22 ms·
Nintendo Switch prevents downgrades by irreparably blowing its own fuses (2020)
- tormock 5y agoNintendo is worst then Facebook (in different ways)
- deleted 5y ago[deleted]
- Wowfunhappy 5y agoNintendo creates works of art. Facebook creates ad platforms. I wish Nintendo's consoles were less restrictive, but there are worse evils.
- DaiPlusPlus 5y agoOne of Apple's defenses against EU regulators wanting them to allow side-loading is downright whataboutism as they point to games-consoles as similarly locked-down, single-marketplace platforms that extract the same 30% cut of sales revenue from developers. And there are plenty of non-game titles on the Xbox and PlayStation stores (Netflix, alternative web-browsers[1], even a Google Stadia client... sort-of [2]), so I'm surprised you're applying double-standards to games-consoles when they're almost identical in nature to Apple's walled-garden. [1] https://www.windowscentral.com/internet-browser-may-be-removed-xbox-store-grab-now-or-risk-missing-out https://www.windowscentral.com/internet-browser-may-be-remov... [2] https://www.reviewgeek.com/98799/you-can-now-play-google-stadia-games-on-xbox/ https://www.reviewgeek.com/98799/you-can-now-play-google-sta...
- judge2020 5y agoWhile I generally agree, I think the point most people have with being OK with game consoles and not iPhones boils down to: A. Game consoles are sold at a loss or very near-cost; often they only end up making some <5% per-unit profit due to the sheer volume of their production. Devices with direct evidence for this are PS5[0] and Steam Deck[1]. For iPhones, it can feel unfair when apple is making app store margins on top of their 30%+ per-device margins, but I support the idea that Apple's profit margins take into account app store margins and the devices would be x% more each year if developers could go completely without IAP for in-app digital purchases. B. Nintendo et al. specifically sell these as "game consoles", so combined with (A), it feels fine that they get their 30%. For iOS, being locked into the App Store serves only the purpose of total security, where basically nothing downloaded from the app store can siphon data from other apps via a sandbox escape or otherwise jailbreak the phone for silent spyware purposes. 0: https://www.techradar.com/news/ps5-has-only-just-stopped-losing-money-for-sony-but-thats-normal https://www.techradar.com/news/ps5-has-only-just-stopped-los... 1: https://www.nme.com/news/gaming-news/gabe-newell-says-steam-decks-aggressive-pricing-painful-but-critical-2995253 https://www.nme.com/news/gaming-news/gabe-newell-says-steam-... (pretty heavily implied; Steam will also end up making money post-sale via their 30% cut)
- Wowfunhappy 5y agoI'm not happy that the Nintendo Switch is locked down, and any ruling against Apple which also applied to console manufacturers would be great news in my book. I just have better things to be angry about. The thing is, I feel quite comfortable asserting that nobody uses a Nintendo Switch as their primary computer. If an app isn't available on the Switch, people can download it on something else. If an app isn't available on the iPhone, protesters in Hong Kong die: https://news.ycombinator.com/item?id=21210678 https://news.ycombinator.com/item?id=21210678 Locked down consoles are regrettable; locked down phones are an affront to free society.
- tormock 5y ago> I'm not happy that the Nintendo Switch is locked down, and any ruling against Apple which also applied to console manufacturers would be great news in my book. I just have better things to be angry about. I'm just sad about where the technology world is heading
- Wowfunhappy 5y agoWell, I guess that's the other thing—Nintendo has been doing this for as long as they've been in the business. The NES launched with a so-called "lockout chip" to block unlicensed software. This was a key part of Nintendo's strategy for the NES, which launched after the so-called video game crash of 1989, when consumers stopped buying video games because they'd been burned by too many low-quality cash grabs. Nintendo's "seal of quality" program enforced very high standards, unlike anything seen on any platform today. I hesitate to bring this up, because an old bad thing is still a bad thing. But it's not a new bad thing.
