r/switch2hacks • • 16d ago

Hacking News We apparently have a game dump of a Switch 2 Commercial game

Post image

From what I could deduce from the tweet, despite being only an Userland bug (not a full hack), he has now access to a decrypted game code, and might be able to study it line by line to find how the PAC (Pointer Authentication Codes) is read in each game. This is huge news. What do you guys think of this?

1.1k Upvotes

172 comments sorted by

•

u/NiftyNovaaa 16d ago

Hi everyone, i am trying to become more up-to-date on the Nintendo Switch 2 hacking developments, keeping track of the Switch 2 hacking timeline from release to present day. I've kind of missed a lot this year though. If you've been keeping track of all the hacking news, please reach out to me! Userland hacks/bugs like in this post, noteworthy developments, anything from the start of the year 2026 to now, if you think it's interesting i want to hear about it. You can contact me through the r/switch2hacks Discord server, just send me a DM. Thanks!

→ More replies (3)

209

u/MysticPrysm 16d ago

Apparently it's only some code, and no assets or anything. But still potentially useful.

83

u/An1nterestingName 16d ago

They replied saying that they can dump game files, but don't want to. Honestly I hope they publicise this or someone else finds it so we can get proper music dumps.

62

u/rasjahho 16d ago

Considering this guy cares about bug bounties I doubt it. Unless someone else gets to it before he reports it to Nintendo lol.

37

u/NoSatisfaction3754 16d ago

If you look at Nintendo's HackerOne page, some reports are marked as "duplicate"; that means Nintendo actually pays out even if two people found the same bug.

9

u/Badzieta 15d ago

The fact that the report got publicly disclosed even though it was a duplicate doesn't mean a reporter got paid out... just take a look of the timeline of the report, you won't see "XXX awarded XXX with a bounty.", which you can see on proper, valid, non-duplicate, disclosed reports.
Nintendo isn't a charity.

8

u/garf02 16d ago

IIRC to get a bounty you have to submit it before making it public..

0

u/Ok_Simple_459 16d ago

Does Nintendo have a program like HackerOne in the first place?

6

u/BreafingBread 16d ago

This is basically the first major milestone for Switch 2, right? Even if not public.

Crazy to think that the Switch took 4 months to have public dumps. It took Switch 2 1 year, 3 months and 10 days. And it's not even public yet lol.

13

u/An1nterestingName 16d ago

The Switch was so fast because it used a hardware architecture that already existed.

13

u/appletechgeek 16d ago

i mean tbf the switch 2 is also a pre existing architecture. it's just that all hardware is so obscenely expensive that it isnt really viable for us to get anything,

the switch 2 is afaik the cheapest entry to that architecture atm, unless you can catch a cruise missle since apparantly it's somewhat the same architecture lol,

2

u/Flashy-Vermicelli-32 8d ago

Sorry if this is dumb question or ignorant

I heard one of the newer AI models found a bunch of zero day hacks in Microsoft and other programs ; is there conceptually people attempting that now with the switch 2

2

u/adburl2 5d ago

Not really, those AI analyses work because they have the software to analyse. For Switch 2 we don't even have game dumps (or if we do, it's encrypted dumps, and even AI can't brute-force the level of strong encryption the Switch 2 has) let alone system dumps.

1

u/Gaeldouche 16d ago

its slightly custom the version of the orin chip in the switch 2 is specifically modified for security

2

u/get_homebrewed 15d ago

no it isn't lol, they took out the more robust arm cores for standard ones

0

u/An1nterestingName 16d ago

It's custom hardware. Switch 1 was mostly off-the-shelf.

4

u/EmergencyPool910 15d ago

Not really thought the tegra 239 is based on the tegra 234

4

u/Joseki100 15d ago

It was public, well documented and it shipped with a huge Nvidia hardware exploit.

None of the 3 is now true which is why it's gonna take a while.

People think what happened to the og Switch is the norm, it's not.

3

u/9th_Sage 16d ago

Nah, they were just unlucky and the Nvidia supplied bootrom had exploitable bugs.

2

u/nmkd 15d ago

What's the point of dumping assets? Code is what's interesting

9

u/Odonnellspup 15d ago

model and music rips would be huge, it took a long time to get clean music from Mario Kart World and the same is gonna apply to many future games.

