deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

DNS spoofing turns a Mac into a fake Twitch server to capture PS5 streams

A technical writeup shows how to redirect the PS5's built-in Twitch broadcast to a local machine by spoofing DNS, enabling Discord screen sharing without a capture card.

DNS spoofing turns a Mac into a fake Twitch server to capture PS5 streams

A Mac posing as Twitch

A technical writeup published on yashgarg.dev, which reached Hacker News's front page, explains how to intercept a PlayStation 5's live broadcast and redirect it to a computer on the same network — turning the console's built-in streaming feature into a general-purpose screen share that works with apps like Discord. The method needs no capture card and no console modification, only control over the DNS answers the PS5 receives.

According to the author, the motivation was practical: they regularly play games for friends watching on Discord, but the PS5 offers no Discord screen sharing. The standard workaround — an HDMI capture card feeding OBS on a Mac — costs over $100. Sony's Remote Play partly bridges the gap, but it forces the controller and earphones onto the receiving device, introduces occasional input lag, and leaves stream quality entirely under the PS5's control.

How the PS5 streams

When the broadcast button is pressed, the PS5 sends audio and video using RTMP, the Real-Time Messaging Protocol that Twitch and YouTube use for live ingest. The key detail, as the writeup explains, is that the console does not hardcode Twitch's server addresses — it resolves them through DNS on every broadcast. Whoever controls the DNS response controls where the stream goes.

Why the obvious spoof fails

Pointing ingest.twitch.tv at the Mac was the first attempt, and it did not work. That hostname is an HTTPS discovery endpoint on port 443: the PS5 asks it which regional ingest server to use and receives an address such as ap-southeast-1.prod.fi.contribute.live-video.net. The actual push then travels over RTMPS, RTMP wrapped in TLS, and the console validates the server certificate against trusted certificate authorities. A self-signed certificate fails, and the PS5 provides no way to install custom CAs.

YouTube looked more promising because its ingest accepts plain RTMP on port 1935, with no TLS to fake. The PS5 streamed to the Mac without complaint — for about 60 seconds. The console periodically checks YouTube's API to confirm the broadcast is live, and when YouTube reports no such stream, it stops sending.

Finding the plaintext path

The breakthrough came from watching dnsmasq's query log during a broadcast. The PS5 resolves ingest.global-contribute.live-video.net, which chains down to aps30.contribute.live-video.net — the real RTMP server, speaking plain RTMP with no certificate check in the way. Spoofing the parent domain contribute.live-video.net captures every subdomain, and with it the actual stream.

The setup

Two pieces do the work: dnsmasq, configured to answer the PS5's queries for Twitch's ingest and live-video domains with the Mac's LAN address (192.168.8.175 in the posted config), and nginx-rtmp, listening on port 1935 to accept the incoming broadcast. Both are bundled and managed by a small macOS menu bar app the author built; nginx's on_publish callback posts to the app on localhost:9988 whenever the PS5 starts streaming, surfacing a ready-to-copy RTMP URL.

Redirecting the console is handled at the router. On a GL.iNet device running OpenWRT, the author used DHCP option 6 with a tag matching the PS5's static lease, so only that console receives the Mac as its DNS server — no manual configuration on the PS5, and no effect on other devices.

The result is a 1080p60 H.264 stream with stereo AAC audio arriving directly at the Mac. The author plays it in mpv using the low-latency profile (mpv --profile=low-latency --audio-buffer=0.3 ...) for under a second of delay, then shares the window to Discord. The setup has reportedly run reliably for weeks, and the full source code has been published.

Why it matters

The writeup is a tidy demonstration that DNS remains a soft trust boundary. The PS5 treats TLS as non-negotiable where RTMPS applies, and that protection holds — but a legacy plaintext path on port 1935 was left open, and a periodic API check is the only backstop on the one service that uses it. For players, this is a zero-cost alternative to capture hardware and a way around Sony's closed streaming stack. For platform engineers, it is a reminder that locking down hardware and locking down protocols are not the same thing — and that this particular door stays open only as long as plain-RTMP ingest does.

  • #ps5
  • #dns
  • #rtmp
  • #streaming
  • #networking

Related posts