Hacking qlutoo got a talk at 34c3's console hacking/security section!

Resaec

Well-Known Member
Member
Joined
Dec 19, 2017
Messages
409
Trophies
0
XP
885
Country
Germany
The major vulnerability was patched out, yes. 1.0.0 will remain the most broken and therefore the most "free" but it and 3.0.0 are all the same still limited to the old keys, everything after that was revoked and re-issued. 1.0.0 will just be so insecure as to give one the most open playground, but its also nearly impossible to acquire.
Everyone at 3.0.0 or below can write custom content to eMMC using kernel. Once they got it right, they could temp update or ghost an update in memory and SD to play newer games.
Or once they crack the CoT they could mod the firmwares and give you fully functional updated firmwares with game compatibility up to that point.
 

the_randomizer

The Temp's official fox whisperer
Member
Joined
Apr 29, 2011
Messages
31,284
Trophies
2
Age
38
Location
Dr. Wahwee's castle
XP
18,969
Country
United States
well if your switch is updates you will probably have to wait untill its hard to get a 3.0.0 switch so then they will try to exploit newer firmwares

Right, but you don't have any source or ETA on when that 4.0.0 firmware hack will be, so....yeah. Nothing is known about that right now.
 

Kilim

ReiNX Official Dad™
Member
Joined
May 14, 2017
Messages
220
Trophies
0
Age
31
XP
1,630
Country
United States
would really like some further clarification on my 1.0 switch - i understand that homebrew has to be on version 3.0 but is staying on 1.0 for much easier access to CFW installation a good idea?
 
  • Like
Reactions: charlieb

Resaec

Well-Known Member
Member
Joined
Dec 19, 2017
Messages
409
Trophies
0
XP
885
Country
Germany
It just came to mind, that there is this nice tool called "rowhammer". This could be used to escalate to root privileges or escalate services that they are able exploit :D
But thats only possible once they get some intel on mem layout n things
 

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
Everyone at 3.0.0 or below can write custom content to eMMC using kernel. Once they got it right, they could temp update or ghost an update in memory and SD to play newer games.
Or once they crack the CoT they could mod the firmwares and give you fully functional updated firmwares with game compatibility up to that point.

Effectively dual-booting is a solution, but it requires access to the higher firmware such that you can do make something to dual boot. Otherwise, how would you get around the revised encryption and updated keys to which (unless I am making an oversight) they'd have no access to on lower firmwares since the revoke in 3.0.1?

Its possible I am being dumb but the write up seems simpler than the reality, lol.
 

Ericthegreat

Not New Member
Member
Joined
Nov 8, 2008
Messages
3,455
Trophies
2
Location
Vana'diel
XP
4,279
Country
United States
would really like some further clarification on my 1.0 switch - i understand that homebrew has to be on version 3.0 but is staying on 1.0 for much easier access to CFW installation a good idea?
I'm doing the same thing, from what i know we can upgrade with a cart when we need to upgrade.
 
  • Like
Reactions: g4jek8j54 and Kilim

Kilim

ReiNX Official Dad™
Member
Joined
May 14, 2017
Messages
220
Trophies
0
Age
31
XP
1,630
Country
United States
I'm doing the same thing, from what i know we can upgrade with a cart when we need to upgrade.
yeah good to know i'm not the only one thinking it - just got Pokken so if push comes to shove i can just update if needed

don't want to be put in a situation where a 1.0 downgrade is necessary for CFW installation (but the downgrade could fail and brick your switch)
 
  • Like
Reactions: snoofly

g4jek8j54

Well-Known Member
Member
Joined
Aug 30, 2007
Messages
532
Trophies
0
Website
Visit site
XP
437
Country
United States
thing is I’m honestly not bothered about piracy. I just want to wait until the machine is open as much as possible

I asked on discord and think the consensus is the real meat would come from khax and cold boot/keydumps only perhaps possible from exploited bootrom (pkg1ldr?) which i think was hinted from the talk and would only be accessible from 1.0.0.

Also I was thinking that as the devs on the talk do not condone piracy but want to help public enable homebrew, it is best for them also to steer us to 3.0.0 for the same reason.

Anyway, that’s just my finding/thoughts so I’m going to hold out and stick on 1.0.0 for now.

What "discord" are you referring to? Excuse my ignorance, but I'm not familiar with that site.

Also, thanks for posting this information. I watched the presentation, and enjoyed it. However, I was also partially wondering whether I should stay at 1.0.0, based on what SciresM has said in the past, or find Pokken and update to 3.0.0. That helps to clear things up a little bit.

