Homebrew [Coming Soon] OTPless A9LH installation on N3DS (no 2.1 downgrade)

Swiftloke

Hwaaaa!
Member
Joined
Jan 26, 2015
Messages
1,772
Trophies
1
Location
Nowhere
XP
1,506
Country
United States
only if we have the OTP, or the hash of the first 0x90 bytes.... and since it would patch this method, you'd have to go back to the old way of obtaining the OTP.... it has other implications as well, which I won't mention here
I'm confused here... :unsure:
If the arm9loader is unencrypted, why can't we just write the older version? Unless you're talking about a hardware revision? Or a new version of arm9loader that would re-encrypt the secret sector so that we can't swap keys?
 

dark_samus3

Well-Known Member
Member
Joined
May 30, 2015
Messages
2,372
Trophies
0
XP
2,042
Country
United States
I'm confused here... :unsure:
If the arm9loader is unencrypted, why can't we just write the older version? Unless you're talking about a hardware revision? Or a new version of arm9loader that would re-encrypt the secret sector so that we can't swap keys?
arm9loader is bundled with FIRM, so we have to change all of FIRM, not just arm9loader (since each section is hashed, and the hashes are signed). Also, not to mention, if they did re-encrypt the secret sector, we'd need to obtain our OTP by DGing to 2.1 and then re-encrypting with aes-ecb to use older versions of FIRM (since the arm9loader there would be expecting ECB, and end up decrypting garbage keys from NAND), that would mean going back to 9.2 wouldn't be possible and we'd need a whole new arm9 exploit to do the process of downgrading to 2.1.
 

annson24

The Patient One
Member
Joined
May 5, 2016
Messages
1,191
Trophies
0
Age
32
XP
1,843
Country
Philippines
Great work, this will trim down my a9lh installation proccess from 45mins to just 15mins on a v9.2 already N3DS.

Ps. Posted just to follow the thread. Sorry.

Sent from my SM-N930F using Tapatalk
 

Swiftloke

Hwaaaa!
Member
Joined
Jan 26, 2015
Messages
1,772
Trophies
1
Location
Nowhere
XP
1,506
Country
United States
Also, not to mention, if they did re-encrypt the secret sector, we'd need to obtain our OTP by DGing to 2.1 and then re-encrypting with aes-ecb to use older versions of FIRM (since the arm9loader there would be expecting ECB, and end up decrypting garbage keys from NAND), that would mean going back to 9.2 wouldn't be possible and we'd need a whole new arm9 exploit to do the process of downgrading to 2.1.
Ah, that makes sense. Thanks for taking the time to explain :)
 

SciresM

Developer
OP
Developer
Joined
Mar 21, 2014
Messages
973
Trophies
3
Age
33
XP
8,294
Country
United States
don't forget when you had to build your own installers, or have others build them for you (:ninja:). I did a9lh on all of my systems when you had to do that.

Are we playing this game?

I did arm9loaderhax before any public releases with a custom key by manually hex editing/encrypting NAND.

LaK6GzA.png
 

annson24

The Patient One
Member
Joined
May 5, 2016
Messages
1,191
Trophies
0
Age
32
XP
1,843
Country
Philippines
If we're really playing this game, I found the OTPless vuln :^)
Hands down. :bow:

I see AuroraWright has added support for the New 3DS OTP-less installation on her SafeA9LHInstaller. Well, that's a go signal for me to use the latest Beta release of UnsafeA9LHInstaller.
 
  • Like
Reactions: KiiWii

Garblant

Well-Known Member
Member
Joined
Apr 1, 2016
Messages
726
Trophies
0
Age
25
Location
Alola
XP
508
Country
United States
Hands down. :bow:

I see AuroraWright has added support for the New 3DS OTP-less installation on her SafeA9LHInstaller. Well, that's a go signal for me to use the latest Beta release of UnsafeA9LHInstaller.
I know you really don't want to but, WAIT. It's still called UnsafeA9LHInstaller for a reason.
 
