10 ms·
How the Nintendo Switch prevents firmware downgrades
- polyomino 8y agoE fuses require a lot of power to burn in the fuse. So find the pin in the chip with high voltage, and suppress it to prevent e fuses from burning in.
- koala_man 8y agoI would assume that the firmware also verifies that the fuses have been burnt before continuing booting.
- dpiers 8y agoIt does, but this prevents your system from being irreversibly updated by accident. I remember removing R6T3[1] on my Xbox 360 so that it wouldn't accidentally be updated to a non-homebrew/exploitable version. Without the resistor present, the voltage wasn't high enough to burn the eFuses. An update could run, fail to boot, and I could reflash it to the old version. 1: http://www.free60.org/wiki/R6T3 http://www.free60.org/wiki/R6T3
- internalfx 8y agoHow many fuses does it have?
- rubyn00bie 8y agoI think it's around 31... Though that's from memory and a very bad attempt to read and understand this: http://switchbrew.org/index.php?title=Fuses http://switchbrew.org/index.php?title=Fuses
- zylent 8y agoThe fuse in question is FUSE_RESERVED_ODM7. The Switchbrew wiki says the fuse array for this stores 256 bits of data. http://switchbrew.org/index.php?title=Fuses#eFuses http://switchbrew.org/index.php?title=Fuses#eFuses as an aside, this is not new information to anyone following switch homebrew development.
- jonluca 8y agoThere are 256 bits in ODM_RESERVED, and 8 ODM_RESERVED, so I think there are 32 bits. That's 32 major FW revisions (as it seems they're only blowing a fuse for every X.0.0 version)
- zylent 8y agoIf there are 256 bits, wouldn't they just burn one bit per major revision leaving 256 possible revisions? Is there something I'm missing here?
- NedIsakoff 8y ago256 bits in all ODM_RESERVED. There are 8 ODM_RESERVEDs. 256/8 = 32 eh?
- zylent 8y agoAhh, I didn't catch that and was thinking ODM_RESERVED_8 = 256 bits. Thanks!
- deleted 8y ago[deleted]
- Danieru 8y agoThat would explain why Nintendo has been so quick to bump major version numbers. The community was quite disappointed when major version five released and had no significant new features. If Nintendo is trying to prevent down grading they must expect to use these fuses earlier in the console life span rather than later.
- sjm-lbm 8y agoFWIW, the concept here isn't exactly new - at least the Xbox 360 and a few other devices have had similar functionality[1]. [1] http://www.tested.com/tech/585-how-efuses-work-and-why-theyre-not-as-bad-as-you-think/ http://www.tested.com/tech/585-how-efuses-work-and-why-theyr...
- haZard_OS 8y agoThe very first paragraph of the article made this clear already. It even mentioned the Xbox by name.
- BillinghamJ 8y agoThe wording of the title makes for a kinda misleading implication. This is pretty standard - they're called e-fuses. It isn't "blowing" in the sense that an actual fuse does, but it is permanently/irreversibly writing bits to indicate the minimum version.
- kmm 8y agoIf not by actual fuses, how is it implemented? There has to be some sort of physical change for it to survive without power indefinitely
- crankylinuxuser 8y agoA read operation determines if the connection is "connected" or "disconnected". It actually is litte bits of wire inside silicon that get over-current'ed and do burn away. And then a read operation returns "Disconnected". There's no way to 'reconnect' a eFuse, in the way there's no way to reconnect an automotive fuse. So yes, eFuses are a form of hardware destruction.
- zaksoup 8y agoI think the parent is being pedantic. All the literature I could find on eFuses (including the wikipedia article) either used 'blowing' to refer to permanent writing, or '"blowing"' (in scare quotes). Whether or not that is descriptive of the physical process that's occurring, it certainly seems to be a reasonable term for anybody to use to talk about the functionality of eFuses.
- kevin_thibedeau 8y agoExcept that in many cases the "fuses" can be reset by wiping the firmware from the part and restoring it to a factory clean state.
- pjc50 8y agoThen it's not really a fuse in the normal chip sense.
- leggomylibro 8y ago>It’s theoretically possible to physically modify the SoC and replace the fuses, but it’s so prohibitively invasive and expensive that it’s not a real option. Are there any examples of this being done? Not necessarily on the Switch, just with these sorts of fuses. It can be really interesting to see people repair SoCs, like in this iPhone repair: https://www.youtube.com/watch?v=nap0gtds5tQ https://www.youtube.com/watch?v=nap0gtds5tQ
- ythn 8y agoSeems like you could still "downgrade" via an upgrade: 1. Disable firmware digital signature verification (not sure if this is at the hardware level or not) 2. Modify the older firmware such that its reported version is newer than your current version 3. "upgrade" to the older firmware version
- notriddle 8y ago> 1. Disable firmware digital signature verification (not sure if this is at the hardware level or not) That's supposed to be very difficult to do.
- Scaevolus 8y agoExactly, every stage of the boot is supposed to validate the next stage before continuing. The recently discovered bootrom exploits break that chain of trust, allowing unsigned code to execute.
- zorkw4rg 8y agoMaybe for their next console they could wire the case so it will destroy some crypto chips when anyone attempts to open it. Another idea might be to wire in a radio clock with a set date in the future that causes a over voltage in the SoC, that could be more accurate than to rely on the obsolescence of the glued in battery. Also I think they should learn from Sim City (2013), I know EA eventually released a patch that put the server side single player code in the client again, but Nintendo should learn from that mistake. But with all seriousness, Nintendo really should learn from the failures in their past, I mean come-on! I can still play Zelda on my original Game Boy Pocket I can even replace the batteries without any tools, come on what were they thinking! /edit although.. I do like that you damage the switch everytime you put it in the dock, must give them that
- bArray 8y ago>Blowing a fuse is irreversible— once it’s been set it can never be undone. Sounds impossible, until you find out that if you don't blow them hard enough you can get fuse re-flow under hot conditions. Good fun to debug. In theory (untested to my knowledge), if you super cool the chip you could lower the resistance of the fuse and prevent it from blowing and absorb heat around the fuse, but it's probably not all that practical for casual game players. As for getting to the problem at hand (force downgrading your system), some potential solutions (nothing easy): * Careful control over the chip's power and you could perform a power supply timing attack, tricking the processor logic. This seems like a bit of a stab in the dark though. * Assuming the bootloader is loaded into some form of RAM, you could look towards modifying the RAM as the chip boots to contain some kind of "skip" code for set pins. Game consoles have hardly been beyond the realm of needing mod-chips to access different features... * The other option would be to replace the chip containing the bootloader with a non-upgraded one.