Hacking What stops us from 100% custom Firmware?

  • Thread starter Thread starter XDM
  • Start date Start date
  • Views Views 18,366
  • Replies Replies 142
  • Likes Likes 3

XDM

Overseer of bad luck
Member
Joined
Dec 30, 2010
Messages
1,662
Reaction score
550
Trophies
1
Location
Dystopian Earth
XP
2,825
Country
United States
I am wondering, now we have came so far in the 3ds hacking community with gateway, homebrew, apps and emulators. and now we even have some semi custom firmwares via exploits. we even have access to the SYSnand and the ability to install there now.
but i was wondering what stops us from becoming the full hacked 3ds we want to be? a custom firmware installed to the SYSnand with no security/signature checks. Just boot up the 3ds and your done, like a psp.
now i dont know much about 3ds coding/devs but i would assume its because of the inability to forge these files?

ticket.db
certs.db
title.db
import.db

or perhaps because even if we do, a simple update could patch the whole thing so that would keep up limited to one version?
im just swinging in the dark here.
some Pro information would be appreciated.
 
I've been wondering this too. Someone correct me if I'm wrong but I think it's something similar to what halted the PS3 scene for so long. Encryption on the system was so strong it wasn't cracked until someone leaked the keys.
 
  • Like
Reactions: Margen67
Some noob information, it's all about those encryption keys. If we had the keys that nintendo uses to encrypt and decrypt the sysnand I believe we could literally do a 100% edit on the 3DS. I think my statement is at least half right. Gotta wait for that pro answer.
 
  • Like
Reactions: Margen67
Well there are a few possible reasons. There are no hackers that want piracy on the 3ds or hackers dont want to release anything. Maybe a temp CFW is better because touching sysNAND could be dangerous where having a emulated NAND your protected. Maybe there isnt really much of a bonus of having a full cfw.

Those are my opinions
 
I've been wondering this too. Someone correct me if I'm wrong but I think it's something similar to what halted the PS3 scene for so long. Encryption on the system was so strong it wasn't cracked until someone leaked the keys.

Even the PS3 isn't fully open yet afaik, people still need either systems on 3.55 or soldering skills and the right mods, there is no softmod available for it that runs from the latest firmware. I'm hoping the 3DS scene comes close to the psp scene of old.
 
  • Like
Reactions: cvskid and Margen67
AFAIK, no access to exploiting the boot loader means that we need the FW to be properly signed. We can't properly sign the FW because we don't have the keys. So instead we use an exploit to run code, which then reboots with patches, or alternatively running the system off SD instead, where we can modify it as we please.

But no access to the boot loader or keys means we can't touch the startup system.
 
Some noob information, it's all about those encryption keys. If we had the keys that nintendo uses to encrypt and decrypt the sysnand I believe we could literally do a 100% edit on the 3DS. I think my statement is at least half right. Gotta wait for that pro answer.
But don't we already have the 7x keys? I think?
 
  • Like
Reactions: Margen67
We can't, because the 3DS boot ROM verifies the firmware so if it isn't signed it won't boot. Only Nintendo has these keys, they're not even on the 3DS. It's kind of like how newer wiis don't work with bootmii, because they don't have a usable exploit in boot1. Such an exploit could be found in the 3DS boot ROM too, but it's a whole lot more secure than the Wii was and we can't even read the boot rom.
 
  • Like
Reactions: ll0rT
We can't, because the 3DS boot ROM verifies the firmware so if it isn't signed it won't boot. Only Nintendo has these keys, they're not even on the 3DS. It's kind of like how newer wiis don't work with bootmii, because they don't have a usable exploit in boot1. Such an exploit could be found in the 3DS boot ROM too, but it's a whole lot more secure than the Wii was and we can't even read the boot rom.

It would be wonderful if we could get to the level of the Wii. (Or the old ones at least)
 
  • Like
Reactions: Margen67
But don't we already have the 7x keys? I think?


AFAIK we have decryption keys for games. Still no way to properly sign the stuff, which is why we can't create legit CIAs (we can only rip them). This doesn't really effect the FW at all, since it's different keys and such needed entirely.

The issue is getting properly signed (and encrypted) code to run as FW. We can't do this at the moment because we can't sign our custom code, and we can't modify the boot loader to accept it regardless.
 
  • Like
Reactions: Margen67
But don't we already have the 7x keys? I think?

I heard something as well regarding that, not sure why we didn't at least have a cfw on 7.x before pasta, maybe palatines work wasn't open source and if it was maybe no one was willing to improve upon it.
 
As brute forcing the encryption isn't exactly viable, what's the next best option? Is it trying to find some way to look at the boot ROM? Or will KARL open up new possiblities when (if) it's released?
 
  • Like
Reactions: Margen67
I heard something as well regarding that, not sure why we didn't at least have a cfw on 7.x before pasta, maybe palatines work wasn't open source and if it was maybe no one was willing to improve upon it.


Well 'we' didn't, but there's certainly people who were using the keys to have a CFW on newer than 7.X. Gateway in particular I think was using them for their card. And even "CFWs" aren't modifying the booted FW (which is a different issue entirely).
 
  • Like
Reactions: Margen67
The best option might have been the decapping fund lol. If someone could code software that allows the pc's to combine processing power and bruteforce it it might be doable, sorta like seti@home for the 3DS :P Probably not possible though but I can dream.
 
Like Kafke said, this isn't a keys issue, although having all the keys would certainly be nice. This is an issue of not being able to sign content, and signing cannot be reversed or done even with a complete bootrom dump as far as I know. For now the only way around this issue of signing is to exploit ARM9 and modify the firmware loaded into RAM.
 
The best option might have been the decapping fund lol. If someone could code software that allows the pc's to combine processing power and bruteforce it it might be doable, sorta like seti@home for the 3DS :P Probably not possible though but I can dream.

It's unfortunate there were so many a-holes trying to prevent this from happening in the decapping thread that was going on last year. It's like, if it doesn't affect you, just f**k off, why ruin other people's enjoyment?
 
  • Like
Reactions: Margen67
correct me if I'm wrong, best bet at this point would be investigating actual hardware modifications to circumvent checks at boot. thats how it sounds to me atleast?
 
correct me if I'm wrong, best bet at this point would be investigating actual hardware modifications to circumvent checks at boot. thats how it sounds to me atleast?

Like the modchips of old? I don't think I've messed with those since the PS2. That would actually be kinda fun, hardmodding something again.
 
correct me if I'm wrong, best bet at this point would be investigating actual hardware modifications to circumvent checks at boot. thats how it sounds to me atleast?


That's called a hard mod, and has been done for every console ever, except for the newest ones. Most people dislike the idea of having to physically modify their hardware. And quite often there's some sort of software patch that causes problems with the mod.

The current 3DS hard mod simply allows backup/restore of the sysNand without needing a software exploit. So you can update to sysnand 9.7 and restore back to 9.2 whenever you'd like. No getting around the boot loader yet. But I'm guessing that's because we already have software exploits and people don't care to mess around with hardware stuff.
 
  • Like
Reactions: Margen67

Site & Scene News

Popular threads in this forum