How do Mariko modchips work?

  • Thread starter Thread starter Nakamichi
  • Start date Start date
  • Views Views 2,488
  • Replies Replies 2
  • Likes Likes 2

Nakamichi

Well-Known Member
Member
Joined
Dec 10, 2021
Messages
1,114
Reaction score
1,140
Trophies
2
Age
38
XP
4,218
Country
Germany
I have been wondering what is it that those modchips actually do?
I heard people talk about it "glitching" the system?
Is that true and if so, how does that lead to us being able to run homebrew?
 
In non layman terms: The modchips perform an undervolting which is timed to occur when the memory compare used to compare the hash of the BCT (Boot Configuration Table) RSA Public key is checked, this allows an attacker to insert their own BCT RSA Public key, and thus sign the BCT with their own keypair (which allows to use an artibtrary bootloader).

The timing is calculated using BCT reads from the eMMC controller, that is one of the reason the eMMC controller needs to be connected to the modchip (that and on the fly BCT/Bootloader injection)
 

Site & Scene News

Popular threads in this forum