Hacking Question Is downgrading possible?

realjumy

Woooosh!
OP
Member
Joined
Apr 24, 2018
Messages
188
Trophies
0
XP
1,594
Country
United Kingdom
Considering how deep our level of access to the device is, is it possible to downgrade the firmware of the Switch to a lower version? And this this, I mean actually downgrading, not using emunand to emulate previous versions.

Seeing how we have been asked to stay in lower versions and taking into account that I can't find anything posted officially, I wonder if this is because it's not possible, or because the method has not been disclosed (yet).
 

Phenj

Well-Known Member
Member
Joined
May 22, 2018
Messages
493
Trophies
0
XP
1,905
Country
Italy
When we will reach the point where we can disable fuses-check, downgrade would be totally useless. You would have complete control of your console anyway.
 
  • Like
Reactions: Quantumcat

Lacius

Well-Known Member
Member
Joined
May 11, 2008
Messages
18,100
Trophies
3
XP
18,342
Country
United States
Downgrading will always be pointless. If you downgrade your system version, then you will always have to use RCM to be able to launch your Switch OS. Since you can use RCM to launch CFW on all system versions anyway, downgrading is pointless.

It is highly unlikely that there will ever be any way around this.
 

MHDestination

Well-Known Member
Member
Joined
Sep 12, 2009
Messages
392
Trophies
0
Location
Under your bed
XP
888
Country
Germany
Hekate does already temporarily disable fuse checks.

Downgrading is possible. But you will need to go through RCM to boot the system.

That won't change ever. We can't permanently disable fuse checks (without a modchip).
These checks are performed by the bootloader. And we can't patch it,
since it's read only.
 
  • Like
Reactions: realjumy

realjumy

Woooosh!
OP
Member
Joined
Apr 24, 2018
Messages
188
Trophies
0
XP
1,594
Country
United Kingdom
Hekate does already temporarily disable fuse checks.

Downgrading is possible. But you will need to go through RCM to boot the system.

That won't change ever. We can't permanently disable fuse checks (without a modchip).
These checks are performed by the bootloader. And we can't patch it,
since it's read only.

So AutoRCM is a required 1st step, right?
 

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,032
Trophies
2
Age
29
Location
New York City
XP
13,446
Country
United States
More accurately, we need a coldboot-based exploit to bypass the fuse check because we need a hack that occurs before the fuse check. RCM is just one example of a coldboot that can bypass the fuse check. Unfortunately, the only coldboot we have is tethered so its still kinda pointless to downgrade because you would still need to tether to avoid the check.
 
  • Like
Reactions: realjumy

Ryab

Well-Known Member
Member
Joined
Aug 9, 2017
Messages
3,282
Trophies
1
XP
4,554
Country
United States
Considering how deep our level of access to the device is, is it possible to downgrade the firmware of the Switch to a lower version? And this this, I mean actually downgrading, not using emunand to emulate previous versions.

Seeing how we have been asked to stay in lower versions and taking into account that I can't find anything posted officially, I wonder if this is because it's not possible, or because the method has not been disclosed (yet).
No reason too but im sure its possible its just the switch can detect if the FW on the nand has been flashed
 

Lacius

Well-Known Member
Member
Joined
May 11, 2008
Messages
18,100
Trophies
3
XP
18,342
Country
United States
More accurately, we need a coldboot-based exploit to bypass the fuse check because we need a hack that occurs before the fuse check. RCM is just one example of a coldboot that can bypass the fuse check. Unfortunately, the only coldboot we have is tethered so its still kinda pointless to downgrade because you would still need to tether to avoid the check.
Any untethered coldboot exploits that can't be installed with RCM (e.g. the future untethered coldboot exploits that will might someday be released for 1.0.0, 2.0.0-3.0.0, and 3.0.1-4.1.0) will require that the Switch can successfully boot into Horizon without RCM. Downgrading will always be pointless.
 
Last edited by Lacius,
  • Like
Reactions: Quantumcat

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,032
Trophies
2
Age
29
Location
New York City
XP
13,446
Country
United States
Any untethered coldboot exploits that can't be installed with RCM (e.g. the future untethered coldboot exploits that will someday be released for 1.0.0, 2.0.0-3.0.0, and 3.0.1-4.1.0) will require that the Switch can successfully boot into Horizon without RCM. Downgrading will always be pointless.
I don't believe those unreleased exploits are coldboots. I think they are warmboots. Someone must have gotten confused with the terminology between softmod and coldboot. But yes, downgrading is pointless due to the fuses.
 