- kyle_martin1 5y agoThis is common in modern embedded devices. Sometimes they're called eFuses. https://imxdev.gitlab.io/tutorial/Burning_eFuses_on_i.MX/ https://imxdev.gitlab.io/tutorial/Burning_eFuses_on_i.MX/
- senectus1 5y agoyup, Samsung Phones have them as well. a clever but despicable tool.
- moloch 5y agoYeap, I think the Xbox 360 was the first (or one of the first) to implement this protection back in 2005 - https://www.youtube.com/watch?v=uxjpmc8ZIxM https://www.youtube.com/watch?v=uxjpmc8ZIxM
- eigenform 5y agoWii and PS3 too :)
- josephh 5y agoHas there been any research on reseting these fuses via fault injection attacks?
- willcipriano 5y agoI believe it's irreversible, they need to be replaced not reset.
- RajT88 5y agoIf it could be reset, it'd be a breaker, not a fuse. ;)
- tuankiet65 5y agoThe fuses aren't being protected from modifications by the firmware, but they are physically burnt - no way to reverse that.
- bumblebritches5 5y ago
- paulcole 5y agoVery cool idea to accomplish what they wanted!
- encryptluks2 5y agoThis is why emulators are so great. Companies want you to rent everything and convince you that you're happy to do so.
- fundmondawyaya 5y agoNintendo is probably still feeling burned by the NDS. It was a fantastic console, and fairly open. It had two ARM CPUs (one per screen), and there was a terrific homebrew scene. Some of my first embedded C programs were for the NDS lite. It had ebook readers, paint programs, a toy Linux port, the whole 9 yards. But, that openness also made it open to piracy. The way you loaded code onto the system was through "flashcarts". They were shaped like game cartridges, but they had a microSD slot on the top and an internal MCU which often ran a firmware that could load game ROMs from the filesystem, and even add features like cheats and save-states. The widespread availability of those devices dramatically shrank the market for NDS games. Developers were dropping off the platform well before the 3DS came out, and Nintendo started to pay much more attention to DRM. It was sort of a sad situation. The ability to write your own software for a handheld game console was amazing in the 2000s, but that openness ended up suffocating the platform.
- tomrod 5y agoThey should adjust the business model to address market demand. Be a platform, not (just) a console. Works great for Apple and Play!
- fastball 5y agoApple has put a lot of effort into making app piracy very difficult on their platform, arguably more than Nintendo.
- baud147258 5y agoBeing just a platform didn't work so well for Atari (see the crash of 1983). And both the Apple and Play stores have a terrible reputation for allowing (nearly) anything on their stores, which is something that Nintendo would want to avoid.
- dyingkneepad 5y agoThere is one thing about video-game piracy that I never understood. Back when I was a kid, there was a lot of piracy for Playstation 1 games. In my home country you could buy any game for the price of a Big Mac. It didn't matter that the game CDs contained copy-protection, the CDs you could buy also had them and were indistinguishable from the original CDs. Then PS2 came (or was it PS3?) and all the pirate CDs/DVDs simply disappeared. I never understood what made game media piracy nonviable with newer consoles. Why can't the pirates simply copy every single bit of the newer game media as they did before?. I think the WII had some piracy CDs easily available but you also had to mod your console somehow. I'd be happy to have an answer from any of the hackers here :). Edit: I'm not talking about "home piracy" where you copy your CD in your PC using cloning software, I'm talking about industrial one, you could buy these games in real stores that also sold other stuff brought from China.
- sefrost 5y agoI can remember people brazenly advertising console "chipping" in my local newspaper in the UK. I don't know why it stopped when we went from PS1 to PS2 (or Xbox).
