Slashdot Mirror


Hackers Manage To Run Linux On a Nintendo Switch (techcrunch.com)

Romain Dillet reports via TechCrunch: Hacker group fail0verflow shared a photo of a Nintendo Switch running Debian, a distribution of Linux. The group claims that Nintendo can't fix the vulnerability with future firmware patches. According to fail0verflow, there's a flaw in the boot ROM in Nvidia's Tegra X1 system-on-a-chip. When your console starts, it reads and executes a piece of code stored in a read-only memory (hence the name ROM). This code contains instructions about the booting process. It means that the boot ROM is stored on the chip when Nvidia manufactures it and it can't be altered in any way after that. Even if Nintendo issues a software update, this software update won't affect the boot ROM. And as the console loads the boot ROM immediately after pressing the power button, there's no way to bypass it. The only way to fix it would be to manufacture new Nvidia Tegra X1 chips. So it's possible that Nintendo asks Nvidia to fix the issue so that new consoles don't have this vulnerability.

64 of 119 comments (clear)

  1. Re: Uhhh... by Anonymous Coward · · Score: 3, Interesting

    I suspect this ROM will be deeply embedded as part of the IC and will be impossible to reprogram; it isnâ(TM)t an eprom itâ(TM)s part of the Silicon.

  2. Re: Uhhh... by darkain · · Score: 1

    Seconding this. From the way things read, it appears to be part of the Tegra chip itself, not a separate chip. However, that doesn't mean it isn't flashable. I'm not sure about this specific implementation, but playing with microcontrollers like ARM or AVR chips, they all have embedded persistent storage banks for code and data on the same die as the processor (and well everything else for that matter, being full SoC)

  3. Guess my perspective is different by oldgraybeard · · Score: 4, Insightful

    "have this vulnerability" duh! a vulnerability?

    Anything I can re-purpose by loading Linux on it is a plus in my world ;)

    Just my 2 cents ;)

    1. Re:Guess my perspective is different by Z00L00K · · Score: 4, Interesting

      And is this a vulnerability to the Nintendo software and games? To me it looks like it's just a re-purposing of the hardware.

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
    2. Re:Guess my perspective is different by Anonymous Coward · · Score: 4, Informative

      It could also be used to implement a custom bootloader stage that loads the next stage of Nintendo's OS, but ignore a bad signature so that it could have been modified to allow running pirated games. This is every bit as serious as the "sighax" one on 3DS -- a similar unpatchable vuln in the bootrom burned into the CPU -- except that sighax was discovered late in the product cycle.

  4. Not a vulnerability by Anonymous Coward · · Score: 4, Insightful

    You have to physically put something on the device to make it work in this way. Being in control of a device you physically control isn't a vulnerability, it's a feature. Being in control of a device because something something network internet packet is a vulnerability.

  5. Re:Women love fat men by PopeRatzo · · Score: 1

    Long as the wallet is fat.

    --
    You are welcome on my lawn.
  6. Re: Uhhh... by Z00L00K · · Score: 1

    Some ROMs are OTP (One Time Programmable), so once you have loaded them they can't be changed.

    The question is if the hole can be easily plugged.

    --
    If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
  7. Congratulations! by Anonymous Coward · · Score: 1

    You used "Hacker" in the correct context!

  8. Re:Women love fat men by fizzer06 · · Score: 1

    Long as the wallet is fat.

    The only bulge in my pants the ladies seem to care about.

  9. Re: Uhhh... by ShanghaiBill · · Score: 1

    Some ROMs are OTP (One Time Programmable), so once you have loaded them they can't be changed.

    That used to be common, but is rare today except in super cheap 8 and 4 bit chips. You can usually erase and rewrite programmatically, or using JTAG.

  10. You can run Linux on it, because of vulnerability by Anonymous Coward · · Score: 2, Interesting

    This is not something to celebrate.

    In the old days, when people said "Hackers got Linux running on a toaster", it meant that some clever people spent some time figuring out how to write hardware-specific Linux components for the toaster; it meant that Linux was improving, and growing.

