Hacking derrek: we also got the #NintendoSwitch TrustZone code!

  • Thread starter Thread starter punderino
  • Start date Start date
  • Views Views 34,087
  • Replies Replies 187
  • Likes Likes 25
  • Like
Reactions: Deleted User
Coincidentally, Google's Project Zero published an article detailing potential exploits in ARM TrustZone software today. In particular, there's an exploit in most Qualcomm implementations and older versions of Trustonic’s Kinibi TEE, which is present in Samsung's Exynos-based phones prior to the Galaxy S8 and S8+.

One interesting thing the article mentions is rollback (downgrade) protection, which is also present in Wii U and has been verified to be present on Switch. The implementation mentioned here is eFuses, whereas Wii U's implementation used SEEPROM.
Oh it's confirmed now. Kind of figured that would happen sooner or later.
 
Oh god damnit, it's gonna be like the 360 all over again. No real way to downgrade.

The switch does use fuse downgrade protection -- you can actually tell this by dumping and reverse engineering its (plaintext) stage 1 bootloader.

And obviously I can't tell the future, but whatever I eventually work on will be released for people to use, since that's kind of the point.
 
Last edited by SciresM,
The switch does use fuse downgrade protection -- you can actually tell this by dumping and reverse engineering its (plaintext) stage 1 bootloader.
Ah my apologies. Read efuses and instantly remembered the 360 stuff
 
I said "does" -- you were right that switch is protected similar to how xb360 was (though I've never owned an Xbox and don't actually know how that worked in reality)
lol i'm fucking tired. Thanks for correcting me again haha

--------------------- MERGED ---------------------------

I said "does" -- you were right that switch is protected similar to how xb360 was (though I've never owned an Xbox and don't actually know how that worked in reality)
Edit: I just realised who I'm bloody talking to. If it's the real sciresM, glad I was right so! And hi! lol :)
 
https://twitter.com/derrekr6/status/889556685353881600
One step closer!
Trustzone is basically the deepest security module, it's like arm9 on the 3DS, and IOSU on the Wii U. (I believe at least.)
Homebrew when?

Holy shit. HOLY. SHIT. First they dumped kernel and now they have fucking TRUSTZONE?! That's really impressive. FIVE MONTHS. F I V E.
Also:
125 people currently viewing this thread
86 guests and 39 members
 
Efuses..... Great.... I'm having visions of endless threads where people bricked their switch trying to downgrade.

It'll happen. It doesn't matter what type.. Some overhyped weirdos will bite the bullet and brick their systems. It always happens.
 
Well, i don't like Piracy so early in console Life. But i want a Nintendo Swicht but it's so expensive here Brazil. And if i paid for console I'll no have money for any game :(
You could always do what I did, I bought the Switch in the UK and sent it to my boyfriend in Brazil and had to pay £320 in taxes. I could've cried.
 
  • Like
Reactions: Deleted User

Site & Scene News

Popular threads in this forum