Homebrew 9.5 Encryption Broke By Yellows8

SLiV3R

3DS Friend Code: 0473-9069-2206
Member
Joined
Jan 9, 2006
Messages
2,319
Trophies
2
Website
soundcloud.com
XP
1,847
Country
Yifan lu said that yellows8 is the sharpest RE in the 3ds scene. If you look at 3ds brew 95 % of all exploits are his discoveries. But gw are a team with more than 2 ppl involved. So it should not be impossible for them either I guess..
 
  • Like
Reactions: Slushie3DS

Arras

Well-Known Member
Member
Joined
Sep 14, 2010
Messages
6,318
Trophies
2
XP
5,409
Country
Netherlands
IIRC another person also managed to hack it as well, and all the other keys could be extracted already (ie the rest of Nintendo's trap cards to stop emuNAND on N3DS). So whatever plans Nintendo had to block emuNAND with this are gone. They really messed this one up.
9.4 was already hackable on n3DS. The new key they added on 9.5 can be (apparently easily) extracted, yes, but what's preventing them from just changing it again, but without the mistake they made here?
 

shinyquagsire23

SALT/Sm4sh Leak Guy
Member
Joined
Nov 18, 2012
Messages
1,977
Trophies
2
Age
26
Location
Las Vegas
XP
3,765
Country
United States
9.4 was already hackable on n3DS. The new key they added on 9.5 can be (apparently easily) extracted, yes, but what's preventing them from just changing it again, but without the mistake they made here?

To be honest I'm not sure what the entire situation is with the keys, but I recall mathieu also extracted the keys and the slip-up also exposed the other key slots.

Wait, found that tweet:
https://twitter.com/Mathieulh/status/562923931565555714

TLDR; They dun messed up, and all their extra key slots they made to fend off Gateway are useless apparently without new hardware.

EDIT: Looks like it *might* be possible for this to be cleared by Nintendo, but basically the issue is that the key slots they used for encryption aren't cleared even on hard reboot, so I'm guessing you could grab those fairly easily from a vulnerable firmware. Full tweet is this:
Dear @Nintendo I spotted an implementation failure on the *New* 3DS that allows keyslot 0x11 to remain uncleared after a hard reboot. this allows to derive the secondary/regular key for keyslot 0x11 (by performing the AES-ECB on the unit and gathering the result). This basically makes the *New* 3DS ARM9 added cryptography step very much useless. this attack also allows a third party to get the KeyX for keyslots 0x18-0x20 (aka *New* 3DS Only keys) making those worthless too
 

amback

Well-Known Member
Member
Joined
Jul 7, 2014
Messages
110
Trophies
0
Age
30
XP
251
Country
United States
And yet still not any mention on sysnand 9.3+ support :/ for gateway.
or does this mean we will see gateway support for 9.3+?

someone please explain it to me
 

lemanuel

Maxconsole's All-Knowing Lurker
Member
Joined
Dec 11, 2014
Messages
2,095
Trophies
0
XP
1,254
Country
Portugal
And yet still not any mention on sysnand 9.3+ support :/ for gateway.
or does this mean we will see gateway support for 9.3+?

someone please explain it to me

the only thing this can possibly be used for is enabling emunand to work in 9.5 in the N3DS. But it means nothing for sysnand.
 

shinyquagsire23

SALT/Sm4sh Leak Guy
Member
Joined
Nov 18, 2012
Messages
1,977
Trophies
2
Age
26
Location
Las Vegas
XP
3,765
Country
United States
the only thing this can possibly be used for is enabling emunand to work in 9.5 in the N3DS. But it means nothing for sysnand.

Basically this, also they patched the main hole used to for emuNAND (from sysNAND) in 9.5 which was firmlaunch-hax, to 9.5 is still a bit of a wall if it's on your sysNAND at all. 9.3 just patches the main tool used to execute code arbitrarily, although it may be possible to go around this using gsphax. Woudln't hold my breath for it though.
 
  • Like
Reactions: lemanuel

davhuit

Well-Known Member
Member
Joined
Nov 23, 2005
Messages
994
Trophies
0
XP
550
Country
France
It'll take a while before seeing a game that require 9.5, probably no games during 2015 will require it as games are often developped long before their releases.

Before fixing emunand 9.5 on N3DS, they first have to actually release the exploit anyway xD
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    SylverReZ @ SylverReZ: @OctoAori20, Thank you. Hope you're in good spirits today like I am. :)