    Today, when people say it, they mean that some shady group of people used some shady techniques to exploit a bug in the toaster, and if you want to do the same on your toaster, then you'll probably have to download from some shady website a shady black-box binary blob that will run the exploit for you, without you ever really knowing just WTF is going on; it means that personal computing is further collapsing.

  11. Re: Uhhh... by Anonymous Coward · · Score: 1

    You would have had more credibility if you didn't post with your GOD DAMNED IPHONE

  12. If you have to explain by Anonymous Coward · · Score: 1

    That Debian is a Linux distro and what a ROM is, perhaps this isn't an article meant for slashdot.

    1. Re:If you have to explain by DontBeAMoran · · Score: 1

      What is this? An article for ANTS?!

      --
      #DeleteFacebook
    2. Re:If you have to explain by hduff · · Score: 1

      What is this? An article for ANTS?!

      MakeArcherReferenceAboutThis.jpg

      --
      "I believe in Karma. That means I can do bad things to people all day long and I assume they deserve it." : Dogbert
    3. Re:If you have to explain by DontBeAMoran · · Score: 1

      ThisWasAZoolanderReference.jpeg

      --
      #DeleteFacebook
  13. They managed? by darthsilun · · Score: 1

    The most common connotation in my half century of speaking English is that they somehow _barely_ did it. At the last minute, with duct tape and baling wire. And who knows, they might not be able to do it again.

    Whereas if they "got Linux running on it", then just say it plainly: they got Linux running.

    I mean WTF, this is like saying someone's "sorta pregnant." No, they're either pregnant or they're not. There is no half pregnant. There is no "managed to run it.". It's running. Case closed. End of Discussion.

  14. Download roms? by iamhassi · · Score: 1

    How long until we can download Switch roms? Sounds like you could even have your own switch store with free roms to download straight to the device

    --
    my karma will be here long after I'm gone
    1. Re:Download roms? by mentil · · Score: 1

      Technically, you can already download the ROMs, if you know where to look (some games technically come on NAND chips though). The Wii, Wii U and 3ds all had homebrew apps that let you download from a list of other homebrew apps. AFAIK noone bothered making an app that would download pirated stuff, since wherever it links to would be shut down right away.

      --
      Corruption is convincing someone that the selfless ideal is the same as their selfish ideal.
  15. Re: Uhhh... by DontBeAMoran · · Score: 5, Insightful

    When old-timers talk, ROM means ROM. If we meant EEPROM, we would have said EEPROM.

    Now get off the freakin' lawn!

    --
    #DeleteFacebook
  16. Hackers Manage to Run Linux on. . . by RazorSharp · · Score: 2

    Hackers Manage to Run Linux on X is probably to most common beginning to a /. headline. As long as new devices are manufactured, nerds will make them run Linux. Imagine if all these countless man hours were spent making Linux work on PCs.

    --
    "From the depths of my skeptical and rationalist soul, I ask the Lord to protect me from California touchie-feeliedom."
    1. Re:Hackers Manage to Run Linux on. . . by mentil · · Score: 2

      X runs on Linux, not the other way around.

      --
      Corruption is convincing someone that the selfless ideal is the same as their selfish ideal.
  17. Could mean kernel runs but drivers don't by tepples · · Score: 1

    There is no half pregnant.

    Depending on context, more precise terms could be any of the following:

    • Pregnant with one offspring, in a species that ordinarily produces litters of 2
    • Pregnant with offspring missing its hind limbs, as an analogy to the term "half lady" formerly used for circus performers missing both legs high above the knees. These include Jeanie Tomaini (then) or Jen Bricker (now).
    • Halfway to term in pregnancy

    There is no "managed to run it.". It's running.

    "Barely running Linux" is likely to mean running without driver support for the hardware features that an end user would expect to be able to use with a port of Linux. A Linux system without input, accelerated graphical output, audio output, persistent file system, networking, or power management is a starting point. But until it's shown running an application as a proof of concept, such as something using SDL, it's still in a state that one could describe as "barely" or "managed to".

    1. Re:Could mean kernel runs but drivers don't by JustAnotherOldGuy · · Score: 1

      There is no half pregnant.

