Hacking What's the challenge with the XCI loader?

FR0ZN

Well-Known Member
Member
Joined
Nov 2, 2013
Messages
1,393
Trophies
1
Age
37
XP
3,917
Country
United States
there is what is called Telemetry data on the console itself, that keeps track of pretty much everything that you do on your switch. if you factory reset that report remains, there are ways to wipe but calls for almost an instant ban as you break the natural sequence if it and it flags nintendo when they check it.

That's why the only way to really be safe is to have a clean NAND and restore before doing online activity. An NAND restore everything from the point of the backup, including the telemetry report.

Well I used the Homebrew launcher via the web applet while I was on 3.0.0 - that was way before any of the good RCM exploits happen.
These old homebrew methods weren't very stable and modified the error code to something like *****-1337 or so.
I'm pretty sure these are all over my telemetry data as well.
 

_hexkyz_

Well-Known Member
Newcomer
Joined
Oct 4, 2018
Messages
60
Trophies
0
XP
447
Country
United States
Could that solution be used if paired with the requirement that the user needs to dump their own sector data from a game card? Like, include everything up to the game card sectors? It would obviously need to come with a homebrew capable of doing that or does the type of dumping needed require specialized hardware or tools?

Yes, it's definitely possible. However, dumping the necessary data will require specialized tools that don't exist yet.
Essentially, you must forge most of the gamecard controller's authentication process and then request these special sectors from the gamecard. I've documented all that some time ago in the wiki: https://switchbrew.org/wiki/Gamecard_ASIC

However, this is detectable if you go online by accident, for example. If you bought a game and used the card's authentication sectors for something like this, you could be tracked down fairly accurately.
 

Nezztor

Well-Known Member
Member
Joined
Nov 8, 2016
Messages
488
Trophies
0
XP
1,338
Country
Mexico
Yes, it's definitely possible. However, dumping the necessary data will require specialized tools that don't exist yet.
Essentially, you must forge most of the gamecard controller's authentication process and then request these special sectors from the gamecard. I've documented all that some time ago in the wiki: https://switchbrew.org/wiki/Gamecard_ASIC

However, this is detectable if you go online by accident, for example. If you bought a game and used the card's authentication sectors for something like this, you could be tracked down fairly accurately.

Thanks for all your support! I am happy that you are on the light side aka hacking ninty instead of sony dark side jk, any Christmas gifts planned like some way to activate rcm without payload? Santa hexkyz
 

nl255

Well-Known Member
Member
Joined
Apr 9, 2004
Messages
3,004
Trophies
2
XP
2,813
Country
Yes, it's definitely possible. However, dumping the necessary data will require specialized tools that don't exist yet.
Essentially, you must forge most of the gamecard controller's authentication process and then request these special sectors from the gamecard. I've documented all that some time ago in the wiki: https://switchbrew.org/wiki/Gamecard_ASIC

However, this is detectable if you go online by accident, for example. If you bought a game and used the card's authentication sectors for something like this, you could be tracked down fairly accurately.

I would think it wouldn't be that easy to track down as from what I have seen most retailers don't record the individual serial number when you buy games and even if they did tracking the person down would require getting the store records and then credit card records which is slow and expensive and that assumes the person didn't buy the game card with cash. Not to mention that if it was rented there might be no way to determine that information assuming the person in question waited a month or so before using it.

As for tracking them down by their IP address why haven't they already done that for people using SX's XCI loader which should be even easier to detect via telemetry since the same data is used for everyone rather than requiring users to rip the data from one of their own cards.
 

KhenemetHeru

Well-Known Member
Newcomer
Joined
Apr 22, 2015
Messages
80
Trophies
0
Age
51
Location
New Britain, CT
XP
321
Country
United States
An XCI loader and running the games from USB External HDD are the two things needed in the free CFWs, and why I feel I got my money's worth with SX OS from Day 1 - I consider it paying for the dongle, not for the software, the rest was gravy. I agree with the convenience argument, it's much more desirable to have single XCIs built with the DLC and updates stitched in so you never have to install any data to the SD at all. I would be using the free CFW if not for that lack - well that, and the anti-piracy moralizing which is bull.

On the other hand, if I had a 1TB microSD card I wouldn't care so much (but $400+ is not worth it to me, now that they're out), or if a method to run NSP files like XCI files (without installing them) would be developed.
 
D

Deleted User

Guest
I think if there is a open sorce XCI loader the feature with the external HDD is no big problem.
 

josete2k

Well-Known Member
Member
Joined
Apr 24, 2009
Messages
680
Trophies
1
Age
43
Location
Spain
XP
1,625
Country
Spain
  • You can install DLC and updates with .NSP unlike .XCI which have to rely on buying/downloading them (or using .NSP in conjunction which defeats the purpose using a .XCI in the first place)
  • .NSP are smaller than even a trimmed .XCI file
  • .NSP have faster load times than .XCI files
  • .NSP can be installed without an SD card
  • .NSP can be launched without an SD card

- nsp updates don't need fake tickes
- nsp and xci (cleaned, not trimmed) are exactly same in size.
- nsp and xci have same time access while nsp is installed on SD.
- true
- how can you launch a fake nsp without an SD card?
 
