• Hey, guest user. Hope you're enjoying NeoGAF! Have you considered registering for an account? Come join us and add your take to the daily discourse.

Nintendo launches 3DS Vulnerability reward program on HackerOne

axisofweevils

Holy crap! Today's real megaton is that more than two people can have the same first name.

BennyBlanco

aka IMurRIVAL69
This would've been a good idea 3 years ago, which is pretty much in line with everything Nintendo has had their hands in recently.
 

jmga

Member
Too late, N3DS security was completely broken more than a year ago. And thankfully everything is open source.
 

Platy

Member
Smea take on this :

3IP7Jk1.png

Dr7GaiU.png

https://twitter.com/smealum/status/805956889011855361
 

Blizzard

Banned
Snitches get stitches.
This is a bit of a tangent, but I wish this cultural attitude would change. Reporting or blocking crimes are generally good things, and people shouldn't feel that it's acceptable to harass or intimidate people who go about it.

There are cases where illegal things may be relatively harmless, but I strongly feel the associated attitude affects more of society than merely the harmless crimes segment, silencing or intimidating people who might report things like rape or sexual harassment.


I do agree that the 3DS bounty is a good idea but potentially a few years late. Still, I suppose Nintendo might as well try to get with the times? Without trying they're guaranteed not to get there.
 
Seems weird they would do this now with the Switch launching in 3 months and the 3DS slowly fading away as a result. Then again it's Nintendo.
 

Effect

Member
Seems weird they would do this now with the Switch launching in 3 months and the 3DS slowly fading away as a result. Then again it's Nintendo.

Unless it will be helpful with the Switch itself and whatever might ultimately replace the 3DS. The Switch is very likely more home console that can be portable instead of a true portable replacement for the 3DS. I wouldn't be surprised at all if there is a true 3DS replacement in a year or two that is the iPad Mini to the Switch's iPad Pro/iPad. Whatever it might be might very well be backwards compatible (assuming the Switch itself already isn't) with the 3DS software and they want to know what other weaknesses it has now.
 

M3d10n

Member
Finding vulnerabilities on the 3DS this late still yields knowledge that can be used to plug possible holes in the Switch.

I think there's near zero chance the Switch will run 3DS carts.
 
It might keep a 11.0 downgrade or kernel exploit from happening since all the hackers who care about the scene have released their projects and all the ones who want to profit off it already did with the Gateway bullshit. If someone finds a hole in the Switch to allow piracy you'll be damn sure they will make some proprietary piracy card and make $2 million instead of $20000.
 

SalvaPot

Member
I am pretty sure they are looking to form a base going into switch.

Edit: Nice to see a lot of other users think the same way.
 
Min reward is 100USD, they could easily end up being jerks like facebook and tell hackers to fuck off as a reward.

Nintendo will pay rewards to the first reporter of qualifying vulnerability information ranging from $100 USD to $20,000 USD
However, you agree that by submitting such information to Nintendo, even if the information is not eligible for a reward, you grant Nintendo a worldwide, perpetual, irrevocable, non-exclusive, transferable, sublicenseable, fully-paid and royalty-free license under any and all intellectual property rights that you own or control to use, copy, modify, create derivative works based upon and otherwise exploit such information for any purpose.
 

sonto340

Member
Nintendo has mostly fixed the vulnerability in the 3ds firmware by making it impossible to downgrade above 11.0.
That said there's supposedly an exploit floating around in private communities right now which this may be a move to patch before it's released publicly

Of course if you're below 11.0 or have a second 3ds that's exploited already that's meaningless but it's better than nothing.
 

rekameohs

Banned
The 3DS OS is a security disaster. For example, people can pirate games directly from Nintendo's servers without impunity. It makes sense to prepare for holes in legacy code in the Switch OS.
 

Erheller

Member
Nintendo has mostly fixed the vulnerability in the 3ds firmware by making it impossible to downgrade above 11.0.
That said there's supposedly an exploit floating around in private communities right now which this may be a move to patch before it's released publicly

Of course if you're below 11.0 or have a second 3ds that's exploited already that's meaningless but it's better than nothing.

I'm pretty sure that the exploit you're talking about is slowhax, which should already be patched in 11.2.
 

jediyoshi

Member
The 3DS OS is a security disaster. For example, people can pirate games directly from Nintendo's servers without impunity. It makes sense to prepare for holes in legacy code in the Switch OS.

To be fair, this is also the case with Sony's content distribution.
 

Pokemaniac

Member
Finding vulnerabilities on the 3DS this late still yields knowledge that can be used to plug possible holes in the Switch.

I think there's near zero chance the Switch will run 3DS carts.

Nintendo has already confirmed that Wii U and 3DS physical media will be incompatible. As far as I know, they haven't said anything yet regarding digital licenses.
 
In case you needed any more proof Nintendo doesn't care about the Wii U anymore...

Well yeah, unlike the 3ds the Wii U is not being actively produced and very much being treated as legacy. No way they'd invest anything in this kind of program for a dead/dying system. 3ds has at least another year of support/investment and perfect for using as a testing ground for Switch. I'm sure Nintendo is dying to move past Wii U.
 
Top Bottom