Homebrew Question Unban concept? certs question

  • Thread starter Deleted User
  • Start date
  • Views 5,468
  • Replies 50

blahblah

Well-Known Member
Member
Joined
May 16, 2018
Messages
1,132
Trophies
0
Age
35
XP
1,472
Country
United States
bruteforce = trying diffrent passwords till it works
in this situation is the password the cert

Good luck brute forcing the AES-256. Let me know how it goes.

--------------------- MERGED ---------------------------

bruteforce wouldn't work, since it pretty hard to guess more than 7 different digits. i dont know how the cert is related to the hardware, but copy a cert from another device could work.

But if you log in on both devices you risk another ban.

A cert from another device will work with non-public patches for Atmosphere. Without those patches, a local cert 'origin' check fails.

Using the same cert on multiple consoles is a near-instant ban, though. So it's pointless.
 
Last edited by blahblah,

Biduleman

Well-Known Member
Member
Joined
May 3, 2006
Messages
148
Trophies
1
Age
34
Location
Québec
Website
Visit site
XP
863
Country
Canada
for this is the Bruteforce

Wikipedia said:
Breaking a symmetric 256-bit key by brute force requires 2^128 times more computational power than a 128-bit key. Fifty supercomputers that could check a billion billion (10^18) AES keys per second (if such a device could ever be made) would, in theory, require about 3×10^51 years to exhaust the 256-bit key space.

I hope your computer is fast because you're gonna wait until the death of the universe to finish your bruteforce.
 
Last edited by Biduleman,

blawar

Developer
Developer
Joined
Nov 21, 2016
Messages
1,708
Trophies
1
Age
40
XP
4,311
Country
United States
Good luck brute forcing the AES-256. Let me know how it goes.

--------------------- MERGED ---------------------------



A cert from another device will work with non-public patches for Atmosphere. Without those patches, a local cert 'origin' check fails.

Using the same cert on multiple consoles is a near-instant ban, though. So it's pointless.

Its worse than brute forcing sha256, he needs to break rsa2048 I believe.
 
  • Like
Reactions: ELY_M

2Siralv

Well-Known Member
Member
Joined
May 12, 2018
Messages
103
Trophies
0
Age
28
XP
531
Country
Canada
Thier was a talk around that yes devs have done it its possible but wont be public for a long time it cam somehow get a diff cert and inject it into the nand is possible jst no tut on how where and what to use its private
 

blahblah

Well-Known Member
Member
Joined
May 16, 2018
Messages
1,132
Trophies
0
Age
35
XP
1,472
Country
United States
Thier was a talk around that yes devs have done it its possible but wont be public for a long time it cam somehow get a diff cert and inject it into the nand is possible jst no tut on how where and what to use its private

Wrong on multiple counts.

1: You can't just inject the cert. There is a local (done by Horzion, not Nintendo Online Services) certificate check. If the certificate did not originate from the console being used, you will not be able to auth with Nintendo Online. You need special patches for your CFW.

2: Using the same cert that someone else is also using online = near instant ban.

3: Injecting certs is trivial. There's even an easy to use app that does it, Incognito. But see #1.
 

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,312
Trophies
2
XP
18,156
Country
Sweden
Even if you got a cert you somehow need to patch your switch to the accept the new one. I believe they implemented checks for this.
 

2Siralv

Well-Known Member
Member
Joined
May 12, 2018
Messages
103
Trophies
0
Age
28
XP
531
Country
Canada
Wrong on multiple counts.

1: You can't just inject the cert. There is a local (done by Horzion, not Nintendo Online Services) certificate check. If the certificate did not originate from the console being used, you will not be able to auth with Nintendo Online. You need special patches for your CFW.

2: Using the same cert that someone else is also using online = near instant ban.

3: Injecting certs is trivial. There's even an easy to use app that does it, Incognito. But see #1.

I said i dont know how its done jst know that it involves injection and its true had it confirmed by switch homebrew dev himself and no not a dev that makes a small homebrew one that made the switch cfws and exploits possible with his methods but agree to disagree no one knows what they have acheived privatly until one day someone gets mad or wants the 15min fame and release it like the hbg shop n ruin it for alot of ppl especially pushing away some great devs contributing.
 

blahblah

Well-Known Member
Member
Joined
May 16, 2018
Messages
1,132
Trophies
0
Age
35
XP
1,472
Country
United States
I said i dont know how its done jst know that it involves injection and its true had it confirmed by switch homebrew dev himself and no not a dev that makes a small homebrew one that made the switch cfws and exploits possible with his methods but agree to disagree no one knows what they have acheived privatly until one day someone gets mad or wants the 15min fame and release it like the hbg shop n ruin it for alot of ppl especially pushing away some great devs contributing.

