Hacking Anti-Piracy on 3DS Games?

  • Thread starter Thread starter jastolze
  • Start date Start date
  • Views Views 12,234
  • Replies Replies 37
That's exactly what a live patch is. :rolleyes:

The console can "tell the game" that everything's fine just as easily as it can tell it that the region and the firmware are correct. As for the so-called "new features of firmware", I wouldn't be so keen on thinking that those too cannot be accounted for with patches. The console's been out for quite some time now and any alteration of system calls is running head-first into a possibility of lack of compatibility with already released games ("Ridge Racer 3D", anyone?). As for new features altogether, there's only so much space for firmware. I'd say that not much will be changed from now on in terms of how games are ran or made much like there weren't any substantial additions to the PS3's instructions since 3.55, at least none that would actually influence games.
He means like ios on the wii, we have no way of adding more.
 
If games included AP on 3DS Games, how would someone bypass that? Is it possible to edit games like Pokemon X/Y or the newer Zelda one?

If so, what would need to be done and would it be time consuming?

Thanks!

Sorry, but nobody has managed to decrypt a rom, only bypass what checks the validty of a rom on the 3ds (if I understood that correctly).

Pokemon X/ Y look amazing...and the just hearing you talking about stealing it just grinds my gears.
I really wish the Gateway could have waited...because if this takes off...devs possibly will pull out of 3DS development like the PSP. I hope that they won't work for Gateway [at least for a while]...so they have incentive to release another zelda or pokemon 3D game in the future.

Thumbs up for being very funny.
 
Some good statements there foxi4, but there's 1 statement I might have to disagree on

The no system is perfect

Don't get me wrong your right about that, but the device just might be good enough to block out a software hack, each time a new gen system comes out its been more harder to software hack it and most likely its just going to harder from years to come. I mean it just might come to a point where you can only hack devices by using a mod chip.
 
He means like ios on the wii, we have no way of adding more.

Except we've already added more into empty slots which is exactly what cIOS'es are and unlike what people seem to think. Of course the 3DS's OS works nothing like that, but never the less, the principle remains the same.
 
There has been some good discussion and some drivel thus far, I will move sideways and take it bit more high concept than practicality type discussion for my reply.

Generally there are three stages of anti piracy.

1) At device/firmware level. This is things like signed/encrypted code, only allowing certain ports to run code (and controlling the means of production for those ports) and all that sort of stuff you get to see hackers laugh at the shoddy implementations of in the presentations we all like watching.

2) Pre hack damage limitation. Not so common in consoles from what I have seen (see the utter farce that was online games with the PS3 post fail0verflow's presentation) and if it is then it is more cheat prevention but knowing the way modern developers are taught some of that is more happy accident. However defensive coding and languages doing the same are increasingly commonly practiced and it is the order of the day in a lot of (most?) other types of software development.

3) Post hack damage limitation. So the device is hacked, it is still a device with several million users and not all of them are hostiles so you get to work out a way to maximise returns as best you can. You can try hoping the developer locks it back down again and then the device dev and software dev can trouble things (force updates, force software to use updates -- it is not so hard to radically rework an SDK to do basically the same thing but change it seriously at binary level) but I have yet to witness this in games (this could change and there is some things that resemble the chance for it, I am not putting money on it happening well though). This requires analysis of the extent of the hack and methods employed by the hackers, typically you then look for some means of detecting you are running on a funny device. On the DS this meant that has flash cart makers would have patched the game to use a different save type you could try detecting that (either by forcing a write to the memory as it was supposed to be, by timing it (there is an example of this in the DS library) or something similar), you could look for general changes (this is one of the main methods) or you can look for a difference (sticking with the DS this would be that most flash carts failed to return a proper response for reading below the memory address 8000 hex in the ROM image).
It gets kind of odd from here on in and you also get to consider things like games shipping with extra hardware, preorder incentives, DLC (the DS had some by the way in the likes of ), but we are having a technical discussion and not a business one so I will leave that out for the time being. Back to the oddities though and you have to consider what you want. As the developer your evil hacker adversary has unlimited resources and infinite time to get around it but just because that is the case it does not mean they will necessarily have it done before the day is out. If you can then make it so your game does not get hacked for 2 weeks, which some in the games industry consider the shelf life and profit earning period of most games for reasons I have never quite been able to figure out*, and then just as people are starting to get bored of your online play have the hacker set come in and boost the amount of people on your servers then fantastic. Related to this is the idea of making it so J Random Bellend has a hard time at said two week mark where P Q Not quite a hacker but can follow a reasonably clear set of instructions after said 2 week mark can get stuff done, here then the idea runs J Random Bellend will possibly go out and still buy the game.

