Lockpick_RCM payload - Official Thread


Description

Lockpick_RCM is a bare metal Nintendo Switch payload that derives encryption keys for use in Switch file handling software like hactool, hactoolnet/LibHac, ChoiDujour, etc. without booting Horizon OS.

Source: https://github.com/shchmue/Lockpick_RCM
Payload: https://github.com/shchmue/Lockpick_RCM/releases

Due to changes imposed by firmware 7.0.0, Lockpick homebrew can no longer derive the latest keys. In the boot-time environment however, there are fewer limitations. That means the new keys are finally easy to dump!

Usage
  • Launch Lockpick_RCM.bin using your favorite payload injector or chainload from Hekate by placing it in /bootloader/payloads
  • Upon completion, keys will be saved to /switch/prod.keys on SD
  • If the console has Firmware 7.x, the /sept/ folder from Atmosphère or Kosmos release zip containing both sept-primary.bin and sept-secondary.enc must be present on SD or else only keyblob master key derivation is possible (ie. up to master_key_05 only)
Big thanks to CTCaer
For Hekate and all the advice while developing this!

Known Issues
  • Chainloading from SX will hang immediately due to quirks in their hwinit code, please launch payload directly
 

Attachments

  • AB1248EA-8BB9-448B-83F5-FF68C2579FB1.jpeg
    AB1248EA-8BB9-448B-83F5-FF68C2579FB1.jpeg
    11.2 KB · Views: 0
Last edited by shchmue,
D

Deleted User

Guest
@shchmue is it worth me using this to dump my prod.keys again as I used the latest nro to dump them last time?

Config OFW 7.0.1 CFW Atmosphere 0.8.4
 

8BitWonder

Small Homebrew Dev
Member
Joined
Jan 23, 2016
Messages
2,489
Trophies
1
Location
47 4F 54 20 45 45 4D
XP
5,348
Country
United States
@shchmue is it worth me using this to dump my prod.keys again as I used the latest nro to dump them last time?

Config OFW 7.0.1 CFW Atmosphere 0.8.4
The nro can only dump keys up to 06 (when on 6.2.0), this new payload can dump up to and including the newest 07 keys.
(It is worth it if you want the newest keys)
 

shchmue

Developer
OP
Developer
Joined
Dec 23, 2013
Messages
791
Trophies
1
XP
2,367
Country
United States
Lockpick homebrew can still dump titlekeys while this can't. I'm about to push a commit that checks and doesn't overwrite Lockpick_RCM's key file in case you want to dump titlekeys and you're on 7.
 
  • Like
Reactions: Deleted User

Goffrier

Well-Known Member
Member
Joined
Dec 19, 2018
Messages
181
Trophies
0
Age
44
XP
428
Country
United States
but it will work™

--------------------- MERGED ---------------------------

i dont care if they are stealing i just wait their release for 7.x support
 
  • Like
Reactions: Ita54_2

chrisrlink

Has a PhD in dueling
Member
Joined
Aug 27, 2009
Messages
5,560
Trophies
2
Location
duel acadamia
XP
5,737
Country
United States
if only we stole code from TX (XCI loader) cause i just bought a SATA3 to USB adapter for that

--------------------- MERGED ---------------------------

yea. it’ll be funny seeing SX with the Atmosphere sept logo

and you think ppl will care? (maybe team atmos not the end user) besides a feature i want is sxos exclusive i doubt any pro piracy dev would make an xci loader from scratch
 

Beegyoshi

New Member
Newbie
Joined
Mar 5, 2019
Messages
3
Trophies
0
Age
29
XP
65
Country
Singapore
Hi shchmue,

I just started trying to install cfw to my switch so I'm still trying to understand the jargons used. I was unable to get my tegra keys and title.keys through the lockpick.nro and I thought this current method will aid me. However, i was only able to get the prod.keys and not the title.keys. I have previously installed and played games on my switch before and I'm sure my SD card is not corrupted but I'm still having trouble getting the title keys. My firmware is 7.0.0 and my switch serial is XAJ100XXXX. Do you have any idea what's going on? Thank you for any possible solutions. :)
 

shchmue

Developer
OP
Developer
Joined
Dec 23, 2013
Messages
791
Trophies
1
XP
2,367
Country
United States
Hi shchmue,

I just started trying to install cfw to my switch so I'm still trying to understand the jargons used. I was unable to get my tegra keys and title.keys through the lockpick.nro and I thought this current method will aid me. However, i was only able to get the prod.keys and not the title.keys. I have previously installed and played games on my switch before and I'm sure my SD card is not corrupted but I'm still having trouble getting the title keys. My firmware is 7.0.0 and my switch serial is XAJ100XXXX. Do you have any idea what's going on? Thank you for any possible solutions. :)
you can run this then run Lockpick 1.2.2 to get both
 

Beegyoshi

New Member
Newbie
Joined
Mar 5, 2019
Messages
3
Trophies
0
Age
29
XP
65
Country
Singapore
Hi shchmue.

I have tried both methods and I got both title.keys and prod.keys. I followed your step and ran lockpick 1.2.2 on my switch. However, this error message appeared.

get Tegra keys failed. Warning: Saving limited keyset. Dump TSEC and Fuses with Hekate.

I was still able to obtain both keys at the end. Can this error message be ignored?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: aeiou