Hijacking the PS5's RTMP stream

(yashgarg.dev)

142 points | by ibobev 5 hours ago ago

38 comments

  • londons_explore 2 hours ago

    Kinda sad that it's 2026 and this data still goes over the internet unencrypted...

    RTMP and all the video and audio protocols behind it aren't trivial either - I bet there are hundreds of exploits waiting to be found that any three letter agency sitting on the internet can use to take over your PS5 and all credentials stored within too...

    • opello 21 minutes ago

      Wouldn't this require a man-in-the-middle since the PS5 is transmitting data to a specific server, YouTube or Twitch in the article?

      There are extensions to RTMP to use encryption or even just TLS. But do you mean that the risk of fragments of audio and video bitstreams going out unprotected presents a remote code execution risk? That seems less a problem of vulnerability and more one of privacy.

    • rezonant 2 hours ago

      Well, the server just responds with acknowledgement information, the client is doing most of the work and most of the complex parts of RTMP are hand waved and faked by both the client and the server because no one cares about how Flash used to work.

      So somewhat unlikely to be able to exploit it but have at it hass.

      I'd imagine it'd be easier to exploit the server side, actually.

      • londons_explore 39 minutes ago

        Yeah, but the server is most likely running the whole thing in a docker container with no permissions to do anything. Big companies security teams tend to require that when opening non-trivial third party code up to the internet.

        The client on the other hand I would guess is running it's code as root, or at least something with full GPU access.

  • jprjr_ an hour ago

    Feel like there's a few parts missing that I'm not getting.

    The author mentions that the PS5 uses RTMPS to push video up to twitch - but suddenly it just uses plain RTMP?

  • Muromec 3 hours ago

    Don't mind me, I'm just sitting here with my HDMI-RX port on rk3588 being happy that is works and I didn't brick the board when doing uboot update to uncurse it.

    • concerneddork 3 hours ago

      Lucy, esplain please.

      • kotaKat 3 hours ago

        rockchip something-or-other that's on the KiwiPi 5B. iirc it can strip hdcp and all that jazz, too? one of the ports is labeled "HDMI RX" for input.

        https://kiwipi.com/blog/rk3588-hdmi-in-test/

        • bityard 37 minutes ago

          Man, that article has _all_ the AI smells. Here's the only interesting part:

              gst-launch-1.0 v4l2src device=/dev/video0 ! videoconvert ! autovideosink sync=false
          
          I guess it just has an HDMI capture chip on-board. If you have a spare USB port, these are under $20 everywhere.
  • Transformanshen 14 minutes ago

    Honestly the DNS trick in this post is neat but I'm not setting up dnsmasq just to share my screen. This is the kind of thing where Sony could just let you stream to anything and they don't, and it's annoying

  • ImpostorKeanu 2 hours ago

    I'd kill for a Bluetooth peripheral workaround. I've a Clicks Power Keyboard that'd be great to use with the PS5.

  • mixdup 4 hours ago

    Maybe I'm missing something but there seems to be a gap between "figure out the REAL hostname" and "we no longer have to worry about the stream never showing up on YouTube"

    • Sebb767 4 hours ago

      The live-video.net domain belongs to Twitch. So, from what I can gather, apparently the OP switched back to Twitch streaming and the last-hop RTMP server does not use certificates.

      • fnctrev an hour ago

        twitch doesnt actually require tls. it uses plain rtmp over port 1935 and rtmps over port 443.

    • Aissen 4 hours ago

      Me too. YouTube was given up, and what the op did was to use Twitch streaming and redirect it before the forward to a TLS-verifed server, bypassing verification:

      > redirects the actual stream to the Mac without any certificate issues.

  • tamimio 3 hours ago

    You can combine the last two steps the nginx and mpv with obs and gstreamer, or just gstreamer really.

  • PaulHoule 2 hours ago

    Vote with your $ and get a gaming PC. Don’t let people who remember the 1990s tell you it will be a sweaty experience, install Steam and it won’t be. There are like 15 exclusive games for the PS5, what’s the point?

    • tantalor 2 hours ago

      I'd rather eat poison than use Windows.

      • occz 40 minutes ago

        Linux works quite well for gaming these days. I have a desktop that used to run Windows 11, which is EOL, so I was faced with either upgrading to Windows 12 or trying out Linux on desktop.

        So far there have been zero games that have had issues. Granted I've only really had time to play 5 or so games, but I am genuinely impressed with how far it's come.

      • RankingMember 2 hours ago
      • freshpaint 2 hours ago

        Don’t use Windows. Try CachyOS or Bazzite.

