Write up by hexkyz and SciresM on exploiting the Switch microprocessor

Flame

Me > You
OP
Global Moderator
Joined
Jul 15, 2008
Messages
7,419
Trophies
3
XP
19,762
Country
United Kingdom
switch-atmosphere.png



In the link below you can see a write by hexkyz and SciresM on the Nvidia Falcon microprocessor deteails on how it was exploitable. it also gives all sort of insight of how the switch works and what not. off course to the aveage joe it will be all alien on how to use this information but to people with enough knownledge this information could be very helpful but will they help us is another matter.


:arrow: source
 
Last edited by Flame,

Razor1993

Well-Known Member
Member
Joined
Mar 20, 2010
Messages
150
Trophies
0
XP
643
Country
Germany
A team of hackers probably has irreparable access to the security chip of the Nintendo Switch. The root keys can also be extracted.

Switch.png


Several hackers and developers seem to have finally cracked the hardware security of the Nintendo Switch and thus also the security of the Nvidia SoC called Tegra X1, which serves as the basis of the console. Already in 2018, it was possible to bypass the protection of the boot ROM used via a quite trivial bug. However, even the clever patch for this problem from Nvidia and Nintendo seems to be completely overcome now.

The problem with the first hack three years ago was that the boot ROM chip cannot be patched easily. The corresponding vulnerable commands are hardcoded, so a patch against the attacks seemed rather unlikely in devices that were already sold at the time. And already before, it was possible to execute own code on the Switch and even read the console's keys.

However, as Switch hacker Plutooo now writes, a "clever guy" had pointed out a separate security chip to the manufacturers, which is present on the X1 and had not been used until then. With the update 6.2.0 for the Switch firmware, Nintendo actually used it and completely rebuilt the startup process with the help of this chip called TSEC.

"Nintendo has apparently done the impossible: A) got its secure boot back and B) introduced new key material." So the old hack was worthless with the new firmware. Unsurprisingly, the Switch hackers then turned their attention to the TSEC chip and continued to find numerous bugs, which now just probably cannot be changed for all devices sold with the chip so far. And probably not even for new devices without a major hardware revision.

Source: Hexkyz & SciresM via hexkyz.blogspot.com
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • crafthp434 @ crafthp434:
    at all
  • crafthp434 @ crafthp434:
    like i searched all folders
  • NinStar @ NinStar:
    are you using haxchi, tiramisu or aroma?
  • crafthp434 @ crafthp434:
    yeah
  • NinStar @ NinStar:
    no, I'm asking which one of them you are using
  • crafthp434 @ crafthp434:
    aroma
  • NinStar @ NinStar:
    in that case, there is no such thing as homebrew launcher for aroma
  • NinStar @ NinStar:
    you have to launch your homebrews directly from the wii u menu
  • NinStar @ NinStar:
    there is a plugin that display them on the wii u menu, pretty sure it is enabled by default
  • crafthp434 @ crafthp434:
    so like it doesnt exist
  • crafthp434 @ crafthp434:
    yeah
    ?
  • NinStar @ NinStar:
    it doesn't exist, at least not for aroma
  • crafthp434 @ crafthp434:
    ohhhhh
  • NinStar @ NinStar:
    on tiramisu you can access it by opening mii maker
  • crafthp434 @ crafthp434:
    okay
  • NinStar @ NinStar:
    I don't have a wii u anymore to test it myself, but if homebrews are not visible on the wii u menu I think you can press L + R + minus to open the plugin menu, there should be an option called "homebrews on wii u menu" or something similar
  • crafthp434 @ crafthp434:
    nope
  • crafthp434 @ crafthp434:
    it is L+dpad down+ select
  • crafthp434 @ crafthp434:
    but homebrew is appearing in the home menu btw
  • NinStar @ NinStar:
    yes, now I remember it
  • NinStar @ NinStar:
    then it is working, I also don't like that they did this but it is the only option you have if you are using aroma
  • crafthp434 @ crafthp434:
    i just didint know the homebrew launcher didint exist in aroma
  • crafthp434 @ crafthp434:
    thanks btw
  • Xdqwerty @ Xdqwerty:
    Im downloading fallout 3 goty edition
    +1
    Xdqwerty @ Xdqwerty: Im downloading fallout 3 goty edition +1