Lockpick_RCM payload - Official Thread


Description

Lockpick_RCM is a bare metal Nintendo Switch payload that derives encryption keys for use in Switch file handling software like hactool, hactoolnet/LibHac, ChoiDujour, etc. without booting Horizon OS.

Source: https://github.com/shchmue/Lockpick_RCM
Payload: https://github.com/shchmue/Lockpick_RCM/releases

Due to changes imposed by firmware 7.0.0, Lockpick homebrew can no longer derive the latest keys. In the boot-time environment however, there are fewer limitations. That means the new keys are finally easy to dump!

Usage
  • Launch Lockpick_RCM.bin using your favorite payload injector or chainload from Hekate by placing it in /bootloader/payloads
  • Upon completion, keys will be saved to /switch/prod.keys on SD
  • If the console has Firmware 7.x, the /sept/ folder from Atmosphère or Kosmos release zip containing both sept-primary.bin and sept-secondary.enc must be present on SD or else only keyblob master key derivation is possible (ie. up to master_key_05 only)
Big thanks to CTCaer
For Hekate and all the advice while developing this!

Known Issues
  • Chainloading from SX will hang immediately due to quirks in their hwinit code, please launch payload directly
 

Attachments

  • AB1248EA-8BB9-448B-83F5-FF68C2579FB1.jpeg
    AB1248EA-8BB9-448B-83F5-FF68C2579FB1.jpeg
    11.2 KB · Views: 0
Last edited by shchmue,
D

Deleted User

Guest
@shchmue is it worth me using this to dump my prod.keys again as I used the latest nro to dump them last time?

Config OFW 7.0.1 CFW Atmosphere 0.8.4
 

8BitWonder

Small Homebrew Dev
Member
Joined
Jan 23, 2016
Messages
2,489
Trophies
1
Location
47 4F 54 20 45 45 4D
XP
5,365
Country
United States
@shchmue is it worth me using this to dump my prod.keys again as I used the latest nro to dump them last time?

Config OFW 7.0.1 CFW Atmosphere 0.8.4
The nro can only dump keys up to 06 (when on 6.2.0), this new payload can dump up to and including the newest 07 keys.
(It is worth it if you want the newest keys)
 

shchmue

Developer
OP
Developer
Joined
Dec 23, 2013
Messages
791
Trophies
1
XP
2,367
Country
United States
Lockpick homebrew can still dump titlekeys while this can't. I'm about to push a commit that checks and doesn't overwrite Lockpick_RCM's key file in case you want to dump titlekeys and you're on 7.
 
  • Like
Reactions: Deleted User

Goffrier

Well-Known Member
Member
Joined
Dec 19, 2018
Messages
181
Trophies
0
Age
44
XP
428
Country
United States
but it will work™

--------------------- MERGED ---------------------------

i dont care if they are stealing i just wait their release for 7.x support
 
  • Like
Reactions: Ita54_2

chrisrlink

Has a PhD in dueling
Member
Joined
Aug 27, 2009
Messages
5,574
Trophies
2
Location
duel acadamia
XP
5,797
Country
United States
if only we stole code from TX (XCI loader) cause i just bought a SATA3 to USB adapter for that

--------------------- MERGED ---------------------------

yea. it’ll be funny seeing SX with the Atmosphere sept logo

and you think ppl will care? (maybe team atmos not the end user) besides a feature i want is sxos exclusive i doubt any pro piracy dev would make an xci loader from scratch
 

Beegyoshi

New Member
Newbie
Joined
Mar 5, 2019
Messages
3
Trophies
0
Age
30
XP
75
Country
Singapore
Hi shchmue,

