Hacking Could it be possible to downgrade the switch somewhen

  • Thread starter Thread starter Noctosphere
  • Start date Start date
  • Views Views 14,944
  • Replies Replies 89
Status
Not open for further replies.

Noctosphere

Nova's Guardian
Member
Joined
Dec 30, 2013
Messages
7,903
Reaction score
22,684
Trophies
6
Age
32
Location
Biblically accurate Hell
XP
27,204
Country
Canada
I know this is a total noob question that has already been answered : No, you can't downgrade the switch because of efuses
Well I just need to know, will it be possible somewhen to hack the switch deep enough to be able to skip the verification of efuses when booting up the console?
please dont call me noob, i know i am
 
I know this is a total noob question that has already been answered : No, you can't downgrade the switch because of efuses
Well I just need to know, will it be possible somewhen to hack the switch deep enough to be able to skip the verification of efuses when booting up the console?
please dont call me noob, i know i am
not for a long while
 
This talk about efuses, pardon my noob terminology understanding but this isn't a real bomb related situation right? I already don't like my battery exploding on me. :blink:
 
Wait, but what if you made earlier (or modded the current) NAND backup to have less fuses? A NAND backup would have eFuse data, so if you restored on one an old FW, you can reset the fuses and the FW, right?
 
Once efuses are "blown" they can't be repaired by any means. It's not a physical fuse, but an electrical one (hence the "e"). The switch will check them upon boot. With each new update something is done with the efuses to make sure you're on the firmware you should be on. I don't know all the technical details, but this is the main idea of it and why the switch cant be downgraded.
 
  • Like
Reactions: McWhiters9511
Once efuses are "blown" they can't be repaired by any means. It's not a physical fuse, but an electrical one (hence the "e"). The switch will check them upon boot. With each new update something is done with the efuses to make sure you're on the firmware you should be on. I don't know all the technical details, but this is the main idea of it and why the switch cant be downgraded.
you... havent read the OP, obviously
 
oh i see, i though you were talking to me
next time, quote the one you are talking to avoid that please ;)
Ok

I can't really answer your question because I'm not a software or electrical engineer. All I know (may not be right, but i think it is) is that the number of efuses blown has to be softcoded into each update so it knows how many are supposed to be blown. If we were to be able to restore our old NAND or downgrade in any way, we might be able to edit the value inside of the dump that represents the number that are supposed to be blown in that dump and then restore it.

For example, if on update 3.0.0, 5 efuses are blown, and our console is on on update 4.0.0, which may check if 7 efuses are blown, we could modify our 3.0.0 nand dump to check for 7 blown fuses instead of 5.

This is just my theory, it may be correct and it may not be.
 
Last edited by DarkFlare69,
Ok

I can't really answer your question because I'm not a software or electrical engineer. All I know (may not be right, but i think it is) is that the number of efuses blown has to be softcoded into each update so it knows how many are supposed to be blown. If we were to be able to restore our old NAND or downgrade in any way, we might be able to edit the value inside of the dump that represents the number that are supposed to be blown in that dump and then restore it.

For example, if on update 3.0.0, 5 efuses are blown, and our console is on on update 4.0.0, which may check if 7 efuses are blown, we could modify our 3.0.0 nand dump to check for 7 blown fuses instead of 5.

This is just my theory, it may be correct and it may not be.
I bet the eFuse = version encoding is in Bootrom. Nintendo would be smarter than to make the encoding writable.
 
That's true. So we'd need access to the bootrom to be able to trick it
That'd be useless. The name says it all–bootrom–it's READ-ONLY. So, we couldn't change it. Also, I could only think the eFuses are physical, since the only way would be to make them Read-Only, but then the console couldn't set them...
 
That'd be useless. The name says it all–bootrom–it's READ-ONLY. So, we couldn't change it. Also, I could only think the eFuses are physical, since the only way would be to make them Read-Only, but then the console couldn't set them...
Sighax for the 3ds is a bootrom exploit.
 
Sighax for the 3ds is a bootrom exploit.
SIGH...
YOU CAN'T EDIT BOOTROM. PERIOD.
In fact, after Bootrom Lockout, you can't even Read Bootrom.
Sighax takes advantage of problems in the Bootrom code, specifically in the Signature parser, hence the name Sighax.
Read this for information about how Sighax works.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum