Hacking AutoRCM Implementation by Reisyukaku

D

Deletedmember448668

Guest
Hey I already know i'm going to get shit for this comment but I'm still a tad skeptical so fuck it. Here it is.
Can you make a video powering off your switch, pluging your usb c in and then using Auto-RCM? Unfortunately, this proves nothing as you could have already been in RCM. Sorry to be such a skeptic, but I mean, I could literally make a video right now and do the same thing :) And I will to prove my point if needed.
 
Last edited by ,

Lacius

Well-Known Member
Member
Joined
May 11, 2008
Messages
18,099
Trophies
3
XP
18,338
Country
United States
Hey I already know i'm going to get shit for this comment but I'm still a tad skeptical so fuck it. Here it is.
Can you make a video powering off your switch, pluging your usb c in and then using Auto-RCM? Unfortunately, this proves nothing as you could have already been in RCM. Sorry to be such a skeptic, but I mean, I could literally make a video right now and do the same thing :) And I will to prove my point if needed.
Why are you skeptical? It's a simple modification we all knew was possible since before TX advertised it.
 
  • Like
Reactions: Reisyukaku

Huntereb

Well-Known Member
Member
Joined
Sep 1, 2013
Messages
3,234
Trophies
0
Website
lewd.pics
XP
2,446
Country
United States
Can you make a video powering off your switch, pluging your usb c in and then using Auto-RCM? Unfortunately, this proves nothing as you could have already been in RCM. Sorry to be such a skeptic, but I mean, I could literally make a video right now and do the same thing :) And I will to prove my point if needed.
It works, I've used it myself. It literally bricks your console, there's not much to prove. If you don't like your bricked console, execute the payload again and turn it off. You're not losing anything if you have a NAND backup.
 
D

Deletedmember448668

Guest
Why are you skeptical? It's a simple modification we all knew was possible since before TX advertised it.
I'm supporting their efforts 100%, just skeptical..for reasons
It works, I've used it myself. It literally bricks your console, there's not much to prove. If you don't like your bricked console, execute the payload again and turn it off. You're not losing anything if you have a NAND backup.
But the point of the video is to show that they have a working Auto-RCM right? If it bricks your console what's the point? Maybe i misread your comment about bricking..idk. Is that what you're saying?
 
Last edited by ,

Lacius

Well-Known Member
Member
Joined
May 11, 2008
Messages
18,099
Trophies
3
XP
18,338
Country
United States
I'm supporting their efforts 100%, but the

But the point of the video is to show that they have a working Auto-RCM right? If it bricks your console what's the point? Maybe i misread your comment about bricking..idk. Is that what you're saying?
AutoRCM works by "bricking" the console. It makes the Switch unable to boot the OS, so it boots RCM (Tegra Recovery Mode) instead. Installing AutoRCM is beneficial because it will always launch RCM on boot, but it also means you will be unable to boot into the Switch OS without first loading an RCM payload through the USB-C port.
 
D

Deletedmember448668

Guest
AutoRCM works by "bricking" the console. It makes the Switch unable to boot the OS, so it boots RCM (Tegra Recovery Mode) instead.
I get that. They are corrupting the boot files, hunters comment makes it sound like a permabrick. Wording used wrong i guess
 

Huntereb

Well-Known Member
Member
Joined
Sep 1, 2013
Messages
3,234
Trophies
0
Website
lewd.pics
XP
2,446
Country
United States
But the point of the video is to show that they have a working Auto-RCM right? If it bricks your console what's the point? Maybe i misread your comment about bricking..idk. Is that what you're saying?
Well, it's not "bricked" for say. The console can't find a validly signed partition to boot, so it launches RCM automatically. Your console is essentially a "brick" unless you launch your firmware using a RCM payload.
 

Reisyukaku

Onii-sama~
Developer
Joined
Feb 11, 2014
Messages
1,534
Trophies
2
Website
reisyukaku.org
XP
5,422
Country
United States
Hey I already know i'm going to get shit for this comment but I'm still a tad skeptical so fuck it. Here it is.
Can you make a video powering off your switch, pluging your usb c in and then using Auto-RCM? Unfortunately, this proves nothing as you could have already been in RCM. Sorry to be such a skeptic, but I mean, I could literally make a video right now and do the same thing :) And I will to prove my point if needed.
Given the previous comments in this thread and other of my threads, i think its safe to assume im well respected enough of a dev to where i can just say "trust me" and that should be enough. I mainly work privately on switch after the cancer that was the 3DS scene so you probably wouldnt know me well enough. But if your 3DS runs ReiNAND, ReiSix or Luma you can thank me (^:
 

Lacius

Well-Known Member
Member
Joined
May 11, 2008
Messages
18,099
Trophies
3
XP
18,338
Country
United States
I get that. They are corrupting the boot files, hunters comment makes it sound like a permabrick. Wording used wrong i guess
Well, it's not "bricked" for say. The console can't find a validly signed partition to boot, so it launches RCM automatically. Your console is essentially a "brick" unless you launch your firmware using a RCM payload.
Without a way to launch an RCM payload using the USB-C port, the Switch is "bricked." If you have access to a way to launch an RCM payload through the USB-C port, then you're not "bricked."