- blamazon 5y agoThings like this I reckon: https://en.wikipedia.org/wiki/Operation_Tangled_Web https://en.wikipedia.org/wiki/Operation_Tangled_Web
- RajT88 5y agoFrom what my memory recalls, the PS2 era was when Sony started going after companies which made not just modchips, but any kind of device which let gamers use their consoles in ways they did not like. Think: Adapters which let you use PS2 controllers on an Xbox and vice versa. Lik-Sang was (again as I recall) the primary target of all this, and was eventually forced to shut down. They were definitely the single best place to buy console modding and other weird and crazy accessories from Asia. After the first volley, Sony and the rest started going after the smaller players, the local console modders, the ROM hosting sites, eventually even the hackers who discovered vulnerabilities themselves. 2002 was when they came for Lik-Sang and it had an immediate chilling effect, and they shut down as of 2006. https://en.wikipedia.org/wiki/Lik_Sang https://en.wikipedia.org/wiki/Lik_Sang By the way - chipping services still operate, but they have a lot of ways of flying not under the radar exactly, but operating in ways which make it not worth it for Sony, Nintendo from going after them. Doing their manufacturing in China (of course), sales from various parts of eastern Europe, and the direct modding services being super-small time modders operating off local sites like OfferUp, Craigslist, or sometimes even eBay. It's overwhelmingly previous generation consoles they offer services for.
- jotm 5y agoTechnically pretty interesting, but I'd never buy something like this. Had enough of encrypted BIOSes that you can only downgrade using a hardware programmer, and Samsung's Kox protection (actually also eFuse) which fortunately only blocks their proprietary garbage from being used ever again. I pay to own not get owned.
- tuankiet65 5y agoToo bad Nintendo produces some of the most popular game franchises like Pokemon or Zelda, and the only way to play them is to buy their hardware. I used to resist buying a Switch, but Breath of the Wild was such an amazing game that I had to get a Switch myself. And to be honest, other consoles are locked down in the same manner. Probably the most open "console" one could get right now is an x86 PC.
- TAForObvReasons 5y agoYuzu is a Switch emulator for computers https://github.com/yuzu-emu/yuzu https://github.com/yuzu-emu/yuzu Skyline is a Switch emulator for android https://github.com/skyline-emu/skyline https://github.com/skyline-emu/skyline Both still require an actual console for actually making backups of your games.
- em500 5y agoI don't know about Skyline, but for Yuzu it's trivial to download prod.keys and nsp/xci of every game and play anything without paying anyone a dime.
- ansible 5y agoI agree. I used to worry more about DRM, at least when it came to books. These days, it is all about convenience. And the realization that I'm not going to live forever, and how many more times am I really going to read this particular book. Because that's what it is all about. There is some (not large) risk I will loose access to my Amazon account, or Google, or whatever. But for most books, if I get a couple reads out of them, that's practically all the value to be extracted for me. Because of DRM, there is some small chance that I will loose access to a book that is truly a classic, one that deserves to be read repeatedly. In that case, it is OK to just buy it again in some other format, and give the author a little more money (yes, I know not all of the book's sale price goes to the author in most cases). Some of my most favorite works I have purchased multiple times, and I don't regret it. It is the same for games. If you want an exemplary open-world experience, you get a Switch, and buy Breath of the Wild. You then experience it (over months or however long you want to play it) and then it is over. There will probably be something else that will capture your attention next year anyway. If, ten years from now, you really want to play BotW again, and you don't have a Switch, I'm sure buying a used one would work fine. Or else get the current-gen console, and buy the heavily discounted version on that.
- savant_penguin 5y agoThis is an interesting idea, but quoting Stalin, isn't the really important thing the program that counts the burnt fuses? Maybe that's also exploitable Anyway, the article also says that an exploit is already available to bypass that
- deleted 5y ago[deleted]
- xdavidliu 5y agoout of curiosity, what was the original Stalin quote? I'm guessing something like "the important political position is the one that assigns positions to others" or something like that? I would google, but unclear what to search for.