*my best guess is it is a variation on Hollywood accounting where a film "has" to make all its money back at the box office for err "reasons", never mind that most of the rest of the world considers such things a venture and the sum total of merch, DVD sales, licensing and more gets to be added up to determine success.

Now hacking has certain tells and common pathways so there are things you can do at stage 2) in anticipation of stage 3). One example of this might be the binary checks thing already mentioned; the would be hacker is probably going to want to change your binary so outside of any verification done as part of 1) you add a whole bunch of checks to the binary, make them execute at odd times and obfuscate them as you will. Bonus is sometimes you can even convince the would be game copying hacker that they have not penetrated the security as well as they actually have.
Theoretically there is nothing to have stopped a would be 3ds dev from having implemented it in a game already or doing as such tomorrow, save perhaps a boss breathing down their neck to have the product out of the door ("Does the game play? Then ship it." being a common enough motto among game development studios) and what we have heard of the 3ds security might kind of trouble some of the easier methods of doing these checks.
We had a kind of related discussion in the would be WODE for the Wii U announcement thread where things short of a new hardware revision were discussed and it includes things like sending many malformed read/operation requests that a normal device would brush off, timing and so on.
 
I think the real deal here is the previous pokemon game's AP, I feel like that might be getting missed here. Most of the time it's patched by the time you see it, but often there are things like no exp gain, erratic exp gain, freezing, and in firered/leafgreen the message "By the way: If you like this game, buy it or die." and etc.

With no way to patch the games pre or post load, no cheating device or implementation to just untick a few checkboxes, we're likely on the path to creative anti-piracy.

One thing I've always wondered.... Now, the 3ds can download and play games off the SD card, but still applies to the slot;
why don't games, occasionally attempt to write over it's own ROM? Literally, attempt a write to the read only with garbage....
If you have a physical copy, bam, ROM, read only memory dude, this is burnt in, not writable.

If you have.... an SD card plugged into a supercard, zomg it's filling with zeroes and getting toasted. your 3ds is fine, and this behavior wouldn't do anything to a legitimate cartridge. (you could have download games also do this, because hey, why not?)

Of course it wouldn't be long for folks to patch in blocks, add a write-lock toggle to the device, etc, but still. It seems so simple, and I don't understand why this hasn't been done yet. It'd scare the pants off pirates, and devs could say "oh, that's so weird! It must be a bug, interesting that it only effects people with probably pirated copies who might be hesitant to class action our asses because the only thing damaged was the piracy device"
 
and if it's not saving to SD, that'd be a good, but this is all hypothetical, I'm not aware of any AP ever doing this, and I've always wondered why, in the format we have we're using writable flash storage in place of read-only pressed memory and i don't understand how that's never been exploited based on the fact that it's a pretty obvious line in the sand between the two.
 
I think the real deal here is the previous pokemon game's AP, I feel like that might be getting missed here. Most of the time it's patched by the time you see it, but often there are things like no exp gain, erratic exp gain, freezing, and in firered/leafgreen the message "By the way: If you like this game, buy it or die." and etc.

With no way to patch the games pre or post load, no cheating device or implementation to just untick a few checkboxes, we're likely on the path to creative anti-piracy.

One thing I've always wondered.... Now, the 3ds can download and play games off the SD card, but still applies to the slot;
why don't games, occasionally attempt to write over it's own ROM? Literally, attempt a write to the read only with garbage....
If you have a physical copy, bam, ROM, read only memory dude, this is burnt in, not writable.

If you have.... an SD card plugged into a supercard, zomg it's filling with zeroes and getting toasted. your 3ds is fine, and this behavior wouldn't do anything to a legitimate cartridge. (you could have download games also do this, because hey, why not?)

Of course it wouldn't be long for folks to patch in blocks, add a write-lock toggle to the device, etc, but still. It seems so simple, and I don't understand why this hasn't been done yet. It'd scare the pants off pirates, and devs could say "oh, that's so weird! It must be a bug, interesting that it only effects people with probably pirated copies who might be hesitant to class action our asses because the only thing damaged was the piracy device"

In the first paragraph you are confusing results of failure to evade copy detection with the actual detection itself. To do that Nintendo would have to have figured out a way to tell that the game is running on a gateway and as you say we are running what appear to be untouched dumps. This still does not mean it is impossible (timings, presumably pokemon will coincide with an update that has a few teeth, they seem to be having issues with NAND saves and more....) but does make it harder.

