- Joined
- Jun 12, 2008
- Messages
- 1,407
- Solutions
- 1
- Reaction score
- 34
- Trophies
- 1
- Age
- 16
- Website
- Visit site
- XP
- 496
- Country

I think everyone is looking at the wrong kind of exploit. I think what should be done is look for a hardware-based leak, not a software-based one. Then, once a leak in the hardware is found, we can create a payload that can be delivered to make the system do what we want. Then, once that payload is created, we can create a modchip (Like the first Wii exploits) and allow the modchip to be able to hook up through some kind of cord to a computer to update the payload if a new system menu is released.
Hardware-based exploits would work to discover software-based exploits, yes. However, I have never heard of a modchip for a cartridge-based system, because we use flashcarts/flashcards. The closest thing that I know of is a passthrough device (like the PassMe devices of the early DS days). We can't rely on a hardware-based exploit for general use. I can't think of a way to connect such a device to a computer without opening the 3DS, unless you somehow do everything through the game card slot. Anyway, there are all sorts of problems with this. Just can't think of them right now.
Refer to Tweezer exploit. And we don't rely on payloads anymore for the PS3 either, it's all about keys.
Granted, if you replace the firmware then it doesn't matter what protection is used. Of course, the firmware that we'd need to change is probably Mask ROM that only checks the signed Flash ROM. Wait, isn't this what the original Gameboy used but with carts instead of Flash ROM? DER!!! (LOL, if an exploit exists for the checker, it's pretty much unfixable without new CPU dies and not always even then)
Well, I'll wait a while and see what happens. I imagine we'll see a heated race between modders and system manufacturers in the next few years with the Vita and 3DS. I'm curious as to what they'll do.
Yes, Mask ROM would be what needs to be changed if we replaced the firmware (short of keys and such). Next to impossible to replace.
wouldn't we be able to get the private key if we somehow cracked the console key of an encrypted nand dump. i know its a stupid idea but it seams possible
No. Console key = public key, which you use to decrypt. Public key != private key, which you use to encrypt. You can get the private key from a public key, but it requires integer factorization of a semi-prime (assuming the 3DS uses RSA, which I think it does). Try doing that for a 1024-bit number. It's not feasible within our lifetimes (much less the 3DS's lifetime).
User agent faking? Anyone can do that. But we don't have the keys to make the servers give us data, and nintendo will hate our guts for "hacking" our server.Forgive me if this has been posted before. To refrain from sounding like a complete noob, I'll say right now that I have little or no knowledge about this subject, I'm just throwing this out there.
I've seen people post ideas about attempting to inject code by using a proxy to download a modded firmware to the 3DS. This could be a good idea imo if you just took out the mods. Download a 100% legit firmware to the 3DS and find some way to use the computer/proxy as a scanner as it goes through to the 3DS. Again, I have no real knowledge here, but in theory it could reveal some clues as to how the 3DS manages its encryption.
Furthermore, would it not be possible to trick the NUS servers, (I'm assuming that's still where all this is kept) into thinking your computer is a 3DS, in a way tricking the firmware into revealing the encryption keys?
Again, I have very little knowledge on this subject, I'm just making a suggestion. Feel free to troll me now.
Incorrect. We CAN grab data from the servers. However, the data (ie. System Menu updates) is encrypted. So you can get the data, but it's useless. The 3DS downloads the update and then decrypts it with its onboard public keys (which we don't have as of yet). So unless you have the computational power to crack the keys, there's no point. Not to mention that you'd still be missing the private keys. Those are far more useful as we could then sign our own System Menu.