If you install AutoRCM and then something bad happens to your USB-C port that makes it nonfunctional, then you're totally bricked.

Edit: It should be noted that you only need to launch an RCM payload each time you coldboot the system. Once Atmosphere CFW is released, for example, I assume you will load it once and then likely keep your Switch in sleep mode 99% of the time.
 
Last edited by Lacius,

rajkosto

Well-Known Member
Member
Joined
Apr 6, 2017
Messages
819
Trophies
1
XP
2,775
Country
There's only so many ways to change an RSA modulus, family. I've mentioned all kinds of ideas in my private group so it's hard to say 1 person thought of it and everyone else copied.
there is more than one way, a few days ago i did it by just xoring all the pubkey bytes with a random u8, which has about the same recoverability as changing the first byte, but why make it more complicated than it has to be

mine and yours are functionally identical so people can use whichever one they want
now lets just hope THEY do it the same way so all the tools are compatible
 
D

Deletedmember448668

Guest
Well, it's not "bricked" for say. The console can't find a validly signed partition to boot, so it launches RCM automatically. Your console is essentially a "brick" unless you launch your firmware using a RCM payload.
I understand how it works, the boot files are corrupt right? Or is he doing it a different way. Still wouild like to see a video of it in full.
Given the previous comments in this thread and other of my threads, i think its safe to assume im well respected enough of a dev to where i can just say "trust me" and that should be enough. I mainly work privately on switch after the cancer that was the 3DS scene so you probably wouldnt know me well enough. But if your 3DS runs ReiNAND, ReiSix or Luma you can thank me (^:
I've heard your name, i've seen your recent releases, I appreciate your work. But can you see why anyone would be skeptical, even if it is the 1%? Saying "trust me because i'm me" doesnt validate anything (Not being rude, just making a point) Rock on my dude!
 

Qyriad

New Member
Newbie
Joined
Jul 18, 2017
Messages
3
Trophies
0
Age
26
XP
91
Country
United States
Given the previous comments in this thread and other of my threads, i think its safe to assume im well respected enough of a dev to where i can just say "trust me" and that should be enough. I mainly work privately on switch after the cancer that was the 3DS scene so you probably wouldnt know me well enough. But if your 3DS runs ReiNAND, ReiSix or Luma you can thank me (^:
A reminder that there is almost 0 ReiNAND code left in Luma, and most of what remains is boilerplate.
 
D

Deletedmember448668

Guest
Without a way to launch an RCM payload using the USB-C port, the Switch is "bricked." If you have access to a way to launch an RCM payload through the USB-C port, then you're not "bricked."

If you install AutoRCM and then something bad happens to your USB-C port that makes it nonfunctional, then you're totally bricked.

Edit: It should be noted that you only need to launch an RCM payload each time you coldboot the system. Once Atmosphere CFW is released, for example, I assume you will load it once and then likely keep your Switch in sleep mode 99% of the time.
So, here's a question based on that. If we use this method right now, is there no way to get back to normal horizon to play our switch games?
 

Reisyukaku

Onii-sama~
Developer
Joined
Feb 11, 2014
Messages
1,534
Trophies
2
Website
reisyukaku.org
XP
5,422
Country
United States
there is more than one way, a few days ago i did it by just xoring all the pubkey bytes with a random u8, which has about the same recoverability as changing the first byte, but why make it more complicated than it has to be

mine and yours are functionally identical so people can use whichever one they want
now lets just hope THEY do it the same way so all the tools are compatible
it's public knowledge that corrupting nand, or pulling your nand chip out is alt ways of RCM. the modulus is just easy because static data.. and yea, xoring would be a good way too.. that way you can corrupt non-static data. Not sure why you're getting worked up.
 
  • Like
Reactions: peteruk and Lacius

Lacius

Well-Known Member
Member
Joined
May 11, 2008
Messages
18,099
Trophies
3
XP
18,338
Country
United States
So, here's a question based on that. If we use this method right now, is there no way to get back to normal horizon to play our switch games?
You can uninstall AutoRCM and return your Switch to normal. With AutoRCM installed, the only way to launch the Switch OS without uninstalling AutoRCM is by launching CFW of some sort.
 

