Hacking qlutoo got a talk at 34c3's console hacking/security section!

  • Thread starter Thread starter adrifcastr
  • Start date Start date
  • Views Views 76,464
  • Replies Replies 383
  • Likes Likes 19
There's plenty of people in this forum that did, and from what I see, only a few that didn't and are this bitter about it. If you bought a switch to play games, then go play your games and stop worrying about it. If you don't give a fuck about homebrew then I guess you made the right decision for yourself.

Do you think the people that are working on this stuff are doing it for you? Newsflash for ya buds, they're not. They're doing it because they like to do it and are learning and/or need it for their own purposes. Nobody gives a shit whether or not you can pirate games except you.
and where did i state that i am bitter about it? When i updated to play Mario and XC 2 i knew the risk well. Dont just assume things that suit your argenda.
 
Im just happy it moves forwars. Even though i did update and intend to update for every game i want its still good to see that hb and perhaps even a emunand is coming for lower fw. If there is another vulnerability in the future everything will be ready. And if not still awsome to see such stuff happening
 
so the pit 0 bug was fixed in 3.0.1
that's a big fix seeing that got them into the kernel and beyond.
for >3.0.0 would need another serious bug like that
 
  • Like
Reactions: TheGreek Boy
so the pit 0 bug was fixed in 3.0.1
that's a big fix seeing that got them into the kernel and beyond.
for >3.0.0 would need another serious bug like that
my recall from the talk was that it was the carveout pagehandler exploit that got them kernel and was fixed in 2.0.0

pid0/sm:hax ‘only’ allows userland access to all the base level services
 
my recall from the talk was that it was the carveout pagehandler exploit that got them kernel and was fixed in 2.0.0

pid0/sm:hax ‘only’ allows userland access to all the base level services
sm:hax only allows userland but they also outlined how you can get kernel. someone just needs to to autromate it.
 
sm:hax only allows userland but they also outlined how you can get kernel. someone just needs to to autromate it.
Yes. But that's only for 1.0. SciresM has confirmed there's no kernelhax on 3.0 and there won't be one for a long while, public or private.
 
sm:hax only allows userland but they also outlined how you can get kernel. someone just needs to to autromate it.
I thought that's what he was saying at the end part of the talk. Where he was callinh it the "UnTrust Zone". From what I caught it seems like the deep sleep function may be vulnerable? I'm not an expert or anything though, I just watched the talk and try to follow along.
 
I thought that's what he was saying at the end part of the talk. Where he was callinh it the "UnTrust Zone". From what I caught it seems like the deep sleep function may be vulnerable? I'm not an expert or anything though, I just watched the talk and try to follow along.
its not a vuln persay but something wanted. It just can be exploitet du other bugs.
 
its not a vuln persay but something wanted. It just can be exploitet du other bugs.
Pretty sure he said that when it goes to sleep the keyslots are stored in the main eMMC and when its waking up theres a point where the keyslots are vulnerable to being read. Then he said something like "Thats not important for homebrew, but could lead to other interesting possibilities". Seemingly pointing to piracy etc
 
Last edited by DayVeeBoi,
Pretty sure he said that when it goes to sleep the keyslots are stored in the main eMMC and when its waking up theres a point where the keyslots are vulnerable to being read. Then he said something like "Thats not important for homebrew, but could lead to other interesting possibilities". Seemingly pointing to piracy etc
from what i got, the switch saves all important data decrypted on the eMMC the problem is that it doesnt verify the decryption and the files it get when waking up or so.
would like to be corrected if i remember/understood it false.
 
Last edited by ken28,
So I just watched that chunk again, and what he says is that the keys can be encrypted/decrypted to and from keyslots which enables you to do "secure key derivation". It would allow you to decrypt one key into another slot without it having to leave memory. Then he says "Maybe you could think of some cool things to do with that".

In sake of completeness, I don't know if any of that is FW dependant and if he's referring only to version 1.0 but it sounds like this is to do with the way the crypto hardware works so maybe it is relevant for any FW that is exploitable? I dont know.

from what i got, the switch saves all important data decrypted on the eMMC the problem is that it doesnt verify the decryption and the files it get when waking up or so.
That's correct, he does say something like this, I remembered it wrong. I was just pointing this part of the talk out in my first reply because it seemed like the most valid part in regards to piracy and it seems like everyone forgot about it or didnt watch it that far or something.
 
Last edited by DayVeeBoi,
I maybe jumping the gun here but the guys said in their talk that a Homebrew Launcher was coming soon.. But in what form? will it be installed to the switch like an app or will it be more of a Homebrew Launcher that boots apps from the browser?
 
I maybe jumping the gun here but the guys said in their talk that a Homebrew Launcher was coming soon.. But in what form? will it be installed to the switch like an app or will it be more of a Homebrew Launcher that boots apps from the browser?
Probably like Wii U, requires opening the browser every time.

To install titles you need kernelhax and that will only work on 1.0, not 3.0.
 
I maybe jumping the gun here but the guys said in their talk that a Homebrew Launcher was coming soon.. But in what form? will it be installed to the switch like an app or will it be more of a Homebrew Launcher that boots apps from the browser?
I'm assuming it'll be akin to the similar operating systems of the 3ds and Wii u, where a higher kernel access is required to install custom channels, and will instead be launched either via a payload on the sd card or through the web applet.
 
Probably like Wii U, requires opening the browser every time.

To install titles you need kernelhax and that will only work on 1.0, not 3.0.

Yeah, see, the problem is almost no one has 1.0.0, and consoles of that are impossible to locate. That's awfully discouraging.
 
I can get a 1.0.0 for $600 AUD but I already have a 4.1.0 and cbf getting it just for a 1.0.0
 
I'm assuming it'll be akin to the similar operating systems of the 3ds and Wii u, where a higher kernel access is required to install custom channels, and will instead be launched either via a payload on the sd card or through the web applet.

The impression I got from the talk was that you trigger the exploit in the web applet and that loads apps from sd card.
 

Site & Scene News

Popular threads in this forum