- pxx 5y agoIt's not actually a Stalin quote. See e.g. https://fanaro.io/articles/quote_2_stalin/quote_2_stalin.html https://fanaro.io/articles/quote_2_stalin/quote_2_stalin.htm... or https://www.politifact.com/factchecks/2019/mar/27/viral-image/no-joseph-stalin-didnt-say-statement-about-electio/ https://www.politifact.com/factchecks/2019/mar/27/viral-imag...
- savant_penguin 5y agoJust got busted I did not know this is a false quote :)
- cyounkins 5y agoThere are things called fuses on AVRs that cannot be changed by running code but can be set and unset multiple times by an external programmer. These are apparently different. https://en.wikipedia.org/wiki/Efuse https://en.wikipedia.org/wiki/Efuse describes the mechanism of action: "eFuses can be made out of silicon or metal traces. In both cases, they work (blow) by electromigration, the phenomenon that electric flow causes the conductor material to move."
- greggsy 5y agoI think Samsung used these for Knox?
- lucb1e 5y agoCorrect. It's a pain in the bum. I might add that Fairphone has an official procedure to flash the original rom and re-lock the bootloader, I tried it with the FP3 at least and that worked on the first try.
- Rebelgecko 5y agoThey're pretty common in TPM-like things
- 4gotunameagain 5y agoAVR fuses are regular non volatile memory, just specifically for configuration purposes
- retSava 5y agoAha, I was under the impression that it was simply and literally a question of passing too much current through a conducting trace internally, causing the internal resistance to overheat it, thus melting it. Perhaps that would be a method too unreliable or something. Perhaps I should read the wikipedia entry before speculating :).
- londons_explore 5y agoThere are a bunch of ways to make efuses. Modern ones are typically flash memory that simply doesn't have the circuitry for erasure.
- gjsman-1000 5y agoIf you think burnable fuses to prevent downgrading is interesting, wait until you see the black magic that Apple cooked up to prevent iPhone downgrades. No fuses there - just an incredibly complex mess of nonces, digitally signed tickets, and secret generator keys.
- gnabgib 5y agoiPhone.. famously home to burnable fuses[0][1] (although in principal they're for security/unique device identification) [0]: https://www.theiphonewiki.com/wiki/Security_Fusings https://www.theiphonewiki.com/wiki/Security_Fusings [1]: https://www.theiphonewiki.com/wiki/ECID https://www.theiphonewiki.com/wiki/ECID
- w0mbat 5y agoApple internal iOS devices used by engineers are "dev-fused". This hardware configuration opens up the device to some extent, allowing Apple engineers more latitude when developing software. There have been articles saying that Apple lets some third party security people use these devices. E.G. https://macdailynews.com/2019/08/06/apple-hands-hackers-secret-iphones-in-a-bid-to-boost-security-to-offer-apple-mac-bug-bounty/ https://macdailynews.com/2019/08/06/apple-hands-hackers-secr... I can see how giving that access that might make sense, but I don't know if that article is true. Dev-fused devices would also be very useful to Apple adversaries like NSO in developing hacks so I would actually expect Apple to continue to keep tight control over them.
- saagarjha 5y agoApple does not provide third parties access to developer fused devices. They do have a "security research device" program that allows nominally more access to the device, kind of equivalent to most jailbreaks these days, but definitely falling short of a development fusing or what something like checkra1n would get you.
- throwaway201025 5y ago> Apple internal iOS devices used by engineers are "dev-fused". We at Samsung use a similar mechanism called Anti Rollback Prevention (ARP). It is a switch that can be enabled for normal devices if the employees using them are given an approval by their boss. Only a handful of employees have access to it, and the switch turns off by itself after a defined period.
- deleted 5y ago[deleted]
- Commodore63 5y agoThe Xbox 360 Xenon chips also had efuses to prevent downgrades.
- 14 5y agoHackers eventually found a way to downgrade but you would not be able to connect to Xbox live. It did allow you to hack the Xbox and play pirated games and homebrew.
