Indie Game Removed from Switch After Dev Reveals It Has a Hidden Code Editor
nintendolife.com
nintendolife.com
>Everyone is an armchair expert. Everyone thought the worst. You've seen that I've been called a dick, idiot, and everything in between. Because sensationalised news sells. If the narrative was 'I added a sandbox to A Dark Room that lets you mod the game and provide a medium for kids to code (and technical parents to show their kids what they do),' it would have gone unnoticed.
This is just desperate. Nintendo are notoriously protective of their platforms and their IP. It has been an essential part of their business model for over 30 years, going back to the NES10 chip. Expecting Nintendo to disregard their own Terms of Service because this specific breach is well-intentioned is utterly naive.
Rajan says: "I snuck it in assuming that plugging in a USB keyboard and pressing the "~" key wasn't part of the test plan". He intentionally deceived Nintendo as to the nature of his app by including a hidden feature that allows for arbitrary code execution. He announced the existence of that feature on social media. What else did he expect to happen?
https://www.reddit.com/r/SwitchPirates/comments/9lspva/compl...
You are overstating its use, however.
I worked for a game division of Sony at the time, and we were furious at the mothership for that incident.
There is a perfectly reasonable debate to be had about bootloader unlocking, sideloading and consumer choice, but this is not that debate. The issue here is fundamentally about someone intentionally deceiving a business partner.
Sidebar: There are no shortage of tablet-ish computers that will run arbitrary code. The Joy-Con controllers are class-compliant and will work with any Bluetooth host. There are open alternatives, but a lot of people buy the Switch specifically because it offers a curated experience with clear age ratings and effective parental controls.
To meaningfully contribute to the debate on walled gardens, it is first necessary to acknowledge their relative popularity compared to open platforms. If walled gardens were universally and unconditionally bad, it is implausible that they would have such broad market acceptance. In the case of Nintendo, this issue is particularly acute - many informed observers credit the NES10 chip and the Nintendo Seal of Quality with saving the video games industry.
Getting approval to develop for the Switch is much harder.
You can buy Wii U and 3DS dev kits right away, though. And boy they are EXPENSIVE.
The switch is completely thoroughly irreversibly jailbroken at the hardware level already. I don't think the secret purpose was to be a jailbreak.
This has been fixed in hardware revisions since about a year ago. Getting a unit that is vulnerable to the so-called RCM exploit has become increasingly difficult.
(The boot9strap exploit against the 3DS, on the other hand, was never fixed. One wonders why.)
This has got to be a joke.
There's a few lines here that need to be drawn somewhere. Nintendo sells access to a platform to developers. It's not unreasonable that they aren't allowed free reign to control what's run; at some point one developers free reign would conflict with anothers.
Should the consumer have free control over what's running on their hardware? Perhaps. Let's for the sake of argument assume yes.
Then how should Nintendo and third party developers deal with hackers? Completely cut their access to Nintendo/game services? Now they have a brick.
The lines drawn for developers and consumers with respect to game consoles make sense and generally work for all involved.
I think your point has legs in other contexts (i.e. Apple products, right to repair, etc) just not here. If people feel differently they should vote with their dollars, but managed walled gardens will always be greener in some aspects.
These are truly walled gardens. Worse, these walled gardens are monopolies that can and are abused by large companies.
So, either people are painfully stupid or a managed platform has some appeal over free ones.
Continuity, ease of use, various warranties/guarantees make walled gardens attractive. If consumers have free reign and brick their device, it's hard to expect the manufacturer to have/honor any warranty. If developers have free reign there's no guarantee another application won't break theirs or that they won't break someone else's... or that it'll work with whatever the consumer is doing.
Yes, an obvious counter point is *nix systems, but there is some authority in that ecosystem which keeps most things working. It's still not painless to setup/use which prevents it from effectively competing with windows/Mac OS.
Simply put, the price of admission into a walled garden comes with some perks/guarantees/warranties which aren't readily available elsewhere.
