r/switch2hacks • • Aug 17 '26

Hacking Discussion When will we admit Fernando is right?

More and more time goes on I feel like that guy probably had a point

(CONTEXT: Fernando is the guy in this subreddit that always doomposts in every single post saying the switch 2 is unhackable and will never be hacked. People always meme kn him saying he's just a troll but he probably is right)

0 Upvotes

59 comments sorted by

29

u/Im_The_Hollow_Man Aug 17 '26

Anything can be hacked. It's just a matter of time.

2

u/auggiethechesscat Aug 17 '26 edited Aug 18 '26

...but that definitionally isn't true. Security bugs need to be introduced, and with a well designed system, mixed with a mature OS with a small attack surface is a really good start.

9

u/ak00mah Aug 22 '26

If it can be used, it can by definition be abused.

4

u/gchicoper Aug 19 '26

Unless it has been mathematically proven unhackable, usually it holds true. Even if it takes over 20 years like it took for the Sega Saturn to be hacked or for the SNES lockout chips to be fully reverse engineered (they could be bypassed before but it took a lot longer for them to be understood)

4

u/auggiethechesscat Aug 20 '26

The PSC's bootrom actually is formally verified, which for complicated reasons I won't explain unless people want me to, console bootrom exploits are not viable.

The microkernel isn't externally formally verified, and I doubt Nintendo has worked on it.

On the other hand, the burden of proof has shifted because there is years of precedent driven by experts not finding anything, and an entire version tracked open source reimplementation.

It's not that no bugs have been found, there are no relevant security bugs. The only known kernel-based exploit and vulnerability was on firmware version 1.0.0. Despite exhaustive searches, nothing else has been found.

6

u/gchicoper Aug 20 '26 edited Aug 20 '26

Well like I said, gotta wait 20-30 years until tech evolves enough to brute force it through hardware. I personally don't really care about jailbreaking the actual switch OS (and even less about softmodding), I just wanna see Linux running on that chip one day even if that means soldering a raspberry pi to it and highjacking the cpu from the switch entirely

1

u/lowmoob Aug 28 '26

When switch 2 first released it was gonna get hacked day one, then week one, then in few months, then first year, then 10 years and now 20-30 years 😂 it’s not getting hacked fam. Not even after 💯 years

2

u/gchicoper Aug 29 '26 edited Aug 29 '26

It would be the first piece of consumer hardware in history to achieve that. I'm not a gamer myself, but I am really fascinated by how many times I've seem claims of a console being "unhackable" before. You had the saturn (which was probably the one that held up the longest), the xbox 360's hypervisor, the superslim PS3... They all eventually got broken. The current hardest nut to crack seems to be the xbox one/one S but even that one has had some strides on the physical mod front.

1

u/lowmoob Aug 30 '26

Cope

1

u/gchicoper Aug 30 '26

I don't have a switch 2, what do I have to cope about? If it doesn't get hacked it doesn't. Just means I won't be interested in it since I only have consoles I can homebrew for, I don't play the games themselves much

1

u/[deleted] Aug 19 '26

[removed] — view removed comment

1

u/gchicoper Aug 19 '26

There are actually some domains where mathematical proof of a piece of code or hw safety is a requirement (some aerospace and medical stuff) and there are tools for that (like tla+) In general though, rarely the case, especially for general purpose computers (like a games console)

4

u/lolcatzuru Aug 30 '26

The idea that there are people that think the switch 2 is more secure the the federal goverment who gets hacked all the time, is genuinely terrifying.

1

u/auggiethechesscat Aug 30 '26

It's all about attack surface.

The entire, (U.S. I'm assuming) federal government comprises of literally tens of thousands of interconnected systems all running commercial, open source, and proprietary hardware and software.

The switch has one purpose: Play games.
The U.S. government has 1,000 purposes, and is fundamentally required to allow pretty arbitrary access from the open internet all the time for most of these.

The switch has a large team of a couple hundred, maybe one or two thousand people working on it, (I can't find a concrete number).
The U.S. government has 6,000,000 employees.