      Depending on context, more precise terms could be any of the following:

      No, no, no. "Pregnant" is an absolute term, like "dead" or "unique" or "zero". There's no "half pregnant", or "almost unique" or "half zero".

      (Yes, people use the term "half dead", and it indicates imprecise thought. People also say shit like "really unique", and that's also ignorance at play.)

      --
      Just cruising through this digital world at 33 1/3 rpm...
  18. But... by richy+freeway · · Score: 1

    Can it run Linux?

  19. Re: Uhhh... by willy_me · · Score: 3, Informative

    Yes, people now use FLASH memory but place it into read-only mode. It is cheaper when one requires relatively large amounts of memory - as would be required by a ROM. There is probably a way to program the memory if you interrupt the boot sequence before the OS is loaded. One would require a hardware connection - such as JTAG. But from the perspective of the OS, it behaves just like a ROM.

    Or perhaps there is a jumper to enable read/write access. I believe the Asus Chrome Box units protected their boot ROM this way. Only instead of a jumper you had to remove a screw.

  20. DOOM? by hduff · · Score: 2

    But can it play DOOM?

    --
    "I believe in Karma. That means I can do bad things to people all day long and I assume they deserve it." : Dogbert
    1. Re:DOOM? by richy+freeway · · Score: 1

      But can it run Crysis?

    2. Re:DOOM? by wonkey_monkey · · Score: 2
      --
      systemd is Roko's Basilisk.
  21. Re:Wow. by hduff · · Score: 1

    So, you didn't bother explaining what "LCS" meant in the article a few days ago, but you thought you had to tell us what DEBIAN was? FFS slashdot, WHO THE FUCK IS YOUR AUDIENCE?

    Debian/Ubuntu, et al fanbois, it seems are the audience they are looking for.

    --
    "I believe in Karma. That means I can do bad things to people all day long and I assume they deserve it." : Dogbert
  22. why not make it flash rom? by Joe_Dragon · · Score: 1

    why not make it flash rom?

    1. Re:why not make it flash rom? by Megane · · Score: 1

      Because then an exploit could re-program it to be even more... open.

      --
      #naabhaprzrag, #sverubfr-000, #agi-fcbafberq, negvpyr[pynff*=' negvpyr-ary-'] { qvfcynl: abar !vzcbegnag; }
  23. Re:Uhhh... by daid303 · · Score: 2

    Unmodifiable early boot rom is very common. The Wii also had it. The Wii also had a bug in it that they fixed in a later hardware version. See http://wiibrew.org/wiki/BootMi...

    The reason for it not being EEPROM is simple. They don't want anyone to modify it, as it's the start of the secure boot process. Allowing modifications on it would defeat the goal of this ROM.

  24. Re:Uhhh... by wonkey_monkey · · Score: 1

    Did the person writing this not know that ROMs can be reprogrammed such as an EEPROM?

    Did the person writing this not know that not all ROMs are EEPROMs? And that even if they are, if they are not exposed as such to the operating system then the operating system will not be able to reprogram them?

    --
    systemd is Roko's Basilisk.
  25. How dare people control the computers they own! by jbn-o · · Score: 3, Insightful

    What you point out is a part of a larger and more significant problem that gets into another /. thread—"What is missing in tech today?". What's missing is an appreciation that computer owners ought to be able to use their computers in the way they wish, fully owning and controlling their own computers. What's present is a focus on relatively minor issues like what gadgets people might find slightly more convenient to use (but apparently not to own).

    Since people want this (the phrase "jailbreaking" is a testament to this; we wouldn't need this term if people enjoyed having their devices "jailed") the corporate proprietor-friendly media (and repeater sites) remind us when covering a story like this in multiple ways: from eschewing any reminder of the freedom to run, inspect, share, and modify published computer software like calling the installed OS "Linux" even when Debian calls their system GNU/Linux and the proper name is on the screenshot (just above the "fail0verflow" textual graphic), to using propagandistic language. There's also suggestion that the code is to be seen as "potential[ly] weak" instead of a means of allowing owners to control their own computers, and blaming fail0verflow should they choose to publish the means by which they installed Debian GNU/Linux on the Nintendo Switch for enabling "homebrew apps and (of course) software piracy". Ridiculous unchallenged and undefended anti-user views throughout which is par for the course in corporate media.

