This doesn't sound like it itself "exploits" anything, just deflates Nintendo's attempted scheme to exploit their customers by booby trapping their hardware. If you rigged your car to destruct 30 minutes after it went out of cell service, sold it to an unsuspecting buyer, and then laughed when they got stuck in the desert, you'd be rightfully thrown in jail. But yet these companies keep attempting to pull the same sh…
It’s half and half. This scheme defeats Nintendo’s attempt to control what console owners do with their own hardware, it’s true. But it also allows console owners to be exploited by malicious hardware (say, a cheap charger).
The “unpatchable” exploit that makes every current Nintendo Switch hackable
61–70 of 78 posts
Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable
#62This doesn't sound like it itself "exploits" anything, just deflates Nintendo's attempted scheme to exploit their customers by booby trapping their hardware. If you rigged your car to destruct 30 minutes after it went out of cell service, sold it to an unsuspecting buyer, and then laughed when they got stuck in the desert, you'd be rightfully thrown in jail. But yet these companies keep attempting to pull the same sh…
I actually kind of liked the Gameboy approach. You needed to include a byte-for-byte image of the trademarked Nintendo logo in order for the boot ROM to run your cartridge. So there were no technical hurdles to running your code in it, but it just made it legally dangerous to distribute.
Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable
#63Earlier quoted context omitted.
Sounds kind of like a Tesla, now that you mention a car like that. They already will call and threaten you if you own a Tesla and mess around with it under the hood. https://www.slashgear.com/expect-an-irate-call-if-you-try-to... How much further will they go? Will they remotely disable it? Or perhaps, they'll send it into "Service Needed" mode and cripple it?
It ought to be the law that anything I can do, is fair game. If I fuckup something it shouldn't be under warranty, but only for the issues the tinkering causes. If I can connect to a port in the car I've paid for, and read something, it's not industrial espionage. That is just Tesla being lazy and trying to get security-by-obscurity, instead of a proper secure implementation.
There was another episode where Jason Hughes was denied firmware updates after rooting his car. Elon responded that no punitive action was intended and that he views white hat hacking as a gift, and they seemed to resolve it pretty quickly.
It will be interesting to see how Tesla responds to these cases when FSD is available.
edit: Here's the original post: https://teslamotorsclub.com/tmc/threads/successful-connectio...
> This evening I got a call from service center :crying: They told me Tesla USA engineers seen a tentative of hacking on my car... I explained it was me because I tried to connect the diagnosis port to get some useful data (speed, power, etc...). They told me it can be related to industrial espionage and advised me to stop investigation, to not void the warranty.... Don't know if they really seen something in the log, because I just sniffed the network. Or maybe they seen the port scanning with nmap ? Or maybe they just read this topic ? :eek:
Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable
#64Earlier quoted context omitted.
False dichotomy.
Not everything has to be a fallacy, I remember when people understood the concept of tongue-in-cheek . DRM (10NES) was a core part of the strategy for the console that brought a recovery from the 1983 video game crash. And even today publishers value a platform that is able to combat privacy (see: Denuovo and the lengths AAA productions go to delay piracy in PC.
About 1/3rd of the consoles sold didn't contain the DRM, yet the Japanese market still saw similar growth.
Publishers value Denuovo, is there any proof that it helps sales?
Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable
#65Earlier quoted context omitted.
If she truly wanted to make it free, why secretly tell Nintendo and nVidia first? It's a cat-and-mouse game, and this mouse wants to tell the cat how to catch the other mice. In the old scene, you'd be branded a traitor for doing that.
"Why disclose this at all? Why not hold onto this in order to increase the number of affected Switch consoles? Unfortunately, this bug affects a significant number of Tegra devices beyond the Switch, and beyond even the X1 included in the Switch. I can tell you, it wasn't fun to find a bug with such a broad impact; it significantly complicated the ethics involved. In the end, given the potential for a lot of bad to b…
If it was a remote exploit, I'd certainly agree about the ethical dilemma, but everything I've read suggests that this requires physical access.
As for being used in cars... don't get me started on what manufacturers are doing these days to stop repairs and modifications... just search "John Deere tractor hacking" to get a taste of what I mean (some articles and good discussion here on HN too.)
Calling someone a traitor because they decided to responsibly disclose a vulnerability is just childish.