Again, what you are saying is wrong.

Injecting a cert is trivial. But that alone will not get you online. The rest of your post is undecipherable gibberish.

--------------------- MERGED ---------------------------

I kind of want them for a project to restore virus killed switches but if they are private, I won't ask for them.

Not my place to distribute them. I'm sure someone will at some point, though. You'd need a lot more to get a bricked Switch to boot again, though. All that online play needs is the cert check patched out, bricks need a crapload of other things.
 
Last edited by blahblah,
  • Like
Reactions: WiraR46

iriez

Well-Known Member
Member
Joined
Oct 27, 2016
Messages
549
Trophies
0
Age
49
Website
www.xbins.org
XP
1,867
Country
United States
then say how does it works?

With RSA encrypted signing. If you truly want to understand why what you are postulating won't work then you need to learn the basics about cryptography.

You cannot create a valid certificate. The entire point of creating a certificate is that it uses encryption schemes that allow it to not be faked or spoofed.

If you had Nintendo signing key you would be able to create a new certificate. Without that signing key you cannot create a new valid certificate.
 
  • Like
Reactions: TotalJustice

AveSatanas

Well-Known Member
Member
Joined
Aug 7, 2018
Messages
153
Trophies
0
XP
950
Country
Chad
did you even understand what i want to do?
I dont want to sign anything i will try do get an already signed cert
"get an already signed cert" can mean two things: getting someone else's cert with their consent, or brute force until you get a signed one.

Former is piracy, and is out of question. Latter would take trillions of years with current hardware available to consumers, however even if you get a signed cert, it may not work, read my reply to the quote below:

To be fair, bruteforcing should be achievable once quantum computing reaches its potential. I do not expect Nintendo Switch Online to still be available by that point tho.

Even if you somehow brute force a valid, signed cert, there's no guarantee that it'll be accepted by N. They might be keeping a list of valid certs and checking requesting certs against those or they might be keeping a list of banned certs (CRL etc). Latter makes a lot more sense, but this is N we're talking about-- they've rarely made choices that align with industry standards.

My point is that this is a ridiculous idea, even if you are NSA. It would literally be faster, cheaper and more-likely-to-happen to bribe someone at N to get your cert unbanned, or, like, even faster and cheaper would be to get a new switch.
 
  • Like
Reactions: hippy dave

henryford

New Member
Newbie
Joined
Aug 16, 2018
Messages
3
Trophies
0
Age
38
XP
107
Country
Germany
Its worse than brute forcing sha256, he needs to break rsa2048 I believe.
I think the console cert is AES-256 (not sha since sha is a hashing algorithm, not an encryption one), and the game certs are rsa 2048. Regardless, AES-256 is way, way stronger than RSA 2048.
 

Paulsar99

Well-Known Member
Member
Joined
May 15, 2018
Messages
1,095
Trophies
0
XP
2,543
Country
Togo
Seriously you're better off start saving money now and buy a new switch then use your old one for homebrews rather than waiting for the hack that could unban you.
 

AveSatanas

Well-Known Member
Member
Joined
Aug 7, 2018
Messages
153
Trophies
0
XP
950
Country
Chad
I think the console cert is AES-256 (not sha since sha is a hashing algorithm, not an encryption one), and the game certs are rsa 2048. Regardless, AES-256 is way, way stronger than RSA 2048.
he said rsa, not sha. using an symmetric key for a cert wouldn't make any sense, and aes is symmetric, while rsa is asymmetric. For bruteforcing, RSA2048 is much, much harder to brute force than AES256, simply due to the key length (256 vs 2048 bits).
 

Nerdtendo

Your friendly neighborhood idiot
Member
Joined
Sep 29, 2016
Messages
1,770
Trophies
1
XP
4,645
Country
United States
No. Please stop making threads about bans. No one wishes to explain to you how the security works, but any idea that you have will not work. Just accept being banned.

There will be no 'brute force'. There will be no 'just edit a few bytes'. That's not how the security model works.
If someone wishes to know more about how something works or has an idea about something, why stop them from asking. I'm getting quite tired of people shutting others down just because they don't fully understand a concept and wish to know more.

Everyone here is a real life person and deserves to be treated as such
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Psionic Roshambo @ Psionic Roshambo: https://www.youtube.com/watch?v=A0FyqCEfD0E