Having the game overwrite the SD card of the flash cart. It may or may not be illegal for them to do that (it is largely held as illegal for an entity to remove a virus from a computer if that virus turns a computer into a member of a botnet without consent from the machine owner -- flash carts are not wholly illegal in all locations and it is not just for giggles we use terms like backup around here) and that is just considering a handful of countries, to try to sort that over all the locations a game might be sold would be a nightmare. Similarly there are whole protocols involved in writing to data and so very far from standard memory copy. That said there are a few save patch detection methods that work on a broadly similar theme.
 
Having the game overwrite the SD card of the flash cart. It may or may not be illegal for them to do that (it is largely held as illegal for an entity to remove a virus from a computer if that virus turns a computer into a member of a botnet
Can you source that? I work for a large company in malware removal and not only do we routinely remove botnet related infections but we have categorization specifically for these items so we can quantify what and how much of what we're working with day-to-day, and this is nothing I've ever heard of or encountered. We also have a good chunk of international work besides USA/CAN, so I'm pretty curious if/where this could possibly be the case.
 
It took years upon years to get the PSP to the stage it is in now - just a few years back having anything beyond an early PSP-2000 meant that you couldn't even dream of running ISO's or homebrew. It wasn't "easy", but the free factor was there indeed. I'm actually expecting the 3DS to get its own flavor of CFW somewhere down the line - I don't see why it couldn't once more of its secrets are revealed.[/quote]


Sorry but that is markedly untrue....PSP was hacked almost the day after it was released in the US....you could use devhook on the original launch 1.5fw version US PSP and run roms from a folder path (not iso)....it wasn't long after taht dark alex released an actual .iso loader and then not long after that that we could do CFW on psp1000 and psp2000....even after $ony patched almost immediately after the pandora battery solution was discovered which would allow you to fully downgrade and recover a semi-brick on any psp 1000 or 2000......Then the prometheus loader came out that would let you load newer (up thru 5.5) firmware games on old CFW......

So you sir are entirely wrong in that the psp was easily hackable/modable almost from the second it came out and any lame attempt $ony made to secure it was easily thwarted and it cost almost nothing as you could even make your own pandora battery if you had a hacked phat and a spare battery with the pandora battery maker app. The 3DS has been out since March 2011 meaning it took almost 2.5 years to get a piracy solution and even at that it is only applicable to a small number of units and costs $80+......so don't worry with already 30mil+ units out and awesome games on the horizon from now thru 2014 the 3DS is in no danger of becoming a PSP....

And lastly the PSP was not sunk because of piracy anyways....it had a lot of flaws in its design that if it wasn't modded it would have never sold the 70mil units it did....plain and simple UMD sucked, battery life sucked, performance sucked and all that was greatly improved by hacking it...It took the PSP more than 7 years and 4 itterations to reach 70mil sales where the 3DS in two years and two iterations has sold over 30mil...so the trajectory is much different and that as much as anything is what attracts development (which is why the WiiU is struggling because it sold great out of the gate but has slumped since january).
 
My apologies that was quite weakly phrased --you can remove infections if you are asked to, if it is your job to do so for given systems (though I would usually argue you have failed very hard if it has got to that stage) or you get in contact with people and they say "please sort it out", removing such things without the consent of the owners of the infected systems is a far trickier operation. Various owners of shaded hats have (and may have even exploited) different options but if it is hard or illegal for something as straight up damaging as a botnet then the considerably more grey area stuff of flash carts on a user owned device in a post sega vs accolade world (if we are sticking with the US) and the general quagmire that is IP law all around the world is a even less likely to have a simple solution.

The removing the malware itself usually comes up around the time they either find the command and control servers, reverse engineer the protocols or otherwise get a way they could do it (more than a few bots will have a killswitch in them). However they are then limited to controlling the DNS ( http://www.informationweek.com/secu...hanger-fbi-updates-net-access-shuto/232900868 ), redirecting the odd bit of traffic, sending a popup to the screen or doing somewhat more passive ways of neutering the networks (I think it was the people tasked with reverse engineering conficker that found the domain generation algorithm and got ahead of the curve).
 
