Homebrew Nintendo now has a 3DS bug bounty page open

shelby--san

Well-Known Member
Member
Joined
Nov 20, 2016
Messages
111
Trophies
0
Location
Montréal, Québec
XP
77
Country
Canada
No. However they are trying to stomp out everything according to the page

Yes, I have seen that. ;(
Why now, though. Isn't the 3DS EOL?

use the very method we used to write back the firms

Would they really go that far? :unsure:
They had the means to patch the other, more primitive exploits we had before.. and except for QR code injecting, pulling games from eShop (instead of patching them) and nuking TubeHax...
I feel they waited far too long to take actions.
 

angelus kun

Well-Known Member
Member
Joined
Aug 7, 2015
Messages
363
Trophies
0
Age
28
Location
in my dreams
XP
322
Country
Mexico
why nintendo dosent read github pages of luma source code a9lh source code on gbatemp wiki and 3dbrew i think they know everything about this but the money its more useful for they
 
  • Like
Reactions: Autz

Alex658

Well-Known Member
Member
Joined
Jun 4, 2010
Messages
1,206
Trophies
1
Age
29
Location
Colombia
XP
1,195
Country
Colombia
luma has firmprotection so it won't let a9lh be over written

Okay, I'll reply to you just this one time to see if you get it.

Remember the way a9lh worked? How you had to get back to 2.1 to get the console keys and install the exploit?
Well, they still have the master keys, since OTP cannot be changed (one time programmable code), they could just as easily overwrite firm 0/1 by re-exploiting their own code, or somehow reversing a9lh.

Well, this shall prove amusing, now more than ever i want to see what is disclosed by smea at the talk. they claimed to have won the game after all.
 

Raylight

Paranoid Temper
Member
Joined
May 10, 2014
Messages
1,178
Trophies
1
Age
34
Location
Who wants to know?
Website
sites.google.com
XP
2,890
Country
United States
Okay, I'll reply to you just this one time to see if you get it.

Remember the way a9lh worked? How you had to get back to 2.1 to get the console keys and install the exploit?
Well, they still have the master keys, since OTP cannot be changed (one time programmable code), they could just as easily overwrite firm 0/1 by re-exploiting their own code, or somehow reversing a9lh.

Well, this shall prove amusing, now more than ever i want to see what is disclosed by smea at the talk. they claimed to have won the game after all.
Last i heard he was arrested in japan. was that true?
 

hacksn5s4

Banned!
Banned
Joined
Aug 12, 2015
Messages
4,332
Trophies
0
XP
1,322
Country
i got a9lh because its permant homebrew and it gives you full acess to the system before homebrew got patched and you had to stay on an older firmware and not be able to play online you can also install homebrew to the homemenu
 

Mikemk

Well-Known Member
Member
Joined
Mar 26, 2015
Messages
2,093
Trophies
1
Age
28
XP
3,159
Country
United States
Why now, though. Isn't the 3DS EOL?
Obviously not, if they're investing tens to hundreds of thousands of dollars removing exploits.

Remember the way a9lh worked? How you had to get back to 2.1 to get the console keys and install the exploit?
A9LH can install on any version 9.2-, only dumping the OTP needs 2.1, and that need only be done once
 
  • Like
Reactions: SSG Vegeta

SaffronXL

The Grand Galactic Inquisitor
Member
Joined
Nov 17, 2016
Messages
340
Trophies
0
XP
1,016
Country
United States
They pay based on the severity of the issue, they're not going to give $20k for some exploit that has little to no practical use...
They're never going to pay anyone anywhere near $20k, and you know it. If they can, they should hire more full-time security pros. These bounty schemes can work well for stopping undiscovered or unpublicized exploits, but the 3ds is 99.9% totally hacked by exploits that are common knowledge, and even open sourced on github. The time to fix this was 6 years ago, that genie ain't goin back in that lamp.
The only information type I can imagine that would actually be beneficial to Nintendo is regarding:
  • Dissemination of inappropriate content to children
That could be improved on. But the other stuff isn't going to change through a silly bounty program.
 

hacksn5s4

Banned!
Banned
Joined
Aug 12, 2015
Messages
4,332
Trophies
0
XP
1,322
Country
still its not like nintedo can go in your house and take your hacked 3ds away so why bother only people who don't know about hackign will update there systems
 

Alex658

Well-Known Member
Member
Joined
Jun 4, 2010
Messages
1,206
Trophies
1
Age
29
Location
Colombia
XP
1,195
Country
Colombia
Obviously not, if they're investing tens to hundreds of thousands of dollars removing exploits.


A9LH can install on any version 9.2-, only dumping the OTP needs 2.1, and that need only be done once

I know that, but you cannot install a9lh without the OTP in o3ds no matter the version. And OTPless on 9.2 wasn't much of a success after it was deemed unsafe by aurora for N3DS. I'd rather pretend that didn't happen.
 

Mikemk

Well-Known Member
Member
Joined
Mar 26, 2015
Messages
2,093
Trophies
1
Age
28
XP
3,159
Country
United States
And OTPless on 9.2 wasn't much of a success after it was deemed unsafe by aurora for N3DS. I'd rather pretend that didn't happen.
It's not unsafe, it's just buggy. They'll eventually put it back in the guide after they figure out what caused the bricks.
 