What I had in mind was more a long the lines that windows/Mac OS isn't transparent and the consumer has limited control over what it's doing and how to implement things. Furthermore their official app stores are a walled garden of sorts.
Consumers/developers have a good deal of freedom on these platforms and with that comes breakage in various forms. Malware, instability, etc. And to deal with that you have repair shops/programs. System resets, fresh installs etc. Maintenance becomes a responsiblity of the consumer.
Like I said, the lines can move based on context. Moving the needle further towards freedom for developers/consumers gets you *nix systems - which is harder for your average consumer to maintain/use. Moving away gets you iphones/consoles, etc which "just work" and flaws in software/hardware handled by the manufacturer.
[1] https://english.stackexchange.com/questions/15276/is-this-us...
https://blog.oxforddictionaries.com/2012/03/26/rein-or-reign...
But still understandable with the kind of context - "take the reins" and "take the reigns" would be imply "take control", no? (Sure, it's clunky, but that's English for you.)
Small nit - you probably mean "outside of using them to play Nintendo-approved games" since there's only 2 Nintendo games on the Switch here and 6 non-Nintendo games.
By providing something like OtherOS, you remove the incentive for that group to crack your console.
It is fairly telling that the PS3 was only cracked after OtherOS was removed.
As I recall, ultimately Hotz managed to compromise the device's root key, and Sony determined that it was impossible to protect the key (after replacing it) as long as OtherOS continued to exist.
I don't know what you mean here. You can play the latest Mortal Kombat on the Switch, too.
Nintendo keeps providing excellent gaming experience that no one else does. Super Mario Odyssey is awesome not because it's the same old Mario guy from NES, but because it is just a great game.
Nintendo games are not polluted by the games-as-service and free-to-play monetization mindsets as badly as other platforms.
I don't like a lot of their rigidity, such as takedowns or still not getting rid of having stuff segregated by regions, but I appreciate what they contribute to the world of video games.
But why does this have to do with draconian lock-down rules? Presumably, allowing homebrew code is not gonna affect the above at all.
When I want something with solid gameplay that doesn't just sell because the graphics are so good (or whatever marketing flavour of the month is in vogue at the moment), a Nintendo console is what I go to.
But if i want to produce homebrew for my own machine, I'd have to get permission from nintendo. I also have to pay for that priviledge, when the hardware is something i have purchased.
You say this and there was certainly a time when I would have agreed with you. Sadly, the reality doesn't match that belief so I no longer think that is the case.
See that is nostalgia talking.
Furthermore, he notes that he regrets it and takes full responsibility: "I acted alone and stupidly."
Although, you could also buy special batteries that would let you root a PSP...what a weird handheld.
The point is, who knows, the game's scripting language could have shipped with an undocumented 'write word to memory' function.
Very different thing.
It is massively unprofessional to ship an Easter Egg without broad consent to do so. Planning a fun "secret" for your users? Great! Surprising people involved in the publishing pipeline, esp. in a "will I get caught" way? Not so great. That's where Rajan went off the rails.
(Edit: pkroll is correct, the final penalties were $21 million.)
In that in both cases the backlash is more ridiculous than the Easter egg itself?
The revelation that, in addition to those kinds of sex, a crude sex minigame could be revealed, if one made a bit flip to a config file with the help of third party software or hardware, led to:
* $21 million in penalties.
* The city of Los Angeles suing the company.
* A class action lawsuit whose initial plaintiff was a lady who bought the game for her 14 year old grandson, which would end with 2700 claimants being compensated.
* Hillary Clinton calling on the FTC to "take immediate action."
* Senator Lieberman, working with Clinton, proposed a law making the sale of violent games to children a federal crime.
But such an Easter egg could put Nintendo in a similar situation, and I can see why they can't let developers get away with hidden content like this. It would set a bad precedent.
No, no, he only embedded Ruby. Not Rails.
