AI Weekly Malaysia

Back to items Summaries

Hijacking the PS5's RTMP stream

ID
29946
Status
summarized
Published
28 Sep 2026, 11:35 PM
Fetched
30 Sep 2026, 2:08 AM
Provider
Hacker News
Category
dev-community
Original URL
https://yashgarg.dev/posts/hijacking-ps5-rtmp-stream/
Source URL
https://hnrss.org/best

Summary

Score
5.5
Created
30 Sep 2026, 2:10 AM
Tags
Audience
developers

What happened

Yash Garg documents routing a PS5's broadcast stream to a local machine instead of Twitch, because the PS5 has no native Discord screen sharing and a capture card costs upwards of $100. The key finding is that the PS5 resolves ingest.twitch.tv via DNS on every broadcast, but that host is only a discovery endpoint — it returns a regional ingest hostname like ap-southeast-1.prod.fi.contribute.live-video.net, where the real stream is pushed. Spoofing that ingest host runs into RTMPS (RTMP over TLS on port 443), and the PS5 validates the certificate against trusted CAs, so a self-signed cert fails.

Why it matters

The practical lesson is that hostname secrecy isn't the control — the discovery-then-ingest split plus CA-validated TLS is. If you build a client that pushes to a vendor endpoint, note that a self-signed cert or a DNS override won't get you past it, and that a two-step discovery call means blocking one hostname isn't enough. The write-up is truncated at the certificate-validation failure, so the actual workaround isn't shown in the text we have.

Discussion angle

Which is the real lock here — DNS control or certificate validation — and what does that mean for anyone building a client that talks to a vendor-controlled ingest endpoint?

Top