they really needed to hire good security experts. Alienating the hacker community is not a good idea.”

He also makes sure to separate the sort of hacking that he does from the PSN attacks: “Running homebrew and exploring security on your devices is cool, hacking into someone else’s server and stealing databases of user info is not cool,” he said. “You make the hacking community look bad, even if it is aimed at douches like Sony.”

One potential project Hotz says he was working on was a PlayStation Network alternative that jailbroken (or hacked) PS3s could use to play multiplayer games and download homebrewed software. That project ultimately never happened once Sony set its legal hounds on him.

Hotz went on to say that he bets “Sony’s arrogance and misunderstanding of ownership put them in this position” — a common sentiment among the hacking community.

“Sony execs probably haughtily chuckled at the idea of threat modeling. Traditionally the trust boundary for a web service exists between the server and the client,” he said. “But Sony believes they own the client too, so if they just put a trust boundary between the consumer and the client (can’t trust those pesky consumers), everything is good. Since everyone knows the PS3 is unhackable, why waste money adding pointless security between the client and the server? This arrogance undermines a basic security principle, never trust the client.”

He suggests that the hacker shouldn’t sell the stolen private data (which includes credit card numbers and would likely fetch a high price in some circles), and that he’d love to see a breakdown of just how the hack was completed. But with Sony and law enforcement on red alert to find the culprit, I don’t suspect we’ll see a breakdown of the attack anytime soon.

  • http://pulse.yahoo.com/_3UVCUGZPSDFCHBQXJJ7CC6PDUU Joy Payne

    This kid is a world class douche. He knows as well as everyone else that “homebrew” is simply a smokescreen for allowing illegal downloads. He is part of the problem that the entertainment community as a whole is having right now and it's keeping new honest creators from breaking in while keeping those already “in the club” deep in money. So, good job, idiot. Thanks for ruining it for a lot of good people out there.If he's so smart, why does he need to hack anything at all? Instead of piggybacking on another's work, why not get together with others in the hacker community and build your own system and network for homebrewing? I'll tell you why … because he's LAZY.

  • Guest

    Don't piss off the hacking community? Please! Every hacker needs to be arrested. Did Sony need better security? Obviously. But they should have never settled out of court with that puny GeoHot. The fault does NOT lie with the execs of Sony like GeoHot would like us to believe. The fault lies with hackers that can't stand to play by the rules and in most cases can't play games as they are made so resort to hacking to make it easier. Hackers are scum of the earth and need to be dealt with.

  • http://www.andrewconn.com Andrew Conn

    @Joy and @ GuestOne: you both sound like you work for Sony.Two: if a consumer buys something, then they should have the right to do whatever they want with it. It's their property. That's what a lot of corporations don't get, in my opinion. Or, they do 'get it', but use legal action instead of innovation and intelligence to prop up their business models.Three: I agree with Hotz, that Sony's arrogance brought this upon them. I don't agree with stealing data and possible credit card fraud, but I think Sony deserves every ounce of what they got. Hopefully there's a lesson in there somewhere for them.

  • http://pulse.yahoo.com/_5IZY7KXSMYEJYGCJCJ35RU7JGA religous equal

    @Joy and @GuestYour comments show the obvious ignorance to your knowledge of what a hacker really is. Hackers are everywhere and are usually the ones that come up with innovating ways to solve complex problems. Without hackers, True Hackers, we would never have innovation. The people who just break into stuff for malicious reasons are not really hackers. That said, I would refrain from insulting someone or something without actually understand them at all.Also, I agree completely with Andrew Conn, they reap what they sow. In this age in which anything and everything is getting exploited, why Sony chose not to secure millions of people's information is beyond me. Then again, maybe they just didn't realize that people are just naturally curious, and fooled themselves to think that a simple paper would protect them and the information of millions.Hopefully they learn from this event, but who knows…

  • http://pulse.yahoo.com/_KO5MQ6ZZIOEMU46AZHOUCJDRMM dan m

    I'll jump on the anti-Joy bandwagon (sorry, Joy):Hotz made the homebrew as a reaction to Sony removing the “install other operating system” feature from the PS3 last year. You can hardly blame consumers for wanting the functionality they thought they purchased initially, and for being pissed that Sony took it away. What % of consumers really go through the trouble of installing another operating system and finding cracked games to play? How much money is that REALLY costing Sony? Answer: Less than this fiasco cost them.