- willcipriano 5y agoYou could connect to Xbox live if you had one of the undetectable modchips with a switch that allowed you to flop between regular and modded firmware. Even with modded firmware you could go on live for a while, even cheat at multiplayer games flying around and stuff until you got banned.
- Jerrrry 5y agoironically, the modchips were only "undetectable" because MS never thought a KV (the keyvault containing the RSA keypair tied to that mobo serial) would not match the motherboard it ran on. The first players to use a xenon keyvault on a jasper mobo got away with it for years just because MS overlooked a decent assumption.
- 14 5y agoWell this might not be entirely true. Hackers found a way to downgrade the Xbox 360 after fuses were blown but you would not be able to use online functions with your home brew or pirated games unless they developed a dual kernel boot and used a normal kernel and no home brew to go back online. https://www.engadget.com/2007-08-25-efuse-successfully-blown-xbox-360-kernel-downgrades-possible.html https://www.engadget.com/2007-08-25-efuse-successfully-blown...
- Jerrrry 5y agoIt was possible, just incredibly difficult, to correctly respond to the challenges requested, and stay online, undetected, indefinitely.
- trevor-e 5y agoHow is this considered legal? I get the cat and mouse chase between devs and the reverse engineering communities, but this seems to cross the line into physical destruction of property, at least at face value.
- xwdv 5y agoIf we didn’t have profit protection measures like this everything would be much more expensive and that’s not a better alternative for most consumers.
- Sosh101 5y agoWell that's a whole other debate, but I'd like to know the legality now.
- xwdv 5y agoYou agreed to the terms of service. There is little to nothing you can do.
- Sosh101 5y agoYou can't write just want you want in an agreement. There are things that are not legally enforceable - even if the other party has agreed to them.
- ryandrake 5y agoI wonder if a company included "We have the right to send a company agent to enter your home and destroy this product." in their Terms Of Service, and you "agree" to it, would that simply allow them to do so? EDIT: I am not a lawyer, but I've always been surprised that Terms Of Service and End User License Agreements aren't routinely voided by courts. Aren't they perfect examples of unconscionable and adhesive [1] contracts? These seem to tick all the boxes: One-sided, no meaningful choice, no meeting of the minds, significant differences in bargaining power between the parties, no ability to negotiate, take-it-or-leave-it terms. You'd think these things were total junk, but they're everywhere and somehow enforceable? Why? 1: https://www.jensenlawmn.com/adhesion-contracts-unconscionable https://www.jensenlawmn.com/adhesion-contracts-unconscionabl...
- Animats 5y agoComing soon to a car near you.
- userbinator 5y agoRemote attestation is the enemy of our freedom.
- kccqzy 5y agoRemote attestation isn't inherently evil. Remote attestation can protect your privacy too. You can run code on a public cloud, with remote attestation proving that the cloud provider cannot read the memory of your VM, even if they use a malicious hypervisor. (That's of course assuming in your threat model you trust the hardware maker but not the cloud provider. The sentiment in this thread is clearly don't trust the hardware maker.)
- mindslight 5y agoOr you can just run security-critical code on your own hardware on your own premises, as has been and will always be the answer for strong security. If a legal contract with a datacenter is not enough of a security guarantee, then neither is a wink from a hardware manufacturer. The societal downsides from abuse of remote attestation - eg computational disenfranchisement of end users - far outweigh any claimed benefits.
- eru 5y agoWith secure attestation you only need to trust eg Intel and only when they manufactured your device, and not random cloud providers forever. Of course, running on your 'own' hardware is a fiction, too: companies themselves are made up of contractual relationships, fiduciary duties and other legal devices. Even if you are running your software on your own in-house datacentres, remote attestation is still useful. (Just like git's commit hashes are still useful, not only when your code lives externally on github, but even when some other department of the same company is hosting your source code.)
- Jerrrry 5y agoeFuses get physically melted by software. Microsoft bricked thousands of illicit China-developer xbox360 kits one spring morning, in the winter of 2010. they also have bricked retail xbox360 consoles of nefarious (teenage) actors. cannot go into more detail on that one. maybe after a few more years.
