Lockpick_RCM payload - Official Thread


Description

Lockpick_RCM is a bare metal Nintendo Switch payload that derives encryption keys for use in Switch file handling software like hactool, hactoolnet/LibHac, ChoiDujour, etc. without booting Horizon OS.

Source: https://github.com/shchmue/Lockpick_RCM
Payload: https://github.com/shchmue/Lockpick_RCM/releases

Due to changes imposed by firmware 7.0.0, Lockpick homebrew can no longer derive the latest keys. In the boot-time environment however, there are fewer limitations. That means the new keys are finally easy to dump!

Usage
  • Launch Lockpick_RCM.bin using your favorite payload injector or chainload from Hekate by placing it in /bootloader/payloads
  • Upon completion, keys will be saved to /switch/prod.keys on SD
  • If the console has Firmware 7.x, the /sept/ folder from Atmosphère or Kosmos release zip containing both sept-primary.bin and sept-secondary.enc must be present on SD or else only keyblob master key derivation is possible (ie. up to master_key_05 only)
Big thanks to CTCaer
For Hekate and all the advice while developing this!

Known Issues
  • Chainloading from SX will hang immediately due to quirks in their hwinit code, please launch payload directly
 

Attachments

  • AB1248EA-8BB9-448B-83F5-FF68C2579FB1.jpeg
    AB1248EA-8BB9-448B-83F5-FF68C2579FB1.jpeg
    11.2 KB · Views: 0
Last edited by shchmue,

Kadji

Well-Known Member
Member
Joined
Nov 16, 2006
Messages
198
Trophies
1
Age
35
Location
Germany, NRW
XP
1,450
Country
Germany
Its not mentioned and while I am fairly sure that it should work I have to ask: Is 7.0.1 also supported?
And is the dereived key the same key that was needed when Atmosphere was still in "bring your own keys for 7.x support" mode?

Thanks for clarifying.
 
  • Like
Reactions: shchmue

shchmue

Developer
OP
Developer
Joined
Dec 23, 2013
Messages
791
Trophies
1
XP
2,367
Country
United States
Its not mentioned and while I am fairly sure that it should work I have to ask: Is 7.0.1 also supported?
And is the dereived key the same key that was needed when Atmosphere was still in "bring your own keys for 7.x support" mode?

Thanks for clarifying.
it supports every firmware :) but no the keys for BYOK on 7.x remain private, Sept uses them and clears them from memory.
 

Kadji

Well-Known Member
Member
Joined
Nov 16, 2006
Messages
198
Trophies
1
Age
35
Location
Germany, NRW
XP
1,450
Country
Germany
Ok now I am a bit confused: If I understood right it *does* dump *some* 7.X keys if we provide RCM_Paylock with the files from Atmo / Kosmos.
Are those the keys that would be used in the future to decrypt 7.X games (when they appear in the fututre)?

Sorry if those questions have been answered for about 100 times, the whole 7.X situation is a bit messy and I am out of the loop (private stuff that is kinda ruining my life atm).
 

shchmue

Developer
OP
Developer
Joined
Dec 23, 2013
Messages
791
Trophies
1
XP
2,367
Country
United States
Run this and then run lockpick?
the only thing Lockpick does that this doesn't is derive titlekeys. so unless you want those this is all you need.

--------------------- MERGED ---------------------------

Ok now I am a bit confused: If I understood right it *does* dump *some* 7.X keys if we provide RCM_Paylock with the files from Atmo / Kosmos.
Are those the keys that would be used in the future to decrypt 7.X games (when they appear in the fututre)?

Sorry if those questions have been answered for about 100 times, the whole 7.X situation is a bit messy and I am out of the loop (private stuff that is kinda ruining my life atm).
it dumps and derives all the keys you need to decrypt 7.x files.
 
