Hacking Discussion Coldboot and you: Learning to love the tether

GBA rocks

Well-Known Member
Member
Joined
Jan 4, 2013
Messages
422
Trophies
0
XP
467
Country
Kubas_inko your “might” could prove pretty misleading if the chance is 0.000001%.

The useful message is: stay on 4.1 if you hope in a softwarehax with user interaction at every boot and don’t get your hopes up for a real persistent coldboot.
 

Kubas_inko

"Something funny goes here."
Member
Joined
Feb 3, 2017
Messages
6,319
Trophies
1
Age
23
Location
I gues on earth.
XP
5,032
Country
Czech Republic
Kubas_inko your “might” could prove pretty misleading if the chance is 0.000001%.

The useful message is: stay on 4.1 if you hope in a softwarehax with user interaction at every boot and don’t get your hopes up for a real persistent coldboot.
I gave you guys image of what sciresm said on discord. My "might" means "might" which means nobody knows. So no misinformation here again.

--------------------- MERGED ---------------------------

I did not say it is but the way you said it made it seem like RCM is equal to warmboot that users below 4.0.1 will get wich is not
That's not how I wanted it to sound. I just meant that RCM is warmboot and not coldboot as OP said.
 

kumikochan

Well-Known Member
Member
Joined
Feb 4, 2015
Messages
3,753
Trophies
0
Age
35
Location
Tongeren
XP
3,311
Country
Belgium
I gave you guys image of what sciresm said on discord. My "might" means "might" which means nobody knows. So no misinformation here again.
No he said a coldboot might come but the warmboot will happen on release for users below 4.0.1. You should read that tweet again because that is what it says
 

Kubas_inko

"Something funny goes here."
Member
Joined
Feb 3, 2017
Messages
6,319
Trophies
1
Age
23
Location
I gues on earth.
XP
5,032
Country
Czech Republic
No he said a coldboot might come but the warmboot will happen on release for users below 4.0.1. You should read that tweet again because that is what it says

And you should read my messages. I am TALKING ABOUT OP HERE, not SciresM.
What OP wrote is wrong.
upload_2018-5-24_12-56-47.png

and that's what I was answering the whole time. FG = RCM is not coldboot but warmboot.

And about the tweet: once again, might = might, so no misinformation here... again
 
Last edited by Kubas_inko,
  • Like
Reactions: kumikochan

YamiZee

Well-Known Member
Member
Joined
Aug 18, 2013
Messages
264
Trophies
0
Age
27
XP
1,290
Country
Finland
why cant the fusee exploit be used to bypass the need for an exploit to get coldboot like it was suggested that low firmwares could (possibly in the future). doesnt it allow us to run whatever we want?
 

Maximilious

Whistles a familiar tune
Member
Joined
Nov 21, 2014
Messages
2,571
Trophies
1
XP
1,845
Country
United States
why cant the fusee exploit be used to bypass the need for an exploit to get coldboot like it was suggested that low firmwares could (possibly in the future). doesnt it allow us to run whatever we want?

Because FG (RCM) requires a payload to be sent to it right now. I'm not sure on specifics but it may also be too high in the boot chain to do anything with the file system/eMMC chip since it is a CPU vulnerability. Down the road someone may be able to make a BootMii variant payload from the Wii days, but it's too early for that. It may also not be possible, I'm honestly not sure.
 

mnemonicpunk

Well-Known Member
OP
Newcomer
Joined
May 10, 2018
Messages
78
Trophies
0
Age
36
XP
298
Country
Germany
Since there still seems to be confusion about this: FG is considered a coldboot exploit, because it bypasses the actual bootrom and process of the Switch. It can not, however, alter it. Without injecting a payload from a tethered device it can not function.

Why? Because when you turn your Switch on, the first thing that runs is the bootrom, which calculates a hash of the firmware and compares it to the value it derives from the public key stored in the fuses of the Tegra. Both the bootrom and the pubic key can not be altered (they are burnt into the hardware and can not be written to) and if the firmware is not properly signed it will simply refuse to boot.

So why can Nintendo update the firmware? They have the private key, a solution to a very complicated mathematical calculation that allows them to sign the firmware as authentic. If you know the public key that corresponds to it, you can verify "Aha, it was indeed Nintendo, the owner of the private key who signed this firmware.". Trying to find out this key is considered more or less impossible, since finding it by brute force will take longer than the time the universe will still exist.
 
General chit-chat
Help Users
  • No one is chatting at the moment.
  • Skelletonike @ Skelletonike:
    1H left, such a slow week.
  • Sonic Angel Knight @ Sonic Angel Knight:
    Okay, I had spaghetti :P
  • SylverReZ @ SylverReZ:
    Hope they made lots of spaget
  • K3N1 @ K3N1:
    Chill dog
  • SylverReZ @ SylverReZ:
    Chilli dog
  • Skelletonike @ Skelletonike:
    Damn, I'm loving the new zelda.
  • xtremegamer @ xtremegamer:
    loving the new zelda, i started a game, it was so fucking good, so i
    am waiting on my friend to get home so we can start a new one together
  • Skelletonike @ Skelletonike:
    I just dislike that they don't let me choose the voices before the game starts. Happened with botw as well, had to change to japanese and restart.
  • K3N1 @ K3N1:
    But the important question is can you choose gender
  • Skelletonike @ Skelletonike:
    Same way you can choose Gerald's gender.
  • Skelletonike @ Skelletonike:
    *Geralt, damn autocorrect.
  • Psionic Roshambo @ Psionic Roshambo:
    But can he be trans? Lol
  • K3N1 @ K3N1:
    Zelda transforms into link
  • Psionic Roshambo @ Psionic Roshambo:
    Link I'm not the princess your looking for.... *Pulls a crying game*
  • K3N1 @ K3N1:
    *skirt up* it's exactly what I always wanted
  • Skelletonike @ Skelletonike:
    Just scanned all my zelda amiibos, took a while but didn't get anything that cool, did get the lon lon ranch hylian fabrics though.
  • Skelletonike @ Skelletonike:
    It was pretty funny when I scanned wolf link and got a shit load of meat.
  • K3N1 @ K3N1:
    @Skelletonike, btw I ran that custom for mgs4 on the deck I'm amazed it got that far in game
  • K3N1 @ K3N1:
    Plug in*
  • K3N1 @ K3N1:
    Your favorite activity
  • BentlyMods @ BentlyMods:
    My fav actvity is:

    mario-dancing.gif
    BentlyMods @ BentlyMods: My fav actvity is: