Hacking Hardware Picofly - a HWFLY switch modchip

Adran_Marit

Walküre's Hacker
Member
Joined
Oct 3, 2015
Messages
3,781
Trophies
1
Location
42*South
XP
4,567
Country
Australia
There is nothing that can be expected from something that can't even start hos before atmo.
But there are rumors that there is a private build of the firmware which can boot atmosphere

True story it happened to a friend of a friend of mine 🤣🤣
 

nqtal

Well-Known Member
Newcomer
Joined
Feb 11, 2023
Messages
53
Trophies
0
Age
35
XP
183
Country
Russia
Gentlemen, at what point did we rule out the rp2040 hardware limitation as a possible problem? Initially, it was believed that the chip rests on frequencies. And the rp2040 has only two attachment points to the CPU compared to hwfly with four. Sorry if this issue has already been discussed. I read the topic from the beginning and now on page 33, but we immediately moved from "it's impossible" to "need firmware" :rolleyes:
 
  • Haha
Reactions: qgywibczozfvvl

Lamcza

Typ tego typu.
Member
Joined
Nov 23, 2022
Messages
584
Trophies
0
Age
33
XP
776
Country
Poland
Gentlemen, at what point did we rule out the rp2040 hardware limitation as a possible problem? Initially, it was believed that the chip rests on frequencies. And the rp2040 has only two attachment points to the CPU compared to hwfly with four. Sorry if this issue has already been discussed. I read the topic from the beginning and now on page 33, but we immediately moved from "it's impossible" to "need firmware" :rolleyes:
i mean now it can boot hekate, android and ubuntu if am not wrong :P? So it looks like frimware limitations.
 

Adran_Marit

Walküre's Hacker
Member
Joined
Oct 3, 2015
Messages
3,781
Trophies
1
Location
42*South
XP
4,567
Country
Australia
Gentlemen, at what point did we rule out the rp2040 hardware limitation as a possible problem? Initially, it was believed that the chip rests on frequencies. And the rp2040 has only two attachment points to the CPU compared to hwfly with four. Sorry if this issue has already been discussed. I read the topic from the beginning and now on page 33, but we immediately moved from "it's impossible" to "need firmware" :rolleyes:
It's not a rp2040 limitation, you can see in various videos through the thread people with the chip installed booting to hekate all be it a version that is locked so we can't boot atmosphere.
As such the issue is we either make a firmware that works that doesn't clear the keyslots allowing atmosphere to boot, or we crack the initial leaked firmware that is ID locked OR OR we wriet a new firmware for it from scratch
Post automatically merged:

Let your friends share it, or share the source.

I'm memeing there.

But I have to assume there are people who have it, but can't share it for whatever reason.
 

vittorio

Well-Known Member
Member
Joined
May 12, 2014
Messages
243
Trophies
1
Age
26
XP
999
Country
Italy
It's not a rp2040 limitation, you can see in various videos through the thread people with the chip installed booting to hekate all be it a version that is locked so we can't boot atmosphere.
As such the issue is we either make a firmware that works that doesn't clear the keyslots allowing atmosphere to boot, or we crack the initial leaked firmware that is ID locked OR OR we wriet a new firmware for it from scratch
Post automatically merged:



I'm memeing there.

But I have to assume there are people who have it, but can't share it for whatever reason.
the firmware that circulate are still protected by id
 

BigHorse420

Active Member
Newcomer
Joined
Jan 7, 2023
Messages
25
Trophies
0
Age
34
XP
94
Country
Zimbabwe
Probably because it gets lost in the sea of "how do I install this" or "look at the stuff I bought for when it works"
Anyways, if I have this correct, we have 2 uf2's, one from the actual picofly that doesn't boot due to the ID being unique to the pico, and one that boots, but only non-hos payloads?
For anyone that's looked at this in ghidra, have we found the section where the pio is? That's going to most likely be the main communication, since it would effectively allow the pico to bitbang upwards of 100mhz+. I've more or less emulated the gameboy's APU on a pico with heavy pio usage for the audio output. I wouldn't say I'm a pro, but I know how to work with it to an extent.
Lastly, is there any documentation on how this works on the switch side? even if it's at a high level?
A lot of info isn't public, this is the best I could find https://gbatemp.net/threads/questio...rces-on-the-functionality-of-sx-hwfly.614151/
 

Adran_Marit

Walküre's Hacker
Member
Joined
Oct 3, 2015
Messages
3,781
Trophies
1
Location
42*South
XP
4,567
Country
Australia
the firmware that circulate are still protected by id

There are two firmwares we have in this thread

Firmware 1 - ID locked. Won't boot on other devices
Firmware 2 - Not locked. But has been modified to prevent atmosphere from booting.

