Hacking Could we substitute BOOT0 with hekate?

kevin_1351

Well-Known Member
OP
Newcomer
Joined
Apr 20, 2014
Messages
88
Trophies
0
Age
29
Location
Lugano, Switzerland
XP
497
Country
Switzerland
It's my understanding that they way autoRCM works, is by corrupting BOOT0. So why can't we substitute BOOT0 with something else?

This may be a very ignorant question to ask. Sorry.
 

DinohScene

Gay twink catboy
Global Moderator
Joined
Oct 11, 2011
Messages
22,565
Trophies
4
Location
Восторг
XP
22,944
Country
Antarctica
From what I understand (and if it's anything like the 3DS) corrupting boot0 will make the console boot into a "failsafe" mode (RCM in the Switch's case and the other boot sector in the 3DS) as the processor expects that.
Replacing it isn't as easy as you'd think.
It could be signed or the CPU will simply refuse to load the code you're trying to write.

I'm not up to date on Switch hacking but if it was that easy, you'd already see it applied.
 

kevin_1351

Well-Known Member
OP
Newcomer
Joined
Apr 20, 2014
Messages
88
Trophies
0
Age
29
Location
Lugano, Switzerland
XP
497
Country
Switzerland
From what I understand (and if it's anything like the 3DS) corrupting boot0 will make the console boot into a "failsafe" mode (RCM in the Switch's case and the other boot sector in the 3DS) as the processor expects that.
Replacing it isn't as easy as you'd think.
It could be signed or the CPU will simply refuse to load the code you're trying to write.

I'm not up to date on Switch hacking but if it was that easy, you'd already see it applied.

Indeed, I didn't think that it was going to be easy. But we have all relevant keys If I'm not mistaking. Hekate would have to be modified for this purpose of course. But I don't see why it shouldn't work.

Well, I just wanted to know. Thanks
 
  • Like
Reactions: The9thBit

DinohScene

Gay twink catboy
Global Moderator
Joined
Oct 11, 2011
Messages
22,565
Trophies
4
Location
Восторг
XP
22,944
Country
Antarctica
Indeed, I didn't think that it was going to be easy. But we have all relevant keys If I'm not mistaking. Hekate would have to be modified for this purpose of course. But I don't see why it shouldn't work.

Well, I just wanted to know. Thanks

Last time I checked, which was yesterday I believe, only 40 out of 80 keys where known.
I'm pretty sure that in the not so distant future, we might see something similar to BootMii or Godmode9 at boot but for now...

Personally, I would welcome it.
A almost brickproof console/handheld is better then no safety net at all.
Tho, nothing beats hardware flashers.
 
  • Like
Reactions: The9thBit

kevin_1351

Well-Known Member
OP
Newcomer
Joined
Apr 20, 2014
Messages
88
Trophies
0
Age
29
Location
Lugano, Switzerland
XP
497
Country
Switzerland
Last time I checked, which was yesterday I believe, only 40 out of 80 keys where known.
I'm pretty sure that in the not so distant future, we might see something similar to BootMii or Godmode9 at boot but for now...

Personally, I would welcome it.
A almost brickproof console/handheld is better then no safety net at all.
Tho, nothing beats hardware flashers.

There was a leak just a few days ago that provided us with many more keys; and besides, it's not about the numbers.
 

DinohScene

Gay twink catboy
Global Moderator
Joined
Oct 11, 2011
Messages
22,565
Trophies
4
Location
Восторг
XP
22,944
Country
Antarctica
There was a leak just a few days ago that provided us with many more keys; and besides, it's not about the numbers.

I don't think Nintendo would be as stupid as Sony to hide masterkeys in their firmware.
And with masterkeys I mean that PSP hackers where able to sign homebrew to be ran on OFW haha.
 

ShadowSynthesis

Member
Newcomer
Joined
Jun 17, 2018
Messages
19
Trophies
0
Age
22
XP
279
Country
Spain
I don't think Nintendo would be as stupid as Sony to hide masterkeys in their firmware.
And with masterkeys I mean that PSP hackers where able to sign homebrew to be ran on OFW haha.
But... I have all the masterkeys in a txt, even dev ones...
We decrypt xci's with them...
 

DinohScene

Gay twink catboy
Global Moderator
Joined
Oct 11, 2011
Messages
22,565
Trophies
4
Location
Восторг
XP
22,944
Country
Antarctica
But they have to be somewhere in the switch, thus we can get them.

Hasn't happened with the 3DS, hasn't happened with the Wii U and I doubt it'll happen with the Switch.
I honestly don't think Nintendo is that stupid.

Sony leaving PSP signing keys inside the PS3 firmware was shear stupidity.
 
  • Like
Reactions: focusonme

Sgt. Lulz

Beef up
Member
Joined
Oct 16, 2010
Messages
404
Trophies
0
XP
1,207
Country
United Kingdom
You would need either a bootROM exploit that takes advantage of the launching mechanism for BOOT0, or the ability to forge a valid signature for the substituting package, the latter of which is virtually impossible.

But... I have all the masterkeys in a txt, even dev ones...
We decrypt xci's with them...
You need Nintendo's own private signing keys, which only they have access to, in order to sign a file for the bootROM to accept it as valid.
What the Switch has in its storage are the public signing keys and private decryption keys, which are used for verifying that a file was signed by a specific sender's private signing key (Nintendo, in this case), and decrypting files encrypted with the public decryption key, ensuring that only the holder (or holders, I guess) of the private decryption key are able to decrypt them.
 

TheCyberQuake

Certified Geek
Member
Joined
Dec 2, 2014
Messages
5,012
Trophies
1
Age
28
Location
Las Vegas, Nevada
XP
4,433
Country
United States
Hekate doesn't corrupt anything, autoRCM does. And autorcm doesn't launch anything or "install" anything, it just corrupts a part of it which triggers a failsafe boot into RCM. It doesn't boot any payload itself, it's just the same as standard RCM and will require a USB host still to work.
So no, you can't just install hekate to boot0, that's not how it works
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    SylverReZ @ SylverReZ: https://www.youtube.com/watch?v=dbSORc_3_Yw