9 ms·
The “unpatchable” exploit that makes every current Nintendo Switch hackable
- Thaxll 8y agoSwitch security is a joke and it's really bad for the players, it means that people can hack online games fairly easily. fyi Microsoft > Sony > Nintendo in term of console security. Edit: For people who down vote me do you work in security field or just down vote w/o knowledge?
- Skunkleton 8y agoPeople might be down voting you because "Microsoft > Sony > Nintendo" comes off as grandstanding. As someone in the "security field", you must be aware that poor communication can tarnish otherwise correct information.
- threeseed 8y ago> Nintendo may still be able to detect "hacked" systems when they sign on to Nintendo's servers. The company could then ban those systems from using the Switch's online functions. So at least one positive then. Nintendo will be forced to improve their online services.
- jsiepkes 8y ago> By sending a bad "length" argument Not the first system to go down because of a boundary check failure. Though I was hoping for something more spectacular.
- deleted 8y ago[deleted]
- leggomylibro 8y agoCool! It's too bad that the cracking scene seems so vain, though. This article presented three groups: * One which wants to sell 'jailbreak' kits to enable piracy, while keeping the details to themselves. * One which had planned a related disclosure window amongst the broader community for two days from now, and seems to feel somewhat vocally that this release is very similar to their work. * One which seems like they might have flaunted that window a bit for the credit. It's amazing and inspiring what these people manage to accomplish, but it'd be nice to see less stepping on fingers - imagine what might happen if these groups really cooperated! I guess it's a very reputation-driven scene, but still...
- deft 8y agoThis is just the surface, with personal politics and clashing personalities obscured. The scene is incredibly dramatic and childish.
- av3csr 8y agoThe apex of the scene's pettiness has to be this http://wololo.net/2015/03/18/total-noobs-response-to-latest-tn-x-debate-about-the-z/ http://wololo.net/2015/03/18/total-noobs-response-to-latest-... (tl;dr the custom firmware checks if a certain user is using it, if so it formats their memory card)
- paulie_a 8y agoTo be fair that is pretty funny. If you are going to spite someone...put some effort into it.
- khedoros1 8y agoI remember that in part of modding the Wii, one of the tools asked if you were going to use the tool to play backups. I took it literally; my plan was to rip my game disks and run them from a USB drive. I answered "yes"...and the tool spit up a message against piracy, and set a flag somewhere in the NAND of the Wii. I don't remember exactly how I fixed it...I think there was some undocumented way to clear the flag that you could only find by reading the tool's source. It was a good reminder of how much stupid, blind trust I tend to put into random tools from the internet.
- delroth 8y agoThe nice thing with the console hacking scene is that the people doing actual useful work and the people causing drama are mostly disjoint sets.
- spike021 8y agoThis has always been the case with homebrew/jailbreak scenes, from the PSP to the PS3/PS4, to iOS, etc. There will always be squabbles among the different people and groups involved with finding exploits or developing jailbreak/"hack" "kits". Following from that, there will also always be people who want to jailbreak only to pirate games and there will also be groups who want to disclose the exploits properly, or use them purely for research and non-piracy fun purposes.
- mindslight 8y agoThis doesn't sound like it itself "exploits" anything, just deflates Nintendo's attempted scheme to exploit their customers by booby trapping their hardware. If you rigged your car to destruct 30 minutes after it went out of cell service, sold it to an unsuspecting buyer, and then laughed when they got stuck in the desert, you'd be rightfully thrown in jail. But yet these companies keep attempting to pull the same shit with impunity.
- BoorishBears 8y agoWell it’s your choice, open hardware or billions of dollars invested in an industry employing millions of people...
- yarrel 8y agoFalse dichotomy.
- BoorishBears 8y agoNot everything has to be a fallacy, I remember when people understood the concept of tongue-in-cheek. DRM (10NES) was a core part of the strategy for the console that brought a recovery from the 1983 video game crash. And even today publishers value a platform that is able to combat privacy (see: Denuovo and the lengths AAA productions go to delay piracy in PC.
- reality_czech 8y agoYes, publishers do certainly value a platform that is able to combat privacy. Although lately the combat has been a little one-sided.
- boomboomsubban 8y ago>DRM (10NES) was a core part of the strategy for the console that brought a recovery from the 1983 video game crash. About 1/3rd of the consoles sold didn't contain the DRM, yet the Japanese market still saw similar growth. Publishers value Denuovo, is there any proof that it helps sales?
- white-flame 8y agoI believe this has been known for a while, even though it's just now been "made public" as far as the press is concerned. In the meantime, disassembly of OS updates for the Switch imply that they're adding support for a newer version of the Tegra processor, which many speculate to be a silent hardware upgrade on new systems to boost security, not for a new model with speed upgrades.
- epai 8y agoYep! Looks like the silent hardware upgrade happened in v5.0.0 of the OS. Here's a youtube video published March 13th talking about it: https://youtu.be/ZzsbDGDwg1U?t=5m17s https://youtu.be/ZzsbDGDwg1U?t=5m17s And here's a related reddit discussion on the nintendo switch subreddit: https://www.reddit.com/r/NintendoSwitch/comments/8588c1/50_w.. https://www.reddit.com/r/NintendoSwitch/comments/8588c1/50_w....
- deleted 8y ago[deleted]
- ohthehugemanate 8y agoGreat news for people who want to use their purchased hardware for things Nintendo won't allow... Ie watching movies on the great screen, using generic hdmi adapters, playing games they already purchased for older console versions, or backing up savegames. Also great news for people who want to use their hardware for things that are actively against Nintendo's interests, like playing pirated games. All around, seems like a story of us: 1, them: 0 story.
- voltagex_ 8y agoAlso archiving games+updates. I'll be backing up all my carts as soon as possible. Publishers lose code, assets, entire games (or decide to never re-release them).
- simcop2387 8y agoNot sure about the carts and saves but you can at least push patches and downloaded games to SD cards and back them up. They'll only work for your console as far as I'm aware but that's fine with me.for doing a backup.
- jake_the_third 8y ago> backing up savegames This. I decided against buying a switch because I discovered that it prevents owners from backing up save files. I still don't plan to buy a switch until nintendo supports backing up save files officially like they do with cross-region compatibility. Having to loose 100s of hours of progress for what amounts to an arbitrary reason from a nintendo bigwig is not something I am willing to stomach.
- letsgetphysITal 8y agoBuy used. Nintendo won't get a cent, you'll pay less, and you won't be hit so hard in the wallet if your device fails after this mod.
- asdgjionio 8y agoGreat news! It's absurd that this is called an exploit or a hack. It's apparently wrong for people to use their own computer.
- userbinator 8y agoIn the FAQ, Temkin says she has previously notified Nvidia and vendors like Nintendo about the existence of this exploit, providing what she considers an "adequate window [for Nvidia] to communicate with [its] downstream customers and to accomplish as much remediation as is possible for an unpatchable bootROM bug." Why would you even want to do that...? Money? Fame? As I've heard it said memorably, "would you tell someone who takes you hostage and locks you up, that the lock is actually trivial to open?" This is just further evidence of a fact I've noticed for a long time: a lot of security researchers are pro-DRM, pro-corporatocracy authoritarians, and their vision of "more secure" is a dystopian nightmare. I still remember the good old days, when the hacking/cracking scene was entirely composed of people doing it for the freedom, with no do-gooding snitches to worry about... 10 years ago, if you shared a way to bypass a DRM scheme in the right places, it would live on for a long time. Now, it's more likely that some bastard is going to report it and get it patched in days to weeks.
- dsfyu404ed 8y ago>I still remember the good old days, when the hacking/cracking scene was entirely composed of people doing it for the freedom, with no do-gooding snitches to worry about... >10 years ago, if you shared a way to bypass a DRM scheme in the right places, it would live on for a long time. Now, it's more likely that some bastard is going to report it and get it patched in days to weeks. From the article it looks like someone else was trying to sell it so she put it in the open for free. >The release also seems to be partially a response to Team Xecuter, a separate team that is planning to sell a modchip exploit that can allow for similar code execution on the Switch. Temkin writes that she's opposed to Xecuter's explicit endorsement of piracy and efforts "to profit from keeping information to a few people."
- userbinator 8y agoIf she truly wanted to make it free, why secretly tell Nintendo and nVidia first? It's a cat-and-mouse game, and this mouse wants to tell the cat how to catch the other mice. In the old scene, you'd be branded a traitor for doing that.
- bri3d 8y agoThis has reasonable parallels to the PSP "Pandora's Battery" exploit, which put the device into DFU mode using a battery that emulated the factory service mode jig, and then exploited an issue in the trust chain verification in the first-stage (mask-ROM) bootloader. Similarly fixable with hardware only, which came soon after the exploit. This bootloader bug is much sillier (IMO) than Sony's, though. Sony's was a series of crypto mistakes in the trust chain verification: it decrypted blocks in place and there was an issue in the checksum code that left it vulnerable to a timing attack, so a very, very small valid-but-colliding block had to be constructed and the rest of the bootloader was then freely-injectable. This nVidia/Nintendo mistake is an even sillier basic protocol issue. I think the main lesson here is not to put complex protocol code in your immutable first-stage mask ROM, and if you do, to limit the surface area as much as possible, ensure memory safety, and audit the hell out of it.
- mar77i 8y agoYAY, they published it!!! I think this is amazing news. I'm almost fully convinced to buy a Switch now.
- buildbot 8y agoI wonder if this exploit would be workable on older Tegra systems, like for example a Tegra 3 int he digital cockpit on the Audi S3/R8/TT [1] or the K1 they are selling now [2] - it would be really great to be able to modify and customize those systems. [1] https://blogs.nvidia.com/blog/2016/04/25/virtual-cockpit/ https://blogs.nvidia.com/blog/2016/04/25/virtual-cockpit/ [2] http://www.nvidia.com/object/visual-computing-module.html http://www.nvidia.com/object/visual-computing-module.html
- asiekierka 8y agoYes, as far as I know both the Tegra 3 and K1 are vulnerable.
- misterbowfinger 8y ago> By sending a bad "length" argument to an improperly coded USB control procedure at the right point, the user can force the system to "request up to 65,535 bytes per control request." That data easily overflows a crucial direct memory access (DMA) buffer in the bootROM, in turn allowing data to be copied into the protected application stack and giving the attacker the ability to run arbitrary code. Classic.