Nintendo is very protective of running pirated or unofficial games, ever since the late 80's, when knock-off games were rampant and leading up to today with DRM. I'm sure it's against their policies to sell a game where users are allowed to write arbitrary games/code without Nintendo approval.
It would be different if the game was sold as a Ruby interpreter, because then they could at least verify it's capabilities and make an informed judgement about whether they should allow it.
To get an account there, you must agree to a few things, one being an NDA, and to get a Switch dev kit you must agree to a few more things, as well as go through a case-by-case evaluation of your game idea, if you are not an established game developer.
We won't be seeing the agreement(s) that were likely broken, and if you can see them, you are under NDA.
I have a few guesses, but no, I don't see why Nintendo took issue with this. Is it because users could damage their devices with access to something like this? Is it because this could somehow be used to undermine Nintendo's DRM or cheat in online games?
My hacker nerd side is all giggly.
My security and consumer conscious sides bristle at the idea some dev thought it was a great little in-joke to ship this to unsuspecting users.
That's a very long-winded way of saying, "He should only sell what was advertised."
> unsuspecting users
Nobody is forcing anyone to find or access Easter Eggs. It wasn't malicious nor annoying, it wasn't even accessible unless you attached a keyboard. I haven't seen any backlash from "unsuspecting" buyers, only Nintendo.
I see the potential worries from a security perspective, but as an "unsuspecting" consumer, why would you care?
Actually, I don't see why. The interpreter only runs inside his game. It doesn't root the machine. Why would anyone object to this?
This is obviously bad for nintendo.
And, there has been one pure "software" kernel access released (for 1.0.0), as well as a handful of later kernel exploits that haven't been.
Nintendo is right to be paranoid about ANY code execution, because that is the first step to reducing the pool of end users who can then "root" their consoles.
It’s currently the only known chain, and might be the only one in existence. And yet it’s a big threat. In practice, A Dark Room isn’t a particularly interesting entrypoint due to requiring an usb keyboard (web browser is easier to open). But it's understandable that Nintendo would want to keep those entrypoint to an absolute minimum. Especially since newer hardware revision exist which fixed Fusee-Gelee, the BootROM bug you talked about.
Things like this are why Nintendo doesn't freely allow save file access, or even allow them to be accessed without encrypting them.
If they work this hard to prevent file loading exploits, you can bet your ass there is contract language to prevent what this guy did.
His explanation: https://ruby.social/@amirrajan/101991299426077446
He did security checks: https://ruby.social/@amirrajan/101986725826245184
This is worth nothing to Nintendo and should be worth nothing to other people. This should've been done as a collaboration with Nintendo in order to actually bring Ruby to the Switch, not snuck in.
Anyway; so like Apple (less and less luckily), Nintendo forbids editable code to run on their devices? Or is it allowed if there is a gaming aspect involved? Or just not at all?
It doesn't make intuitive sense to me why a BASIC interpreter would be allowed, but not a Ruby interpreter. The difference is likely that Nintendo was never informed about the Ruby interpreter.
While I wish everything was user-modifiable, I'm generally okay with game consoles being locked down, because they don't bill themselves as general-purpose computing devices. I can't run my own software on my BluRay player either.
Is Excel 97 not a spreadsheet program?
The users? Sure. An authority? No, not really.
I will point out that the Switch already supports untrusted and unvetted code execution—it's called Javascript. The Nintendo Switch may appear to not have a web browser, but it pops up when you try to log into a captive portal. Without it, no one would be able to use public wifi hotspots.
I will also note that Nintendo hasn't exactly done a great job at preventing piracy or homebrew on the Switch—both are available provided you have a somewhat older model, and on the latest firmware even.
Recovery Mode was the fault of Nvidia, not Nintendo. Soon after that was discovered, the silicon for the Switch was iterated and now you need a signed binary, even in recovery mode.