It shows they cannot be trusted, and that they support the actions of companies who want to lock out users from the devices they own.
Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable
#66Earlier quoted context omitted.
I actually kind of liked the Gameboy approach. You needed to include a byte-for-byte image of the trademarked Nintendo logo in order for the boot ROM to run your cartridge. So there were no technical hurdles to running your code in it, but it just made it legally dangerous to distribute.
Interestingly, this could be circumvented - the boot rom does the logo scroll using data from cart, THEN, in a separate loop checks it vs local copy. If you can make the cart read different data at each stage, you are golden! IIRC Argonaut/Jez San had a POC of this using a very simple hardware bodge, intended as a potential way of publishing Eclipse (What became X) without a Nintendo licence. Fortunately - Nintendo w…
Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable
#67This doesn't sound like it itself "exploits" anything, just deflates Nintendo's attempted scheme to exploit their customers by booby trapping their hardware. If you rigged your car to destruct 30 minutes after it went out of cell service, sold it to an unsuspecting buyer, and then laughed when they got stuck in the desert, you'd be rightfully thrown in jail. But yet these companies keep attempting to pull the same sh…
Well it’s your choice, open hardware or billions of dollars invested in an industry employing millions of people...
Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable
#68Earlier quoted context omitted.
Well it’s your choice, open hardware or billions of dollars invested in an industry employing millions of people...
How about an open hardware industry that would employ millions of people? Not to mention the questionable premise that we should have enough work to employ almost everyone. I mean, we're mostly programmers in here. Our primary task is to destroy jobs. Shouldn't free time be a good thing?
That being said, I don’t have major qualms about closed hardware. It creates the incentives that have allowed for massive investment in what is now cutting edge technology, and over time it is trickling down to more open hardware.
The number of proprietary technologies in a modern high-end GPU is staggering. Maybe one could say in an alternate timeline open hardware could have beaten companies creating GPUs with proprietary IPs, but it didn’t really happen. So I’ll take 1080tis with binary blobs over the open alternative.
Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable
#69Earlier quoted context omitted.
Not everything has to be a fallacy, I remember when people understood the concept of tongue-in-cheek . DRM (10NES) was a core part of the strategy for the console that brought a recovery from the 1983 video game crash. And even today publishers value a platform that is able to combat privacy (see: Denuovo and the lengths AAA productions go to delay piracy in PC.
>DRM (10NES) was a core part of the strategy for the console that brought a recovery from the 1983 video game crash. About 1/3rd of the consoles sold didn't contain the DRM, yet the Japanese market still saw similar growth. Publishers value Denuovo, is there any proof that it helps sales?
And if Denuovo actually helps sales is not an easy question to answer since no publisher has come out and said it (that I’ve seen).
The premise seems sound enough, sales follow an “inverse hockey stick”, so design DRM meant to delay cracking instead of stop it and you can get more time with maximum interest and sales, with no easy piracy options.
A few times it’s fallen in hours, and pirates started to write it off, but just recently Far Cry 5's implementation lasted weeks, which seems to be what they’re going for (some versions even lasted months on end).
One could argue no pirates would buy instead of wait, and one could argue all pirates would buy instead of wait, but both would be wrong and the truth is somewhere in the middle, publishers have evaluated that question and apparently the answer is something they like enough to keep shaving margins for
Re: The “unpatchable” exploit that makes every current Nintendo Switch hackable
#70This doesn't sound like it itself "exploits" anything, just deflates Nintendo's attempted scheme to exploit their customers by booby trapping their hardware. If you rigged your car to destruct 30 minutes after it went out of cell service, sold it to an unsuspecting buyer, and then laughed when they got stuck in the desert, you'd be rightfully thrown in jail. But yet these companies keep attempting to pull the same sh…
I actually kind of liked the Gameboy approach. You needed to include a byte-for-byte image of the trademarked Nintendo logo in order for the boot ROM to run your cartridge. So there were no technical hurdles to running your code in it, but it just made it legally dangerous to distribute.
Internet and countries that don't enforce copyright exist you know? You can even get HDCP strippers on Ebay, pretty easily too. Never had any issue finding ISO and roms online, even for the Switch before this hack.
If only the legal side was a good enough security...
If you want a portable device that you can use to run your own software, then go get a tablet that run the Tegra X1, you will get the exact same thing.