Hacking Mariko revision. Does nobody care about hacking these?

SciresM

Developer
Developer
Joined
Mar 21, 2014
Messages
973
Trophies
3
Age
33
XP
8,294
Country
United States
if you don't mind me asking, (since you are here) for unpatched units Is 7.0 software cfw exploit realistic or not? I don't mean now or the near future.

(I don't want to hold you by the books since you already do so much for the community, and would be really rude and unrealistic to ask for a time or date. As I'd imagine your more busy keeping up with Nintendo's shenanigans per update and continued implementation/expanding features of atmosphere)

But I heard that 7.0 is the last software entry point that can have cfw. Has something got in the way of that by any chance?

That's a super "eventually" thing.

On < 8.x Erista units, TrustZone can be compromised if you control the bpmp at wake-from-sleep.

In practice, this means a full userland compromise is needed.

You can maybe do some stuff with tsec or GPU dma if you compromise nvservices, but it needs research and isn't straightforward.



So, pieces needed for cfw on a < 8.0.0 erista console:
* Console is not update nagged (this is unfixable).
* Browser exploit.
* nvservices exploit.
* Further userland escalation.
* TrustZone compromise.

Stuff we have:
* TrustZone compromise.

Stuff we kind of have:
* Browser exploit (I have a webkit 0-day, but I would like to avoid burning it for something like this when it might be useful to me if I want to look at PS5 or a future console).
* The userland escalation bit via tsec or gpu, but this would probably be 50-100 hours of research/work once an nvservices compromise is in hand.

Stuff we don't have:
* nvservices compromise.

Nvservices is pretty dogshit from a security pov, and it's all nvidia code and not Nintendo code -- this means it's lower security.

I'm sure nvservices vulnerabilities exist to be found, but I don't actually have one.

Combining all those factors, it's just super low priority. I expect "eventually" it'll happen, but like...don't expect it any time soon, and it's not an area of active work on my part, especially since it would be so much work and so few people will benefit from it.

So what, am I seriously just going to shell out $60 when Nintendo releases another game I want?

Even ignoring the fact that I and other hackers don't support and aren't motivated by piracy, it may surprise you to learn that the fact that you don't want to pay for games doesn't make exploitable bugs magically exist.

Perhaps a clear analogy: I'd prefer not to have to pay my rent. Unfortunately my apartment's lease, like Mariko units, doesn't have any exploitable bugs. My not wanting to pay my rent doesn't make any bugs exist in my lease.

My options, then, are to pay my rent or live somewhere else.

Your options are to buy switch games, or not play games on your switch.
 
Last edited by SciresM,

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,138
Country
United States
the ones who complain about a $60 game are the same ones who get pissed off at theflow for making 10 grand for disclosing an exploit on the ps4. they do absolutely nothing in the scene, yet they feel entitled.
 

zenjiki

Well-Known Member
Member
Joined
Feb 13, 2006
Messages
108
Trophies
1
XP
1,378
Country
United States
We have 3 OG switches all unbanned and just been used for retrogaming with emulators I'll sell you 1. How much you willing to pay to not pay $60 for new games? lol Love my retrogaming though, so its going to cost.
 
Last edited by zenjiki,

JeepX87

Well-Known Member
Member
Joined
Aug 17, 2016
Messages
1,754
Trophies
0
Age
36
XP
3,273
Country
United States
DM me a link, please!

SX Core and SX Lite are no longer manufactured so don't bother to hunt for this and cost is going up due to higher demand.

You have to wait for next clone in near future.

So what, am I seriously just going to shell out $60 when Nintendo releases another game I want?

I have no sympathy for people whoever pirate the game and you just contaminated the CFW that supposed to use with homebrew, save sharing and cheating, so you gave Nintendo a major reason to crack all of us who use CFW down because you want to pirate the game.

Go find a job or ask your boss for pay raise if they don't pay you enough.

I'm not going assist with people whoever want to pirate the games and you are on own.

SX Core and SX Lite are no longer manufactured, anyway.

Edit: I don't mean to be rude to you and it is very bad deal to bring up about pirated games.
 
Last edited by JeepX87,
  • Like
Reactions: Skelletonike

Deleted member 546149

Well-Known Member
Member
Joined
Dec 18, 2020
Messages
2,000
Trophies
2
XP
6,972
It has been 4 full years since the Switch has been released, and 2 years since Mariko was released. Yet, we still have no softmod for Mariko. What's taking so long?
People have been trying to install CFW but it's very hard to find a bug that allows it. HB channel may be different but no one try experimenting with basic homebrew anymore.

