Hacking 11.0.0-33 : The Aftermath

  • Thread starter Thread starter Plailect
  • Start date Start date
  • Views Views 48,977
  • Replies Replies 178
  • Likes Likes 82
So if want to be on 11.0 and use NTR I need to install Luma? And thus far, I can safely install Luma, then update to 11.0 (making sure to have a backup as always) and then continue mostly as usual, even though I'm not on A9LH?
 
"Downgrading in general, regardless of any arm11 kernel exploits (like svchax) released in the future, has been broken (possibly permanently). The firmware now contains a hardcoded list of minimum versions, and will not let us install a system title of a lower version than in the list, even if we have permission to install our own titles. This will make downgrading on 11.0.0's firmware impossible if no software workaround is found."

But wouldn't this need both an arm11 and an arm9 kernel exploit so we can patch the system and modify (minver = 0 for everything) or even bypass that list? Or is that the "software workaround" you are talking about?
 
Thanks for this information. I don't understand everything, but the main features I can grasp.

Can I ask what the future likelihood of breaking a9lh with updated sysnand would be? Could at any time be a whisker away from a brick and I always come here first anyway to check out anything new, but is there anything specific to look out for?
 
But wouldn't this need both an arm11 and an arm9 kernel exploit so we can patch the system and modify (minver = 0 for everything) or even bypass that list? Or is that the "software workaround" you are talking about?

I think you are already aware of how dificult finding new spare arm11 and arm9 exploits is. Also I think you could appreciate if we purposely hide an exploit now to expose it publicly when it doesn't matter anymore. Even if we can, It's not the right time to counterattack.

But hey, if you have any ideas just grab the devkit pro libs and start coding!

--------------------- MERGED ---------------------------

Can I ask what the future likelihood of breaking a9lh with updated sysnand would be? Could at any time be a whisker away from a brick and I always come here first anyway to check out anything new, but is there anything specific to look out for?

As long as you:
1. Keep a backup of your sysnand working
2. Preserve a9lh between updates or changes
3. Are able to boot a9lh decrypt9

You are good to go. Be aware the a9lh is also copied and restored with the backup.
There's no way to block a9lh once installed. There's still ways to block new installs even with the OTP, though.
 
Last edited by Urbanshadow,
  • Like
Reactions: Ikki Barri
"Downgrading in general, regardless of any arm11 kernel exploits (like svchax) released in the future, has been broken (possibly permanently). The firmware now contains a hardcoded list of minimum versions, and will not let us install a system title of a lower version than in the list, even if we have permission to install our own titles. This will make downgrading on 11.0.0's firmware impossible if no software workaround is found."

But wouldn't this need both an arm11 and an arm9 kernel exploit so we can patch the system and modify (minver = 0 for everything) or even bypass that list? Or is that the "software workaround" you are talking about?

Well cfw could do it pretty easily just like they brought svcBackdoor back though it isn't a high priority right now since the NTR/10.2 firmware.bin workaround still works. Of course, if you already have cfw then there is really no need to downgrade anyway.
 
Last edited by nl255,
Well cfw could do it just like they added svcBackdoor though it isn't a high priority right now since the NTR/10.2 firmware.bin workaround still works.

Yeah you are absolutely right, but given how easy is for ninty to break that workaround, having that figured out was nice and reassuring. Now we can just put svcbackdoor back when it's needed.
 
Yeah you are absolutely right, but given how easy is for ninty to break that workaround, having that figured out was nice and reassuring. Now we can just put svcbackdoor back when it's needed.

It would probably be just as easy to fix ninty's breaking of that workaround by modifying the module version checks to make the 10.2 nfirm work regardless of what the modules supposedly require. The only way to actually break the workaround would be for them to make the system modules rely on new functions not present in the 10.2 nfirm.
 
Do you think that still would be possible to access homebrew trough oothax in the future?
 
Can you still update your Rxtools emuNAND firmwarw to 11.0? Just want to be safe.!

EDIT: sysNAND: 9.2
EmuNAND: 10.7
 
Last edited by Shiiouri,
It would probably be just as easy to fix ninty's breaking of that workaround by modifying the module version checks to make the 10.2 nfirm work regardless of what the modules supposedly require. The only way to actually break the workaround would be for them to make the system modules rely on new functions not present in the 10.2 nfirm.

From what I'm reading, looks like you think that through. If you feel like it, go for it. Try to figure out if what you are saying may work or fail.

What am I trying to say is if you don't feel like things are being done well, no one is gonna stop you to constructively fix them.

Complaining about decisions made by devs usually takes you nowhere. Even if you have a perfect valid reason to complaining about.
 
From what I'm reading, looks like you think that through. If you feel like it, go for it. Try to figure out if what you are saying may work or fail.

What am I trying to say is if you don't feel like things are being done well, no one is gonna stop you to constructively fix them.

Complaining about decisions made by devs usually takes you nowhere. Even if you have a perfect valid reason to complaining about.

I wasn't making any complaints about the cfw devs or their work. I was replying to your statement about ninty fixing the workaround, the point is they really can't because the devs can just unfix it just as easily.
 
I wasn't making any complaints about the cfw devs or their work. I was replying to your statement about ninty fixing the workaround, the point is they really can't because the devs can just unfix it just as easily.

It was about the priority of features in the first place if I'm not mistaken (correct me please).
So I understand you have a different opinion on the order in which features should be worked on and delivered. Perhaps I streched a little bit too much the word complain but I think I managed to make the point.
 
Last edited by Urbanshadow,
It was about the priority of features in the first place if I'm not mistaken (correct me please).
So I understand you have a different opinion on the order in which features should be worked on and delivered. Perhaps I streched a little bit too much the word complain but I think I managed to make the point.

What new features? Since ninty hasn't blocked the 10.2 nfirm workaround there is nothing that the devs can really do about it yet. Sure they might be able to come up with something that might work but there is no way to actually test it and thus no real point yet.
 
  • Currently, there is a hardmod workaround to flash an older firm to NAND and re-enable downgrading, but this could possibly be fixed in 11.1.0 and it's only fortunate that it hasn't been fixed yet.

If I'm on version 11 with A9LH and Luma3DS, what would happen if I restored my NAND with my 10.7 backup? Is this still possible?
 
If I'm on version 11 with A9LH and Luma3DS, what would happen if I restored my NAND with my 10.7 backup? Is this still possible?

Nothing, I've done this many times since I updated to 11.0 after messing with my sysNAND a lot (including a few bricks!). It is completely safe to restore a 10.7 NAND after updated to 11.0 with Decrypt9!
 
  • Like
Reactions: spkuja
Nothing, I've done this many times since I updated to 11.0 after messing with my sysNAND a lot (including a few bricks!). It is completely safe to restore a 10.7 NAND after updated to 11.0 with Decrypt9!

Thanks for the info! That puts me at ease. I'll keep all of my previous NAND backups and be sure to make one for version 11 as well :-)
 
Thx @Plailect for the findings and for the A9LH guide.

Any user of the Guide (or Luma3DS + NTR firmware bin in general) will be completely unaffected by most of these changes since the NTR firmware bin replaces 11.0.0's firmware with a lower version firmware.

You forgot to mention Gateway users are completely unaffected as well.
 

Site & Scene News

Popular threads in this forum