They plug holes as soon as they find them. I don't think it's fair to compare the relatively limited number of people that work at Nintendo to the literal army of people that work to break Nintendo's work every day.
https://www.imore.com/how-use-hidden-web-browser-nintendo-sw...
Edit: Oh, the particular article I linked has you use a public, specially-crafted DNS server, instead of setting one up on your home network as I've done in the past. Oh well, same principle.
Plenty of captive portals do indeed require Javascript, which is why the Switch's web browser supports Javascript.
As for their efforts: They've made far more effort than they ever have before. Using homebrew or custom firmware effectively means you can't ever use that device online again (which wasn't the case for earlier consoles).
Are you suggesting that just because they've made mistakes that they would be in any way inclined to let the Ruby thing go?
I didn't mean to suggest that! Sneaking a Ruby interpreter into a game without telling Nintendo was stupid, and Nintendo's response was entirely logical and acceptable.
However, if Nintendo had known about the Ruby interpreter and had reviewed it beforehand, but denied it anyway... well, I still wouldn't find that particularly scandalous, but I would say it's a bit of a dumb precaution on a device with a Javascript engine.
And if Nintendo is hiding the web browser on security grounds, that's dumb too! Who cares if the browser is hidden—as long as it's accessible, the people who'd use it to hack their consoles will jump through whatever hoops are necessary. Making the browser hard to open only hurts regular users.
I find it more likely that the browser is hidden because it's too buggy and unstable for widespread use. I've played with it, and it likes to crash. A lot.
There's a Megaman clone for the DSi version which requires you to scan more than 100 (!) QR codes. That's not fun, and even as an edge case, it's not an experience you want anyone to have with your product. Better to push them to the central server.
I'm betting it would probably be all good until you allowed interfacing with some more basic underlying systems to the language (such as network for example) to the language. They can't be against custom map making for example right? How Turing complete are you allowed to make your custom map editor?
Could you make a video game for these platforms, Nintendo or iOS, where there is a fully... is endogenous the word? virtual machine in the game world that you could program on? Like, the registers and compute cycles weren't real ticks, they actually happen within the game loop?
Like, if I made a space sim¹, and the flight computer ran on PICO-8², and there were actual transistors in the spaceship model, and there was a terminal with actual wires that go to them, would that get banned from the app stores?
¹ (similar to what 0x10c was intended to be)
It's probably moot because I'd expect Nintendo to demand a patched version of the game with Ruby removed to replace the existing version for those who bought it even if Nintendo decides not to allow it up on the store again.
Also Nintendo does have a full BASIC interpreter available for sale on their app store.
This hasn’t been the case for any previous Nintendo console. Xbox does use HyperV to silo games from apps, but we’ve never heard anything about Nintendo doing something similar.
[1] https://media.ccc.de/v/34c3-8941-console_security_-_switch
Even if there are newer, "safer" sandboxed environments, sandboxes are meant to be broken.
http://www.nintendolife.com/reviews/switch-eshop/human_resou...
Nintendo did not intentionally build a way to create and execute arbitrary code in Super Mario World. It happens as a consequence of various unintentional bugs.
The existence of this phenomenon does not tell us anything about what Nintendo is "okay" with on their platforms, because it wasn't created purposefully.
If Super Mario World contained a "code editor", that would be a very different story. You can't very well create a code editor by accident.
Nintendo doesn't write code, people do; we can't say for sure this wasn't intentional. We don't know whether a developer left a trail of backdoors as a protest against Nintendo's well-known policy of tight editorial control of game developers, for example.
However, given the existence of this editorial policy, it's reasonable that they did not intend to include these backdoors in Super Mario World. Perhaps they didn't claw back this title because these backdoors were not known until recently.
This is fair, too. However, if you read about how these particular glitches worked, I find it extremely hard to believe that they would be implemented on purpose.