  • Like
Reactions: realjumy

Lacius

Well-Known Member
Member
Joined
May 11, 2008
Messages
18,100
Trophies
3
XP
18,342
Country
United States
I don't believe those unreleased exploits are coldboots. I think they are warmboots. Someone must have gotten confused with the terminology between softmod and coldboot.
We don't know for sure, but it has been implied that they might work similarly to CBHC on the Wii U (i.e. the system coldboots into OFW, and then an automated process applies the unreleased exploits to load CFW, giving the illusion of coldbooting CFW). Nobody has corrected the Firmware Status thread either.
 
  • Like
Reactions: crazy_p

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,032
Trophies
2
Age
29
Location
New York City
XP
13,446
Country
United States
We don't know for sure, but it has been implied that they might work similarly to CBHC on the Wii U (i.e. the system coldboots into OFW, and then an automated process applies the unreleased exploits to load CFW, giving the illusion of coldbooting CFW). Nobody has corrected the Firmware Status thread either.
Knew I should have attached a source to my last reply. Anyways, this is what Scires is saying about the unreleased exploits and the potential for future coldboots.
cVuMVe0.png




I intend to be fully transparent about this shit, especially going forwards. At present, I'm not aware of any non-RCM means of getting code execution from coldboot. To the best of my knowledge, nobody else is, either.
Also, I contacted OP about updating his graphic. Hopefully, he sees my post and changes it as soon as possible to prevent more misinformation from spreading.
 
  • Like
Reactions: realjumy

Lacius

Well-Known Member
Member
Joined
May 11, 2008
Messages
18,100
Trophies
3
XP
18,342
Country
United States
Knew I should have attached a source to my last reply. Anyways, this is what Scires is saying about the unreleased exploits and the potential for future coldboots.
Also, I contacted OP about updating his graphic. Hopefully, he sees my post and changes it as soon as possible to prevent more misinformation from spreading.
That's the post I was also referring to. SciresM is saying that, on 1.0.0 and possibly 2.0.0-3.0.1, it might be possible to get the system to boot into the normal OS before loading softwarehax via an automated process, simulating a coldboot into CFW similar to how CBHC works on the Wii U.

In principle, there's no other way to do an untethered coldboot into CFW that would simultaneously be dependent on a having particular system version.
 
Last edited by Lacius,
  • Like
Reactions: realjumy

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,032
Trophies
2
Age
29
Location
New York City
XP
13,446
Country
United States
That's the post I was also referring to. SciresM is saying that, on 1.0.0 and possibly 2.0.0-3.0.0, it might be possible to get the system to boot into the normal OS before loading softwarehax via an automated process, simulating a coldboot into CFW similar to how CBHC works on the Wii U.

In principle, there's no other way to do an untethered coldboot into CFW that would simultaneously be dependent on a having particular system version.
That is true. The issue here now is that nobody is working on implementing that type of coldboot for those firmwares. While it is possible in principle, Scires summed it up pretty accurately when he says to "maintain approximately zero hope". But of course, anything is possible so I guess it is false to say that there are no potential untethered coldboots.
 
  • Like
Reactions: realjumy

Lacius

Well-Known Member
Member
Joined
May 11, 2008
Messages
18,100
Trophies
3
XP
18,342
Country
United States
That is true. The issue here now is that nobody is working on implementing that type of coldboot for those firmwares. While it is possible in principle, Scires summed it up pretty accurately when he says to "maintain approximately zero hope". But of course, anything is possible so I guess it is false to say that there are no potential untethered coldboots.
Anyway, to summarize my original point and bring us back on topic, there are two possibilities regarding an untethered coldboot exploit:
  1. It will be something that can be installed with RCM, which makes downgrading pointless.
  2. It will be something that depends on the system's ability to boot into OFW normally, which makes downgrading pointless.
 

ssmatt

Well-Known Member
Member
Joined
Apr 6, 2008
Messages
114
Trophies
0
XP
509
Country
It's absolutely possible at this point.

But if there has been anything made yet to reliably do so, I haven't heard of it.
 
  • Like
Reactions: realjumy

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    K3Nv2 @ K3Nv2: https://youtube.com/shorts/FdYTKAVSsXY?si=9E-2AU0JN-4hRZi3