Hacking Would it be possible to modify the Nand Dump to downgrade the firmware and restore it?

John_Drek

Member
OP
Newcomer
Joined
Apr 30, 2018
Messages
9
Trophies
0
Age
30
XP
72
Country
United States
I'm really really sorry if this is a useless thread but I don't know who else to talk to about this if this is even possible. Is it possible that you can modify a nand dump and downgrade it then restore the nand just like how you are able to downgrade the Nintendo Wii (Just an example).
 

Ryab

Well-Known Member
Member
Joined
Aug 9, 2017
Messages
3,231
Trophies
1
XP
4,457
Country
United States
I'm really really sorry if this is a useless thread but I don't know who else to talk to about this if this is even possible. Is it possible that you can modify a nand dump and downgrade it then restore the nand just like how you are able to downgrade the Nintendo Wii (Just an example).
with the access that we have for sure though it would be far in the future would just require a way to bypass the fuses
 
  • Like
Reactions: andijames

ThisIsDaAccount

Well-Known Member
Member
Joined
Apr 8, 2016
Messages
1,158
Trophies
0
XP
944
Country
United States
I'm really really sorry if this is a useless thread but I don't know who else to talk to about this if this is even possible. Is it possible that you can modify a nand dump and downgrade it then restore the nand just like how you are able to downgrade the Nintendo Wii (Just an example).
In most cases, no, because the switch has something called fuses. The fuses tell the switch what OS version it should have, and if it has something different the switch won't turn on.

EDIT: If we get CFW that ignores what the fuses say, then it's possible
 

TerraPhantm

Well-Known Member
Member
Joined
Jul 27, 2007
Messages
498
Trophies
0
XP
680
Country
United States
Efuses would prevent you from booting it directly, but you could probably boot into it using the RCM vulnerability (but that would also mean you'd need to do that everytime you boot the switch)
 

mikey420

Well-Known Member
Member
Joined
Dec 11, 2015
Messages
911
Trophies
0
Age
30
XP
493
Country
United States
You could theoretically use the bootrom hack to run any version of the system software you'd like but the best way to do so would not be by modifying the actual nand . your best bet would be an "emunand" with all the securities patched out by the loader. Though for the life of me I can not imagine it would be all that helpful to downgrade.
 

Ronhero

Too Weird to Live, Too Rare to Die
Member
Joined
Jun 28, 2014
Messages
3,470
Trophies
1
Location
Arizona Bay
Website
127.0.0.1
XP
2,062
Country
United States
Ive also wondered this myself. Lets say in theory you could dg to 1.0 and install a custom patch to bypass fuse check. Then lets say a software only full cold boot comes along (fingers crossed since I'm still on 1.0) it may in theory let you then boot into emunand.

Just a theory but it would be nice
 

TerraPhantm

Well-Known Member
Member
Joined
Jul 27, 2007
Messages
498
Trophies
0
XP
680
Country
United States
Ive also wondered this myself. Lets say in theory you could dg to 1.0 and install a custom patch to bypass fuse check. Then lets say a software only full cold boot comes along (fingers crossed since I'm still on 1.0) it may in theory let you then boot into emunand.

Just a theory but it would be nice
If you have a patch to bypass the fuse check, then you already have a patch to cold boot into emunand.
 

EclipseSin

Ignorant Wizard
Member
Joined
Apr 1, 2015
Messages
2,063
Trophies
1
Age
35
Location
221b Baker Street
XP
1,737
Country
United Kingdom
There is no way to downgrade an updated switch. If the console is using an exploit to load old firmware, bypassing efuse checks, it is not a downgrade. Without the exploit it would be a brick.

eFuses work just like any other fuse. If it's blown, it is blown, there is no software to reset it as it is an electronic short, not a bit or register.

That said, there are a few use case scenarios, but those are few and becoming less.
 

TheCyberQuake

Certified Geek
Member
Joined
Dec 2, 2014
Messages
5,012
Trophies
1
Age
28
Location
Las Vegas, Nevada
XP
4,432
Country
United States
No you can't.
Modifying the NAND would cause it to fail signature checks.
You can't resign it because we don't have the private keys (which are different from the public keys we currently have)
You could patch signature checks, but at that point you have access to just running cfw anyway, meaning there would be no benefit to using it.
 
D

Deleted User

Guest
It happened on Xbox 360 so I'm sure it could happen here.

Give the Devs time to research the boot process.
 

lembi2001

Well-Known Member
Member
Joined
Dec 29, 2015
Messages
433
Trophies
0
Age
39
XP
1,211
Country
What would downgrading get you?