3

u/Educational_Look_267 15d ago

Reverse engineering
Decrypted code/decrypted binary

2

u/nmkd 15d ago

You gonna reverse-engineer a PNG or what?

Assets = non-code

2

u/Educational_Look_267 15d ago

Why people are so stupid? U read all comment on x? Bc gezine says its going to use it for study PAC on the sw2

-2

u/[deleted] 16d ago

[deleted]

2

u/NoSatisfaction3754 16d ago edited 16d ago

If they haven't managed to do anything with the original Switch (which lacks PAC) over all these years, why do you think they'll manage to do something with the Switch 2? Let me know when the Switch 1 v2 can be hacked without a modchip—that’s when a discussion about hacking the Switch 2 might be worth having. Basically, there's a lot of talk, but they can't even hack the Switch 1 without a modchip, lol. (basically they haven't been able to beat Horizon OS on Switch 1 which is much less secure than the one on Switch 2 lol)

-2

u/RudeGolden 16d ago

Who cares if the S2 eventually needs a modchip or not?

2

u/MysticPrysm 16d ago

I'm confused with the attitude lol. I was agreeing it's still huge news, clarifying it wasn't the whole game.

1

u/Lagoo157 16d ago

Mad over nothing. Go outside and take a deep breath

1

u/BallingAndICantGetUp 16d ago

they deleted the comment, but im gonna say the OP of that comment, needs to touch some grass

106

u/GhoulSlaying 16d ago

I don't have anything important to add. I just wanted to say that that is such a creative way to dump data.

47

u/ArthurMegaHard 16d ago

Honestly, even if the switch 2 doesn't get hacked, as a CS student, just seeing the offensive security techniques applied in jailbreaking a console is cool enough

11

u/mario61752 16d ago

I don't understand...how can you just transmit game code and assets over...HDMI??

61

u/ArthurMegaHard 16d ago

Think of it like this. Gezine made the Switch itself take the game's code (the 1s and 0s) and turn it into a super fast video of flashing colored boxes, kind of like giant, rapid-fire QR codes. The Switch sent this video out through the HDMI cable thinking it was just the game visual output instead of the actual raw code, and the capture card simply recorded it like a normal, but weird-looking, gameplay video. Since gezine made the rules for the colors (for example, knowing that a red pixel means '1' and a blue pixel means '0'), he just ran a program on his PC that watched the recorded video, translated the colors back into 1s and 0s, and rebuilt the game's code piece by piece.

32

u/esketitethan 16d ago

What the fuck that’s insane

-3

u/nmkd 15d ago

Why? Have you never seen QR codes?

Or fiber network, for that matter

1

u/sendsomepie 13d ago

Qr codes are an impressive feat historically, just because it's commonplace now doesn't mean it's not impressive.

5

u/sagebrushrepair 16d ago

An HDMI modem?

4

u/mario61752 16d ago

Ok I guess what I don't understand is, how did they get the switch 2 to format data into a video in the first place when it hasn't been hacked?

1

u/BeltOwl 16d ago

All data in a computer is represented by bits, meaning everything is 1s and 0s, and all formats do are give purpose to these 1s and 0s. So all he did is pass those 1s and 0s in the exact same order through HDMI and wrote it back out on his computer. It's the same as being able to copy a handwritten letter in a foreign language without understanding what it means.

10

u/Lagoo157 16d ago

I think what he’s asking is, how was it possible to get the switch to display the code in video form at all since it hasn’t been hacked

4

u/BeltOwl 16d ago

Ah in that case, Gezine seems to have an userland hack through a specific game, and I believe he's only able to access the files of this specific game, though that's pure speculation. By having access to the userland he was able to write a program that could take the contents of the RAM (possibly even just directly accessing the filesystem for this game), and serialize it into this video-compatible format.

8

u/ArthurMegaHard 16d ago

Gezine confirmed that he can only extract the binary and assets of a specific vulnerable game, so it's not an exploit present in every game

3

u/lowmoob 16d ago

Mfw the game is switch 2 welcome tour

1

u/snil4 15d ago

That would be huge if true since that game is one of the few that utilises a lot of the features of the switch 2. This would hugely help emulation development.