  • Like
Reactions: huma_dawii

huma_dawii

Well-Known Member
Member
Joined
Apr 3, 2014
Messages
3,880
Trophies
2
Age
33
Location
Planet Earth
XP
4,271
Country
United States
Ok now I am a bit confused: If I understood right it *does* dump *some* 7.X keys if we provide RCM_Paylock with the files from Atmo / Kosmos.
Are those the keys that would be used in the future to decrypt 7.X games (when they appear in the fututre)?

Sorry if those questions have been answered for about 100 times, the whole 7.X situation is a bit messy and I am out of the loop (private stuff that is kinda ruining my life atm).
I hope your life gets better :) stay strong.

--------------------- MERGED ---------------------------

the only thing Lockpick does that this doesn't is derive titlekeys. so unless you want those this is all you need.

--------------------- MERGED ---------------------------


it dumps and derives all the keys you need to decrypt 7.x files.
I got only 126 keys, normal? On 7.0.1
 
  • Like
Reactions: lordelan

shchmue

Developer
OP
Developer
Joined
Dec 23, 2013
Messages
791
Trophies
1
XP
2,367
Country
United States
I hope your life gets better :) stay strong.

--------------------- MERGED ---------------------------


I got only 126 keys, normal? On 7.0.1
yes that's the count for 7.x

though I'd caution generally not to be too focused on key count as long as you have those you need. for example, consoles on 6.2.0 can dump a master kek and tsec root key that can't be dumped on any other firmware but those are just intermediate calculations and aren't as important as their result for anyone using this software
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • SylverReZ @ SylverReZ:
    @HiradeGirl, This commercial doesn't need to be made.
  • Veho @ Veho:
    I get what they were trying to say but what the ad actually says is "we tried to cram a ton of features into the iPad but all of them got irreparably mangled
    in the process."
    +2
  • K3Nv2 @ K3Nv2:
    That'll be fixed in the next update
  • K3Nv2 @ K3Nv2:
    Did Janet Jackson release a new song
    +2
  • Veho @ Veho:
    Is Janet Jackson alive?
    +1
  • Maximumbeans @ Maximumbeans:
    And has she put her boob away yet?
    +1
  • Veho @ Veho:
    Her boob is the cause of all this current shit :angry:
    +1
  • Sonic Angel Knight @ Sonic Angel Knight:
    I hope this is a dream and I'm not actually leaving messages for others to see. :ninja:
    +1
  • Veho @ Veho:
    You are not.
  • Veho @ Veho:
    Nobody is reading what you post.
  • Psionic Roshambo @ Psionic Roshambo:
    That Dell data breach is worse than people probably realize....
  • Psionic Roshambo @ Psionic Roshambo:
    When I worked for Dell we had access to data about military contracts and addresses for high ranking people.
  • Psionic Roshambo @ Psionic Roshambo:
    I personally handled a call from the second highest person at Raytheon. That call bothered me a lot... The guy was nice and smart what bothered me was the way management basically just blew him off instead of going the extra mile to help him.
  • Psionic Roshambo @ Psionic Roshambo:
    In the end that call ended up costing Dell millions in lost contracts with Raytheon, and really the issue could have been solved for like 450 bucks lol
  • NinStar @ NinStar:
    sometimes I wonder why anyone would ever buy mega man x legacy collection 2
  • NinStar @ NinStar:
    I always thought that capcom shuffled the games in these collection, but apparently they are all in chronological order, which makes legacy collection 2 worthless
  • BakerMan @ BakerMan:
    guys, i want to start singing pirate metal songs and sea shanties if i play sea of thieves
  • The Real Jdbye @ The Real Jdbye:
    find a pirate metal playlist
  • The Real Jdbye @ The Real Jdbye:
    and sing along
  • BakerMan @ BakerMan:
    nevermind i just learned swearing is against the rules in sea of thieves

    i was about to start singing the song i last put in "what song are you currently listening to" yesterday
  • BakerMan @ BakerMan:
    but yeah ig so
    BakerMan @ BakerMan: but yeah ig so