  • http://twitter.com/danramosd Dan Ramos-Dominko

    every hacker should be arrested? could you please define hacker to me? i like to hack my webcam and wiimote to create a 3d tracking device, should i be throwin in jail for that? I also like to write programs that hack my operating system so i can submit patches for them, is that hacking? I use wireshark to sniff the wireless traffic on a network while preforming a DOS attack, that surely must be considered hacking. You must of have missed the part where he says “You make the hacking community look bad,”. All 'hackers' arent bad people, and they shouldnt all be arrested. Hell, a lot of them probably have higher end jobs than you ever will because of their ability to 'hack' so well. Next time you think a whole group of people should be arrested and call of them scum, make sure you know what group of people youre really referring to.

  • http://profiles.google.com/pishkin69 Déal Loyie

    You people are idiots! You're all just pissed off because you can't play COD. Can it and set your gamer rage aside because this guy is totally right in everything he says. Your lives online would be equal to just about nothing if it wasn't for hackers. Saying every hacker needs to be arrested is like saying anyone who's ever downloaded a movie FOR FREE should be arrested. Don't play it off like your a saint and stick your nerrow minded opinions up your asses because they don't mean shit.Sony got owned, enough said…it sucks cuz I can't use my ps3 but on the other hand I can admire someone with the balls and know how to pull off something like this.

  • mackypoo

    youre just as big a douche as he is. assuming you know him. assuming you know what his thought process is. assuming that people want to make their own system just to run homebrew (you should look up what homebrew is). and most importantly, assuming EVERY person who hacks their system just wants it for illegal downloads.

  • GodEGO

    you all need to just stop being so immature. TO THE NON HACKER : most hackers should not be put in the same class as whoever it was that hacked sony's servers. It's a hobby of theirs and most of the time it is harmless. it's not every hackers fault that this happened. TO THE HACKER: All the anger you hear is well founded. dont take it so personal. People need to vent. Alot of the overly pissed off people online only have a playstation and dont have any other way to play online games. I assume most of you have multiple systems or if not at least a great computer that you can play games online with. how would you feel if all your favorite means of entertainment suddenly stopped working? i bet you'd be pissed and almost feel lost. Those guys up top are just angry they can't do what they love. and anyway it sounds like they are more pissed at cheaters than anything. which i would have to agree with them, cheaters aren't fun. Most people out there like pure straight up compitition to know who's better. I know i do. and that's why alot of people who cheat will never admit that they do cheat because they want to be seen as being legitly good. AND TO YOU GEOHOT: im not exactly sure what you did when you figured out how to jailbreak the PS3 OS, but if you were able to get in and actually create things that manipulated actual gameplay of online games (i.e. promote cheating) than you deserved sony coming after you. If thats the case more than 90 percent of the gaming community is your enemy too, you have no sympathy from us. I don't really know many of the details and frankly i dont care what you do with the playstation. but if or when you made it possible for people to manipulate existing game code and use things that werent in the original game you crossed the line and pissed alot of people off. if you didnt do such a thing, well then im sorry lol. So who ever hacked sony's servers, shame on you. You think you are hurting sony. YOU”RE NOT. you tell us gamers “THINK ABOUT THE BIG PICTURE”. how bout i tell you to do the same. this is nothing to sony. in the grand scope of things, they will “recover” from this minor burn and still make billions of dollars more after this. you believe you have some great cause your fighting for. what exactly is that? your not fighting for our freedom, and piss on you if you believe you are. oh if anything you're fighting for the freedom of a TINY percentage of the population to be able to get this “bad ass custom app on their iPhone”. That's not freedom. You want to make a difference in this world?! Hack the Federal Reserve database release all their records! Hack into wall street and crash the whole system! You are hurting the little guy with your selfish wants and narrow sighted vision. Alot of small game developers are taking a very big hit because of what you have done not to mention all of us small fry in the world who just want to get online at night and play instead of watching lame tv shows. Dont sugar coat your actions by saying “ITS FOR THE GREATER GOOD” or whatever you may think. think about your neighbor or your friends who arent as technically savy as you, who dont have these insanely powerful gaming computers to fall back on. think about all the people who's credit card numbers you've stolen that are struggling to get by in this world who are gonna take a big hit on their credit reports which may prevent them from buying a car or house. Or, maybe its you dont care as long as you get yours. well then if thats the case… then i guess there's no telling you.