- water8 5y agoSorry I modified the dvd firmware when I was a teenager. It was really important to me to get level 50 in Halo 2. Hope you can understand lol.
- Jerrrry 5y agoIt's okay. I had a 50 in every H3 playlist, and my own cease and desist letter from a few different AAA companies. We've all been there...
- sharken 5y agoEven John Carmack got in trouble with the police at one time. Luckily he got off with a warning.
- deleted 5y ago[deleted]
- _fat_santa 5y agoI fondly remember flashing my DVD drive on my 360 when I was 15 to play Saints Row (I had an ITCH for a GTA like game). Back then I was scared shitless of possibly bricking it. Now looking back, I laugh because of how trivial the mod was. Pretty sure this was a major contributing factor to me eventually perusing tech in my career.
- KyleJune 5y agoModding Xbox/Xbox 360 was for many people. I got started programming with writing CoD MW2 mods.
- hnthrowaway0315 5y agoNot a console player, can someone explain why consumers want to downgrade their console(s)? I Googled a bit and it seems people would like to have more vulnerable to hack their devices, but why did they upgrade in the first place? Is it forced upgrade?
- gfxgirl 5y agoI upgrade because the new game I want to play won't play if I don't. Also the on console store will refuse to work.
- justapassenger 5y agoYou don’t control initial version you get when you buy it (either new or second handed). Often you also first use stock before you learn about/want to start hacking it.
- hnthrowaway0315 5y agoThanks, yeah with hardware there is a lot of complexity. I guess if someone owns a Switch with original firmware, it might be sold with a premium?
- ajmurmann 5y agoDon't know about Switch, but I recently sold a PS4 Pro on eBay and I got a ton of requests to please at the firmware version because they wanted a particular old version that can be rooted
- naikrovek 5y agoNearly forced. once the console downloads the update, it will be applied automatically upon reboot. The alternative is to never connect to WiFi, ever, and some do that. Generally, consumers would want to downgrade because older versions have vulnerabilities that are fixed in newer versions. these vulnerabilities allow console owners to do what they want with their hardware, and gaming communities have shown Nintendo time and time again that if it is possible to use game hardware for game piracy, it will be widely used for that purpose. Those of us who want a neat standardized hardware platform to hack on without pirating anything are in the noise floor for companies like Nintendo, so we have no representation among neither pirates nor the console manufacturer.
- neonihil 5y agoI believe we need new laws declaring that consumers can run whatever versions of software they want on devices they OWN. This applies to iPhones, Gaming consoles, and Teslas too. Companies must allow downgrades, and consumers must be able to permanently disable update prompts.
- ineedasername 5y agoWhich jurisdiction are these laws?
- neonihil 5y agoI meant we need these new laws. (Fixed in original comment)
- passerby1 5y agoYes. By the way, the parent comment highlights an important point of having lots of countries and jurisdictions which has very different view on this. My prediction is that it will be fragmented.
- _ehqz 5y agoPretty simple fix to the problem. Just destroy any company that doesn't comply with the will of the people. (yes, I know this is problematic, but companies like Nintendo for example need to be brought to heel.)
- foobaw 5y agoQualcomm did the same thing on their phones back in the days (known as QFUSE). Not sure about right now.
- nhoughto 5y agoWhy does it need to physically modify the hardware via melting fuse when that fuse is read by enclave / boot loader code itself? If trusted code is trusted then couldn’t it store its state securely without melting fuses? I must be missing something, either the bootloader execution is trusted and should be able to store state securely, Secure Enclave style, or it’s not and melting things doesn’t solve the problem as compromise of the code means the fuses can be ignored..
- charcircuit 5y agoOld updates are considered trusted since they were signed by the manufacturer. The state of (a least an approximation of) the current verision is stored using efuses as state. If you had a secure enclave that had long term storage it it, but prevented decrementing the version would be equivalent, but efuses are much simpler of a construction.