--------------------- MERGED ---------------------------

Just for the record, as a hacker who's been involved in every cfw-related exploit for the switch and works on this stuff regularly: it's probably not going to happen.

I've sunk ~300-400 hours of my time investigating Mariko exploit stuff.

There are no trustzone bugs. This means no custom firmware.

There are no kernel bugs. This means no shitty fake custom firmware where you pretend you hacked trustzone, which is something I was prepared to work to support if I found the right bug.

Nintendo got the security right this time. Waiting for a software exploit is almost certainly not gonna do anything for you.

Mariko is almost impossible to install cfw on, but what about plain hb[/QUOTE]
 

SciresM

Developer
Developer
Joined
Mar 21, 2014
Messages
973
Trophies
3
Age
33
XP
8,294
Country
United States
Mariko is almost impossible to install cfw on, but what about plain hb

My analysis is basically the same.

Getting plain hb requires full userland compromise.

Mariko fixes the GPU DMA bug; getting just homebrew isn't impossible but isn't happening any time soon.

You'd have to find an exploitable bug in FS, and good luck with that lmao.
 

JeepX87

Well-Known Member
Member
Joined
Aug 17, 2016
Messages
1,754
Trophies
0
Age
36
XP
3,273
Country
United States
My analysis is basically the same.

Getting plain hb requires full userland compromise.

Mariko fixes the GPU DMA bug; getting just homebrew isn't impossible but isn't happening any time soon.

You'd have to find an exploitable bug in FS, and good luck with that lmao.

I'm wonder about patched Switch prior to Mariko?
 

SciresM

Developer
Developer
Joined
Mar 21, 2014
Messages
973
Trophies
3
Age
33
XP
8,294
Country
United States
I'm wonder about patched Switch prior to Mariko?

You'd need a browser exploit + an nvservices compromise.

Then you'd be able to use the GPU dma bug to play homebrew games.

Note that you'd have almost no privileges -- this means no editing savedata, no overclocking or using interesting system modules, no custom themes, no game mods, etc etc. Homebrew games that don't use special privileges only.

See a few posts above -- you still need an nvservices bug and a browser exploit, and it's kind of like "who cares" imo when it doesn't let you do game mods or save editing.

Probably not impossible, but hard for me to imagine anyone with the skill to find the bugs sinking in all the time/effort?
 

legendheaven

Well-Known Member
Member
Joined
Oct 31, 2015
Messages
208
Trophies
0
XP
1,185
Country
United States
You'd need a browser exploit + an nvservices compromise.

Then you'd be able to use the GPU dma bug to play homebrew games.

Note that you'd have almost no privileges -- this means no editing savedata, no overclocking or using interesting system modules, no custom themes, no game mods, etc etc. Homebrew games that don't use special privileges only.

See a few posts above -- you still need an nvservices bug and a browser exploit, and it's kind of like "who cares" imo when it doesn't let you do game mods or save editing.

Probably not impossible, but hard for me to imagine anyone with the skill to find the bugs sinking in all the time/effort?
U got me fish pokemon I find bug and I did cfw but still have problems 3/1 brick.... My old posts I said I find a method lol
 

Deleted member 546149

Well-Known Member
Member
Joined
Dec 18, 2020
Messages
2,000
Trophies
2
XP
6,972
You'd need a browser exploit + an nvservices compromise.

Then you'd be able to use the GPU dma bug to play homebrew games.

Note that you'd have almost no privileges -- this means no editing savedata, no overclocking or using interesting system modules, no custom themes, no game mods, etc etc. Homebrew games that don't use special privileges only.

See a few posts above -- you still need an nvservices bug and a browser exploit, and it's kind of like "who cares" imo when it doesn't let you do game mods or save editing.

Probably not impossible, but hard for me to imagine anyone with the skill to find the bugs sinking in all the time/effort?
You could still pirate :)
th
 

Skelletonike

♂ ♥ Gallant Pervert ♥ ♀
Member
GBAtemp Patron
Joined
Dec 26, 2008
Messages
3,436
Trophies
3
Age
32
Location
Steam City
XP
2,690
Country
Portugal
Tbh, I'm pretty happy with that.

Once the switch dies, they can do whatever with it, for now, I'd rather it remains the way it is, at least for the Mariko version.
 