I just started trying to install cfw to my switch so I'm still trying to understand the jargons used. I was unable to get my tegra keys and title.keys through the lockpick.nro and I thought this current method will aid me. However, i was only able to get the prod.keys and not the title.keys. I have previously installed and played games on my switch before and I'm sure my SD card is not corrupted but I'm still having trouble getting the title keys. My firmware is 7.0.0 and my switch serial is XAJ100XXXX. Do you have any idea what's going on? Thank you for any possible solutions. :)
 

shchmue

Developer
OP
Developer
Joined
Dec 23, 2013
Messages
791
Trophies
1
XP
2,367
Country
United States
Hi shchmue,

I just started trying to install cfw to my switch so I'm still trying to understand the jargons used. I was unable to get my tegra keys and title.keys through the lockpick.nro and I thought this current method will aid me. However, i was only able to get the prod.keys and not the title.keys. I have previously installed and played games on my switch before and I'm sure my SD card is not corrupted but I'm still having trouble getting the title keys. My firmware is 7.0.0 and my switch serial is XAJ100XXXX. Do you have any idea what's going on? Thank you for any possible solutions. :)
you can run this then run Lockpick 1.2.2 to get both
 

Beegyoshi

New Member
Newbie
Joined
Mar 5, 2019
Messages
3
Trophies
0
Age
30
XP
75
Country
Singapore
Hi shchmue.

I have tried both methods and I got both title.keys and prod.keys. I followed your step and ran lockpick 1.2.2 on my switch. However, this error message appeared.

get Tegra keys failed. Warning: Saving limited keyset. Dump TSEC and Fuses with Hekate.

I was still able to obtain both keys at the end. Can this error message be ignored?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Psionic Roshambo @ Psionic Roshambo:
    That Dell data breach is worse than people probably realize....
  • Psionic Roshambo @ Psionic Roshambo:
    When I worked for Dell we had access to data about military contracts and addresses for high ranking people.
  • Psionic Roshambo @ Psionic Roshambo:
    I personally handled a call from the second highest person at Raytheon. That call bothered me a lot... The guy was nice and smart what bothered me was the way management basically just blew him off instead of going the extra mile to help him.
  • Psionic Roshambo @ Psionic Roshambo:
    In the end that call ended up costing Dell millions in lost contracts with Raytheon, and really the issue could have been solved for like 450 bucks lol
  • NinStar @ NinStar:
    sometimes I wonder why anyone would ever buy mega man x legacy collection 2
  • NinStar @ NinStar:
    I always thought that capcom shuffled the games in these collection, but apparently they are all in chronological order, which makes legacy collection 2 worthless
  • BakerMan @ BakerMan:
    guys, i want to start singing pirate metal songs and sea shanties if i play sea of thieves
  • The Real Jdbye @ The Real Jdbye:
    find a pirate metal playlist
    +2
  • The Real Jdbye @ The Real Jdbye:
    and sing along
  • BakerMan @ BakerMan:
    nevermind i just learned swearing is against the rules in sea of thieves

    i was about to start singing the song i last put in "what song are you currently listening to" yesterday
  • BakerMan @ BakerMan:
    but yeah ig so
  • The Real Jdbye @ The Real Jdbye:
    swearing not allowed in a pirate game? what has the world come to
  • BakerMan @ BakerMan:
    (here's the song for context)
  • BigOnYa @ BigOnYa:
    Just add -izle to the end of every curse word, you will be fine.
    +2
  • The Real Jdbye @ The Real Jdbye:
    i like alestorm
    +1
  • The Real Jdbye @ The Real Jdbye:
    @BigOnYa too many syllables
    +1
  • BakerMan @ BakerMan:
    same lmao
  • BigOnYa @ BigOnYa:
    hi, welcome to the Temp!
    +1
  • BakerMan @ BakerMan:
    Welcome to the Underground!
    +1
  • BakerMan @ BakerMan:
    the booty boogie from (once again) the donkey kong country cartoon could also be a good song to sing while playing sea of thieves
  • BigOnYa @ BigOnYa:
    Please insert 25 cents for an additional 30 minutes of talk time.
    +1
    Psionic Roshambo @ Psionic Roshambo: https://www.youtube.com/watch?v=tG7fk_DUz5g +1