Huntereb

Well-Known Member
Member
Joined
Sep 1, 2013
Messages
3,234
Trophies
0
Website
lewd.pics
XP
2,446
Country
United States
I understand how it works, the boot files are corrupt right? Or is he doing it a different way. Still wouild like to see a video of it in full.
This tool modifies a single byte in the partition headers of your NAND, breaking their signature. The console won't boot what doesn't look valid.

A reminder that there is almost 0 ReiNAND code left in Luma, and most of what remains is boilerplate.
So you're reminding us that without ReiNAND, Luma wouldn't exist? :v)
 

memomo

( ͡° ͜ʖ ͡°)
Member
Joined
Nov 30, 2013
Messages
1,079
Trophies
0
Age
31
XP
750
Country
works greet in 4.1

but I switched back to normal because it still pc-dependent
Anyway, it's good to see our beloved developers do an amazing progress
 

Attachments

  • AutoRCM.jpg
    AutoRCM.jpg
    34.6 KB · Views: 556
D

Deletedmember448668

Guest
You can uninstall AutoRCM and return your Switch to normal. With AutoRCM installed, the only way to launch the Switch OS without uninstalling AutoRCM is by launching CFW of some sort.
Which leads to my next question. As you seem to be a beacon of knowledge, I will be your student. :) I'm new to this shit and still learning how eveyrthing works. When AutoRCM is released to the public (non-TX version), will we be able to play our Switch games? Right now in it's current iteration, my switch games do not boot while in any CFW.
 
Last edited by , , Reason: word

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • TwoSpikedHands @ TwoSpikedHands:
    @Sicklyboy I am wanting to fully change the game and bend it to my will lol. I would like to eventually have the ability to add more characters, enemies, even have a completely different story if i wanted. I already have the ability to change the tilemaps in the US version, so I can basically make my own map and warp to it in game - so I'm pretty far into it!
  • TwoSpikedHands @ TwoSpikedHands:
    I really would like to make a hack that I would enjoy playing, and maybe other people would too. swapping to the EU version would also mean my US friends could not legally play it
  • TwoSpikedHands @ TwoSpikedHands:
    I am definitely considering porting over some of the EU features without using the actual ROM itself, tbh that would probably be the best way to go about it... but i'm sad that the voice acting is so.... not good on the US version. May not be a way around that though
  • TwoSpikedHands @ TwoSpikedHands:
    I appreciate the insight!
  • The Real Jdbye @ The Real Jdbye:
    @TwoSpikedHands just switch, all the knowledge you learned still applies and most of the code and assets should be the same anyway
  • The Real Jdbye @ The Real Jdbye:
    and realistically they wouldn't

    be able to play it legally anyway since they need a ROM and they probably don't have the means to dump it themselves
  • The Real Jdbye @ The Real Jdbye:
    why the shit does the shitbox randomly insert newlines in my messages
  • Veho @ Veho:
    It does that when I edit a post.
  • Veho @ Veho:
    It inserts a newline in a random spot.
  • The Real Jdbye @ The Real Jdbye:
    never had that i don't think
  • Karma177 @ Karma177:
    do y'all think having an sd card that has a write speed of 700kb/s is a bad idea?
    trying to restore emunand rn but it's taking ages... (also when I finished the first time hekate decided to delete all my fucking files :wacko:)
  • The Real Jdbye @ The Real Jdbye:
    @Karma177 that sd card is 100% faulty so yes, its a bad idea
  • The Real Jdbye @ The Real Jdbye:
    even the slowest non-sdhc sd cards are a few MB/s
  • Karma177 @ Karma177:
    @The Real Jdbye it hasn't given me any error trying to write things on it so I don't really think it's faulty (pasted 40/50gb+ folders and no write errors)
  • DinohScene @ DinohScene:
    run h2testw on it
    +1
  • DinohScene @ DinohScene:
    when SD cards/microSD write speeds drop below a meg a sec, they're usually on the verge of dying
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Samsung SD format can sometimes fix them too
  • Purple_Heart @ Purple_Heart:
    yes looks like an faulty sd
  • Purple_Heart @ Purple_Heart:
    @Psionic Roshambo i may try that with my dead sd cards
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    It's always worth a shot
  • TwoSpikedHands @ TwoSpikedHands:
    @The Real Jdbye, I considered that, but i'll have to wait until i can get the eu version in the mail lol
  • I @ I-need-help-with-wup-wiiu:
    i need help with nusspli failed downloads, can someone respond to my thread? pretty please:wub:
  • Sheeba- @ Sheeba-:
    I can't wait to hack my 11.00 PS4 pro
    Sheeba- @ Sheeba-: I can't wait to hack my 11.00 PS4 pro