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,329
Trophies
2
XP
18,209
Country
Sweden
"no overclocking" that's like one of the best features of a homebrewed Switch. Like with the Vita. Some games require OC to work, atleast feel smooth.
 
  • Like
Reactions: Jayro

Deleted member 546149

Well-Known Member
Member
Joined
Dec 18, 2020
Messages
2,000
Trophies
2
XP
6,972
No, you couldn't.

Piracy requires substantially higher privileges than homebrew, not lower.

In the low privileges homebrew scenario described, you very much would not be able to pirate games.
You could without sigpatches, for example, the USB loader, or an sd loader

--------------------- MERGED ---------------------------

Anyways there will be cfw one day, whether it's near or end of life
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • TwoSpikedHands @ TwoSpikedHands:
    Do I restart now using what i've learned on the EU version since it's a better overall experience? or do I continue with the US version since that is what ive been using, and if someone decides to play my hack, it would most likely be that version?
  • Sicklyboy @ Sicklyboy:
    @TwoSpikedHands, I'll preface this with the fact that I know nothing about the game, but, I think it depends on what your goals are. Are you trying to make a definitive version of the game? You may want to refocus your efforts on the EU version then. Or, are you trying to make a better US version? In which case, the only way to make a better US version is to keep on plugging away at that one ;)
  • Sicklyboy @ Sicklyboy:
    I'm not familiar with the technicalities of the differences between the two versions, but I'm wondering if at least some of those differences are things that you could port over to the US version in your patch without having to include copyrighted assets from the EU version
  • TwoSpikedHands @ TwoSpikedHands:
    @Sicklyboy I am wanting to fully change the game and bend it to my will lol. I would like to eventually have the ability to add more characters, enemies, even have a completely different story if i wanted. I already have the ability to change the tilemaps in the US version, so I can basically make my own map and warp to it in game - so I'm pretty far into it!
  • TwoSpikedHands @ TwoSpikedHands:
    I really would like to make a hack that I would enjoy playing, and maybe other people would too. swapping to the EU version would also mean my US friends could not legally play it
  • TwoSpikedHands @ TwoSpikedHands:
    I am definitely considering porting over some of the EU features without using the actual ROM itself, tbh that would probably be the best way to go about it... but i'm sad that the voice acting is so.... not good on the US version. May not be a way around that though
  • TwoSpikedHands @ TwoSpikedHands:
    I appreciate the insight!
  • The Real Jdbye @ The Real Jdbye:
    @TwoSpikedHands just switch, all the knowledge you learned still applies and most of the code and assets should be the same anyway
  • The Real Jdbye @ The Real Jdbye:
    and realistically they wouldn't

    be able to play it legally anyway since they need a ROM and they probably don't have the means to dump it themselves
  • The Real Jdbye @ The Real Jdbye:
    why the shit does the shitbox randomly insert newlines in my messages
  • Veho @ Veho:
    It does that when I edit a post.
  • Veho @ Veho:
    It inserts a newline in a random spot.
  • The Real Jdbye @ The Real Jdbye:
    never had that i don't think
  • Karma177 @ Karma177:
    do y'all think having an sd card that has a write speed of 700kb/s is a bad idea?
    trying to restore emunand rn but it's taking ages... (also when I finished the first time hekate decided to delete all my fucking files :wacko:)
  • The Real Jdbye @ The Real Jdbye:
    @Karma177 that sd card is 100% faulty so yes, its a bad idea
  • The Real Jdbye @ The Real Jdbye:
    even the slowest non-sdhc sd cards are a few MB/s
  • Karma177 @ Karma177:
    @The Real Jdbye it hasn't given me any error trying to write things on it so I don't really think it's faulty (pasted 40/50gb+ folders and no write errors)
  • DinohScene @ DinohScene:
    run h2testw on it
    +1
  • DinohScene @ DinohScene:
    when SD cards/microSD write speeds drop below a meg a sec, they're usually on the verge of dying
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Samsung SD format can sometimes fix them too
  • Purple_Heart @ Purple_Heart:
    yes looks like an faulty sd
  • Purple_Heart @ Purple_Heart:
    @Psionic Roshambo i may try that with my dead sd cards
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    It's always worth a shot
  • TwoSpikedHands @ TwoSpikedHands:
    @The Real Jdbye, I considered that, but i'll have to wait until i can get the eu version in the mail lol
    TwoSpikedHands @ TwoSpikedHands: @The Real Jdbye, I considered that, but i'll have to wait until i can get the eu version in the...