Homebrew Is the OTP SHA256 hash console specific?

  • Thread starter Thread starter mashers
  • Start date Start date
  • Views Views 4,183
  • Replies Replies 29
If nobody wants to do the math (and trusts somebody else's), this link calculates the probability of a hash collision. For the OTP hash, we have 256 bits, and ... brb checking how many 3DSs have sold ... 58.85 million, so let's just bump that to 59,000,000 for convenience ...

The site reports: "There is a 1.503125×10^-62 chance of a hash collision." Expressed longform, that's 0.00000000000000000000000000000000000000000000000000000000000001503125/1.

Keep in mind, this assumes that you personally have access to all 59 million of those hashes and the capacity to test them all against a target 3DS; in reality a user would probably have somewhere between about 1 and 5 depending on how many models they own. In practice, you'd be better off trying to bruteforce the OTP hash instead--essentially that's all you're doing by collecting up the hashes of other 3DS's OTPs anyway, just with a really shitty methodology.

Basically yeah, don't worry about this.
 
I would say it's possible to get two consoles with the same hash, but it's fairly unlikely that I would just stumble upon/steal a 3ds, and then have another 3ds on hand with the same hash. Along with that, you have to take into account the likelyhood of whoever steals it even knowing what A9LH is, let alone OTP and it's hash.
 
  • Like
Reactions: GilgameshArcher
it would probably be much quicker to test all possible password combinations, one thing i did notice @mashers (unless its changed since i last tested) was that if my password was UP, DOWN, the system would make it clear it was expecting 2 buttons, keeping the length a mystery would help make things harder for potential thieves
 
He mathimatically proved it's possible but almost impossible due to the low number. If you know the opposite you know the question.

Even more impossible, given the (comparatively) low number of systems in existence. It's almost a certainty that no two consoles will in fact have the same OTP hash.
 
Even more impossible, given the (comparatively) low number of systems in existence. It's almost a certainty that no two consoles will in fact have the same OTP hash.
So for those who don't understand:
It's not guaranteed to be perfectly unique, but the statistical odds of having another system with the same hash is so unlikely that it works perfectly fine for the purpose @mashers wants to use it for.
 
It is 256 bit :)

The SHA1 is 256 bits, what it is hashed on doesn't need to be 256 bits. I.e. if you calculate the SHA1 on an 8 bit value, then you will only ever create 256 different SHA1. I hope that for every number of bits less than 256 then you would get a different SHA1, although I don't know if that has been proven. Once you calculate a hash on more than 256 bits, then you risk the chance of a collision. If it's calculated on 114 bits (which is 912 bits) then if Nintendo made enough 3DS to run out of 114 bits then for every SHA1 there would be another 2 to 3 3DS with the same SHA1.

Nintendo haven't made that amount, but what we don't know is whether the values they put into the OTP create a good distribution of SHA1 values. They may have randomly found a collision.

I need to know in practical terms not numerical, hence not the stats.

You want someone to guess? How many times do you want someones guess to be right? i.e. is it ok to be right 9 times out of 10, 99 times out of 100, 999 times out of a 1000 etc.

Even more impossible, given the (comparatively) low number of systems in existence. It's almost a certainty that no two consoles will in fact have the same OTP hash.

People don't understand probability, birthday paradox is real. I suspect Nintendo tried to make them non-colliding, but I don't know whether they did and how successful they would be.
 
Last edited by smf,
  • Like
Reactions: Ryccardo
People don't understand probability, birthday paradox is real. I suspect Nintendo tried to make them non-colliding, but I don't know whether they did and how successful they would be.
actual probability is like 1.5 x 10^-60, nothing to worry about
 

Site & Scene News

Popular threads in this forum