{"id":64050,"date":"2018-04-25T06:54:02","date_gmt":"2018-04-25T06:54:02","guid":{"rendered":"https:\/\/www.biphoo.com\/bipnews\/?p=64050"},"modified":"2018-04-25T06:54:02","modified_gmt":"2018-04-25T06:54:02","slug":"switch-hackers-say-nintendo-cant-patch-their-new-jailbreak","status":"publish","type":"post","link":"https:\/\/www.biphoo.com\/bipnews\/technology\/switch-hackers-say-nintendo-cant-patch-their-new-jailbreak.html","title":{"rendered":"Switch Hackers Say Nintendo Can&#8217;t Patch Their New Jailbreak"},"content":{"rendered":"<h2 style=\"text-align: justify\"><span style=\"font-size: 18pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">Switch Hackers Say Nintendo Can&#8217;t Patch Their New Jailbreak<\/span><\/strong><\/span><\/h2>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">This week, two hacking groups have independently released methods that allow a user to jailbreak the Switch, which one group is already using to run a ported version of Linux on Nintendo\u2019s device. The worse news for Nintendo\u2014the hackers say the exploit is due to a bug in the system\u2019s processor chip, meaning that Nintendo can\u2019t patch it out in a firmware update.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">The flaw revolves around the Switch\u2019s Tegra processor\u2019s USB Recovery Mode, or RCM, which hackers say can be easily overflowed with data using another computer tethered via the USB connection. Doing so makes it possible to bypass the security surrounding the Boot ROM, effectively opening Pandora\u2019s box in terms of what can be installed and run on the machine. This includes transforming the Switch into a handheld that can run Linux in addition to its standard \u201cHorizon\u201d operating system.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">While hackers had hinted at this vulnerability back in January of this year, this is first time several groups have discussed in detail how it works and what the consequences will be. The exploits were announced yesterday by the hacking group ReSwitched, which is calling its method Fus\u00e9e Gel\u00e9e, and today by Fail0verflow, which calls its ShofEL2. While both methods involve different code, the steps are similar and utilize the same bug in Nvidia\u2019s Tegra X1 processor. Because the bug is in the chip\u2019s hardware, rather than the code, the groups say that there is not much Nintendo can do at this point besides fixing it for the consoles it sells in the future.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">\u201cSince this bug is in the Boot ROM, it cannot be patched without a hardware revision, meaning all Switch units in existence today are vulnerable, forever,\u201d the group Fail0verflow wrote on its blog. It\u2019s unclear when Nintendo and Nvidia became aware of the problem and whether or not the companies have begun taking steps to address it, but since there are already 14.8 million Switches out in the wild, the vulnerability is already widespread, and includes any Android devices which also use the Tegra X1.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">While initiating the exploit is extremely complex, and not currently user-friendly enough for your average Switch owner to attempt, an important part of it relies on shorting the number 10 Pin in the Switch\u2019s right-hand Joy-Con connector. This what initiates the Tegra chip\u2019s recovery mode, at which point users can take advantage of the flaw in the chip allowing data overflow to access the Boot ROM. It\u2019s a pretty devastating bug in terms of security for the console as well, with consequences far beyond hackers simply being able to run custom operating systems. \u201cSince the vulnerability occurs very early in the boot process, it allows extraction of all device data and secrets, including the Boot ROM itself and all cryptographic keys,\u201d the group wrote.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Both exploits are currently in their early stages. Fail0verflow claims it has Dolphin, the GameCube and Wii emulator, running on Switch, which foretells a future in which Switch owners can load up their devices with classic Nintendo games (or anything else) without paying a dime. But the method is not exactly user-friendly at this point, so it\u2019s unlikely the average Switch owner will want to go messing around with hardware-level tricks just to play Luigi\u2019s Mansion.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Fail0verflow, in its FAQ, writes that it\u2019s easy to break platforms like Switch by running bad software on them. \u201cWe already caused temporary damage to one LCD panel with bad power sequencing code,\u201d it wrote. \u201cIf your Switch catches on fire or turns into an Ouya, it\u2019s not our fault.\u201d<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">These two exploits are how people have been able to upload the system\u2019s Boot Rom data to places like Pastebin, where it appeared over the weekend, leading other people to begin sharing their own information about the security flaw as well. ReSwitched decided to share its breakdown of what it\u2019s calling the \u201cFus\u00e9e Gel\u00e9e coldboot vulnerability\u201d this week, ahead of a more complete explanation of its findings on June 15.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">\u201cFus\u00e9e Gel\u00e9e was responsibly disclosed to Nvidia earlier, and forwarded to several vendors (including Nintendo) as a courtesy,\u201d wrote ReSwitched hacker Katherine Temkin in an FAQ about the exploit.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Fail0verflow, whose exploit utilizes the same bug in the Tegra chip, decided to likewise reveal its own findings alongside everyone else\u2019s in an attempt, it says, to separate its work from the attempts at software piracy that will likely follow from it. \u201cThe bug will be made public sooner or later, likely sooner, so we might as well release now along with our Linux boot chain and kernel tree, to make it very clear that we do this for fun and homebrew, and nothing else,\u201d the group wrote in its post.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">These exploits aren\u2019t the only way that hackers are trying to open up the Switch to run all software. As Ars Technica reports, another group called Team-Xecuter has been working on a modchip it plans to sell that would also allow custom code to be executed on the Switch. ReSwitched\u2019s announcement of the Fus\u00e9e Gel\u00e9e bug could be partially an attempt to get ahead of that group\u2019s release, whose methods Temkin disagrees with.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">\u201cNot just do they publicly endorse piracy, and seek to profit from keeping information to a few people, but they\u2019re also willing to drop a 0-day that affects a broad swathe of devices on the public without any responsible disclosure,\u201d she wrote in her FAQ. \u201cAll in all, I think that Team Xecuter seems to be without morals or scruples, and I am happy to do as much as I can to reduce their profitability and thus disincentivize these kinds of awful behaviors.\u201d<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">While it seems that Nintendo\u2019s ability to address the flaw in the Switches currently on the market is limited, it could still alter the hardware it sells in the future. Eurogamer\u2019s Digital Foundry speculates that it\u2019s possible the T214 Tegra processor referenced in a Switch 5.0.0 firmware update could signal the company already has plans to move away from the compromised T210 model the exploits are currently dependent on. Nintendo did not immediately respond to a request by Kotaku for comment.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 8pt;color: #000000\">Source:-https:\/\/kotaku.com\/switch-hackers-say-nintendo-cant-patch-their-new-jailbr-1825508582<\/span><\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.biphoo.com\/bipnews\/technology\/switch-hackers-say-nintendo-cant-patch-their-new-jailbreak.html\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground: #ffffff !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 630px !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>Switch Hackers Say Nintendo Can&#8217;t Patch Their New Jailbreak This week, two hacking groups have independently released methods that allow a user to jailbreak the Switch, which one group is already using to run a ported version of Linux on Nintendo\u2019s device. The worse news for Nintendo\u2014the hackers say the [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":64051,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[692,133865,14505,12073,14823],"class_list":["post-64050","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology","tag-latest-technology-news","tag-switch-hackers-say-nintendo-cant-patch-their-new-jailbreak","tag-technology-news-headlines","tag-technology-news-today","tag-technology-news-usa"],"_links":{"self":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/64050","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/comments?post=64050"}],"version-history":[{"count":0,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/64050\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media\/64051"}],"wp:attachment":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media?parent=64050"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/categories?post=64050"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/tags?post=64050"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}