10 ms·
How the Nintendo Switch prevents downgrades by irreparably blowing its own fuses
- hd4 6y agoThere is an easy workaround developed by the Switch homebrew community, simply upgrade from within a custom firmware (such as Atmosphere-NX) and run a tool called ChoiDuJourNX which bypasses the fuse-burning. If you're careful you can keep a backup trail going all the way back to your original device firmware and restore/downgrade it using the Hekate system tool. It has already been pointed out that there isn't much reason to do this, AFAIK the main reason people either held out on older firmwares or kept up a backup trail to them was in order to take advantage of possible firmware-version-specific exploits, the gold standard being a coldboot exploit.
- rekoil 6y agoAnd for those who stayed on the 4.1.0 fuseset (or certain versions below that) there are warmboot exploits available. So those who are able to "normally" boot those firmwares do not need to use AutoRCM (or an RCM-"jig") to access RCM anymore.
- hd4 6y agoWhile this is true, I was essentially saying that you don't have to remain on an older firmware as long as you're careful about how you move around between versions. I'm on 10.0 but I could go back to 3.1.0 anytime, and then move somewhere in between those versions if we got a coldboot exploit for example (which according to notable members of the Switch homebrew community is not likely).
- rekoil 6y agoYeah, sure, you can ignore the fuses, but only if you assist the boot process using a jig and an injected payload. The stock Horizon kernel from FW 10.3 won't boot if your fuseset is for 3.1.0, unless you inject a chainloader which fakes the fuseset or removes the check. Edit: I see what you were referring to, I was unspecific in my comment, updated it!
- roblabla 6y agoThe reason this "easy workaround" works at all is that there is a BootROM exploit that trivially allows running arbitrary code in the BootROM. This allows us to run our own bootloader instead of Nintendo's, bypassing their fuse burning logic. Had Nvidia not fucked up their USB implementation (along with other part of their platform), this would have been harder to bypass. [0]: https://www.reddit.com/r/SwitchHacks/comments/7rq0cu/jamais_vu_a_100_trustzone_code_execution_exploit/ https://www.reddit.com/r/SwitchHacks/comments/7rq0cu/jamais_...
- artsyca 6y agoI don't want to sound like I'm pontificating or defecating on the corporacy at everyone's favorite hardware company but it strikes me that these sorts of lapses are cultural and stem from this tedious emphasis everyone places on having "relaxed working environments"[0] Does it surprise you that the product of this culture also has relaxed security characteristics? [0] https://www.nvidia.com/en-us/about-nvidia/culture-at-nvidia/ https://www.nvidia.com/en-us/about-nvidia/culture-at-nvidia/
- monsieurbanana 6y agoThank you for making me laugh in these trying times.
- artsyca 6y agoI gotta keep it real for you sir banana, the only way to have a legit conversation on this platform is to have an equal number of up and downvotes.
- nemothekid 6y agoAh yes, compared to every other company that has never had an exploit ever.
- heavenlyblue 6y agoDoes anyone even like Nvidia?
- camgunz 6y agoAre these fuses extremely small? I would assume they’re easy to bypass otherwise.
- wutbrodo 6y agoFrom the beginning of the article: > It’s theoretically possible to physically modify the SoC and replace the fuses, but it’s so prohibitively invasive and expensive that it’s not a real option.
- camgunz 6y agoYeah I read that but, I wanted to know why.
- mlyle 6y agoThey are produced by lithography and are on the actual die of the system-on-chip that contains the processor. I believe they're IBM's eFUSE technology on Tegra, but antifuses have been used for similar purposes: https://www.semanticscholar.org/paper/IBM-System-z9-eFUSE-applications-and-methodology-Rizzolo-Foote/874d3974a4a8b3d3214fc30d132e07581701d915/figure/0 https://www.semanticscholar.org/paper/IBM-System-z9-eFUSE-ap...
- mmglr 6y agoA few questions: 1. What was the intended use case behind the Tegra having 32 blowable fuses? Did Nvidia intend for those fuses to be used in this manner? 2. What is a non-retail switch?
- mlyle 6y agoFuses and OTP are a very common thing to throw in to systems. Most microcontrollers offer capabilities like this, and now they're drifting into more general purpose, larger SOCs. Maybe you use it to keep a serial number, or to separate product families, or for something like this. Tegra's main purpose of the fuses is to handle holding cryptographic keys, boot parameters, and to disable the debug port. But since they have a fuse unit already, they provide a few words for the end-user to use as they please. I too am curious what "non-retail" means in this context.
