• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Huge Nintendo Switch exploit (potential hack) found on firmware 3.0.0

Yes, this is always the case. Based on the history of nintendo homebrew, they will find a way to work around this eventually.

I mean, you do understand that people can pirate games to their 3ds STRAIGHT FROM THE ESHOP, right? Nintendo is not good at this.
It's already been discussed by a handful of people in the scene here, you actually can't compare the effectiveness of the methods used on the 3DS with this system despite the fact that it's based on it. Very different scenario. It's like saying you can unlock a robot with a toothpick because that's what you used to reset a Buzz Lightyear Toy
 
You didn't bother reading I bet, but any firmware at 3.0.0 and lower legitimately can't access online pay or the eShop. They are stranded.


Don't be too sure about that. Anything beyond 3.0.0 is a different beast altogether.

They did the same thing on PS3, but you could update to custom firmware based on new versions to play newer games once they replaced the changed code in the firmware. Either way this opens up the entire system so it will be easier to find other exploits to take advantage of also.
 

Vena

Member
They did the same thing on PS3, but you could update to custom firmware based on new versions to play newer games once they replaced the changed code in the firmware. Either way this opens up the entire system so it will be easier to find other exploits to take advantage of also.

The firmware race is harder in more modern systems, you'll need a new major exploit and, eventually that to will be patched or reported to HackerOne. There's no telling how long it will take to get the keys from 3.0.1 and few will risk sacrificing a Switch on lower firmware due to the fuses. To keep up with the firmware you'd have to keep buying Switches.

PS4 was opened on 1.76, same story. PS3 ended on 3.55.

It took months for this to go public, 3.0.1 isn't even being touched yet by the scene because they can play around in 3.0.0. So who's going to crack 3.0.1 any time soon?
 

Samemind

Member
Wait, what?! How is such a thing even possible lol!!!

The main thing I think is that they didn't make a network account mandatory to use the eShop. This allows you to buy games without providing Nintendo any identification that's stored outside the device. After gaining full control of the device, I guess it was pretty simple to spoof anything you needed to tell Nintendo's servers, since they relied entirely on what you were telling them.

Some of this might be inaccurate, but I think it's close enough.
 

Olimar

Neo Member
As optimistic as this sounds, it'll be a long while before we have any type of homebrew for the Switch. There is no major understanding of the Switch OS nor how to build binaries for the system, let alone injecting them. This is great for developers so that we can have this later in the future, but for anyone else it's really not too useful.

Hopefully the wait is short.
 
It is a download tool that takes the files straight from Nintendo servers, not EXACTLY downloading from the eshop for free

No, there's a method to download DIRECTLY from the ACTUAL eShop. It's ridiculous. But it doesn't seem to be stopping Nintendo from supporting the system, so that's good.
 
The main thing I think is that they didn't make a network account mandatory to use the eShop. This allows you to buy games without providing Nintendo any identification that's stored outside the device. After gaining full control of the device, I guess it was pretty simple to spoof anything you needed to tell Nintendo's servers, since they relied entirely on what you were telling them.

Some of this might be inaccurate, but I think it's close enough.

Man, I always thought Nintendo was really bad at online systems, but this one exceeded my wildest expectations.
 
This early in the system's life I don't think it's worth holding off on updates for exploits.

I bought a Henkaku friendly Vita since the system isn't getting any more games I care about, and being able to play my full PSP library on my Vita is worth giving up online and PSN access.

But with the Switch, it will still have a full, healthy online scene for years to come, and I have enough devices that will play classic Nintendo games (n3DS, Wii U, GBA, etc) that I don't really need to have that on my Switch just yet.
 
Man, I always thought Nintendo was really bad at online systems, but this one exceeded my wildest expectations.

It's not exclusive to Nintendo; I believe the same could be done on hacked PS3s, downloading pirated games from PSN servers.

People keep saying Nintendo is terrible at securing their systems, but it's a very difficult problem that every company, organization and piece of software struggles with. Every major OS in use today gets frequent updates to patch newly discovered exploits, including Microsoft, Google, Apple, etc.
 