- nhoughto 5y agoah right so they do this to avoid having a proper secure enclave, like a very focused secure storage capability related to what the efuses are logically related to. Makes sense, I guess i just assumed they would have a secure enclave like phones etc as consoles are one of the original 'trusted computing' devices that people buy and obviously to avoid piracy etc having it work properly is important but also hardware BOM is a consideration too. I guess the secure enclave having storage introduces another attack too, wiping/corrupting/replacing that storage somehow, thus efuses, simpler and more straightforward.
- qiqitori 5y agoHmm, I have done some work in this field but obviously haven't seen all the board variations out there. The secure enclave (let's call it that because you did) will usually contain a master key that facilitates crypto operations on things in storage. This master key may be programmed using e-fuses. This is a one-time operation (and yes I have once accidentally written a key that I didn't want to write on a development board). You may only get secure storage and secure boot etc. once that is set up. So when the board already has e-fuses on the board it's not a big deal for the manufacturer (of the board) to include a couple or even a whole bunch extra for whatever the user (i.e. manufacturer of the device) has in mind. For example, you may be able to invalidate a master key and add a new one, up to n times. Search for e.g. 'imx e-fuses' for details (or try this link https://imxdev.gitlab.io/tutorial/Burning_eFuses_on_i.MX/ https://imxdev.gitlab.io/tutorial/Burning_eFuses_on_i.MX/)
- roastedpeacock 5y agoMillion dollar question. Anyone know about the inner workings of the various Switch modchips that allow homebrew on newer consoles with RCM exploit patched?
- roblabla 5y agoLast I heard, it was doing some power glitching to bypass/nop-out some signature check or some such. There aren't much details in the public, but a very similar hack is publicly documented for the vita: https://arxiv.org/pdf/1903.08102.pdf https://arxiv.org/pdf/1903.08102.pdf .
- surewe 5y agoTo be more specific: they use voltage glitching during the BOOT0 signature check.
- elilev 5y agoA lot of android devices do this actually.
- shmde 5y agoI went to a 3rd party repair guy to get my PS4 slim repaired. He started talking about efuses and how if the companies detect anomalies in their firmware they blow the fuses so they have to take it back to main company to get it fixed. Its quite strange to see the topic a day after at the top of hackernews.
- bullen 5y agoWhat was wrong with the PS4?
- DeathArrow 5y agoPermanently altering the physical state of your device doesn't mean causing destruction from a legal perspective. I wonder if an owner can sue companies that do this.
- CraigJPerry 5y ago>> Each software version expects a different number of fuses to be blown — if more than is expected, it fails to boot That branch in the code could be interfered with. Over writing it with NOOP instructions might not be easily possible due to verification of code signing but there’s other techniques like power glitching.
- ChrisRR 5y agoIf it were that simple then downgrading hardware would be a breeze
- CraigJPerry 5y ago>> simple I don’t think anyone has ever referred to the process of power glitching a chip as “simple”.
- aa-jv 5y agoI unintentionally blow the eFuse on the Qualcomm chips I'm developing for, all the time .. its very frustrating and surprisingly easy to do with their tools. I'm ideologically opposed to using this feature 'productively', but it definitely makes it simpler (cheaper) for the company to maintain installed base versions...
- mort96 5y agoWhy and how does it make stuff easier for the company? Can't the company just... not support older versions of the software? What's the difference in burden on the company between a user who just declines updates for years and a user who installs upgrades but then downgrades again? Surely the customer support response in all cases is "install the latest version"?
- zamadatix 5y agoThe cability provides for a lot more than blocking software downgrades e.g. setting the boot signing key and then locking it with an efuse so only matching signed images can be booted or the inverse, enable unsigned custom firmware but blow a fuse to mark the device has been allowed to run custom software (which may impact hardware DRM systems during boot).
