Hacking jamais vu - a 1.0.0 TrustZone code execution exploit for the Nintendo Switch

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
It seems like Nintendo screwed up big time with the Switch, I remember 3DS exploits were hard to get a hold on but it seems everyone and their mom are tearing the swtich security apart :wtf:

You've got the wrong idea.

We're exploiting nVidia's screw ups. Nintendo has been the one fixing things and the reason we tell people not to update, their code/security has been nearly rock solid but they have a lot of bullshit to mitigate from nVidia who, as we have come to learn, are fairly incompetent at software security.
 
  • Like
Reactions: peteruk

Tony_93

Well-Known Member
Member
Joined
Jun 13, 2015
Messages
2,457
Trophies
1
Location
California
XP
2,436
Country
United States
You've got the wrong idea.

We're exploiting nVidia's screw ups. Nintendo has been the one fixing things and the reason we tell people not to update, their code/security has been nearly rock solid but they have a lot of bullshit to mitigate from nVidia who, as we have come to learn, are fairly incompetent at software security.

From Reddit:

For context, 1.0.0 was a "beta" firmware internally referred to as "Pilot", which Nintendo had to ship with early consoles in order to meet manufacturing deadlines. It contains many critical security issues fixed in later firmware revisions.

It doesn't seem like Nvidia's screw up but Nintendo's... I'm I wrong?
 

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
From Reddit:

It doesn't seem like Nvidia's screw up but Nintendo's... I'm I wrong?

The 1.0.0 software, yes, was a beta but the things we're leveraging are coming from system designs and backdoors from nVidia themselves. The early Nintendo firmware was not yet working to mitigate the mess because it hadn't been completely finalized by that point.

This compromise, for instance, was buried and fixed in 2.x, requiring a different method (currently private) to get into the TZ.
 
  • Like
Reactions: Tony_93

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
Seems like a lot of exploits have been nVidia's fuckup.

They are, and they are being 'covered', which is why things are being kept secret for the long-term. Otherwise, you're going to make entry into the scene later very difficult if not impossible due to downgrade protection and ever increasing mitigation.

For the time being, 4.x is a hard point but there are still *some* holes. This is why it is stressed to not update.
 
Last edited by V-Temp,
  • Like
Reactions: peteruk

Tempest228

Well-Known Member
Member
Joined
Jul 13, 2015
Messages
226
Trophies
0
XP
263
Country
United States
They are, and they are being 'covered', which is why things are being kept secret for the long-term. Otherwise, you're going to make entry into the scene later very difficult if not impossible due to downgrade protection and ever increasing mitigation.
Isn't it already going to be pretty difficult going forward? 4.x has potential, but it seems it will be a long while. TX raised the red flag to Nintendo there is a problem in the bootrom. Also imagine they are hunting for the TZH as well. From the sounds of it, the switch will be pretty rock solid soon.
 

Pluupy

_(:3」∠)_
Member
Joined
Sep 13, 2009
Messages
1,945
Trophies
1
XP
2,265
Country
United States
What does this mean? That these people have worked out a software hacking method for 3.0 switch consoles?

The team xecuter modchip is still useful because it is for recent firmware, right?
 
Last edited by Pluupy,

Kioku

猫。子猫です!
Member
Joined
Jun 24, 2007
Messages
12,003
Trophies
3
Location
In the Murderbox!
Website
www.twitch.tv
XP
16,126
Country
United States
What does this mean? That these people have worked our a software hacking method for 3.0 switch consoles?

The team xecuter modchip is still useful because it is for recent firmware, right?

Seemingly for now. Still have some hopes For TX.
 

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
Isn't it already going to be pretty difficult going forward? 4.x has potential, but it seems it will be a long while. TX raised the red flag to Nintendo there is a problem in the bootrom. Also imagine they are hunting for the TZH as well. From the sounds of it, the switch will be pretty rock solid soon.

We don't tell you to not update for shits and giggles. /shrug

You'll notice how this release came long, long after the bug had been thoroughly mitigated. That tells you just how thorough they (Nintendo) are with their work. This applies to every major fuse-burning patch but its not always addressing the same or all areas, which is why some bugs persist across fws and why no one is revealing anything to do with 2.x+.
 

Thelonewolf88

Well-Known Member
Member
Joined
Jun 11, 2016
Messages
304
Trophies
0
Age
35
XP
333
Country
United States
I'd love to be a fly on the wall at Nvidia's HQ meeting with Nintendo, as I bet someone(s) responsible has been bitch slapped because of this security mishap. I bet the chief at N thought "Fuck we should have went with AMD".
 
D

Deleted-355425

Guest
I'd love to be a fly on the wall at Nvidia's HQ meeting with Nintendo, as I bet someone(s) responsible has been bitch slapped because of this security mishap. I bet the chief at N thought "Fuck we should have went with AMD".

No one sells a product that's guaranteed against exploitation, terms and contracts would of been signed.
 
  • Like
Reactions: peteruk

Kioku

猫。子猫です!
Member
Joined
Jun 24, 2007
Messages
12,003
Trophies
3
Location
In the Murderbox!
Website
www.twitch.tv
XP
16,126
Country
United States
I'd love to be a fly on the wall at Nvidia's HQ meeting with Nintendo, as I bet someone(s) responsible has been bitch slapped because of this security mishap. I bet the chief at N thought "Fuck we should have went with AMD".
In what world do you think AMD is more secure?
 

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
I'd love to be a fly on the wall at Nvidia's HQ meeting with Nintendo, as I bet someone(s) responsible has been bitch slapped because of this security mishap. I bet the chief at N thought "Fuck we should have went with AMD".

That's really not how this works. If it causes problems for Nintendo for some reason, they will bring that to the table for the Switch 2 and the next Tegra iteration (or any refab of the TX1 if that happens). Maybe it will manifest in a friendlier deal, maybe nVidia will hire some actual software engineers. Who knows.

AMD (in fact, no one really except like... Apple) has nothing to offer in this area, and custom fabs are a thing of the past in this day and age, expensive, and wholly impractical. nVidia was the right choice for the device that Nintendo wanted to make and, as far as the device itself is concerned, they knocked it out of the park. And these sorts of bugs are not isolated to nVidia, we're just seeing concerted effort to break them now and not others.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    Xdqwerty @ Xdqwerty: Managed Budokai Tenkaichi 3 to work