Homebrew The bootroms

Aletron9000

Well-Known Member
Member
Joined
May 10, 2016
Messages
1,716
Trophies
0
Location
Classified
XP
1,610
Country
United States
That should already be quite doable without any bootroms. Hell the "bigbluemenu" that everyone was using for so long is nothing but a dev "rom" with a banner and (maybe) encryption/signing swap.

But at first, it was a dev .cia, someone took it, put it into a dev unit and decrypted the cia, then reencrypted it on a retail system. I mean we would be able to decrypt dev roms on the computer without a dev unit.

Which would make things easier and cheaper
 
Last edited by Aletron9000,

sirocyl

Are we Geniuses or what?
Newcomer
Joined
Apr 30, 2012
Messages
92
Trophies
1
Age
31
XP
324
Country
United States
The "Dev bootrom" is identical to the master, production, retail bootrom. In fact, the only place the bootrom itself would vary, is in an engineering sample pre-release - likely one with a socketed SoC, too.

The only thing that differs, is the contents of the OTP area, and what bootrom does with them - the OTP holds secondary keys, system identification/registration numbers, and system configurations/provisioning.

The bootrom holds a key which is used to decrypt the OTP area, which is the same key in all configurations.

Also, the bootrom key may be responsible for "factory things", such as preinstall and the provision/registration process (which "burns" the OTP in the first place).
That way, if said "factory things" were to leak from the factory, they'd be useless without the bootrom secret.
 

Poryhack

Well-Known Member
Member
Joined
Oct 18, 2009
Messages
332
Trophies
0
Age
32
XP
254
Country
United States
But at first, it was a dev .cia, someone took it, put it into a dev unit and decrypted the cia, then reencrypted it on a retail system. I mean we would be able to decrypt dev roms on the computer without a dev unit.
That has also been possible for some time using nothing but ctrtool/makerom, provided the dev CIA is using the "fixed" dev NCCH keys. See for yourself (ctrl+F, "dev_fixed_ncch_key"). Spoiler alert: For non-system titles it's literally just zeros.
 
Last edited by Poryhack,

dankzegriefer

Banned!
Banned
Joined
Aug 19, 2015
Messages
896
Trophies
0
Age
40
XP
560
Country
United States
So if timing is that short, what about making a loop that increments the number of ms each time so we get the timing with brute force?
ms might be too fast.

--------------------- MERGED ---------------------------

That has also been possible for some time using nothing but ctrtool/makerom, provided the dev CIA is using the "fixed" dev NCCH keys. See for yourself (ctrl+F, "dev_fixed_ncch_key"). Spoiler alert: For non-system titles it's literally just zeros.
DevMenu is always encrypted as a system title.
 

Poryhack

Well-Known Member
Member
Joined
Oct 18, 2009
Messages
332
Trophies
0
Age
32
XP
254
Country
United States
New versions use new NCCH crypto.
Ah, well in that case yes. It would require keys from the bootrom (or at least keys that haven't been discovered yet) to decrypt on a computer. Should also be possible to decrypt with Decrypt9 on an updated dev system.
 

Poryhack

Well-Known Member
Member
Joined
Oct 18, 2009
Messages
332
Trophies
0
Age
32
XP
254
Country
United States
Last edited by Poryhack, , Reason: added missing link

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    They'll be getting in the territory of portable Pcs anyway
    +1
  • BigOnYa @ BigOnYa:
    Again you get what you pay for, its like buying a S series for $300 but its only 1440p native, if you want true 4k, gotta get the X model for $500. But yea you right, when moms buying it anyways, you gotta stay cheap.
  • K3Nv2 @ K3Nv2:
    They could use HD out on their TV no real need for a monitor these days tbh the purists will disagree
  • K3Nv2 @ K3Nv2:
    I'm kind of phasing out on the need for wanting all these consoles cool to have but they just become dust build ups
  • BigOnYa @ BigOnYa:
    I here ya there, I have too many myself, and have hard time letting them go, since most of mine I've modded at some point. Anymore I just play Switch on the go, seriesx at home.
  • Xdqwerty @ Xdqwerty:
    ack my throat
  • K3Nv2 @ K3Nv2:
    I need to invest in some storage totes tbh
  • BigOnYa @ BigOnYa:
    Tots?
  • K3Nv2 @ K3Nv2:
    Tootles
  • BigOnYa @ BigOnYa:
    Tootles? Wtf
  • K3Nv2 @ K3Nv2:
    Oh tootles
  • BigOnYa @ BigOnYa:
    Oh totes , lol, like Tupperware storage, I gotcha
  • BigOnYa @ BigOnYa:
    I'm designing my own entertainment cabinet for my man cave, to store all my systems, then I'm also designing a power supply/HDMI switcher so I can switch to whichever system I want, and power it also. Already picked up the cabinet board, but tinkering with my drawings before start
  • BigOnYa @ BigOnYa:
    But yea, I have frogger arcade cabinet that I gutted and put a Pi4 then Pi5 into, but it never gets played much anymore, should sell it. Even when the kids come over, they don't want to play on it, just the xbox. TMNT and Simpson's arcade is still so fun on it, esp w 2 players.
  • K3Nv2 @ K3Nv2:
    Gonna check out the new Garfield looks like garbage
  • BigOnYa @ BigOnYa:
    Can't wait to see the new "stick" that can actually play Ps3 or 360 games. I know they are getting close.
  • BigOnYa @ BigOnYa:
    @Xdqwerty didn't you see the new garfield?
  • K3Nv2 @ K3Nv2:
    Ah it's all animated I was hoping for some live action
    +1
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, yes i did
  • T @ TheSusKing:
    does anyone know if you can run android apps on a usb
  • K3Nv2 @ K3Nv2:
    You mean use a external usb thumb drive as storage? Yeah it depends on the phone
  • T @ TheSusKing:
    no, i mean if i could store the app on the usb so it doesnt take up my storage
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, why do you ask?
    K3Nv2 @ K3Nv2: https://youtu.be/iAJ-J1R7juY?si=ZKM6T19bTLp533m4