They're a consequence of a series of run-of-the-mill memory errors across the game's code. There would have needed to be a group of developers conspiring to make this possible... and for what? So a very dedicated player can spend hours painstakingly inputting a flappy bird game that will be lost when the system is turned off?
I don't think you know what "built-in" means.
Arbitrary code execution and bugs are not "Easter eggs".
Almost every word in your comment is wrong.
You don't have to be online to run a Switch. And the Switch uses solid state memory so loading times are pretty good.
Can someone ELI5 what the issue is here or why there's any reason for remorse? Since it's a text adventure game, what's the difference between the game as allowed (text adventure) and the sandboxed bundled ruby? What's the difference between those 2 things? (A sandboxed ruby seems strictly equivalent to a text adventure game to me.) Not trying to be obtuse, just don't get it.
Is there some more context here? I'm still confused.
The first computer I had access to had BASIC built in. Having control of a computer of what runs and not is an absolute basic right of ownership.
And from these computers called "game consoles", you the purchaser have none of that.
That's not to say that jailbreaking, or any other gaining of execution is inherently bad, it just depends on the use-case- as a teenager, programming on a Switch sounds great, while as a parent, the possibility of my kid gaining access to unlimited blood and gore, Konami code style, might turn me off the platform.
I guess the Overton window is shifting away from a position of software freedom; which is unfortunate. :-/
I haven't seen anyone defending Nintendo's use of proprietary platform lock-in, but only that Nintendo should have been notified about it as part of publishing the game.
There's whether you should be able to run your own code on your own device, which I think most people here are on board with.
Then there's whether you should be able to misrepresent what you've agreed to ship through someone's network when you've presumably signed contracts and made statements about that end up being untrue. I think most people would agree that Nintendo should have the ability to control what they allow in their store.
Finally, there's how these interact, because you can only really run stuff on the switch that Nintendo allows in their store, which makes the issue much more complicated.
Which part of the issue someone focuses on will likely inform how their comment is formed, but also how they interpret other people's comments, whether they are really focusing on the same aspect of the issue or not.
If you remember what happened on the 3DS with Cubic Ninja [0], that game’s level editor allowed the console to run homebrew code. That was inevitably another vector for piracy at a time where Nintendo was already grappling with the for-profit piracy enabler that was Gateway.
Based on this I can’t personally say if Nintendo is against homebrew running on their consoles or if they’re trying their hardest to prevent piracy, at the expense of homebrew. I do think that the feature included in A Dark Room would have had better chances of staying if the dev hadn’t kept it a secret through the publishing process, though.
[0] https://wikipedia.org/wiki/Cubic_Ninja#3DS_homebrew_exploit
And I'm perfectly fine with that. It's an entertainment device. I have plenty of things that I can run my code on.
> As for microwave ovens and other appliances, if updating software is not a normal part of use of the device, then it is not a computer. In that case, I think the user need not take cognizance of whether the device contains a processor and software, or is built some other way. However, if it has an "update firmware" button, that means installing different software is a normal part of use, so it is a computer.
The Switch does have an "update firmware" function, in addition to being able to install software (games) from the internet or from physical media, so it definitely counts as a computer under this definition.
That's it.
If you expected more, you've been lied to. It does exactly what it's supposed to do, exactly what it was sold to do, and it does this very well.
If you want development hardware, then buy development hardware. There's no shortage of it; it's everywhere. Go nuts.
If you buy commercial hardware meant for use by end users, made by a company that fights hard against piracy, you get hardware that is anywhere between "annoyingly difficult" all the way to "virtually impossible" to use in your own way. This should not come as a surprise.
The Switch is sold as a game console, and nothing more. Certainly not a development platform. If you can squeeze a development platform out of an off-the-shelf Switch, you are lucky. If you can't, then you got exactly what you were sold, and you have (in my eyes) very little room to complain about the lack of development capability. You knew what you were buying when you bought it.
If that was true, that would be fine.
But that's not it. It also has restrictive digital signatures that prevent you from running games designed for it.