- sirn 6y ago>I too am curious what "non-retail" means in this context. Maybe dev kits? AFAIK Switch has at least two dev kits (SDEV/EDEV) for different purposes so it kinda makes sense to call them non-retail.
- Luuseens 6y ago"non-retail" are usually either devkits, or units used for demo stands in shops.
- izacus 6y ago1. Most likely - Switch isn't the first console which used fuses like this. Xbox 360 had them as well.
- henrikeh 6y agoOne common use case of the fuses is to prevent attack vectors which downgrade software to a vulnerable version. Using the OTP fuses older versions can be prevented from running to some extend.
- pjc50 6y ago
- dvhh 6y agoThis was already in use in other game system (for example the xbox 360, see https://en.wikipedia.org/wiki/IBM_eFUSE https://en.wikipedia.org/wiki/IBM_eFUSE )
- felipelemos 6y agoThe article explicit says that on the very first paragraph.
- CodeArtisan 6y agoAlso in use in Samsung smartphones: https://en.wikipedia.org/wiki/Samsung_Knox#e-fuse https://en.wikipedia.org/wiki/Samsung_Knox#e-fuse
- slim 6y agoIt backfires like this : users are trained to never upgrade. Games that target a specific version lose sales.
- syspec 6y agoIn practice users don't even know what version they're on
- daveFNbuck 6y agoI don't think this applies to consoles like the Switch. I don't think the average user ever feels the need to revert to an earlier firmware version, and games don't target particular firmware versions. They tend to just work.
- ElCapitanMarkla 6y agoHow many people running CFW are buying games though?
- jowsie 6y agoWe do exist!
- hrktb 6y agoAs a user, I feel Nintendo has been pretty good about updates: they don't update a lot, and each updates has user facing features with QOL improvements. It's not in the same situation as iOS updates that were effectively slowing down the devices or Windows Update that don't seem to the user to bring anything.
- FakeRemore 6y ago> each updates has user facing features with QOL improvements You must be joking. The meme about "stability intensifies" with Switch updates isn't just a joke. Most of their updates are minor bugfixes and "increasing stability" (fixing exploits). They're far more interested in fixing exploits than they ever were in improving the OS in any meaningful way for the user. It's been 3 years and the only major QOL change I see on that list is making the all software page not useless. https://en.wikipedia.org/wiki/Nintendo_Switch_system_software https://en.wikipedia.org/wiki/Nintendo_Switch_system_softwar...
- outadoc 6y agoI'm unclear on how these hardware fuses actually work. Are they actual fuses that can be burnt on will by excessive power? When the article says: > The boot loader verifies a specific fuse, FUSE_RESERVED_ODM7, to prevent downgrading. Each software version expects a different number of fuses to be blown [...] Does this mean FUSE_RESERVED_ODM7 actually contains multiple fuses?
- ThePowerOfFuet 6y ago> I'm unclear on how these hardware fuses actually work. Are they actual fuses that can be burnt on will by excessive power? No, they're not like the fuses in your house. These can be blown by software to irrevocably change something which can then be verified later, or in other cases to prevent reprogramming of a microcontroller (which can be programmed only if the programming fuse is still intact. >Does this mean FUSE_RESERVED_ODM7 actually contains multiple fuses? No, that's the name of one fuse. Once you upgrade the device next time, the upgrade tool would, for example, blow FUSE_RESERVED_ODM8; older software would verify that this fuse (and the higher-numbered ones) are NOT blown, and refuse to boot otherwise.
- outadoc 6y agoThanks! Definitely more clear.
- arghwhat 6y ago> No, that's the name of one fuse. No, it's a 32-bit segment belonging to the 256-bit odm_reserved segment. FUSE_RESERVED_ODM7 is specifically the last 32-bit segment. Some fuse information can be read here: https://docs.nvidia.com/jetson/archives/l4t-archived/l4t-3231/index.html#page/Tegra%20Linux%20Driver%20Package%20Development%20Guide/bootloader_secure_boot.html https://docs.nvidia.com/jetson/archives/l4t-archived/l4t-323....
- arghwhat 6y ago"Fuses" in this context are just non-volatile memory that cannot be reset. Once a bit is set to 1, it stays there. They're often used for configuration and for things like sealing off programming/readout on microcontrollers. FUSE_RESERVED_ODM7 is 32 bits wide, hence contains "32 fuses". The system has many fuses, but 256 bits (RESERVED_ODM0-RESERVED_ODM7) are for the device manufacturers to use for their own purpose, which is what Nintendo is doing here.