So we either need firmware to be hacked, firmware 2 to be restored to allow atmosphere or write a new firmware for it.
 

vittorio

Well-Known Member
Member
Joined
May 12, 2014
Messages
243
Trophies
1
Age
26
XP
999
Country
Italy
There are two firmwares we have in this thread

Firmware 1 - ID locked. Won't boot on other devices
Firmware 2 - Not locked. But has been modified to prevent atmosphere from booting.

So we either need firmware to be hacked, firmware 2 to be restored to allow atmosphere or write a new firmware for it.


we need to crack the firmware 1 or rewrite it
 
  • Like
Reactions: impeeza

Kingdedede

Member
Newcomer
Joined
Jan 28, 2023
Messages
24
Trophies
0
Age
49
XP
404
Country
Italy
@rehius we know that you are against piracy... but between Hwfly and people who sell firmware for rp2040 who charge to receive a firmware that you already have..... this is to tell you that piracy is still there regardless of you and your firmware ... indeed we would all be grateful if you made it public thanks
 

ppeach

Well-Known Member
Newcomer
Joined
Mar 13, 2023
Messages
63
Trophies
0
XP
209
Country
Zimbabwe
What is the conclusion reached in the 99 pages of discussion?
FW is not publicly available and there is no one here who can create FW.
 

Lamcza

Typ tego typu.
Member
Joined
Nov 23, 2022
Messages
584
Trophies
0
Age
33
XP
776
Country
Poland
bottom line is i don't think you will ever see a public firmware that boots Atmosphere
Bet that Tendo thinks the same about their patched switches "they will never break it is unhackable" :D but yes because it is just illegal :D we will probably never see a public one but I bet we will see something under the table xD

@rehius we know that you are against piracy... but between Hwfly and people who sell firmware for rp2040 who charge to receive a firmware that you already have..... this is to tell you that piracy is still there regardless of you and your firmware ... indeed we would all be grateful if you made it public thanks
Leave that man alone :D bet he is not against piracy but he is against piracy for free so it is probably his firmware and probably he is selling it :D and nothing wrong with it I mean for me Tendo will be mad ofc but that is not my business
 

Piorjade

Well-Known Member
Member
Joined
Nov 8, 2015
Messages
142
Trophies
0
XP
407
Country
Gambia, The
bottom line is i don't think you will ever see a public firmware that boots Atmosphere
I wouldn't say that

Problem is it seems like nobody here is actually interested enough to start working on a fw themselves

That or there are people working on one and just don't want to share it here because their PMs will explode with demands and questions like "are you done yet?"
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Xdqwerty @ Xdqwerty:
    sigh
  • Xdqwerty @ Xdqwerty:
    @a_username_that_isnt_cool, could you change your username?
  • Xdqwerty @ Xdqwerty:
    i guess not...
  • Xdqwerty @ Xdqwerty:
    yawn
  • Xdqwerty @ Xdqwerty:
    anybody here?
  • P @ PKNate:
    nope
  • BakerMan @ BakerMan:
    fun fact: 7 years by lukas graham, supermassive black hole by muse, and megalomania all have the same bpm
  • BakerMan @ BakerMan:
    girls just wanna have fun and renai circulation also share the same tempo as the few i said before
  • Xdqwerty @ Xdqwerty:
    @BakerMan, megalomania the live a live song?
  • BakerMan @ BakerMan:
    wait no, megalovania*
  • BakerMan @ BakerMan:
    my bad
  • K3Nv2 @ K3Nv2:
    I don't forgive you
  • BigOnYa @ BigOnYa:
    The nerve of that guy, gosh.
  • K3Nv2 @ K3Nv2:
    Yeah expecting me to forgive gtfo
  • Psionic Roshambo @ Psionic Roshambo:
    But how could the Dr have known you didn't want to be circumcized?
  • K3Nv2 @ K3Nv2:
    He didn't you just wanted your dick to be fondled
    +1
  • K3Nv2 @ K3Nv2:
    Watching dune 2 it's eh
  • Psionic Roshambo @ Psionic Roshambo:
    Dune one sucked
  • Psionic Roshambo @ Psionic Roshambo:
    The original with Patrick Stewart was Great
  • K3Nv2 @ K3Nv2:
    A sexual psycopath that love pain where have I heard that before
  • BigOnYa @ BigOnYa:
    In your high school diary?
  • K3Nv2 @ K3Nv2:
    No but your wife let's me read her diary the word psychopath comes up more than sexual
    +1
    K3Nv2 @ K3Nv2: No but your wife let's me read her diary the word psychopath comes up more than sexual +1