1

u/lowmoob 15d ago

Yeah but Gezine mentioned that a vulnerability in that specific game let him hack it. So it would be funny if the only rom that could be dumped was welcome tour. So you would end up with an emulator and the only rom is welcome tour. Only speculation anyway but was just a funny idea to me

→ More replies (0)

2

u/mario61752 16d ago

Ah I did a little digging around, and it seems like he save transferred a vulnerable game to switch 2 to perform this? I did study computer security but this is mind-blowing. I can't fathom how someone just figures out how to write code to extract RAM or game files like that

2

u/Jubei_Kiba 13d ago

basicamente funciona assim, todo código no computador tem a sua representação em hexadecimal, digamos assembly x86:
JMP
Short Jump código hexa: EB
(seguido de 1 byte de deslocamento relativo)
Near Jump código hexa: E9
(seguido de 32 bits)
JNZ
Short Jump código hexa: 75
(vai até 127 bytes)
Near Jump código hexa 0F 85
(seguido de 4 bytes de deslocamento relativo)

O que eu quero dizer com isso: não obrigatoriamente eu preciso abrir um executável x86 em um disassembler/debugger/depurador, entendendo bem de hexadecimal eu poderia escrever diretamente no arquivo do disco.

Então em um cenário que você tem uma brecha de um save game e consegue abrir um mini editor hexadecimal já é o caminho para começar a "fuçar", você executa o jogo, o jogo abre, vc modifica algo, você executa o jogo novamente o jogo lê um arquivo do disco, você vai lá e edita novamente, você executa o jogo novamente e agora o arquivo que o jogo abre é o transportador de dados via HDMI, e assim vai indo, a engenharia reversa exige paciência, intuição e persistência (além do estudo e conhecimento sobre o assunto que nunca é 100% - sempre tem algo novo).

2

u/RequirementNo1852 16d ago

Something like QR coded but more avanced and a lot of them. There are some apps that let transfer files from phones this way and store large files as YouTube vídeos

6

u/1238482772929 16d ago

Noble prize level shit love it

5

u/Tiktokbadsupport 16d ago

i thought the same i would really be interested to see the process 

20

u/PacketLoss-Indicator 16d ago

Really fascinating method of dumping, reminds me of that guy who dumped a copy of Pokemon Emerald by recording the game's audio after a crash.

16

u/xXBeefyDjXx 16d ago

Switch 2 carts can be dumped on a modded switch 1 including the switch 2 data, of course that's only part of the puzzle.

The more interesting part is seeing a proper "jailbreak" on S2 native hardware.

6

u/pofehof 16d ago

Switch 2 carts can be dumped on a modded switch 1 including the switch 2 data, of course that's only part of the puzzle.

Can you elaborate on this? It it simply using nxdumptool or something?

2

u/xXBeefyDjXx 15d ago

Pretty much. Tell it to do a full dump of the cart and it will. This mainly works better on titles that are Switch 1 compatible from what I've seen so far but there's already floods of backups verified for S2 content including full games and I have managed to backup my copy of Animal Crossing S2 edition and Breathe of the Wild too.

4

u/pofehof 15d ago

This mainly works better on titles that are Switch 1 compatible from what I've seen so far

I have managed to backup my copy of Animal Crossing S2 edition and Breathe of the Wild too.

Probably because the Switch 2 Edition carts can still be run on Switch 1 systems. Switch 2 only cartridges haven't been dumped as far as I know, but it won't hurt to test it out.

1

u/xXBeefyDjXx 15d ago

I've seen Switch 2 full game dumps in the wild so there's gotta be a way, either the mig dumper or switch 1 as the reader 👀

Decrypting them I don't know, haven't tried it.

4

u/pofehof 15d ago

I've seen Switch 2 full game dumps in the wild so there's gotta be a way

Are you sure that they were Switch 2 only games and not Switch 2 Edition games? I don't think there would be any way for people to verify it?

7

u/FernandoRocker 15d ago

You are wrong.

The Switch 2 Edition games (like the ones you mentioned) are Switch 1 games + a Switch 2 patch that acts like a DLC.

You are just dumping the Switch 1 game.

2

u/pofehof 15d ago

Don't know why you were downvoted for this. This is likely the answer and OP didn't differentiate between Switch 2 games (can't be run on Switch) and Switch 2 Edition games (can be run on Switch).

4

u/Polyglot-Onigiri 15d ago

A modded switch can read and dump switch 2 titles?