There is no point in downgrading. A fully working Emunand or CFW with signature patches is the best case scenario.

As has previously been stated the FW checks that the number of burnt efuses match the hardcoded figure in the firmware. If not a kernel panic and ensues and your switch is effectively dead.

Efuses are impossible to revert back to their unburnt state once tripped. There would be no benefit from running a downgraded OS anyway as you lose the ability to play game that require a newer FW.

Once Scires finishes Atmosphere we will see what benefits we get and where others can expand on the work.
 

notimp

Well-Known Member
Member
Joined
Sep 18, 2007
Messages
5,779
Trophies
1
XP
4,419
Country
Laos
What would downgrading get you?

There is no point in downgrading. A fully working Emunand or CFW with signature patches is the best case scenario.

Started from a modchip, or having to be tethered to another powered device on every boot. ;) Then getting banned from N being able to detect the modchip based on voltage fluctuations. ;) (The last part is not that likely - but still.. ;) )

There would be no benefit from running a downgraded OS anyway as you lose the ability to play game that require a newer FW.
Of course you could run it in CFW if they are getting updated regularly. :) Just not online, for long. Probably. ;) (Depending on a couple of unknowns).
 
Last edited by notimp,

WaterBotttle

Well-Known Member
Member
Joined
Dec 19, 2014
Messages
163
Trophies
0
Age
34
XP
307
Country
I've seen this question pop up a few times and I also had the thought myself. However it won't work.

The Switch has e-fuses, which act as a permanent counter in the processor.

The Switch bootloader (The 2cd piece of code to run after the bootrom) checks the values of the e-fuses (http://switchbrew.org/index.php?title=Fuses#Anti-downgrade)

If the value of the firmware is too low compared to the e-fuses because you've tried to downgrade then the bootloader will not continue any further.

There is a way to downgrade but it's not very useful, see here.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • HiradeGirl @ HiradeGirl:
    Wii U is also great.
  • HiradeGirl @ HiradeGirl:
    For DS games.
  • HiradeGirl @ HiradeGirl:
    Also, 3DS games through NTR streaming on Wii U.
  • HiradeGirl @ HiradeGirl:
    It's very cool.
  • HiradeGirl @ HiradeGirl:
    Even playable.
  • K3Nv2 @ K3Nv2:
    If you can have main game on big screen and touch lay out on wiiu tablet I can see that
  • Xdqwerty @ Xdqwerty:
    @HiradeGirl, I have a broken o3ds xl
  • Psionic Roshambo @ Psionic Roshambo:
    Phones worked great for DS emulation with DraStic and a controller that held your phone
  • Psionic Roshambo @ Psionic Roshambo:
    But sadly that's coming to an end
  • Xdqwerty @ Xdqwerty:
    @Psionic Roshambo, atleast I think the latest version's apk is archived somewhere
    +1
  • K3Nv2 @ K3Nv2:
    Yeah it works great but it's the obvious Ds factor you loose from it it's not like playing atari games on atari because Nintendo actually use to give a reason to buy their hardware
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Honestly Ken I actually have the hardware and it's hacked and works fine, prefer my phone lol
  • Psionic Roshambo @ Psionic Roshambo:
    Microphone is more sensitive, DraStic has a high res mode, screen is way better just overall a better experience
  • K3Nv2 @ K3Nv2:
    I just like game consoles how they were intended to play if they have a unique enough reason to buy them anything else yeah just download emulation for it
  • Psionic Roshambo @ Psionic Roshambo:
    Oh and touch screen infinity better lol
  • HiradeGirl @ HiradeGirl:
    @Xdqwerty It's still on Play Store.
  • HiradeGirl @ HiradeGirl:
    for free
  • HiradeGirl @ HiradeGirl:
    Install before they remove it.
  • K3Nv2 @ K3Nv2:
    I'd like to see a DS emulator that allows casting top screen to TV then use bottom for the touch screen stuff
    +1
  • HiradeGirl @ HiradeGirl:
    I used a vertical touch 22" monitor for playing some 3DS games through Citra.
  • K3Nv2 @ K3Nv2:
    Can't be that far off from it not like ds requires super hardware
  • HiradeGirl @ HiradeGirl:
    @K3Nv2 I did that using Citra for 3DS games. Bottom screen was my smartphone. Until I got the touch screen.
  • SwordShielder @ SwordShielder:
    Use a TV
  • K3Nv2 @ K3Nv2:
    Citra allows it already?
  • HiradeGirl @ HiradeGirl:
    Yes.
    HiradeGirl @ HiradeGirl: Yes.