    1. Re:How dare people control the computers they own! by uvajed_ekil · · Score: 1

      Third parties like content providers and software developers are complicit in stopping you form using your hardware as you choose. One example off the top of my head: not being able to run certain streaming apps on rooted Android devices. If you have the audacity to simply take control of your hardware, some unrelated companies won't let you run their software or buy their content. I suppose they have a right to do this, and their terms of service are probably fairly well written, but that doesn't make them right. I suppose they can put what they want in the TOS though, since you don't have a God-given human right to use Netflix or PS Vue (or whatever) on your own terms.

      --
      This is a hacked account, for which the owner can not be held responsible.
  26. Re: Uhhh... by JustAnotherOldGuy · · Score: 1

    When old-timers talk, ROM means ROM. If we meant EEPROM, we would have said EEPROM.

    Exactly.

    --
    Just cruising through this digital world at 33 1/3 rpm...
  27. Re: Uhhh... by AmiMoJo · · Score: 1

    It really depends if they actually have the hardware necessary to write the flash memory. It requires a higher than normal voltage, so if the chip wants to have self programming capability then it has to have as high voltage generator.

    While this hardware is cheap it's not free, and carries risks. It can accidently erase or corrupt the flash memory. To mitigate that you need brown out protection, but even that isn't perfect so you will see a higher failure rate.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  28. Re: Uhhh... by Highdude702 · · Score: 1

    I'm not even old, but been into electronics long enough, that when I read that I thought exactly the same thing(He would have said EE/EPROM had he meant it) If this was not already +5 insightful, I would have added one.

  29. Re:Sure, it runs it much slower than the PS4 or Xb by Z80a · · Score: 1

    It's a portable gaming system pretending it is also a tv console to pretend nintendo didn't dropped the tv console market.
    But on the other hand, it does have the smallest gap to the consoles a nintendo portable ever did.

  30. FTDI chip ? UART bootloader hack ? by thygate · · Score: 1

    There seems to be no requirement to open the console, or even solder, and the picture shows what seems to be a board with an FTDI chip, and 2 wires going to the console. Is it just a UART, and are they getting into the bootloader that way ? If this is all it takes, then I imagine piracy to be rampant soon. https://pbs.twimg.com/media/DV...

    1. Re:FTDI chip ? UART bootloader hack ? by Megane · · Score: 1

      If there is no requirement to open the console, why is there a strip of flex circuit sticking out of the right side in that picture? Or did they chop up a controller and that flex is from inside the controller?

      --
      #naabhaprzrag, #sverubfr-000, #agi-fcbafberq, negvpyr[pynff*=' negvpyr-ary-'] { qvfcynl: abar !vzcbegnag; }
    2. Re:FTDI chip ? UART bootloader hack ? by ledow · · Score: 1

      If true, it may be possible to just get a "mod controller" box that just replaces one of the controllers for a one-off exploit.

      I suppose it's possible that the nVidia chip involved has an exploit which is somehow possible to activate via a shared bus that happens to include the serial comms of the controllers. It would seem a bit silly, in design terms, but I suppose it's feasible.

      To be honest, I never get why console manufacturers go to such lengths anyway. Go the Android route - if your phone is rooted, we can detect it and deny access to the store. If it's not, you can play ordinary games. If someone is prepared to switch back and forth between the two, let them, it means they are still paying for and playing normal games. If someone buys it just to hack it for homebrew, you aren't going to stop them but at least you get a hardware sale of YOUR hardware rather than "easier-to-hack rival".

    3. Re:FTDI chip ? UART bootloader hack ? by drinkypoo · · Score: 1

      To be honest, I never get why console manufacturers go to such lengths anyway.

      Nintendo picks up a licensing fee for every official game sold on the console, so they are highly motivated to keep you purchasing licensed titles.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  31. Nothing on me by pooh666 · · Score: 1

    I ran Linuz on a potato clock, next...