- mort96 5y agoI already understood that it allows companies to be user-hostile, that's not what I'm asking about. I'm asking how it makes it simpler/cheaper for the company to maintain installed base versions.
- zamadatix 5y agoBecause it allows them to lock in a signing key and manage custom user images. Regardless if you feel that is user hostile or not it does make it simpler/cheaper for the company to manage the installed versions. The only thing they ever need to validate and support is for is upgrading to their images the way they have specified.
- tentacleuno 5y ago> There are 256 bits in the set of ODM_RESERVED fuses, and there are 8 ODM_RESERVED. This allows for 32 fuses, or 32 future FW versions (provided they burn a fuse on every major release). 32? Is that it? So if Nintendo want to push more than 32 updates, they either need to not blow any more fuses, or stop using the fuses when they've all gone? Wouldn't they be totally useless then?
- rtpg 5y agoIt would be pretty tough to find 32 unique exploits! Remember, Ninty doesn’t need to burn one for each update, just for the ones they consider important enough.
- zamadatix 5y agoPrecisely, if 1 exploit downgrade block every 6 months for 16 years isn't effective enough then there is no number of fuses that are effective enough.
- deleted 5y ago[deleted]
- wodenokoto 5y agoAs far as I can read the chart, they only burn fuses in major updates, e.g., 9.x->10.x, but not x.7 -> x.8 So they must have some guidelines for what kind of features are worth burning a fuse. But yeah, 32 sounds low. Let's just hope number 32 has an easy exploit :)
- politelemon 5y agoAnd hopefully that is not currently a piece of tribal knowledge that gets lost over time
- Traster 5y agoThe Wii had 4 major versions over the lifetime of the product, and the Wii U had 5. So I think 32 is pretty generous.
- Epiphany21 5y agoCompanies can only get away with this crap because consumers are so still so darn ignorant. I think most people won't accept a car that prevents you from changing your own oil or replacing your own wiper fluid, so it always boggles my mind that so many are still buying computers that lock users out of the firmware and boot process. A Switch is just a toy anyways. Buy a different toy.
- Schroedingersat 5y ago> I think most people won't accept a car that prevents you from changing your own oil or replacing your own wiper fluid, so it always boggles my mind that so many are still buying computers that lock users out of the firmware and boot process. There are countless variations of this in cars. Changing a fuel pump or ignition control module or sometimes even disconnecting a battery activates 'anti theft' features in many cars and companies frequently use the DMCA to prevent repair and maintenance without $10k/year software licenses.
- dotancohen 5y agoI recently had to change the transmission in a '13 Juke. The battery was disconnected, and now three months later I still cannot use the radio. We have the placard with the unlock code, but the radio does not unlock. Had the dealer done the repair, I could probably fight with them to get the radio fixed. But with the independent shop that did the repair, whom I feel did nothing wrong, I do not want to pressure to repair the "collateral damage" that really isn't their fault.
- fxtentacle 5y agoThe reason why games on Switch can "just work" is that the OS provides the DRM. Otherwise, we would see rootkits, spyware, or always-online requirements like the DRM hell that we see with Windows games. It's a trade-off, and I believe there is space for both kinds of devices. I want an unlocked Linux PC and a DRM-monopolized-by-Nintendo Switch so that I can do tinkering, when I want it, but also enjoy games without much technical fuss.
- pixelbreaker 5y agoDoes this breach any right to repair laws?
- fiznool 5y agoAs per the article there are 32 fuses, meaning they can support 32 ‘irreversible’ firmware updates. There have already been 13. What happens when update #33 is needed? Or are they banking on the switch being superseded by that point?
- chrisdotbiz 5y ago13 fuses in 5 years. I don’t think the current Switch hardware is going to be supported for more than 10 years.
- rapjr9 5y agoDoes this mean the upgraded Switch can never be upgraded again? If the upgrade fuses are blown this would imply no further upgrades are possible. If Nintendo can bypass the fuses others might be able to also and hence downgrade their systems.