  • http://pulse.yahoo.com/_EN4PD4YSTEVUA3M4QVOUWLI74I Nietzsche is your Savior

    What I would not give to get my hands on the two people responsible for this; the holier-than-thou Sony CEO and this arrogant, snot nosed piece of sh*t hacker.

  • markymarq

    The problem I'm seeing is most of you who agree with “hackers” state Sony got what they deserve. What you fail to realize is Sony is not “getting” anything. Hackers are only hurting people who play these games, it only hurts the consumer. All the hate that the average consumer has for the hacker is 100% justified. Who gives a shit about the company. Fuck the corporation, hack them do whatever you want, but don't interfere with your fellow gamers ability to game, that shit is fucked up.

  • http://pulse.yahoo.com/_D5EMRE5BWULXWWQFOY7IOFJRBY ray

    Marky is right you fuck the corp. but not the gamers. Marky's gotta tottally good thought on this because what you haven't thought about are the complete and total annihilating no life stonerz, or some of my best friends.Any ways Sony should of been ready for this though because a few years of PSN the guy must have gotten either so no lifed or really bored.. by this he took the hacking to a whole new level by fucking up a whole network. Im just like the rest of you i wanna get home play a few matches of whatever games i feel settle down watch a movie and pass out.. This morning netflix took a shit on me. It won't work either. So that either means Sony is trying to protect are netflix accounts or the hacker is getting deeper.. Personally Sony is the best exept i hate it when you jump in a match of MW2 and all of a sudden your floating and it says FTW with a marijuana leaf by it.. My whole thinking of this is that people who feel the need to hack must be really dumb or really smart.. but when you start fucking with people's lives, money, and physical and mental enjoyment.. If whoever this is does that and all the gamerz completely find out there gunna give whatever they have to knock the shit out of them. Plus hacking games makes them boring you wanna find out if your good at something try finding a job with Sony cuz you'd have it made in the first place, second they should of asked for more security or asked how apple does it thats where Sony fucked up.

  • http://openid-provider.appspot.com/collection60@googlemail.com Collection60

    If Sony had hired GeoHotz instead of suing him, they'd be a whole hell of a lot richer.Firstly, he'd cost less than a fucking lawyer because we all know how greedy those bastards are. And Sony had to pay an entire team to sue him.Secondly, he'd have saved them a few billion dollars by getting their security correct.Sony needs to listen to this kid. He knows what he is talking about.

  • http://openid-provider.appspot.com/collection60@googlemail.com Collection60

    Maybe the COD fan boys will take up bicycling for a change. It's summer time after all!

  • http://twitter.com/Marky_Merk Tabias M

    Maybe you should pick up sucking dick. It's summer time after all!

  • http://profiles.google.com/drewcunningham20 Drew Cuinningham

    completely agree with this…they are criminals..pretending to be making a point!…what point has this made?…only how we need to crack down harder on the 'hacker community'..and to Dan Ramos whatever…”hacking” your webcam to a wiimote is not something I consider hacking..thats manipulating a system and does no damage to anyone…your not hacking into a secure system…hacking can be a loosely termed phrase..and you hacking a system you have no right to be near where millions of peoples personal data is stored…thats criminal on a very large scale!..i'd like to know who's wireless network you perform DOS attacks on?..If the network has nothing to do with you..you shouldn't be there…if i was attacking your postman and filtering the post you get looking at private letters and stopping letters getting to you…would that be ok?….NO…DOS attacks are criminal dipshit

  • http://profiles.google.com/drewcunningham20 Drew Cuinningham

    Sorry…downloading movies for free is a criminal offence!..I don't do it..if i don't have the money to watch a movie…i don't watch it!..Millions of euro are spent on making movies…and movie companies would go out of business and loose everything…and then movies wouldn't have budgets like they do if everyone in the world lived with your principals. Same goes for Sony..they are a company..they make decisions for profit…the more profit they get the more goes to research and development and the rate of improvement in technology quickens. Do you think if everyone got black market televisions and abused big companies we'd have latest 3D televisions that billions of euros research we're spent on…where do you think all that money comes from??..the money tree?…its called supply and demand you moran!..you might be only one small loss in revenue…but if everyone was a dishonest little shit…big companies wouldn't exist and we wouldn't have a Sony playstation in millions of people homes worldwide!