  32. Re:Uhhh... by drinkypoo · · Score: 2

    But just because something is a ROM does not by itself mean it canâ(TM)t be changed.

    If it's actually a ROM, that's exactly what it means. And even if it's a flash ROM that there's no way to write without attaching external hardware, then from the standpoint of a user who doesn't want Nintendo to patch away the vulnerability, it might as well be a mask ROM.

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  33. Re:Uhhh... by Megane · · Score: 1

    It's a direct quote from TFA, and it reads like it was written for third-graders. Not very crunchy.

    --
    #naabhaprzrag, #sverubfr-000, #agi-fcbafberq, negvpyr[pynff*=' negvpyr-ary-'] { qvfcynl: abar !vzcbegnag; }
  34. Re:A new Tegra chip for Switch 2018 by Megane · · Score: 1

    I guess that means I have to buy a Switch now before they come out with an updated boot ROM. I can put it next to the two Wiis I have that haven't even been turned on since Twilight Hack happened.

    --
    #naabhaprzrag, #sverubfr-000, #agi-fcbafberq, negvpyr[pynff*=' negvpyr-ary-'] { qvfcynl: abar !vzcbegnag; }
  35. Highly detailed technical analysis .. by najajomo · · Score: 1

    "when your console starts, it reads and executes a piece of code stored in a read-only memory (hence the name ROM)"

    It's highly detailed technical analysis like the above that I come here for.
    --

    sig: I'll bet you're the kind of guy that hangs round Reddit fapping off over pictures of furries and yellow-scaled wingless dragonkin

  36. Re:Sure, it runs it much slower than the PS4 or Xb by elrous0 · · Score: 1

    This is true. It's basically Nintendo's backdoor way to exit the console market while saving face.

    --
    SJW: Someone who has run out of real oppression, and has to fake it.
  37. Drivers, or putting the cart before the GNU by tepples · · Score: 1

    from eschewing any reminder of the freedom to run, inspect, share, and modify published computer software like calling the installed OS "Linux" even when Debian calls their system GNU/Linux and the proper name is on the screenshot

    I too write the term "GNU/Linux" in part because it's a convenient way to say I don't mean Android. But this particular point isn't quite the strongest in your argument because practically, until enough drivers are ported to let the user interact meaningfully with the GNU operating environment, it's still "Linux".

    1. Re:Drivers, or putting the cart before the GNU by marcansoft · · Score: 1

      Not only that, 0% of the effort has to do with the GNU part. The article title is accurate in using the term Linux. You get the kernel to run, then you grab a binary userspace from your favorite distro. Linux is what matters. The rest follows automatically because it is barely hardware specific if at all.

      You only port GNU/Linux once to any given architecture. After that, all devices using the same architecture only require porting Linux to them.

  38. Re: Uhhh... by willy_me · · Score: 1

    It really depends if they actually have the hardware necessary to write the flash memory. It requires a higher than normal voltage, so if the chip wants to have self programming capability then it has to have as high voltage generator.

    While this hardware is cheap it's not free, and carries risks. It can accidently erase or corrupt the flash memory. To mitigate that you need brown out protection, but even that isn't perfect so you will see a higher failure rate.

    All the SOC chips out there already require multiple power rails at various different voltages. Managing all the power rails is a real pain - TI and others make ICs with internal LDOs and DCDC switches to simplify the process. So all SOCs will all have access to the 3.3V / 1.8V rails required to write to FLASH. Without this, they would never be able to support a USB transceiver.

    The FLASH memory will not require additional hardware for writing - the controller will include all required components. The SOC will simply interface using quad-SPI or some other standardized bus. Unless they have specific reasons to make it complex, they will use a licensed IP module for FLASH memory and that is it. Making it a true ROM would add to the cost and complexity - significantly. WIth transistor budgets the way they are, savings from a read-only ROM are non-existent. Costs associated with an error in ROM that could have been fixed had it been FLASH - scary high.