Here's to hoping I don't need 3.0.1 to play Mario Rabbids or Odyssey.

AsVP6u7.gif
 
Someone once told me the grass is much greener on the other side...

If I do actually keep this second Switch, I'll always feel inferior to the 3.0.0 people because mine will be the 2.2 or 2.3 FeelsBadMan
 

Vena

Member
My switch will come today. Anyway to check firmware version before setting it up?

It will be 2.2.0 or 2.3.0, just don't connect it to the internet.

Be mindful, though, that you'll be unable to use new software going forward because it will have a patch on the cart for 3.0.1 or higher, and it won't play unless you update.
 
It will be 2.2.0 or 2.3.0, just don't connect it to the internet.

Be mindful, though, that you'll be unable to use new software going forward because it will have a patch on the cart for 3.0.1 or higher, and it won't play unless you update.
Which software is 3.01 or higher that's on cart so far? Wanna play Zelda and Mario Kart without worrying.
 

Vena

Member
Which software is 3.01 or higher that's on cart so far? Wanna play Zelda and Mario Kart without worrying.

None yet, that was a warning about going forward.

You'll not be able to play MK online, though. Nor can you get the DLC for Zelda, or any of the performance patches.
 

domocoma

Neo Member
Looks like Targets did a restock last night for anyone looking to pick up another Switch (I'm in MN). The one near me had at least 10.
 

Platy

Member
I believe Splatoon is on cart either 2.3 or 3.0, but I don't know for sure. But Splatoon is also kind of useless without online.

A switch right now is useless without updating.

Mario Odyssey, Pokemon, Fire Emblem, Yoshi, Kirby, Smash 5, Mario Kart 9 ... hell even if they made Sonic Mania 2 chances are that you will not be able to enjoy it.
 

Permanently A

Junior Member
Looks like Targets did a restock last night for anyone looking to pick up another Switch (I'm in MN). The one near me had at least 10.

If I wanted to go out and buy a switch right now, what firmware would it be at? And what games would be playable without updating past 3.0?
 
Amazon still hasn't charged my card or began processing my order from 2 days ago, and I'm having second thoughts about keeping it... when I think about the things I could buy with the price of a new Switch that will likely go unused for months or longer, suddenly seems crazy.

Then again I don't want to kick myself for not securing hackable Switch when I had the chance...
 
Amazon still hasn't charged my card or began processing my order from 2 days ago, and I'm having second thoughts about keeping it... when I think about the things I could buy with the price of a new Switch that will likely go unused for months or longer, suddenly seems crazy.

Then again I don't want to kick myself for not securing hackable Switch when I had the chance...

Might as well keep it to the holidays. If the hack isn't public by then you could probably sell it if there is still a shortage.
 
Might as well keep it to the holidays. If the hack isn't public by then you could probably sell it if there is still a shortage.

Yeah, thanks for reminding me of the rationale for ordering it in the first place. I'm currently saving money for a few-thousand-dollars purchase that I'm planning to make in a few months, so I look at this as "converting" $300 (actually $390 since I'm importing it) into a Switch that I should be able to sell if I need to (might lose ~$25 on it but I'm willing to take that hit if it came to it). I'm not going to be spending the money on anything else for at least three more months (and I might not need them depending on how my financials pan out), so might as well put them into an item that has the potential to be very useful to me and which will likely become much harder to acquire later on.
 

FStubbs

Member
So I'm not understanding. Does it mean the golden age of piracy ... I mean homebrew has started on Switch?

That's too bad if so.
 

epmode

Member
If I wind up buying a second Switch to keep fully updated, how can I get my currently-owned digital games onto the new console without being able to connect the old system to the eShop? Do I have to hope that Nintendo will transfer my purchases? Do they ever reject such requests?
 

epmode

Member
Is there a way to check your firmware version? At the update screen it only tell me that an update is available.
If your console has already downloaded (but not applied) a firmware update, I don’t think there’s a way to check your version number. But I know that the latest firmware is the first release to patch the exploit. So whichever version your console is currently running, it’s vulnerable to the exploit.
 
Top Bottom