SSSL – Hackless SSL bypass for the Wii U
github.com
github.com
If it weren't Nintendo, one would think this could be a creative approach to reviving the console (and its sales).
It could also have been a debug config which made it through the release. I guess we'll never know but this is the part of tech which I love the most: finding ways to break outside the intended capabilities of a platform, just because.
Wii U production ended entirely more than 7 years ago - there's no more stock to sell. It's a legacy platform in every sense of the word.
> By December 2019, Nintendo reported life-time sales of 13.56 million Wii U console units and by September 2022 103.53 million software units worldwide
and
> Despite this, the console had third party releases until 2020.
So software sold in September 2022 can no longer run in April 2024, and you somehow try to justify that by "legacy platform"?
Production stopped, eventually hardware sales stopped, too, but software sales for the locked in hardware did not until recently.
> So software sold in September 2022 can no longer run in April 2024, and you somehow try to justify that by "legacy platform"?
I tend to imagine that every third-party release for the Wii U in 2020 was built for the Switch and made available on the Wii U as a low-cost port. There were no vendors and no Wii U owners at that time who weren't well aware that the platform had died years ago.
What? Wii U software still works fine - you can even still download digital purchases from the eShop if you already own them. The component that was turned off yesterday was the servers used for multiplayer games, which isn’t an unusual thing to see occur this late into a console’s lifespan.
Pretendo are doing good work! Even if most of the worthwhile parts of the console’s library have since been ported to other systems, it’s still nice that some parts of the original experience are going to be preserved.
That is what they're doing, the Pretendo project is building custom servers for the 3DS and Wii U to replace the official ones which just shut down. This exploit makes it possible to point a non-jailbroken Wii U at the Pretendo servers just by changing the DNS settings.
I suspect it's just a normal, regular software bug.
SSL code is often complicated, and the faulty code probably passed a bunch of tests. As the software update was for a decade-old product, which had been discontinued for 4 years, the people who were best placed to spot the new bug had probably already moved on to other projects.
Why mess with the SSL stuff at all? I can't say for sure, but SSL makes it easy to accidentally create a time bomb by, for example, hardcoding a certificate with an expiry date 10 years away. Or a console might have special requirements. For example, a user can leave a device in a cupboard for 5 years without turning it on, so the software update procedure needs extreme backwards compatibility.
It's been years since I read the TLS spec, but a host wildcard like this isn't normally possible, since it bypasses host verification completely.
And the CA verification bypass is also out of line with normal behavior. CA verification is another TLS bedrock behavior.
Together, these basically disable TLS verification. I'm surprised they didn't disable date checking too, because why not go for it at this point.
This isn't a bug, this is designed.
It’s quite a stretch to say that an engineer designed a multi-year project to surreptitiously break TLS so third party stores could be used without CFW (which is also pretty trivial to do on the WiiU).
No, but the most popular one gives you just a callback and people end up using that to build their own insecure, weird strategies.
That's how we end up with things like "the certificate is valid if the issuer DN is this hardcoded string" (very common attempt at pinning an issuer), or "the certificate chain is valid if the chain contains this precise value" (this one, likely another failed attempt at pinning), or indeed the Hashicorp Vault vuln the other week which was roughly "the certificate is valid if it has the right AKID and serial number".
But I suppose if the 3DS servers are actually shut down now, that risk goes away. Primarily I'd just like to backup my saves and the games I legally purchased.
[0]: https://twitter.com/KaeruTeam/status/1340021213352128512
EDIT: Bug exists since 1 march 2021.
At first, it seems nice. But its impossible that Nintendo being nice in anyway, and even less more by adding a bug. This, and Pretendo that seems to expect the bug before the release.
I find this really suspicious.
> We've been holding on to this exploit for this day for quite some time, in case Nintendo decided to issue patches for it.
https://en-americas-support.nintendo.com/app/answers/detail/...
I'm somewhat skeptical that Nintendo won't end up fixing this one too. The eShop is still running so users can continue to download their purchased games: https://en-americas-support.nintendo.com/app/answers/detail/...
> For the foreseeable future, it is still possible to download update data and redownload purchased software and downloadable content from Nintendo eShop.