2

u/saltykalewastaken 4d ago

no, this is false

the switch 1 cannot decrypt or even access the files on switch 2 carts

iirc, it can only dump switch 2 edition carts and only the switch 1 files on those carts

32

u/TheSpiralTap 16d ago

If this is true, and I'm skeptical, this would be some of the craziest shit that has ever happened. I've never even heard of using an HDMI cable like that.

9

u/MysticPrysm 16d ago

Think of it like a morse code. I mean not literally, but it's probably in that realm. Certain patterns being flashed, and then converted into code on the computer.

1

u/TheSpiralTap 16d ago

I get the concept. I've just straight up never heard of it being used like this.

10

u/JCasaleno 16d ago

gezine is the goat, bro pretty much broke the ps5 deadlock and up to yesterday he had zero day exploit(ps5 updated firmware yesterday)

1

u/TheSpiralTap 16d ago

Well good on him! Let's hope it leads to something. I was unaware of this person

3

u/xrerion2 16d ago

there are some videos on yt and some posts on diffent forums about him and he does make some crazy jailbreaks sometimes, the current blueray ps5 jailbreak for firmware 13.42 was made by him, i recommend reading about jailbreaks he have done

1

u/TheSpiralTap 16d ago

No for real, you guys have given me some reading material. The shit he is doing is wild

1

u/Rekusu7991 16d ago

wait im on 13.00 can i jailbreak my ps5 right now?

1

u/Specialist-Stuff-221 16d ago

not yet but kernel exploit is found on 13.60

1

u/Rekusu7991 15d ago

should i download the 13.60 update on a flash drive just incase?

1

u/mikenuun 14d ago

no, the lower the better. stay offline for now. if you must update to 13.60 later you always can using a USB stick

1

u/JCasaleno 16d ago

The exploit has been found but not released yet, follow sonic iso on x, he will release it, he is polishing it rn

1

u/Top-Food-4311 15d ago

He also collects bug bounties dont get your hopes up

5

u/DependentAnywhere135 16d ago

It’s Gezine of course it’s real

53

u/SuperDumbMario2 16d ago

Switch 2 ROM dumped before GTA 6

If this is a full ROM it would be lovely to datamine some games

26

u/MrPabluu 16d ago

nowhere near a rom, just an executable

9

u/shortpie_ 16d ago

seems like it's just what's in RAM so a full ROM is unlikely, we'd have some parts of a binary though so that's really cool

-4

u/nmkd 15d ago

It's a game dump

2

u/MrPabluu 15d ago

NOT a game dump

7

u/JCasaleno 16d ago

gezine is the goat, bro pretty much broke the ps5 deadlock and up to yesterday he had zero day exploit(ps5 updated firmware yesterday)

7

u/Phillyrider807 16d ago

Stuff like this is really cool and gives me hope. I could care less about piracy. I just need a way to edit save files for Gen 10 of Pokemon lmao.

Bring back Powersaves!

-1

u/AMournfulObserver 15d ago

And here I was hoping we could FINALLY have a new gen without hacked Pokemon all over the place and all secrets being datamined day one…

1

u/saltykalewastaken 4d ago

im pretty sure no matter what there will be people posting secrets day one

6

u/ArthurMegaHard 16d ago

A little update from gezine himself. In his words: "I 'can' dump all game files too but I don't care about these"

https://x.com/gezine_dev/status/2100284963845501351?s=20

5

u/Suspicious_Lock_8852 16d ago

Le envío todas mis expectativas a Gezine...

3

u/ruemooooo 16d ago

i remember someone doing this with a gba one time on youtube, its neat

3

u/ruemooooo 16d ago

nevermind! it was audio not video but still neat! https://youtu.be/0-7PSmYYHF0

2

u/tychii93 16d ago

It's crazy how some of these things work like this.

WiiHDMI mods can update their firmware the same way.  You can also dump Saturn save files using a homebrew that plays audio, and have a Linux PC listening via line in with a modem package.

1

u/GlumWoodpecker 15d ago

You can also dump GameBoy saves and ROMs this way, using a GameBoy Colour, a flash cart, and GameBoy Audio Dumper! I used this to get my GameBoy Camera pics onto my computer, where I could then load the save in an emulator and capture high-quality PNG versions of the photos.