  • http://profiles.google.com/drewcunningham20 Drew Cuinningham

    I agree with most of that…and criminal hacking and cheating are different to manipulating a harmless system that has nothing to do with anyone else!As to hacking Sony…I can't understand that. Without Sony and their investing billions of dollars…we wouldn't have a Sony Playstation. Thats the way the world works. Supply and demand. Big companies are central to our technological progress as they fund it!There is no logic behind attacking Sony, suspending a entertainment system with millions of profiles and having normal peoples information open for attack. I don't like how some large companies are run..but I don't blame Sony..I blame the people who hacked the system…who cheat..and generally ruin everything for everyone else!..If you want justice and fight for justice…go after governments!..thats where most the corruption is at!

  • http://profiles.google.com/modulusoperator Brian Collins

    There should be reasonable restrictions on acceptable use of any consumer product, just as we don't want consumers to use volatile fertilizers in bombs or equip their cars with weapons to punish irritating drivers. Modifying products to increase their legitimate performance or range of use should be supported and encouraged as it promotes progress and fair pricing in technological markets.

  • truthasweknowit

    Joy Payne. One thing is for sure, Geohot is no idiot. It takes alot of knowledge and skills to reverse engineer and hack a system, even if the system was poorly secured. But you are right, the majority of hackers take the “easy way” in accomplishing thier goals. It would take an almost unimaginable amount of time for a single hacker (or small group) to develop the usual system they are hacking into to serve thier purpose. I find it hard to beleive that these gifted people can hack into a system, but fail to read the terms of use prior….. Its illegel to hack into most commerically developed software/hardware. If you dont like it, dont buy the systems. Mackypoo, please try not to jusify hacking into a system illegally becuase of the reason, its a contradicting statement. Celloction60, you dont hire a person that ignores the terms of use of your product and give him more acces to your already week system. One thing poeple are failing to realize is sony poor reaction to this incident. Are you telling me theres no way to allow customers to use the online services without having a database with personal information connected to the network? you cant patch the system so people can sign in with a username? My biggest concern in this is Sony's overall commitment to thier customers. “but psn is free”….not when you place an icon on the game's retail box stating (2-X players) Then it become a legal requirement. The money you paided for the game pays for those servers you log into.

  • http://pulse.yahoo.com/_Q3V7PC2KUYIKW53TXWK6K66FWE John

    The best part about some of the arguments in this page is the fact that thinking homebrew is wrong. I mean I remember when the PS3 came out and all the other things you could do with it. Like use it as a computer. That was kinda neat. But then it was downgraded to just a game console. All geohotz wanted to do was restore that feature in a sense. By condemning him because his ability can also be used by others to play downloaded games off the internet is just arse backwards. With that logic you could say Sony was wrong for making something that could in turn be used to do something illegal with. Also, fun fact. How many of you who are preaching own the games you have paid 60 bucks for? None. Because even if you buy the game from a store you do not own it. Google that irony. You are paying for the right to play their product. Another fun thing to google, game trading stores. They will be gone before you know it too. Just look at how much your game companies respect you.

  • http://twitter.com/danramosd Dan Ramos-Dominko

    The only part you got right is 'hacking can be a loosely termed phrase' which was the point of my whole comment.  In the loosest term possible hacking is simply taking a physical or digital structure and altering its functionality to suite your own needs.  My biggest problem is people are talking shit on all hackers when they have no idea who they are referring to.  If you have a problem with the black hat hackers you are referring to than you should be a little more specific.Thats about as ignorant as saying all brown skinned people are terrorist .Oh yeah and I would like to hear your thoughts on TechCrunch's Hackathon.  Are all of them criminals, or did TechCrunch just happen to title this event incorrectly?

  • http://venturebeat.com/2011/08/11/fresh-meat-for-devbeat/ Fresh Meat for DevBeat | VentureBeat

    [...] with leaders in the field and the occasional tidbit of developer drama (come on, don’t pretend it never [...]

  • http://www.socialnetworkbackgroundcheck.com/fresh-meat-for-devbeat/ Fresh Meat for DevBeat | Social Network Background Check

    [...] with leaders in the field and the occasional tidbit of developer drama (come on, don’t pretend it never [...]

blog comments powered by Disqus

GamesBeat is your source for gaming news and reviews. But it's also home to the best articles from gamers, developers, and other folks outside of the traditional press. Register or log in to join our community of writers. You can even make a few bucks publishing stories here! Learn more.

You are now an esteemed member of the GamesBeat community. That means you can comment on stories or post your own to GB Unfiltered (look for the "New Post" link by mousing over your name in the red bar up top). But first, why don't you fill out your via your ?

About GamesBeat