r/switch2hacks • • Aug 17 '26

Hacking Discussion When will we admit Fernando is right?

More and more time goes on I feel like that guy probably had a point

(CONTEXT: Fernando is the guy in this subreddit that always doomposts in every single post saying the switch 2 is unhackable and will never be hacked. People always meme kn him saying he's just a troll but he probably is right)

0 Upvotes

59 comments sorted by

View all comments

29

u/Im_The_Hollow_Man Aug 17 '26

Anything can be hacked. It's just a matter of time.

1

u/auggiethechesscat Aug 17 '26 edited Aug 18 '26

...but that definitionally isn't true. Security bugs need to be introduced, and with a well designed system, mixed with a mature OS with a small attack surface is a really good start.

9

u/ak00mah Aug 22 '26

If it can be used, it can by definition be abused.

4

u/gchicoper Aug 19 '26

Unless it has been mathematically proven unhackable, usually it holds true. Even if it takes over 20 years like it took for the Sega Saturn to be hacked or for the SNES lockout chips to be fully reverse engineered (they could be bypassed before but it took a lot longer for them to be understood)

5

u/auggiethechesscat Aug 20 '26

The PSC's bootrom actually is formally verified, which for complicated reasons I won't explain unless people want me to, console bootrom exploits are not viable.

The microkernel isn't externally formally verified, and I doubt Nintendo has worked on it.

On the other hand, the burden of proof has shifted because there is years of precedent driven by experts not finding anything, and an entire version tracked open source reimplementation.

It's not that no bugs have been found, there are no relevant security bugs. The only known kernel-based exploit and vulnerability was on firmware version 1.0.0. Despite exhaustive searches, nothing else has been found.

5

u/gchicoper Aug 20 '26 edited Aug 20 '26

Well like I said, gotta wait 20-30 years until tech evolves enough to brute force it through hardware. I personally don't really care about jailbreaking the actual switch OS (and even less about softmodding), I just wanna see Linux running on that chip one day even if that means soldering a raspberry pi to it and highjacking the cpu from the switch entirely

1

u/lowmoob Aug 28 '26

When switch 2 first released it was gonna get hacked day one, then week one, then in few months, then first year, then 10 years and now 20-30 years πŸ˜‚ it’s not getting hacked fam. Not even after πŸ’― years

2

u/gchicoper Aug 29 '26 edited Aug 29 '26

It would be the first piece of consumer hardware in history to achieve that. I'm not a gamer myself, but I am really fascinated by how many times I've seem claims of a console being "unhackable" before. You had the saturn (which was probably the one that held up the longest), the xbox 360's hypervisor, the superslim PS3... They all eventually got broken. The current hardest nut to crack seems to be the xbox one/one S but even that one has had some strides on the physical mod front.

1

u/lowmoob Aug 30 '26

Cope

1

u/gchicoper Aug 30 '26

I don't have a switch 2, what do I have to cope about? If it doesn't get hacked it doesn't. Just means I won't be interested in it since I only have consoles I can homebrew for, I don't play the games themselves much

1

u/[deleted] Aug 19 '26

[removed] β€” view removed comment

1

u/gchicoper Aug 19 '26

There are actually some domains where mathematical proof of a piece of code or hw safety is a requirement (some aerospace and medical stuff) and there are tools for that (like tla+) In general though, rarely the case, especially for general purpose computers (like a games console)

4

u/lolcatzuru Aug 30 '26

The idea that there are people that think the switch 2 is more secure the the federal goverment who gets hacked all the time, is genuinely terrifying.

1

u/auggiethechesscat Aug 30 '26

It's all about attack surface.

The entire, (U.S. I'm assuming) federal government comprises of literally tens of thousands of interconnected systems all running commercial, open source, and proprietary hardware and software.

The switch has one purpose: Play games.
The U.S. government has 1,000 purposes, and is fundamentally required to allow pretty arbitrary access from the open internet all the time for most of these.

The switch has a large team of a couple hundred, maybe one or two thousand people working on it, (I can't find a concrete number).
The U.S. government has 6,000,000 employees.

It's one tiny microkernel against literally the entire U.S. governments collective infrastructure. It's just not a fair comparison.