I'm talking about being forced to stay on 1.0.0 and not being able to play new legit games

Define "legit." For me personally, I recently got Mario Kart 8 Deluxe, and The Binding of Isaac, for my 1.0.0 Switch, and am greatly enjoying both of those games. It's actually kind of interesting for me personally, because if I had a higher selection of games, I know that I would have never gotten The Binding of Isaac. I also have Breath of The Wild, which I have gotten a lot of replay value from. It's all about personal preference. The only other game that I am truly interested in is Super Mario Odyssey, which I would like to play at some point. However, that requires an update to 3.0.1, so that same line of reasoning could also be applied to 3.0.0 for some people.
 
  • Like
Reactions: albion

Seelbreaker

Well-Known Member
Member
Joined
Mar 22, 2010
Messages
199
Trophies
0
XP
495
Country
Gambia, The
Since i think i need pegaswitch running i tried to set it up, but unfortunately it doesn't work with the windows ubuntu :(



Code:
npm WARN optional Skipping failed optional dependency /chokidar/fsevents:
npm WARN notsup Not compatible with your operating system or architecture: [email protected]
npm ERR! Linux 4.4.0-43-Microsoft
npm ERR! argv "/usr/bin/nodejs" "/usr/bin/npm" "install"
npm ERR! node v4.2.6
npm ERR! npm  v3.5.2
npm ERR! code ELIFECYCLE

npm ERR! [email protected] install: `node-gyp rebuild`
npm ERR! Exit status 1
npm ERR!
npm ERR! Failed at the [email protected] install script 'node-gyp rebuild'.
npm ERR! Make sure you have the latest version of node.js and npm installed.
npm ERR! If you do, this is most likely a problem with the pty.js package,
npm ERR! not with npm itself.
npm ERR! Tell the author that this fails on your system:
npm ERR!     node-gyp rebuild
npm ERR! You can get information on how to open an issue for this project with:
npm ERR!     npm bugs pty.js
npm ERR! Or if that isn't available, you can get their info via:
npm ERR!     npm owner ls pty.js
npm ERR! There is likely additional logging output above.

npm ERR! Please include the following file with any support request:
npm ERR!     /mnt/c/Users/XXXXX/Downloads/_Switch/git/pegaswitch/npm-debug.log
 

snoofly

Well-Known Member
Member
Joined
Aug 18, 2015
Messages
1,012
Trophies
0
Age
54
XP
2,133
Country
United Kingdom
What "discord" are you referring to? Excuse my ignorance, but I'm not familiar with that site.

Also, thanks for posting this information. I watched the presentation, and enjoyed it. However, I was also partially wondering whether I should stay at 1.0.0, based on what SciresM has said in the past, or find Pokken and update to 3.0.0. That helps to clear things up a little bit.

The reswitched discord
From SciresM just a few minutes back:

From 1.0 am emunand type boot into higher fws type solution will be possible...

Is that if you have a 1.0.0 unit
Do not f******* update it.

and..

userland on 3.0.0 is consolation prize
 

g4jek8j54

Well-Known Member
Member
Joined
Aug 30, 2007
Messages
532
Trophies
0
Website
Visit site
XP
437
Country
United States
The reswitched discord
From SciresM just a few minutes back:

From 1.0 am emunand type boot into higher fws type solution will be possible...

Is that if you have a 1.0.0 unit
Do not f******* update it.

and..

userland on 3.0.0 is consolation prize

Okay, thanks.

Also, thanks for the most recent update.
 
  • Like
Reactions: albion

Kilim

ReiNX Official Dad™
Member
Joined
May 14, 2017
Messages
220
Trophies
0
Age
31
XP
1,630
Country
United States
The reswitched discord
From SciresM just a few minutes back:

From 1.0 am emunand type boot into higher fws type solution will be possible...

Is that if you have a 1.0.0 unit
Do not f******* update it.

and..

userland on 3.0.0 is consolation prize
thanks for this my man - i'll be staying on 1.0

raises the question for me though - would updating an emuNAND FW trip a fuse?
 

8BitWonder

Small Homebrew Dev
Member
Joined
Jan 23, 2016
Messages
2,489
Trophies
1
Location
47 4F 54 20 45 45 4D
XP
5,348
Country
United States
The reswitched discord
From SciresM just a few minutes back:

From 1.0 am emunand type boot into higher fws type solution will be possible...

Is that if you have a 1.0.0 unit
Do not f******* update it.

and..

userland on 3.0.0 is consolation prize
That's pretty cool, hopefully we can get emunand on higher firms in the future.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    Veho @ Veho: The cybertruck is a death trap.