      • zamalek 2 hours ago

        Depending on what you play, you don't have to. But if you play draconian anti-cheat games then fair point.

    • ImpostorKeanu 2 hours ago

      I vote with my time by not maintaining drivers, setting profiles, and evading anticheat rootkits. Also, M$ is cancer.

      • sampullman 2 hours ago

        I just click "Install" and then "Play" in Steam on my non-Windows machine. I guess you can't play Fortnight or whatever, but it works great for me.

      • PaulHoule 2 hours ago

        Playing 20 or so games on my Steam Deck I had to edit one only .INI. The Steam Deck is the only device I've ever seen that pairs perfectly with AirPods every time, it beats Apple devices.

        I also have a big gaming PC/AI development with a NVIDIA GPU and, yeah, NVIDIA's app to maintain drivers is a little skeezy but I just download games on Steam and they "just work" though I am not really a day one kind of gamer unless it is a new Dynasty Warriors or Fate game.

        I'll grant that kernel anti-cheat sucks, if you play that kind of game and cheating bothers you well then... Maybe a locked down environment like the PS5 is a feature and not a bug.

        • jameslars an hour ago

          You kind of undermine your own argument here. The Steam Deck is more a console than a PC, with lots of "just works" baked in either directly or through community support that makes it simple.

          In 2026 I still have to mess with game settings, driver issues, and DRM garbage behavior as a primarily PC gamer. PC gaming is still a long way from "just works" and I think you probably just take for granted a lot of things you have to do to make it work vs a typical console experience.

          • PaulHoule an hour ago

            Look, in the 1990s I was horrified of PC gaming because I was always dealing with kids who thought they were having fun with their PC whereas they were really fighting with an ugly plastic oversized joystick that fell apart two times during a level and had to be recalibrated three times. Or that it was a sweaty battle with the keyboard and mouse that reprises the sweaty battle with the keyboard and mouse I have at work and with my productive hobbies.

            I got into console gaming in the late 00's and had a few portables and an Xbox 360 and a PS 3 just after they became obsolete and played through the libraries. My favorite games were games for the PS Vita from Japanese publishers like Altus, Idea Factory and Acquire. When Sony and the publishers quit investing in the Vita those games went right to Steam. And my experience with Steam is, "click on the Steam icon", pair the Xbox controller, use the controller to pick a game, and sit back. Like yeah, there still are sweaty keyboard-and-mouse games and I might even play one once in a while, but I'd say my experience on the big machine is "console like" with the condition that the kind of games I play are "console like" games.

      • volkercraig 2 hours ago

        get an immutable linux distro

    • catchnear4321 2 hours ago

      Sorry, already own a PS5 and the money for replacements is spoken for.

      I think that was the point?

      • PaulHoule an hour ago

        To be fair with the current RAM prices I don't want to replace any device right now!

  • rezonant 2 hours ago

    Imagine if they just let you specify your own RTMP destination. Crazy thought, I know.

  • charcircuit 3 hours ago

    Another crypto mistake by Sony this time leaving traffic completely unencrypted.

    • rf15 3 hours ago

      is it truly a security issue here? Especially relative to the machine's effort to encrypt the stream.

      • monster_truck 2 hours ago

        Debatable, but historically quite a few consoles and handhelds have been popped wide open by leveraging defects or vulnerabilities in how media is handled. Without looking at an exhaustive list, I believe tif files have claimed the most victims with the next two being split between videos and then media within browsers. I'm aware this is more about out than in, but a gap is a gap and gamers will use whatever they can find.

      • xd1936 2 hours ago

        My video stream sent to a public streaming audience might be seen by the public in transit!

        • charcircuit 2 hours ago

          Both YouTube and Twitch allow you to do non public streams. And someone can get the stream key and stream over you. With the twitch model where stream keys don't get replaced you can imagine a secondary market place selling access to stream content on compromised channels.

  • tvbusy 3 hours ago

    PS5 uses DNS to resolve where to send RTMP stream. The author found out that they cannot spoof the main server since that server uses TLS and it's not possible to make the PS5 trust self made certificate. The author then runs a real Twitch stream and monitors DNS requests and finds DNS of the server that receives the RTMP stream and spoofs only that final server. It's more of a problem with RTMP protocol/Twitch security rather than the PS5.

    • bigfishrunning an hour ago

      If sony wanted the ps5 to only send to twitch, they could absolutely enforce TLS authentication of the server, but they don't, so i guess send your video wherever.