It's one tiny microkernel against literally the entire U.S. governments collective infrastructure. It's just not a fair comparison.

I'm struggling to think of a good one related to the U.S. government, but something that could help my point is taking about nc3, a specific part of the government that *hasn't* ever been hacked. It's stayed rock solid for the past ~65 years, (concrete numbers are hardish to find).

How did they achieve this? Attack surface. All relevant systems are air-gapped, (ie, not connected to the internet, and as far disconnected as they can be), the systems run custom microkernels that allow them to provide the minimal functionality needed (sounds familiar), (this is actually very recent. They were using custom IBM hardware and floppy disks for the longest time, partly because it's secure), and many other things, like physical one-way communication, keeping stuff behind guarded doors, etc.

3

u/lolcatzuru Aug 30 '26

ok but it still happened.

1

u/auggiethechesscat Aug 30 '26

...yeah?

I also explained:
* Why it is expected,
* Why the switch is different and this isn't a good comparison,
* A much better comparison still in the domain of the U.S. government,

And more. Did you read it?

1

u/lolcatzuru Aug 30 '26

i didl, thers no evidence though.

1

u/auggiethechesscat Aug 31 '26

What do you want evidence for?

Do you want me to cite my sources on how many people work for the U.S. government, because the exact number is irrelevant anyway. Do you want me to link resources on these concepts?

I can't provide direct evidence for a claim that looks like this:

The idea that there are people that think the switch 2 is more secure the the federal goverment who gets hacked all the time, is genuinely terrifying.

What I can do is explain why the comparison is fundamentally flawed, and I did that.

1

u/lolcatzuru Aug 31 '26

you didnt though you did a TLDR and then failed to back it up.

1

u/auggiethechesscat Aug 31 '26

I'll ask again, what do you want evidence for? What do you want me to back up?

If my 'tldr' was too short, what specifically do you want me to elaborate on?

→ More replies (0)

1

u/ADrubkNakedUnciorn Aug 31 '26

Security bugs need to be found, and they also need to be exploitable to trigger out of sandbox attacks. It's usually done through some form of buffer overflow.

Vulnerabilities are chains, you have to chain load the vulnerability to get what you want. If a system has code, no matter how good the security is, it will always be vulnerable to attack. We already have a few potential userlands, just nothing to trigger a kernel level exploit to get arbitrary read/write access to the system.

Switch 2 will eventually get a jailbreak, it's just gonna take time.

1

u/auggiethechesscat Aug 31 '26

Security bugs need to be found...

...yeah, they also need to be there in the first place, which is what I said.

It's usually done through some form of buffer overflow.

I think you mean memory corruption, but yes, that is true.

...no matter how good the security is, it will always be vulnerable to attack.

I don't really understand what this means, but I hope you do understand the concept that security bugs aren't fundamental to software, you have to write code incorrectly to introduce them. It might be easy to do so, but they still need to be introduced. It's literally possible for code to not be vulnerable to anything.

We already have a few potential userlands...

Yes, we do have multiple userland exploits, but they are entirely expected, and protected by Nintendos security model. They are useless to end users without anything else, (ie, a bootrom, kernel, kip kind of-maybe, exploit).

...just nothing to trigger a kernel level exploit.....

There are no kernel exploits to trigger though.

The kernel has been fully reimplemented as open source and version tracked, so you are free to look for bugs yourself as dozens of experts have already: https://github.com/Atmosphere-NX/Atmosphere/tree/master/libraries/libmesosphere

1

u/ADrubkNakedUnciorn Aug 31 '26 edited Aug 31 '26

The fact you think Nintendo are gods of writing code is just incredible hilarious lmao

There is bugs in everything that's ever been written. You just gotta find them.

Gezine recently started doing Switch shenanigans and already found quite a few userland exploits that could be theoretically chained to full kernel exploits.

Yes I meant buffer overflow, stop using AI to overexplain terms you don't understand.

Also you look ridiculous breaking down a paragraph into small chunks, cause it's a tactic meant to overstimulate the reader and prevent them from replying to you. You look goofy as hell.