1

u/septumfunk-com 15d ago

not that crazy with digital video output, little crazier with analog video output. you can cram practically whatever data into digital video you want analog is a lot more iffy (audio passed over 3.5mm is analog for the record)

2

u/Polyglot-Onigiri 15d ago

Being able to dump code doesnt automatically mean It’s decrypted. It’s most likely still encrypted, but being able to dump the data at all is a good first step.

5

u/ArthurMegaHard 15d ago

From what I can Tell, he has the decrypted binary, since he extracted It from the CPU registers themselves instead of RAM. In the registers, data can't be encrypted since the CPU needs plain code to be able to read it (it's also why he claims that he can study the PAC codes, If he only had the encrypted code, he wouldn't be able to study anything since it would be unreadable)

1

u/Polyglot-Onigiri 15d ago

Huh, interesting

2

u/hobogodot 15d ago

I don't know how far in the hacking process we are but this seems like an awesome step forward

3

u/Zyvyn 16d ago edited 16d ago

Just to set everyone's expectations straight. Even if he could dump full unencrypted game data it couldn't be used for much past datamining. The goal here isn't to dump games, make rips, etc. Here he has simply ripped the executable of a game to see how they are formatted. Basically he's datamining. However even if a full unencrypted game dump surfaced online it can't really be used for much without a full dump of the system firmware for example.

7

u/KenzieTheCuddler 16d ago

Data mining is still cool

2

u/Zyvyn 16d ago

Oh for sure.

1

u/MarioStrikerz 16d ago

Mind you nobody here is saying that data mining is uncool, just that this doesn’t lead to full unencrypted game dumps on its own. This is a reasonable statement given that users following the scene have taken a WebKit exploit in userland to essentially mean the same thing.

2

u/Pokeguy211 16d ago

I would love for data mining to return but at the same time it’s been really cool to not have anything spoiled before release.

2

u/Individual_Holiday_9 16d ago

I want a modchip so bad lol

2

u/JewUnit1 16d ago

My spare launch switch 2 is yearning for a jailbreak. Keep it coming.

Still on day 1 update and wifi off. Can't wait!

1

u/Nice-Ad-6552 16d ago

What the hell? Real news? Where am I?

1

u/SOVEREIGNBOSS 15d ago

I’m from the PlayStation scene. I’m curious about Nintendo. Would love to play ghost of Tsushima or gta 5 on portable device.
Can anyone explain me this scene a bit?

4

u/pofehof 15d ago

Gezine made another tweet mentioning that it's a single game that allowed him to do this, he can't do this with every Switch 2 game.

According to the admins of the PKHeX (Pokemon save editor tool) server, this is simply good for research and not much else. This isn't a way to get into a Switch 2, or will help emulation. It's unlikely that there will be anymore exploits other than this.

1

u/septumfunk-com 15d ago

i think gta (V) may get a release on switch 2 officially though, COD got one recently and the older games have switch ports i dont see it as out of the question

1

u/blowupnekomaid 12d ago

there is still no hack available to end users, and no one knows if there will be one any time soon. gezines hack is more for academic purposes in hopes of leading to something more substantial. its the most substantial news so far in the hacking scene since the switch 2 launched but it still doesn't mean that much on it's own. the switch 2 so far has been extremely well secured against hacks. on switch 2 the only games you can play are from the nintendo eshop or official cartriges. if you want to play those games portable you'll need a pc handheld, or a laptop

1

u/SOVEREIGNBOSS 10d ago

Ah guess it’s tighter security than ps5/Ps4
Guess it’s not worth it to buy Nintendo. I never grew up with it so Mario game etc has no value for me. I am more of AAA game enjoyer.
Mahne in future you could play gta5 or watch dogs ok ninetnod it would be so cool.

2

u/blowupnekomaid 10d ago

there is always the chance they could get ports of those games but yeah. depends on if third parties can be bothered. the zelda games are probably the most appealing for the AAA audience, there is some third party stuff like cyberpunk as well.

1

u/Hopeful_Minimum95 14d ago

dumping by capture card o.O

1

u/memoryman18 14d ago

Exciting news, I mean it's the most I've heard progress wise in months and it sounds huge to me.

1

u/Rusty1031 14d ago

Crazy. This reminds me of the guy that dumped GBA carts in one huge audio file

1

u/Jacquess78 13d ago

Finnaly

1

u/Tieigo96 13d ago

Usually how exploits work, if there is a KEX could be through a Gamesave breaking the console free. We've seen it before with multiple consoles.