Last edited by Garblant,

einhuman197

Well-Known Member
Member
Joined
Aug 17, 2015
Messages
985
Trophies
0
Location
Inside your bootloader (´◉◞౪◟◉)
XP
771
Country
Germany
I think it's a bit too over-cautious to say don't use this without hardmod. Everyone said this when 9.2 downgrade came out and the chance that you Hardbrick your 3ds after formatting (!) is less than 1%. So far there are no known bricks with this. Happy a9lh masterrace everyone (back to 02/16 :3)
 

annson24

The Patient One
Member
Joined
May 5, 2016
Messages
1,191
Trophies
0
Age
32
XP
1,843
Country
Philippines
I know you really don't want to but, WAIT. It's still called UnsafeA9LHInstaller for a reason.
Don't you think the risk in using this is just as risky as downgrading a N3DS to v2.1? In what I can see, I think this is much safer than doing ctrtransfer to v2.1. There's risk during the transfer proccess, there's risk after the downgrade has been made. Heck, it's even written in BOLD on Plailect's guide. I don't think a person is stupid enough to brick by pressing only one button. Then again, I still haven't tried this yet so I might be that stupid one to brick with a press of a button. haha
 

Urbanshadow

Well-Known Member
Member
Joined
Oct 16, 2015
Messages
1,578
Trophies
0
Age
33
XP
1,723
Country
Don't you think the risk in using this is just as risky as downgrading a N3DS to v2.1? In what I can see, I think this is much safer than doing ctrtransfer to v2.1. There's risk during the transfer proccess, there's risk after the downgrade has been made. Heck, it's even written in BOLD on Plailect's guide. I don't think a person is stupid enough to brick by pressing only one button. Then again, I still haven't tried this yet so I might be that stupid one to brick with a press of a button. haha
You are comparing Monster trucks with lemons there. I suggest to wait. No hardmod, no hypebrick. Just wait.
 
Last edited by Urbanshadow,

Akira

I'm not a SHRIMP!!!!
Member
Joined
Apr 28, 2013
Messages
1,246
Trophies
0
XP
1,666
Country
United States
Don't you think the risk in using this is just as risky as downgrading a N3DS to v2.1? In what I can see, I think this is much safer than doing ctrtransfer to v2.1. There's risk during the transfer proccess, there's risk after the downgrade has been made. Heck, it's even written in BOLD on Plailect's guide. I don't think a person is stupid enough to brick by pressing only one button. Then again, I still haven't tried this yet so I might be that stupid one to brick with a press of a button. haha
I believe it's called "risky" since not a lot of people haven't tested this yet. Unlike the one on the guide, which has been tested by a lot users. They are just being cautious to avoid newbies getting bricked if somewhat they fucked up somewhere.
 

kalkito

Member
Newcomer
Joined
Sep 29, 2016
Messages
13
Trophies
0
Age
33
XP
80
Country
Are they focused in improving the method or testing the safety of the current method? If it can be reproduced a number of times without an incident then it's ready for a tutorial.
 

JayArRosario

Well-Known Member
Newcomer
Joined
Jan 31, 2016
Messages
45
Trophies
0
Age
29
XP
81
Country
This would be great since most of the time, I'm dealing with N3DS units. I'd love to try this for real, but unfortunately I don't have a unit with permanent hardmod. I just do hardmods temporarily :)
 

JayArRosario

Well-Known Member
Newcomer
Joined
Jan 31, 2016
Messages
45
Trophies
0
Age
29
XP
81
Country
You don't need a hardmod, it's safe.
I know it doesn't require hardmod at all. But if you failed and bricked your unit (or something like that) while doing the process, since it's still called "Unsafe", you have to do a hardmod to restore your NAND dump.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    ZeroT21 @ ZeroT21: No way, Switch pro will be next