Hardware [FALSE] Foxconn accidentally leaks Wii-U private keys...

Status
Not open for further replies.

Frank Cadena

Well-Known Member
Member
Joined
Sep 13, 2009
Messages
317
Trophies
0
XP
123
Country
What I'm interested in is whether Nintendo is going to sue Foxconn for the leaking of the design related docs. If this were to happen to Apple design schematics, which values it's secrecy highly, Foxconn would be sued like you wouldn't believe.
 

snikerz

Well-Known Member
Member
Joined
Nov 30, 2008
Messages
502
Trophies
1
Website
Visit site
XP
462
Country
Lesotho
2138725-makes-horrible-troll-thread-people-actually-buy-it.jpg
 
  • Like
Reactions: 3 people

Dimensional

Well-Known Member
Member
Joined
Dec 7, 2008
Messages
1,008
Trophies
1
Age
34
Location
Texas
XP
2,791
Country
United States
Clearly a lot of people here don't understand any cryptography.

Obviously the article is fake, but Foxconn most likely don't have the private keys anyway since they have no need for them. The file packages they'd be flashing would already be signed. Private keys never leave the business that created them, otherwise they can't be considered private. Finally, consoles only contain public keys and nothing more. Public keys are of course useless for hackers because they're only used to verify that signed packages are legitimate.
The consoles would have the public keys coded into the systems, not the private, but the private key is required to sign the programs that will be installed onto the system. Assymetric encryption and signatures: When you sign a program, what happens is the system creates a checksum of the program or a file, something that is used to verify the file isn't corrupted. Then the private key is use to encrypt the checksum, so that when you verify the signature, the public key decrypts the checksum and compares that with the file again. Signatures ensure 2 things. That the file isn't corrupted and thereby won't screw up the system, and verifies that it came from official sources and hasn't been altered in any way that could cause problems, like for PCs, installing a virus unknowingly.

Foxxconn could have the private keys, since private and public keys go in pairs and you sometimes have to give them both to ensure that development of the units goes smoothly, but only the public keys would be written into the system. Private keys, as said, would remain private, but mistakes like this can release them to the public and basically destroy the security of this system. Best example is the PS3. It's root private keys were discovered mathematically. Foxxconn could have had the private keys documented and accidentally leaked it.

So if the private keys were found, all one would need to do now is find the common key, aka the public key, and they would have full access to the system. And changing the private key would invalidate the public keys and so would invalidate all signatures for everything made for that console. Only good thing about this for Nintendo is that it was discovered early before the console was scheduled to be released. If it had happened after it was release and already had a large library of games and content, they would have to resell every game, updated for the new common key, because the games already in the hands of consumers would suddenly not work. It would be almost as bad as Nintendo releasing a system update that bricks systems that weren't modded or anything.

They could have the private keys, and that was one of the few ways people could get ahold of it. Don't count this as a lie just yet. It's still possible.
 

PolloDiablo

Madre de Dios! Es El POLLO DIABLO!!!
Member
Joined
Feb 9, 2010
Messages
3,858
Trophies
2
XP
2,952
Country
United States
I'm laughing reading the neogaf thread. People are calling Deadly the "LMFAO-guy from GBAtemp", and saying that we're all "particular people" :lol:
 

smf

Well-Known Member
Member
Joined
Feb 23, 2009
Messages
6,647
Trophies
2
XP
5,885
Country
United Kingdom
Nope, OTP can ONLY be flashed one way. Every single byte by default is 0 in OTP. When it is being written, some bytes are changed to 1. It is impossible to change a byte back to 0 once it has been changed to 1. Bytes that are still 0 can be changed to 1, this can theoretically even be done by the system (if someone wanted to really mess up a Wii, they could change a few 0s in OTP to 1s).

You mention flashing NANDs - that has nothing to do with this. If keys are being stored in OTP, as they were on Wii, they cannot be reflashed (well, they can be increased in value by changing some 0s to 1s, but not properly rewritten to any new randomly generated key).

In the Wii the OTP stores a hash of boot1, the keys however are stored elsewhere.

The Wii-U may be entirely different and we don't know what keys have actually been leaked.
 

KazoWAR

Well-Known Member
Member
Joined
Aug 12, 2008
Messages
1,952
Trophies
1
Age
35
Location
Winter Haven
XP
2,130
Country
United States
I wonder if this was really an accident? :creep:

Anyways, nothing like a mandatory day 1 update can't fix. All they have to do is white list like 10 games or so.
 

DeadlyFoez

XFlak Fanboy
OP
Banned
Joined
Apr 12, 2009
Messages
5,920
Trophies
0
Website
DeadlyFoez.zzl.org
XP
2,875
Country
United States
Wait so no one else but DeadlyFoez has seen the article?

For all we know, he could have made it up. :/
Shush it. He wouldn't do that to us!

Exception: the never-ending update, which he did do to us.
Today is not April Fools day. Plus, I don't know how to write any bit of a good article, especially one that isn't all about how fucking great I am. When it comes down to PR type stuff, I leave it all up to XFlak to write up everything, I just give him ideas on what basically needs to be said. I haven't even gotten the chance to talk with XFlak about this yet.
 

snikerz

Well-Known Member
Member
Joined
Nov 30, 2008
Messages
502
Trophies
1
Website
Visit site
XP
462
Country
Lesotho
Dear snikerz,

I can hereby confirm that no such article has been published on Engadget. As an organization that supports the freedom of the press, we're also offended by the reproach of removing that article.