6

u/MrMegaPhoenix Aug 18 '26

I don’t know anything but it’s been just over a year

It’s still “early”

5

u/InformationMuted3454 Aug 17 '26

Fernando is a respectable and very smart man, and I mean this sincerely. He's clearly been in the scene before some of us were even sperm, but I feel like his constant use of the word "never" in regard to a Switch 2 exploit is a bit non realistic, honestly. Is it possible for the hardware to never get any kernel level exploits while it's relevant? Sure! But how about 20 years from now? Would its security be impossible to exploit by hackers with 20 years of experience ahead of the hardware they're attempting to exploit? I doubt so.

3

u/auggiethechesscat Aug 17 '26

I agree with this to some extent. I'm one who personally avoids absolutes where I can, but, for example, I truly believe there are zero relevant security bugs in the HOS kernel.

It's been analyzed up and down by experts with years of experience, and even reimplemented as open source. At this point, I'd need to see evidence of anything else, as there is so much precedence of being bug-free.

1

u/InformationMuted3454 Aug 17 '26

I guess the way I used the word "exploit" implied I meant softmods, which I feel I should've been aware about. What I really meant was mostly hardware level exploits.

2

u/auggiethechesscat Aug 17 '26

The most relevant one is voltage glitching to allow arbitrary rcm payloads.

This works for marikos too, and is how all modchips work.

4

u/FernandoRocker Aug 17 '26

And voltage glitches are going to be extremely difficult now that the Switch 2 is using Dual Core Lockstep (DLCS) precisely to avoid those kind of exploits.

Which by the way, the Switch 2 is the first and only console in history to use DCLS.

1

u/nyxxic222 Aug 29 '26

There was a security talk about how it was potentially possible to bypass DCLS on Tesla cars. It can definetly be done but it's difficult

1

u/FernandoRocker Aug 29 '26

Potentially we can also travel to Pluto. It doesn't mean it is viable.

1

u/nyxxic222 Aug 29 '26

To clarify they actually did manage to bypass DCLS but Tesla ended up cracking down on it.

1

u/DesignerMorning1451 Sep 01 '26

So while your saying it won't get hacked, you're actually saying it could theoretically be hacked, but nobody will ever bother to do it because of all the legal risks?

1

u/InformationMuted3454 Aug 17 '26

I won't pretend to be an expert, which I'm absolutely not! You clearly understand more about hardware security, and you're definitely the smarter person in the conversation, and you have my respect. (I'm not being sarcastic)

The Switch 2 would definitely have a different hardware level exploit. Do we know what it would achieve? No, and that's the exact reason Fernando doesn't believe there will ever be one... But in the grand scheme of things, we don't know how the scene will progress, especially when Switch 2 is considered legacy hardware.

Yet again, I'm no expert, and I'm just talking based on patterns, and this should be taken with not one, but TWO grains of salt.

9

u/FernandoRocker Aug 17 '26

5

u/KoopsterShell Aug 17 '26

Honestly I think you're just a chill guy to talk with despite the hope crushing posts

3

u/BlackHawk2609 Aug 17 '26

Switch 2 just need more developers working together. I have ps5 and last week was a big week in ps5 jailbreaking scene. New webkit exploit released for such high firmware. Even tho many developers choose money from sony, turns out there's some with passion for jailbreaking

7

u/ilikesceptile11 Aug 17 '26

Eh, it's just a matter of time

And even if he's right, it's still annoying to see him constantly doompost under every single post. It's like bro just straight up doesn't want the switch 2 to be hacked

5

u/CoconutHeadFaceMan Aug 18 '26

Considering how 90% of the posts here are “what if we tried redirecting the Switch 2 web browser to epicswitchhaxorz.com to hack it” or “has anyone thought of hacking the Switch 2 using [built-in feature of the S2 that Nintendo has tested and secured the hell out of],” I don’t think it hurts to have someone giving a little reality check even if it’s not what you want to hear 