- m101 6y agoWhy do they bother with this if someone is going to make a software workaround? Seems like people who would look to downgrade firmware might also be the same that would be able to implement the workaround.
- hd4 6y agoApathy. The vast majority of consumers won't bother. Also, the Switch's security was actually comparatively solid. It was a flaw in the Tegra X1 (thanks Nvidia!) component that led to an exploit being discovered.
- wolfgke 6y ago> There are 256 bits in the set of ODM_RESERVED fuses, and there are 8 ODM_RESERVED. This allows for 32 fuses, or 32 future FW versions (provided they burn a fuse on every major release). Can someone explain how the author gets from the numbers 256 and 8 to the count of 32 fuses?
- nitrogen 6y agoMaybe that's 256 bits divided into eight chunks of 32?
- indigo945 6y agoI think it's the other way around, there's 32 fuse-bytes of 8 fuse-bits each, adding up to 256 bits of PROM.
- marcan_42 6y agoFuses are in 32 bit words. There are 8 such words available for ODM usage, giving a total of 256 fuse bits. However, of those only one word is used for the anti-downgrade stuff. So that's just 32 firmware levels.
- adrr 6y agoWhat happens if some hacker finds a remote exploit and starts blowing all the fuses on people's devices?
- Maxious 6y agoLocal exploits are popular anyway, trick people into downloading the latest game which just wipes out the operating system https://www.nintendolife.com/news/2018/07/fake_nintendo_switch_game_piracy_software_is_bricking_systems https://www.nintendolife.com/news/2018/07/fake_nintendo_swit...
- londons_explore 6y agoIf this was widespread, Nintendo would just release a firmware without fuse checks.
- roblabla 6y agoMore like, they'd just release a firmware without the remote exploit in the first place. The consoles that got their fuses wiped would be bricked anyways, you wouldn't be able to install the firmware without fuse-checks on it through normal methods (Nintendo, however, could replace them easily).
- kiplkipl 6y agoThen they can already brick your device by replacing the firmware. This is the reason for threat models. Don't waste your time worrying about theoretical but redundant attacks.
- m-p-3 6y agoA massive recall and a world of hurt for Nintendo and Nvidia
- unnouinceput 6y agoNintendo switch emulator. Game over.
- classics2 6y agoClickbait title.
- monadic2 6y agoShameful, honestly.
- bibabaloo 6y agoI'm curious, how do Nintendo justify such an anti-consumer protection? It seems like it only really has upside for them.
- orloffm 6y agoJustify to whom? I am a consumer and this is irrelevant to me. And Nintendo has always been aggressively fighting emulation/homebrew, so it is nothing new.
- Jonnax 6y agoThey sell the machine as a single purpose box that plays games sold by them in their store. If someone buys it expecting something different that's really on them.
- manojlds 6y agoWhy is the upside only to Nintendo? If Nintendo can maintain a proper "hack free" device more third parties will be willing to release their games on the Switch - as a consumer my upside is that I get the games.
- bibabaloo 6y agoHuh, that's a really nice way of looking at it. I suppose I was thinking that it's my device that I've paid for so there shouldn't have unnecessary restrictions imposed on it. But it's true that I'd prefer a restricted device with a greater game library over an unrestricted device with no games!
- smichel17 6y ago> If Nintendo can maintain a proper "hack free" device more third parties will be willing to release their games on the Switch I don't think it's quite as cut-and-dry as this. - The draw of a "hack free" platform varies by genre. For competitive multiplayer games, it's a big draw. For single-player and creative games, you might find a larger market in less restrictive, more moddable, platforms (eg, if you were making a Minecraft clone, would you target Switch or PC?). - If the platform is popular enough, the level of lockdown may not affect the calculus that much. - And, of course, it depends on how successful these measures are at preventing hacks. There's a big difference in draw between 50%, 90%, and 100% hack prevention, because of how the knowledge of cheaters affects player perception. Eg, in a competitive game, knowing cheats exist can taint the experience of being outplayed, as you wonder whether your opponent was cheating. Overall, I'm not saying that GP's viewpoint is an invalid one, just that the tradeoffs are a little more nuanced than "more lockdown more games".
- lkjaero 6y agoMaybe this is a dumb question, but can these fuses be blown by accident? Eg: too much power in the switch. How do they mitigate this?