1

u/West-Psychology-6299 13d ago edited 13d ago

So this is why they (console creators) are going to digital only games. Can't dump digital.

2

u/FernandoRocker 13d ago

Nintendo is not going digital only.

1

u/DesignerMorning1451 12d ago

For once I actually hope you're right about something...

-1

u/West-Psychology-6299 13d ago

They've shown that they can. We already have keycards. They are starting digital trades. Definitely laying the groundwork.

1

u/FernandoRocker 13d ago

Keycards are Nintendo's way to avoid code-in-boxes.

Other third party publishers would release games just digitally. It's a way to have retail presence.

1

u/West-Psychology-6299 13d ago

They are also a way to avoid dumping of physical copies. Both can be true. This could be why Sony is also going digital as some of its physical games have led to exploits being found in the system..

2

u/space-c0yote 10d ago

All Nintendo 1st party games have the full game on the cartridge. 3rd parties also all have the option to use a regular game cartridge and not just a Game Key Card if they wanted to.

1

u/West-Psychology-6299 10d ago

For now until another game leads to their system being jailbroken.

1

u/West-Psychology-6299 10d ago

I also said sony not Nintendo

1

u/[deleted] 11d ago edited 11d ago

[deleted]

1

u/West-Psychology-6299 11d ago

Dumping games has led to finding exploits in the past.

1

u/Psychological_Plum72 13d ago

İf nintendo sold shit for 15 20 bucks a game no one would be waiting for hacks. 50 usd for games that are available for 5 bucks elsewhere is a damn ripoff. Hope nintendo gets whats comin

1

u/Cultural_Neat3124 13d ago

tremendous breakthrough !!! now we just need a switch 2 console and a game cartridge and we can finally play the game

1

u/iLiikePlayingWii 12d ago

What the fuck? I actually used to think something like this was possible because of the HDMI ports having blazing fast speeds yet I never saw anyone use any console's HDMI ports for data transfers… I'm shocked it took this long for it to happen

PLEASE PLEASE DUMP SPLATOON RAIDERS, WE NEED THOSE OST SOUND FILES

1

u/KoopsterShell 11d ago

What is the name of the game. And I don't trust gezine will make this public as it's a big entry point for people to study switch 2 game processes. Which could facilitate future code injection and it could be blamed on gezine

1

u/Nearby_Ad_2519 16d ago

Random point but why does it say "Twitter Web App" underneath? I thought Elon specifically asked for the device identifier to be removed off Twitter ages ago, partially because he was embarrassed as he was trying to battle with apple from an iphone. Did they bring it back or smthn?

1

u/ArthurMegaHard 16d ago

I use an extension that removes a lot of the bullshit Elon changed in twitter since he bought It, so it might be that

2

u/Nearby_Ad_2519 16d ago

Oh ok that would explain it, I miss when that existed on stock twitter because it was funny to see celebrities who were promoting Samsung have “via twitter for iOS” underneath their post

1

u/Pokeguy211 16d ago

Same I loved the “Twitter for” he should bring that back.

1

u/PromptBoxOS 16d ago

this is so smart

-1

u/dangaming255 16d ago

I hope this leads to something, possibly emulator progress(doubt it) but i cant think of any uses other than ost dumps(cool but not groundbreaking) and piracy(i'l let you keep your own opinion on that)

4

u/ArthurMegaHard 16d ago

The point of the dump is to understand how the switch2 authenticates games, and by extension, code. If we can figure out how to sign our own code and execute It as If It was legitimate code, we could escalate privileges and make progress on an actual emulator

1

u/dangaming255 16d ago

huh, neat, hope we can do that

0

u/Dynablade_Savior 15d ago

How does that even work, using a capture card to dump stuff from a cartridge?

5

u/ArthurMegaHard 15d ago

He didn't dump from the game cartridge, instead he used a vulnerable game to extract the game running data present in the CPU registers directly, tricking the switch2 into outputing the game instructions as visual input to the screen, which he could then record video of using the capture card and decifer the game code manually based on the colors that appeared on the screen

0

u/SkyLey2 15d ago

What was that game?

