3 ms·
This is really cool stuff! I think it's a particularly novel idea of using on-die fuses to prevent firmware downgrade. I don't know how common that is in the c
by resonanttoe 9y ago
This is really cool stuff!
I think it's a particularly novel idea of using on-die fuses to prevent firmware downgrade. I don't know how common that is in the console security world, but the amount of actual firmware updates vs. software updates in any given device would be pretty low and from what I've read the number of fuses is large enough they're never really going to run out of it.
But I also absolutely love the use of the uninitialized PID argument value to be PID 0. There's a poor engineer sitting at Nintendo looking at that slide and just going "well... shit."
- izacus 9y agoeFuses were first used to prevent downgrades on Xbox 360 actually.
- resonanttoe 9y agoOh cheers! I had no idea. Thanks for the pointer :D
- 0xcde4c3db 9y ago> I think it's a particularly novel idea of using on-die fuses to prevent firmware downgrade. I don't know how common that is in the console security world As far as I know, it's been standard practice ever since consoles started having firmware updates. They don't necessarily blow fuses in the update procedure, but they'll generally fuse off anything below the version that a given unit shipped with.
- paulscoder 9y agoDon't you think Nintendo would prefer that when a product like a Switch goes EOL that it finds a new life generations later through the homebrew community? Honestly, if I hadn't been able to play roms in college 8 years after I had packed my 8bit Nintendo away I would not have purchased anything on virtual console for the Wii.
- resonanttoe 9y agoI think we as users would prefer that Nintendo prefers this. But no, Nintendo wants you to buy the next console that has the Virtual console of all those games you'll emulate through homebrew. Abandonware has ceased to exist in the console world. Especially for Nintendo.
- BearGoesChirp 9y agoI've read a conspiracy theory that Nintendo is wising up a bit to this, but can't do so openly, which is why the SNES classic was just as easy to hack as the NES classic even though a few simple changes could've made it much harder. They know the number of people who would pay $15 for a 15 year old game that hasn't aged well except for nostalgia is limited (assuming they even have the rights to sell it), but the market for hardware that would let them emulate them with a better (perhaps not better but more nostalgic) experience than the simple PC emulator setup is wide open. Thus the NES and SNES classic. As I said, it is just a conspiracy theory, but leaving the power port to transfer data as well as power in the SNES classic after the same design allowed massive hacking of the NES classic does give a slight nod towards the theory.
- resonanttoe 9y agoYeh this sounds plausible. I have felt that the virtual console prices are way to high for what they are. But stuff it in $10 worth of largely OSS and off the shelf hardware with a pretty case and sell it for $60 and I'm all in. I think given that emulation is a pretty well known thing within the target audience for the classic systems, protecting against it is a lost cause. The market for the classics are nostalgia driven game folks which is different from the switch, which is broader. They have to convince Mum and Dad of Shelly the 12yo that there is something there. Of course if Mum and Dad happen to see a game from their childhood that they've forgotten about on the Eshop, so much the better. Plus that entire teenage market isn't as susceptible to nostalgia purchases as the 30-40 market is right now. We'll see another wave of those kinds of devices in 20 years :D. Given the low numbers of the classic systems available, it just had all the ear markings of a small group's side project that may or may not have worked, rather than a complete exec buy in to be the "next-big-thing".
- timdorr 9y ago> the number of fuses is large enough they're never really going to run out of it. "640K ought to be enough for anybody!" But seriously, in the 3DS world, they've been going back and forth with hackers for a long time. There are a lot of updates for that system: http://en-americas-support.nintendo.com/app/answers/detail/a_id/231/~/system-menu-update-history http://en-americas-support.nintendo.com/app/answers/detail/a... Any time you see "Further improvements to overall system stability and other minor adjustments have been made to enhance the user experience," it's them closing an exploit vector. That would be a lot of fuses to blow. I wonder how many of these systems have secure enclaves and some ability to have a WORM-style hardware incrementer. The SoC version of an odometer.
- resonanttoe 9y agoYeh there are a lot of updates. But (and this has come up elsewhere) people call every update a firmware update and its not. Not every update is a firmware update. But every update is a software update. Firmware in this context is (most likely from what I can tell) 2nd stage bootloader that exists in EFI. It's pretty rarely updated. This is Package1 that they talk about here and http://switchbrew.org/index.php?title=System_Versions http://switchbrew.org/index.php?title=System_Versions here. Even less if we're talking about firmware updates that burnt a fuse (bottom of this page http://switchbrew.org/index.php?title=Fuse_registers#FUSE_RESERVED_ODM7 http://switchbrew.org/index.php?title=Fuse_registers#FUSE_RE...) So despite 11 Software updates, there has only been five firmware updates. When we're talking about fuses odm_reserved has 256 bits to play with. Assuming that one bit is 1 fuse. Then they can do 256 firmware updates before they're in trouble. Firmware is a pretty horribly misused term these days.
- timdorr 9y agoFair point! Thanks for correcting me and giving more detail.
- ReverseCold 9y agoThere's a cheap/easy/reliable hardware exploit now, so Nintendo has given up on patching things for the 3DS. In fact, their latest firmware even opens up a new bug.