Live data from Hacker News

The “unpatchable” exploit that makes every current Nintendo Switch hackable

arstechnica.com

31–40 of 78 posts

Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable

#31
In the FAQ, Temkin says she has previously notified Nvidia and vendors like Nintendo about the existence of this exploit, providing what she considers an "adequate window [for Nvidia] to communicate with [its] downstream customers and to accomplish as much remediation as is possible for an unpatchable bootROM bug."

Why would you even want to do that...? Money? Fame? As I've heard it said memorably, "would you tell someone who takes you hostage and locks you up, that the lock is actually trivial to open?" This is just further evidence of a fact I've noticed for a long time: a lot of security researchers are pro-DRM, pro-corporatocracy authoritarians, and their vision of "more secure" is a dystopian nightmare.

I still remember the good old days, when the hacking/cracking scene was entirely composed of people doing it for the freedom, with no do-gooding snitches to worry about...

10 years ago, if you shared a way to bypass a DRM scheme in the right places, it would live on for a long time. Now, it's more likely that some bastard is going to report it and get it patched in days to weeks.

Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable

#32

This doesn't sound like it itself "exploits" anything, just deflates Nintendo's attempted scheme to exploit their customers by booby trapping their hardware. If you rigged your car to destruct 30 minutes after it went out of cell service, sold it to an unsuspecting buyer, and then laughed when they got stuck in the desert, you'd be rightfully thrown in jail. But yet these companies keep attempting to pull the same sh…

Sounds kind of like a Tesla, now that you mention a car like that. They already will call and threaten you if you own a Tesla and mess around with it under the hood.

https://www.slashgear.com/expect-an-irate-call-if-you-try-to...

How much further will they go? Will they remotely disable it? Or perhaps, they'll send it into "Service Needed" mode and cripple it?

Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable

#33

In the FAQ, Temkin says she has previously notified Nvidia and vendors like Nintendo about the existence of this exploit, providing what she considers an "adequate window [for Nvidia] to communicate with [its] downstream customers and to accomplish as much remediation as is possible for an unpatchable bootROM bug." Why would you even want to do that...? Money? Fame? As I've heard it said memorably, "would you tell so…

>I still remember the good old days, when the hacking/cracking scene was entirely composed of people doing it for the freedom, with no do-gooding snitches to worry about...

>10 years ago, if you shared a way to bypass a DRM scheme in the right places, it would live on for a long time. Now, it's more likely that some bastard is going to report it and get it patched in days to weeks.

From the article it looks like someone else was trying to sell it so she put it in the open for free.

>The release also seems to be partially a response to Team Xecuter, a separate team that is planning to sell a modchip exploit that can allow for similar code execution on the Switch. Temkin writes that she's opposed to Xecuter's explicit endorsement of piracy and efforts "to profit from keeping information to a few people."

Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable

#34

In the FAQ, Temkin says she has previously notified Nvidia and vendors like Nintendo about the existence of this exploit, providing what she considers an "adequate window [for Nvidia] to communicate with [its] downstream customers and to accomplish as much remediation as is possible for an unpatchable bootROM bug." Why would you even want to do that...? Money? Fame? As I've heard it said memorably, "would you tell so…

This exploit has nothing specifically to do with DRM, and compromises the entire root of trust chain on devices impacted (including devices which aren't locked down).

Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable

#35

Earlier quoted context omitted.

I actually kind of liked the Gameboy approach. You needed to include a byte-for-byte image of the trademarked Nintendo logo in order for the boot ROM to run your cartridge. So there were no technical hurdles to running your code in it, but it just made it legally dangerous to distribute.

Sega tried this with the Dreamcast, and further, tried to enforce it in court. They lost.

Indeed but since then the DMCA[0] has radically shifted to the law. Sega would win today.

[0] https://en.wikipedia.org/wiki/Digital_Millennium_Copyright_A...

Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable

#36

This doesn't sound like it itself "exploits" anything, just deflates Nintendo's attempted scheme to exploit their customers by booby trapping their hardware. If you rigged your car to destruct 30 minutes after it went out of cell service, sold it to an unsuspecting buyer, and then laughed when they got stuck in the desert, you'd be rightfully thrown in jail. But yet these companies keep attempting to pull the same sh…

Sounds kind of like a Tesla, now that you mention a car like that. They already will call and threaten you if you own a Tesla and mess around with it under the hood. https://www.slashgear.com/expect-an-irate-call-if-you-try-to... How much further will they go? Will they remotely disable it? Or perhaps, they'll send it into "Service Needed" mode and cripple it?

[deleted]

Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable

#37
This has reasonable parallels to the PSP "Pandora's Battery" exploit, which put the device into DFU mode using a battery that emulated the factory service mode jig, and then exploited an issue in the trust chain verification in the first-stage (mask-ROM) bootloader. Similarly fixable with hardware only, which came soon after the exploit.

This bootloader bug is much sillier (IMO) than Sony's, though. Sony's was a series of crypto mistakes in the trust chain verification: it decrypted blocks in place and there was an issue in the checksum code that left it vulnerable to a timing attack, so a very, very small valid-but-colliding block had to be constructed and the rest of the bootloader was then freely-injectable. This nVidia/Nintendo mistake is an even sillier basic protocol issue.

I think the main lesson here is not to put complex protocol code in your immutable first-stage mask ROM, and if you do, to limit the surface area as much as possible, ensure memory safety, and audit the hell out of it.

Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable

#38

Earlier quoted context omitted.

Sega tried this with the Dreamcast, and further, tried to enforce it in court. They lost.

Indeed but since then the DMCA[0] has radically shifted to the law. Sega would win today. [0] https://en.wikipedia.org/wiki/Digital_Millennium_Copyright_A...

IANAL, but the two things seem related, why is GP being down voted? From just a reading of the wiki pages without much law knowledge it does seem like sega would win today? What I am getting wrong?

Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable

#39

In the FAQ, Temkin says she has previously notified Nvidia and vendors like Nintendo about the existence of this exploit, providing what she considers an "adequate window [for Nvidia] to communicate with [its] downstream customers and to accomplish as much remediation as is possible for an unpatchable bootROM bug." Why would you even want to do that...? Money? Fame? As I've heard it said memorably, "would you tell so…

This exploit has nothing specifically to do with DRM, and compromises the entire root of trust chain on devices impacted (including devices which aren't locked down).

Given that the DRM is precisely about stopping owners from controlling their devices fully, I'd say it's pretty relevant to this exploit being able to bypass that.

Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable

#40

In the FAQ, Temkin says she has previously notified Nvidia and vendors like Nintendo about the existence of this exploit, providing what she considers an "adequate window [for Nvidia] to communicate with [its] downstream customers and to accomplish as much remediation as is possible for an unpatchable bootROM bug." Why would you even want to do that...? Money? Fame? As I've heard it said memorably, "would you tell so…

>I still remember the good old days, when the hacking/cracking scene was entirely composed of people doing it for the freedom, with no do-gooding snitches to worry about... >10 years ago, if you shared a way to bypass a DRM scheme in the right places, it would live on for a long time. Now, it's more likely that some bastard is going to report it and get it patched in days to weeks. From the article it looks like some…

If she truly wanted to make it free, why secretly tell Nintendo and nVidia first?

It's a cat-and-mouse game, and this mouse wants to tell the cat how to catch the other mice. In the old scene, you'd be branded a traitor for doing that.

Post reply on HN