Yours sincerely,

Darren Murph
Engadget Managing Editor, Weblogs, Inc.
[email protected]
 

DeadlyFoez

XFlak Fanboy
OP
Banned
Joined
Apr 12, 2009
Messages
5,920
Trophies
0
Website
DeadlyFoez.zzl.org
XP
2,875
Country
United States
Dear snikerz,

I can hereby confirm that no such article has been published on Engadget. As an organization that supports the freedom of the press, we're also offended by the reproach of removing that article.

Yours sincerely,

Darren Murph
Engadget Managing Editor, Weblogs, Inc.
[email protected]
Sounds to me almost like acknowledgement of said article with that wording....
 

snikerz

Well-Known Member
Member
Joined
Nov 30, 2008
Messages
502
Trophies
1
Website
Visit site
XP
462
Country
Lesotho
Electronics manufacturer Foxconn has mistakenly placed the private keys and other design related documents for the Nintendo Wii-U on the public portion of their FTP server that they use for hosting drivers and software. The mistake was noticed by an engineer early Wednesday, but not before the documents had been downloaded more than a dozen times.
FYI, there is no such FTP server. All their drivers are only available via HTTP download.
 

TimS

New Member
Newbie
Joined
Jul 5, 2012
Messages
1
Trophies
0
XP
7
Country
United States
Hey guys, this is Tim Stevens, editor-in-chief at Engadget.

First off, we did not run this post. We've checked all our system logs and nothing like this ran on our site. Additionally, that post is not written using our grammatical and style standards. It just isn't an Engadget post. I don't know who made it up or why, but someone did.

Secondly, the supposed email from Darren Murph posted above is also a fake. I don't know why someone would fake a denial email but it is, indeed fake.

Finally, as proof that I am indeed the real Tim Stevens, I'll be tweeting about this shortly. I'm @Tim_Stevens and you can check it out yourself.

Thanks all for reading, we love you all -- even those making up junk.

-tim stevens
editor-in-chief, Engadget
 
  • Like
Reactions: 6 people

DeMoN

GBAtemp Guru
Member
Joined
May 12, 2004
Messages
7,710
Trophies
1
Website
Visit site
XP
2,634
Country
United States
Thanks for clearing that up, you even linked to here so I believe you.

Edit: Here is the official tweet: https://twitter.com/Tim_Stevens/status/220948945013182464
 

ProtoKun7

GBAtemp Time Lord Regenerations: 4
Former Staff
Joined
Jan 3, 2009
Messages
7,525
Trophies
2
Location
Gallifrey
XP
1,361
Country
United Kingdom
Hey guys, this is Tim Stevens, editor-in-chief at Engadget.

First off, we did not run this post. We've checked all our system logs and nothing like this ran on our site. Additionally, that post is not written using our grammatical and style standards. It just isn't an Engadget post. I don't know who made it up or why, but someone did.

Secondly, the supposed email from Darren Murph posted above is also a fake. I don't know why someone would fake a denial email but it is, indeed fake.

Finally, as proof that I am indeed the real Tim Stevens, I'll be tweeting about this shortly. I'm @Tim_Stevens and you can check it out yourself.

Thanks all for reading, we love you all -- even those making up junk.

-tim stevens
editor-in-chief, Engadget
Thank you for the clarification.

And with that, I declare this thread closed.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • BigOnYa @ BigOnYa:
    I kept thinking jaws was gonna come up and attack
  • K3Nv2 @ K3Nv2:
    Jaws is on a diet
  • K3Nv2 @ K3Nv2:
    Damn power went out
  • BigOnYa @ BigOnYa:
    Ok xdqwerty, your little bro prob tripped On the cord and unplugged you
  • K3Nv2 @ K3Nv2:
    Ya I'm afraid of the dark hug me
  • BigOnYa @ BigOnYa:
    Grab and hold close your AncientBoi doll.
  • K3Nv2 @ K3Nv2:
    Damn didn't charge my external battery either
  • BigOnYa @ BigOnYa:
    Take the batteries out of your SuperStabber3000... Or is it gas powered?
  • K3Nv2 @ K3Nv2:
    I stole batteries from your black mamba
    +1
  • K3Nv2 @ K3Nv2:
    My frozen food better hold up for an hour I know that
  • BigOnYa @ BigOnYa:
    Or else gonna be a big lunch and dinner tomorrow.
  • BigOnYa @ BigOnYa:
    Did you pay your power bill? Or give all yo money to my wife, again.
  • K3Nv2 @ K3Nv2:
    Oh good the estimated time is the same exact time they just said
    +1
  • BigOnYa @ BigOnYa:
    Load up your pc and monitor, and head to a McDonalds dining room, they have free WiFi
  • K3Nv2 @ K3Nv2:
    Sir please watch your porn in the bathroom
    +2
  • BigOnYa @ BigOnYa:
    No sir we can not sell you anymore apple pies, after what you did with the last one.
  • K3Nv2 @ K3Nv2:
    We ran out
  • HiradeGirl @ HiradeGirl:
    for your life
    +1
  • K3Nv2 @ K3Nv2:
    My life has no value my fat ass is staying right here
  • K3Nv2 @ K3Nv2:
    Nearly 4 hours without power :(
  • Veho @ Veho:
    SO POWERLESS
  • K3Nv2 @ K3Nv2:
    Tell Kanye I need power
    K3Nv2 @ K3Nv2: Tell Kanye I need power