  39. Re:Sure, it runs it much slower than the PS4 or Xb by mentil · · Score: 1

    It seems to me that Switch owners either use it predominantly as a handheld or as a portable, few actually 'switch' it up that much. Some people hate tiny screens, others hate cramped controls, others hate sitting in one spot or gaming at home. An unusually powerful handheld that gets all of Nintendo's AAA games means I only have to buy 1 Nintendo device each generation, instead of two, to get all the stuff I want.

    --
    Corruption is convincing someone that the selfless ideal is the same as their selfish ideal.
  40. Re: Uhhh... by AmiMoJo · · Score: 1

    3.3v isn't enough to write cheap flash memory.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  41. Re:Sure, it runs it much slower than the PS4 or Xb by ledow · · Score: 3, Informative

    To be honest, I've enjoyed the vast, vast majority of my gaming life on systems that would be considered so laughably slow and obsolete now that people wouldn't take them off your hands for free.

    It didn't once affect my enjoyment of the games, my enjoyment of replaying the games, or the nostalgia of going back to those same games 30 years later (whether on original hardware or via emulation).

    If you think that anyone who plays games care about how many MHz or how many CUDA cores or how much texture RAM a certain device has, you're sadly in the minority. I gamed through the home computer rivalries, the 8-bit and 16-bit rivalries, PC vs console, online vs local LAN, etc. and not once did I ever care about having what was technically best, compared to what played the games I most enjoyed.

    Nintendo are pretty much the only modern console company that get this. All their effort goes into the game design and new, fun twists, rather than what texture fill rate they can achieve.

    Even in my "PC gamer" years on my twitch-shooters, I still didn't really care about those people who bought the top-line gear, overclocked everything, etc. just to get a few more FPS or a lower ping. It was the game that mattered.

    Same as car-nuts. I'm sure your car does 0-60 in some unfathomably trivial fraction of a second faster than mine. But that's not why I bought the car. Don't put your use case onto me, or entire markets of billions of people who "just want to play a game with the kids".

  42. Dual boot Android by XSportSeeker · · Score: 1

    Call me when they have a dual boot ready for Android, or more specifically, using the Switch as a full nVidia Shield TV.
    I mean, I'm getting one anyways, but that would certainly double the value in my page. xD

  43. Re: Uhhh... by marcansoft · · Score: 1

    Little ARM and AVR chips almost always have embedded Flash memory, and high-performance chips like x86 CPUs and mobile phone SoCs almost never do. It has to do with silicon technology. It is not practical to put Flash memory into a cutting edge silicon process for a bunch of technical reasons.

    So yes, it's ROM. Mask ROM. Not writable.

  44. Re:You can run Linux on it, because of vulnerabili by marcansoft · · Score: 1

    Yes, because when I put Linux on a PS4 I certainly didn't spend several months figuring out how to write hardware-specific Linux components for the PS4.

    Oh, wait, I did. I also happened to reverse engineer the Radeon GPU microcode instruction set. So now every AMD Radeon user can benefit from being able to understand what their GPU firmware is doing, which they couldn't in the past.

    But hey, I guess GitHub is some shady website that serves shady black box binaries, and implementing kexec as a hot-patchable module for the FreeBSD kernel is a decidedly shady technique. Right.

  45. Re:You can run Linux on it, because of vulnerabili by marcansoft · · Score: 1

    Jesus, how did I manage to fuck up the links so badly. Link, link, link. And some bonus stuff.

  46. how usable by sad_ · · Score: 1

    how usable will this turn out the be?
    the nvidia tegra soc has horrible linux kernel support.
    it even made Linus flip the finger at nvidia.

    --
    On a long enough timeline, the survival rate for everyone drops to zero.
  47. Re:Idea to prevent hacking Nintendo Boxes by pcjabber · · Score: 1

    Sony tried this several years ago with the PS3...and subsequently removed it after the community started to exploit it:
    https://en.wikipedia.org/wiki/...

  48. financial implications for Nintendo. by JustNiz · · Score: 1

    > It could have some financial implications for Nintendo.

    Yeah they might sell more switches since they've now just become useful.