4

u/ArthurMegaHard 15d ago

He didn't publicly say what game It was so Nintendo can't immediately patch it

6

u/SkyLey2 15d ago

Good, good to (not) know

😅

1

u/Cultural_Neat3124 15d ago

ocarina of time remake !

-19

u/joefeyzullah 16d ago

HDMI? Is he trolling?

18

u/MrPabluu 16d ago

nah, Gezine is legit, quite curious how this is HDMI related tho lol

9

u/fjfjgbjtjguf 16d ago edited 16d ago

I would imagine the binary data would have been displayed as raw pixel data (maybe in something like a 1bpp format at a lower resolution to increase the chances of a successful decode), potentially with some error correction as well, before an HDMI capture card captures it and it is decoded back into binary using PC-side software. Rinse and repeat until you have converted the entire binary into raw pixels and decoded it on PC. If the monochrome pixels were transmitted at something like 4x integer scale on a 4K output to a 4K capture card, that would mean that each binary image would actually be 960x540 and only contain 64,800 bytes of data, so you would have to repeat and automate this process with hundreds or thousands of images to dump even a small code portion with a few dozen megabytes of data. If he was using a 1080p capture card he would pack even less data into the binary images and would have to transmit even more images. You couldn't just transmit a higher res image or an image using colour because that would decrease decoding success by orders of magnitude, especially since almost all capture cards have chroma subsampling you can't disable, and almost no capture cards will support sending uncompressed frames over USB. All of the capture cards I have used only send video using Motion JPEG

7

u/ArthurMegaHard 16d ago

From what I could tell, since It's userland, he couldn't move the code to his PC normally, so he made the capture card read the code and interpret it as "pixel data" via HDMI to then record the screen and convert back to code.

2

u/nickmullen_real 16d ago

basically many thousands of fancy QR codes

2

u/PsikyoFan 16d ago

Using video, sound, or pulsing periphals lines, has been used as a way to exfiltrate data from secure systems for decades.

2

u/shortpie_ 16d ago

do you know how HDMI video output works? it sends data as image frames, usually as 60 per second (more or less, which creates a constant video output to a monitor, screen or capture card). if OOP isn't lying then they converted a memory dump into image frames, using a capture card to relay them to their PC to record them then converting them into bytes that make a full binary, which they will use for research

-1

u/Pristine_Crab_3724 15d ago

Gezine is a legend

-22

u/FernandoRocker 16d ago

The title is extremely misleading.

14

u/ArthurMegaHard 16d ago

Oh, wait, nvm you're the famous doomposter of this sub lol

5

u/ArthurMegaHard 16d ago

I mean, he probably doesn't have the assets, but getting the decrypted game code is exactly what a dump is, no?

3

u/MrPabluu 16d ago

there is no game code my guy, a binary is the equivalent of an .exe file, just an executable

2

u/ArthurMegaHard 16d ago

Yeah, that makes sense (I might have titled it wrong since I posted the moment I saw his tweet), but at the same time can't he run the executable through a decompiler to see the actual code? That's kinda why I jumped the gun a bit especially since he used the word "dumped" on his tweet

1

u/MrPabluu 16d ago

how do you decrypt something you don't have the keys for?

2

u/ArthurMegaHard 16d ago

That's what confuses me about his post, since he's talking about examining how the PAC works, I just assumed the binary he has is somehow decrypted, since him dumping the encrypted ram would just be "garbage" data, there would be "nothing" to analyse on PC since it would be unreadable by anything except the switch itself

2

u/ArthurMegaHard 16d ago

As far as Gemini can speculate (so take it with a grain of salt), he managed to get the decrypted binary because the extraction was done from the CPU's perspective (cache/registers) rather than reading the encrypted RAM directly. The Switch 2 hardware automatically decrypts the data on-the-fly so the CPU can understand and execute it, and the exploit simply captured this already-decrypted data. Having that decrypted "exe" he can run it through tools like Ghidra to be able to recreate the original source code (without comments of course)

2

u/Ghennon 16d ago

Dude can you shut tf up if you have nothing to add?

"We apparently have a game dump"

EXTREMELY misleading? really? did you read the word "apparently"?

-9

u/Many-Technician3315 16d ago

It's like we watch a cat and mouse games right? LoL When nintendo got announce new update FW and then the new challangers came or we can say intelligence researcher to do the threats? And then who gots the a cold sweats first? LOL HuaHaHaHa Switch2hack on fire!!!!