I can't confirm or deny if I'm a real life pirate :tpi:

eh I guess...the game will sellout regardless...but I just want another game to happen..you don't know HOW long I waited to finally have a 3D pokemon game. I'm going to support them on day one as well. Just like Beyond Two Souls. :) I just don't want the 3DS to become like the PSP. where you saw anticipated games that were "cancelled' or put into "development hell" to later be cancelled.

I have waited for a pokemon 3D game for so long, I posted this a year ago = > http://gbatemp.net/threads/brand-ne...-coming-to-the-wii.317600/page-3#post-4047150

and the answer to your question is YES. if there is a 3DS ROM dump...and someone can edit it...than they can reverse engineer the Anti-piracy code...it's been done on the DS...it most likely will be done on the 3DS




Do what you want, 'cause a pirate is free,
You are a pirate!

Yar har, fiddle di dee,
Being a pirate is all right with me,
Do what you want 'cause a pirate is free,
You are a pirate!
Yo Ho, ahoy and avast,
Being a pirate is really badass!
Hang the black flag at the end of the mast!
You are a pirate!

You are a pirate! - Yay!

We've got us a map, (a map! )
To lead us to a hidden box,
That's all locked up with locks! (with locks! )
And buried deep away!

We'll dig up the box, (the box! )
We know it's full of precious booty!
Burst open the locks!
And then we'll say hooray!

Yar har, fiddle di dee,
Being a pirate is all right with me!
Do what you want 'cause a pirate is free,

You are a pirate!
Yo Ho, ahoy and avast,
Being a Pirate is really badass!
Hang the black flag
At the end of the mast!
You are a pirate!

Hahaha!

We're sailing away (set sail! ),
Adventure awaits on every shore!
We set sail and explore (ya-har! )
And run and jump all day (Yay! )
We float on our boat (the boat! )
Until it's time to drop the anchor,
Then hang up our coats (aye-aye! )
Until we sail again!

Yar har, fiddle di dee,
Being a pirate is all right with me!
Do what you want 'cause a pirate is free,
You are a pirate!

[Spoken:]
Yar har, wind at your back, lads,
Wherever you go!

Blue sky above and blue ocean below,
You are a pirate!
You are a pirate!

[Spoken:] You are a pirate! Ya gobshite!"
 
Part of the problem with some of the AP measures some of you are 'dreaming' up (at least where gateway is concerned) is that they would have to be implemented in a new firmware update.....so they can't retro actively be in fw 4.x/5.x/6.x.....meanwhile when I new game comes out it can try to force a new firmware update, but calls and such can often be averted or disabled to any new firmware features.

We can really only look upon prior history and the history pretty much always favors the hackers/pirates once a system's kernel is accessed and hacked (which the 3DS is accesed thru the DS profile buffer overflow and then hacked thru the launcher file). In the past on DS and GBA the AP stuff has been weak as water and generally gets worked out within days of the rom launching. I honestly don't know why devs even try other than what someone else stated which is if you can hold of piracy for a few days/weeks then you have the launch window to sell before you get pirated......

I have said this before and that is gateway is likely furiously working on 2 things....1. get 5.x/6.x working which will be key to expanding their product sales, making more money, staying in business longer, and getting to develop more....and 2. Getting unsigned code to run....because then even though roms have not been decrypted yet, it gets a lot easier to do when you can run decryption software on the host machine itself. Unsigned code opens up everything else we want including homebrew, multirom, game save patching, real time patching (this can be used to bypass AP and other pesky problems). Also when we get unsigned code we get a lot more people working on the problems so some of the work load can be taken off of gateway's obviously small team and shared by the community and scene groups.....

Last point and you all know this is true....the bigger the release the more 'motivation' gateway/hackers/scene groups usually have to get it working. So when Pokemon and Zelda (Mario Golf as well) come out and if they won't run....everyone will be trying to find a way to get them to run.....in the past sometimes flashcart manufactures have even 'leaked' special patched versions of a game that will work on their hardware until a more generic patch comes along...Supercard did this a number of times for the old Supercard SD....I think lead time is a big factor here in that Mario Golf and Pokemon will be out in a little over a month....Nintendo not even put out 6.3/7.x now that gateway is in the wild...so those games will most likely ship with 5.1 up thru 6.2 and Nintendo may just not have the time to implement new firmware or AP this late in the game....now Zelda and stuff coming out in 2014 may be a different story.
 

Site & Scene News

Popular threads in this forum