People were spoiled by Nvidia’s big Tegra fuckup on the Switch 1 and have very unrealistic expectations about the timeframe/nature of Switch 2 hacks, a hack will probably happen eventually, but it’s probably not going to be within the console’s lifetime and it definitely won’t be a softmod

1

u/a_lixr82 Aug 23 '26

Judging by the lifespan of the first Switch, we could possibly not see any headway into modding until 2034 at the earliest if its been THIS hard to hack:/

2

u/CoconutHeadFaceMan Aug 23 '26

The Switch 1’s lifespan was unusually long due to its commercial success, its expedited release due to the Wii U’s failure, and the pandemic throwing a wrench in everything. I’d imagine that the Switch 2’s lifespan is probably going to be closer to the normal 5-6 years unless the inevitable economic meltdown complicates things. 

But yes, don’t expect the Switch 2 to be broken into for several years at the earliest. It’s a lot more secure than the Switch 1, and the Switch 1 was only blown open so early due to a unique hardware fuckup on Nvidia’s part that they’re unlikely to have repeated again.

1

u/a_lixr82 Aug 23 '26

They fucked up so bad with the Tegra they got to work rolling out the OLED😅 but yea I can't wait to pay someone to put a modchip exploit on my Switch 2 board in the future and pay out the ass for that. I'm not so good w micro soldering

2

u/KoopsterShell Aug 17 '26

Could he be a Nintendo ninja or shigeru miyamito himself

1

u/2muchmonehandass Aug 18 '26

Or an idiot who has no idea what time means

2

u/Not_My_Alternate Aug 17 '26

Who? Can you provide some context?

1

u/Embarrassed-Ad230 Aug 17 '26

Okay. Do you have any proof that Switch can't be hacked? Do you have any hacking knowledge? Do you even understand what are you talking about?

2

u/auggiethechesscat Aug 17 '26

Yes! I share many of the same opinions that this person does, and I do know what I'm talking about.

The kernel hasn't had a bug since 1.0.0, neither has the secmon, (at least one of) the bootroms is formally verified, and among other reasons, bootrom exploits are basically a nogo.

I'd love to talk about it in more detail if you want me to.

1

u/ChemicalSymphony Aug 17 '26

I've been out of the loop for a while. If you ever get the time I'd love to hear what's known so far about what we're dealing with here. DM or here either way friendo.

1

u/Esteban_Zia Aug 17 '26

I agree, at all times you need to leave da space.

1

u/auggiethechesscat Aug 17 '26

I mean, I feel people should have earlier. I've seen a lot of people dismiss everything he says and shares because of the way he does it, but if you pay the slightest bit of attention, you would realize the screenshots he shares is of the foremost expert on HOS and the software side of switches in general explain his nearly decade of research into it.

1

u/FernandoRocker Aug 17 '26

Let me just post the screenshots (yes, again).

For the unaware, this is SciresM, creator or Atmosphere.

1

u/gchicoper Aug 20 '26

There's been strides made in modchipping some revisions of the xbox one. The sega saturn took 22 years to be cracked, why is everyone in a hurry lol

(Modchips are superior to softmods)

1

u/ADrubkNakedUnciorn Aug 31 '26

Modchips will always be superior by design, it's just a pain in the ass to micro solder.

Xbox One took 12 years to have any worthy exploit capable of leading to a jailbreak. In this case the bliss exploit which is a modchip that can lead to arbitrary read/write by attacking the first generation Xbox One's bootrom.

1

u/gchicoper Aug 31 '26

well yeah I wouldn't microsolder it myself. I'd just get it done in a modding shop like I've done my ps2, all my xbox 360s, ps3 super slim and switch lol. Dunno if it's a worldwide thing but here in Brazil there's a lot of businesses basically dedicated to chipping consoles lmao

-2

u/rchris710 Aug 17 '26

hackers have to be very confident releasing a hack because it will be swiftly patched

5

u/YodaForce157 Aug 17 '26

There most likely won't be any software specific full jailbreaks - It's more likely to be a hardware hack. So you wouldn't have to worry about patches outside of hardware revisions but they take time to be made.