Hacking Why must we downgrade to 2.10 from 9.20?

Chiqx

Well-Known Member
OP
Newcomer
Joined
Jul 29, 2016
Messages
92
Trophies
0
Age
33
XP
119
Country
Gambia, The
Hey. I'm asking myself why we have to downgrade from 9.2.0 instead of another version and why exactly 2.1.0? I've done the downgrade myself but now I'm asking myself why I did those steps ^^

Gesendet von meinem SM-N910F mit Tapatalk
 

DBlaze

I don't know what i'm doing.
Member
Joined
Nov 15, 2006
Messages
526
Trophies
1
XP
2,839
Country
Netherlands
Well, if you did read the guide, then you would know why.
Specifically, this part (in the new guide):

"Since version 3.0, the OTP is locked out early in sysNAND boot. There is a New 3DS only exploit that works on 9.6, but it requires extra hardware. The solution we are using is to flash a 2.1.0CTRNAND partition and firmware to the device, allowing us to retrieve the OTP."

So in short and easy terms, you want the OTP of your console, but you can only get it (easily) using 2.1.0.
 
Last edited by DBlaze,

zoogie

playing around in the end of life
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
tl;dr
there's an oversight on < 3.0 that allows the dumping of the console unique data needed to install a9lh.
 

TheToaster

Kishore
Member
Joined
Aug 11, 2015
Messages
467
Trophies
0
Location
USA
XP
979
Country
United States
Hey. I'm asking myself why we have to downgrade from 9.2.0 instead of another version and why exactly 2.1.0? I've done the downgrade myself but now I'm asking myself why I did those steps ^^

Gesendet von meinem SM-N910F mit Tapatalk
For arm9loaderhax, you need the OTP. Nintendo has locked the OTP memory region, but forgot to do so in version 2.1.0
 
Last edited by TheToaster,

PabloMK7

Red Yoshi! ^ω^
Developer
Joined
Feb 21, 2014
Messages
2,615
Trophies
2
Age
24
Location
Yoshi's Island
XP
5,169
Country
Spain
Because Nintendo forgot to block the OTP region after boot. Firmware versions >3.0.0 block the otp region just after booting, so it becomes unaccesible. You need your otp which is unique to you in order to get neccesary keys to make the 3ds think that a9lh is legit.
 

zoogie

playing around in the end of life
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
And what exactly is otp?

Gesendet von meinem SM-N910F mit Tapatalk
One-time-programmable - It's console-unique data burned into the CPU by the factory to help improve the 3ds's security.
Nintendo mistakenly forgot to clear this info out of RAM during boot on < 3.0 firmwares and that's why we downgrade to get it.

Before you ask, no emunand will not work because the OTP is locked shortly after power-on from > 3.0 firms. Boot to 9.2 sysnand then going to 2.1 emunand thus wouldn't work.
 
Last edited by zoogie,

GilgameshArcher

Well-Known Member
Member
Joined
Jul 1, 2012
Messages
638
Trophies
1
XP
717
Country
Brazil
But I get my
One-time-programmable - It's console-unique data burned into the CPU by the factory to help improve the 3ds's security.
Nintendo mistakenly forgot to clear this info out of RAM during boot on < 3.0 firmwares and that's why we downgrade to get it.

Before you ask, no emunand will not work because the OTP is locked shortly after power-on from > 3.0 firms. Boot to 9.2 sysnand then going to 2.1 emunand thus wouldn't work.
But I got my beautiful OTP downgrading my RedNAND
 

sj33

Well-Known Member
Member
Joined
Oct 22, 2013
Messages
4,072
Trophies
2
XP
4,728
Country
Japan
So in short and easy terms, you want the OTP of your console, but you can only get it (easily) using 2.1.0.

because otp is locked versions after 2.1 we need otp for a9lh so its black magic

tl;dr
there's an oversight on < 3.0 that allows the dumping of the console unique data needed to install a9lh.

For arm9loaderhax, you need the OTP. Nintendo has locked the OTP memory region, but forgot to do so in version 2.1.0

Because Nintendo forgot to block the OTP region after boot.
This sounds fun, can I join in?

"You need 2.1 to get your OTP!"
 
Last edited by sj33,
  • Like
Reactions: astronautlevel

Chiqx

Well-Known Member
OP
Newcomer
Joined
Jul 29, 2016
Messages
92
Trophies
0
Age
33
XP
119
Country
Gambia, The
This is so fascinating. Everytime I open up my ds this comes to my mind. Like, those hackers must be geniuses o.o how do you even come up with these hacks and exploits :D
Whatever thanks to all hackers who have made this possible :)
Gesendet von meinem SM-N910F mit Tapatalk
 
  • Like
Reactions: GilgameshArcher

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    Psps still going for $100 on ebay lol
  • ZeroT21 @ ZeroT21:
    i'll consider it
  • ZeroT21 @ ZeroT21:
    if only i can backport the game meself
  • K3Nv2 @ K3Nv2:
    Pretty sure the new flip one can do psp if you don't mind the sp design
  • ZeroT21 @ ZeroT21:
    resistance still has jerky gameplay on emu
  • K3Nv2 @ K3Nv2:
    1gb of ram probably won't help
  • ZeroT21 @ ZeroT21:
    guess i'll stick to playing helldivers 2 for awhile
  • K3Nv2 @ K3Nv2:
    Do people still hate that game or did they fix it
  • ZeroT21 @ ZeroT21:
    fix? there were fixes?
  • ZeroT21 @ ZeroT21:
    i never heard or notice any fix
  • NO111ONE @ NO111ONE:
    @Xdqwerty crashd was the exploit for LG TVs to root practically any.
    I got word of it this january and rooted my TV. Was pretty impressed.
    Since then LG patched the command to root and then the developer mode app itself from making vulnerabilities.

    And then I found out that having a rooted TV lets you use PPPwn to jailbreak a PS4 on firmware 11. Finally uses for my rooted LG (I hate the playstation as such the use is gone)
    +1
  • K3Nv2 @ K3Nv2:
    @NO111ONE, Did you have a arch64 base?
  • NO111ONE @ NO111ONE:
    Honestly didn't care to even poke. The board is W18H
  • K3Nv2 @ K3Nv2:
    I got a 2023 Model turned off update in the homebrew channel maybe if I restore it and run the script again but it might auto update during the process
  • ZeroT21 @ ZeroT21:
    play it safe, keep it off
  • K3Nv2 @ K3Nv2:
    Script keeps getting stuck at Heap grooming now
  • ZeroT21 @ ZeroT21:
    nowadays i just keep my jailbroken ps4 for some exclusives i don't play on pc
  • K3Nv2 @ K3Nv2:
    The youtube adblocker looks nice in the homebrew channel but I pay for premium for like $4 a month under vpn lol
  • ZeroT21 @ ZeroT21:
    i dont even YT much, Net flix is just another bother
  • K3Nv2 @ K3Nv2:
    YT music apps pointless tbh
  • ZeroT21 @ ZeroT21:
    playing old music mostly while browsing/going through comics at archive.org
  • ZeroT21 @ ZeroT21:
    me doin' simple stuff
  • K3Nv2 @ K3Nv2:
    Don't always need a bunch of electronics to enjoy electronics
    +1
  • K3Nv2 @ K3Nv2:
    Issue is we want new and best then it piles up
  • ZeroT21 @ ZeroT21:
    i'm all gud if my browser don't lag
    ZeroT21 @ ZeroT21: i'm all gud if my browser don't lag