  • Like
Reactions: codyjo

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,379
Trophies
2
XP
18,295
Country
Sweden
- nsp updates don't need fake tickes
- nsp and xci (cleaned, not trimmed) are exactly same in size.
- nsp and xci have same time access while nsp is installed on SD.
- true
- how can you launch a fake nsp without an SD card?
By installing it on the NAND.
 

Condemned87

Well-Known Member
Newcomer
Joined
Sep 27, 2018
Messages
65
Trophies
0
Age
44
XP
585
Country
Germany
What causes users to be banned for using .NSP files are not the .NSP files themselves (these are 1:1 copies of eShop games once installed) but the fake tickets used to install/launch them. Therefore, if you install anything that doesn't need a fake ticket, then Nintendo won't know that you're launching it using CFW (because it won't have a fake ticket).

That means I can install my xci files which was made from my original games without any problems? No higher ban risk as playing xci files without installtion?
 

pcwizard7

Well-Known Member
Member
Joined
Aug 2, 2013
Messages
1,409
Trophies
0
XP
1,688
Country
Australia
to the people against xci loader i understand the fight against piracy but what if the xci must have a valid certificate in it? so people can play their own backups. as using your own roms are ok as long as you brought the game
 
Last edited by pcwizard7,

smf

Well-Known Member
Member
Joined
Feb 23, 2009
Messages
6,651
Trophies
2
XP
5,907
Country
United Kingdom
to the people against xci loader i understand the fight against piracy but what if the xci must have a valid certificate in it? so people can play their own backups. as using your own roms are ok as long as you brought the game

The problem is that TX did it first and people hate TX, so they hate XCI loading.

The piracy thing is mostly a smoke screen. There are plenty of hackers who don't care about that, but with the toxicity of the switch scene there is no point.
 

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,379
Trophies
2
XP
18,295
Country
Sweden
The problem is that TX did it first and people hate TX, so they hate XCI loading.

The piracy thing is mostly a smoke screen. There are plenty of hackers who don't care about that, but with the toxicity of the switch scene there is no point.
More of that XCI can't be implemented as it is at the moment since it's extremly illegal. That's why NSPs are "fine-ish" for now.
Or just use 4nxci to convert the xci to nsp and install it :P
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BigOnYa @ BigOnYa:
    Nighty night, wise one, thanks for trying to help.
  • Psionic Roshambo @ Psionic Roshambo:
    To sleep perchance to dream!
  • BigOnYa @ BigOnYa:
    My state has put a heavy tax on vape juice, taxing any juice with nicotine by the weight/oz. So to get around the bs, my local vape store only sells 0 nicotine vape juices, then they also sell straight nicotine in tiny bottles, and you mix it yourself to your 0% juice, lol
    +1
  • BigOnYa @ BigOnYa:
    Damn, is that Wing from South Park?
  • Psionic Roshambo @ Psionic Roshambo:
    BigOnYa hmmm I wonder how long until someone just vapes the straight nicotine lol
  • BigOnYa @ BigOnYa:
    I was gonna say people are not that dumb, but yea you right, some are.
    +1
  • K3Nv2 @ K3Nv2:
    People have put 50mg salt nic in straight subohm coils which is like more powerful hits
    +1
  • BigOnYa @ BigOnYa:
    Hey psi, do they have dress codes down there in FLa, here there are signs on stores that say "No shirt, no service" but curious bout down yonder
  • BigOnYa @ BigOnYa:
    Yea I tried the salts and too strong for me, I prefer the norm juice
  • K3Nv2 @ K3Nv2:
    In Florida they don't serve you if you have clothes on
    +1
  • K3Nv2 @ K3Nv2:
    Fucking raining again
  • BigOnYa @ BigOnYa:
    How can you tell, do you see rain drops on top of other rain drops?
    +1
  • K3Nv2 @ K3Nv2:
    I can tell by whenever your wife done letting out loud ass moans then I get her a ticket back home
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    @BigOnYa, yeah most places demand clothes and shoes, unless it's some really back water place that I am unaware of lol
    +1
  • BigOnYa @ BigOnYa:
    Cool, I got lunch money for tomorrow then.
  • BakerMan @ BakerMan:
    @K3Nv2 call uremum Sloppenheimer the way she givin me this bomb head
    +1
  • K3Nv2 @ K3Nv2:
    I call uremum alzheimer she forgets to leave
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Time to start a vape straight nicotine challenge, Darwin be praised!
    +1
  • K3Nv2 @ K3Nv2:
    Imagine if Hitler had vapes, we promise it's not cyanide it'll help you quit nicotine
    +1
  • BigOnYa @ BigOnYa:
    Please, walk into my patented vape chamber, aka the non smoking area
  • K3Nv2 @ K3Nv2:
    I do wonder how dominate Germany would've been if they just enlisted Jewish people
  • BigOnYa @ BigOnYa:
    They actually enlisted Muslims, seriously, because the Muslims hates Jews, even tho it was not the supreme race. He claimed common hate, is friendship.
  • K3Nv2 @ K3Nv2:
    He could've just made them walking shields kind of a dumb ass move
  • K3Nv2 @ K3Nv2:
    https://a.co/d/3km8bqC lol cd level quality I fucking hope so
    K3Nv2 @ K3Nv2: https://a.co/d/3km8bqC lol cd level quality I fucking hope so