SG6000

Well-Known Member
Member
Joined
Nov 2, 2015
Messages
392
Trophies
0
XP
1,410
Country
United Kingdom
Something tells me that the kind of individual who would diligently and successfully work on finding a system exploit isn't the kind of individual likely to be attracted to a little bit of pocket money in exchange for their discoveries.
 

Alex658

Well-Known Member
Member
Joined
Jun 4, 2010
Messages
1,206
Trophies
1
Age
29
Location
Colombia
XP
1,195
Country
Colombia
If they do manage to patch a9lh and make firm 0/1 write protected (a similar way a9lh+cfw does), we would still have the OTP keys. Where you couldn't rewrite them via normal means, but OTP would give you the highest permission escalation avaliable except for the bootrom.
That's curious.
 

fodder

STARMAN
Member
Joined
Aug 3, 2014
Messages
863
Trophies
0
XP
544
Country
United States
They're never going to pay anyone anywhere near $20k, and you know it. If they can, they should hire more full-time security pros. These bounty schemes can work well for stopping undiscovered or unpublicized exploits, but the 3ds is 99.9% totally hacked by exploits that are common knowledge, and even open sourced on github. The time to fix this was 6 years ago, that genie ain't goin back in that lamp.
The only information type I can imagine that would actually be beneficial to Nintendo is regarding:
  • Dissemination of inappropriate content to children
That could be improved on. But the other stuff isn't going to change through a silly bounty program.
Maybe for the 3DS, sure, but I'm sure once the switch is released they'll update their profile and start giving out those $20k bounties
 

kingaz

Well-Known Member
Member
Joined
Oct 27, 2013
Messages
298
Trophies
0
Age
36
XP
877
Country
United States
No, this doesn't mean that Nintendo is getting serious about fixing 3DS security.

No, this doesn't mean that Nintendo hasn't been keeping an eye on the scene (think of all of the exploit games that have been pulled same-day).

No, this doesn't mean that the 3DS is going to be supported for longer than we thought. It's still on its way out.

This is almost certainly a test run for a possible Switch bug bounty program.
 

Kourin

Touhou Maniac
Member
Joined
Jan 24, 2016
Messages
1,018
Trophies
0
Age
28
Location
Ripple Star
XP
1,236
Country
Australia
It's fake, literally anyone can make these with no proof that you own the domain.

Not to mention it was made a few hours ago and it miraculously was found out straight away.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BigOnYa @ BigOnYa:
    Ban, ban, ban
    +1
  • NinStar @ NinStar:
    super monkey ball
  • HiradeGirl @ HiradeGirl:
    How's everyone doing?
  • HiradeGirl @ HiradeGirl:
    Would you recommend a Meta Quest 2 as first low budget headset?
  • SylverReZ @ SylverReZ:
    @BigOnYa, Maybe he doesn't know how to type words for shit.
  • SylverReZ @ SylverReZ:
    GBAtemp should be legally obligated to ban them, as its against the law to collect information from users under 13 because of COPPA. :tpi:
  • SylverReZ @ SylverReZ:
    @NinStar, Super Monkey Ball: Banana Blitz
  • SylverReZ @ SylverReZ:
    @HiradeGirl, Why not get an Oculus?
  • Psionic Roshambo @ Psionic Roshambo:
    VR is like 3D TVs in my opinion it's cool and all but it doesn't have enough great content.
    +1
  • SylverReZ @ SylverReZ:
    @Psionic Roshambo, Porn exists, Psi.
    +1
  • SylverReZ @ SylverReZ:
    I'm sure you'll live with it.
    +1
  • Veho @ Veho:
    VR had the chance to integrate with existing games and tech but VR companies said "NO, I WANT MY SHIT TO BE STANDALONE AND MY GAMES EXCLUSIVE TO FACEBOOK"
    +2
  • Veho @ Veho:
    Back when Oculus Rift was still starting out and being demoed around, they modded existing games to use it as a 360° immersive screen thing and that was AMAZING.
    +2
  • K3Nv2 @ K3Nv2:
    The tech isn't there for affordable power enough VR headsets at a good market value yet sadly, oculus had a good idea but didn't have enough funds for marketing iirc
    +1
  • Veho @ Veho:
    But now it's "can I use my VR set with my racing games, that would be neat?" "ONLY IF YOU USE OUR DILDOSTICK CONTROLLERS AND RUN THE GAME ON OUR ANDROID-UNDERPOWERED BRICK"
    +2
  • Veho @ Veho:
    The tech to have quality VR goggles at an affordable price is here, but every set has to have 4 additional controllers and be standalone.
    +1
  • K3Nv2 @ K3Nv2:
    These are the same type of gamers that spend $2,000 on a GPU when a $600 GPU gives nearly the same outcome which is what the market looks at for them to do spend more on unneeded bs
    +1
  • K3Nv2 @ K3Nv2:
    If we're talking AAA titles a vr headset would be priced at nearly the same cost as a midrange gaming pc maybe even double
    +1
  • K3Nv2 @ K3Nv2:
    https://www.walmart.com/ip/3439939603 this is cool a portable blackstone
    +1
  • Veho @ Veho:
    The investment group?
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    I think they should bring back the shutter glasses for VR put 120Hz screen in for 60FPS and even a basic phone these days can pull that off
  • Psionic Roshambo @ Psionic Roshambo:
    Head tracking cameras and all
  • Psionic Roshambo @ Psionic Roshambo:
    Have a USB type C connector for power and controller done
    Psionic Roshambo @ Psionic Roshambo: Have a USB type C connector for power and controller done