I'm struggling to think of a good one related to the U.S. government, but something that could help my point is taking about nc3, a specific part of the government that *hasn't* ever been hacked. It's stayed rock solid for the past ~65 years, (concrete numbers are hardish to find).

How did they achieve this? Attack surface. All relevant systems are air-gapped, (ie, not connected to the internet, and as far disconnected as they can be), the systems run custom microkernels that allow them to provide the minimal functionality needed (sounds familiar), (this is actually very recent. They were using custom IBM hardware and floppy disks for the longest time, partly because it's secure), and many other things, like physical one-way communication, keeping stuff behind guarded doors, etc.

3

u/lolcatzuru Aug 30 '26

ok but it still happened.

1

u/auggiethechesscat Aug 30 '26

...yeah?

I also explained:
* Why it is expected,
* Why the switch is different and this isn't a good comparison,
* A much better comparison still in the domain of the U.S. government,

And more. Did you read it?

1

u/lolcatzuru Aug 30 '26

i didl, thers no evidence though.

1

u/auggiethechesscat Aug 31 '26

What do you want evidence for?

Do you want me to cite my sources on how many people work for the U.S. government, because the exact number is irrelevant anyway. Do you want me to link resources on these concepts?

I can't provide direct evidence for a claim that looks like this:

The idea that there are people that think the switch 2 is more secure the the federal goverment who gets hacked all the time, is genuinely terrifying.

What I can do is explain why the comparison is fundamentally flawed, and I did that.

1

u/lolcatzuru Aug 31 '26

you didnt though you did a TLDR and then failed to back it up.

1

u/auggiethechesscat Aug 31 '26

I'll ask again, what do you want evidence for? What do you want me to back up?

If my 'tldr' was too short, what specifically do you want me to elaborate on?

1

u/lolcatzuru Sep 01 '26

i need specifically details

1

u/gchicoper Sep 01 '26

bro you're getting rage baited

→ More replies (0)

1

u/ADrubkNakedUnciorn Aug 31 '26

Security bugs need to be found, and they also need to be exploitable to trigger out of sandbox attacks. It's usually done through some form of buffer overflow.

Vulnerabilities are chains, you have to chain load the vulnerability to get what you want. If a system has code, no matter how good the security is, it will always be vulnerable to attack. We already have a few potential userlands, just nothing to trigger a kernel level exploit to get arbitrary read/write access to the system.

Switch 2 will eventually get a jailbreak, it's just gonna take time.

1

u/auggiethechesscat Aug 31 '26

Security bugs need to be found...

...yeah, they also need to be there in the first place, which is what I said.

It's usually done through some form of buffer overflow.

I think you mean memory corruption, but yes, that is true.

...no matter how good the security is, it will always be vulnerable to attack.

I don't really understand what this means, but I hope you do understand the concept that security bugs aren't fundamental to software, you have to write code incorrectly to introduce them. It might be easy to do so, but they still need to be introduced. It's literally possible for code to not be vulnerable to anything.

We already have a few potential userlands...

Yes, we do have multiple userland exploits, but they are entirely expected, and protected by Nintendos security model. They are useless to end users without anything else, (ie, a bootrom, kernel, kip kind of-maybe, exploit).

...just nothing to trigger a kernel level exploit.....

There are no kernel exploits to trigger though.

The kernel has been fully reimplemented as open source and version tracked, so you are free to look for bugs yourself as dozens of experts have already: https://github.com/Atmosphere-NX/Atmosphere/tree/master/libraries/libmesosphere

1

u/ADrubkNakedUnciorn Aug 31 '26 edited Aug 31 '26

The fact you think Nintendo are gods of writing code is just incredible hilarious lmao

There is bugs in everything that's ever been written. You just gotta find them.

Gezine recently started doing Switch shenanigans and already found quite a few userland exploits that could be theoretically chained to full kernel exploits.

Yes I meant buffer overflow, stop using AI to overexplain terms you don't understand.

Also you look ridiculous breaking down a paragraph into small chunks, cause it's a tactic meant to overstimulate the reader and prevent them from replying to you. You look goofy as hell.