Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
What does Nintendo Switch and iOS 9.3 have in common? CVE-2016-4657 walk-through (youtube.com)
119 points by LiveOverflow on March 13, 2017 | hide | past | favorite | 29 comments


I was at work so unable to watch video, the GitHub[1] page was quite informative though =)

[1] https://github.com/LiveOverflow/lo_nintendoswitch/blob/maste...


The 3DS was hacked multiple times via pre-existing WebKit exploits, you'd think Nintendo would have learned to keep it up to date by now. Apparently not...


Nintendo doesn't directly control the browser. The browser is based on "NetFront" from Japanese company "Access Co. Ltd"

According to Wikipedia, the last "stable release" was in 2012. Which may also contribute to things

https://en.wikipedia.org/wiki/NetFront


Well, you can blame them, because they could have picked a browser that's rather more up to date.


The browser last updated in 2012 seems to be the older Netfront that uses a custom engine, not the Webkit one (Netfront NX).

The older Netfront predates Webkit, it was available for the Dreamcast.


And before that they used pre-Blink Opera.

Nintendo really has bad luck with picking their browser vendors…


Why are they even using a vendor? The work is just integrating webkit in their build pipeline! How can using a vendor not be more hassle, money, time and troubles?


I assume they're asking themselves that question now. Probably it seemed cheaper up front.


Nintendo isn't the only one.

The PS Vita (and PS4, but I may be wrong) were also hacked by a chain of exploits that started with, you guessed it, simple WebKit exploits.


I noticed when I signed into Twitter via the Switch, it used the internal browser, which Twitter identified as Safari. Not sure what the actual User-Agent was, but the big N seems to have just pulled the browser code off the shelf (not surprising).


WebKit based browsers tend to include Safari in their user agent.



The web browser used is Netfront, according to licensing info.


Thanks for very informative video. Sketches and diagrams on top of code are really well done. I wish more tutorials would use them.


>What does Nintendo Switch and iOS 9.3 have in common? CVE-2016-4657 walk-through

For the ESLers out there, the verb here should be do instead of does.


"What does Nintendo Switch have in common with iOS 9.3?" will work too, right?


yes


thanks. I blame it on being not a native speaker :P I fixed it on YouTube.


Just fyi his correction is right but somewhat pedantic: no one would bat an eye at that error in a work email.


This isn't pedantic; it's of the level that it "sounds wrong" and will be immediately noticed and distracting (for a brief moment) to any native speaker, not just pedants.


I'm a big pedant and I agree with the parent; it's not that bad. It might mark an uncompleted word order change for a native speaker "what does A have in common with B?" as opposed to "what do A and B have in common?" but it's not that distracting TBH.


I'm curious by the idea that your co-workers/bosses aren't making minor grammatical errors on a regular basis.


Very well explained video. This was incredibly interesting to watch.


I gotta say, I'm really annoyed at whoever let the cat out of the bag so soon. I'm afraid shit like this will frustrate the efforts of many. Have some patience y'all.


It was already out of the bag. That the switch is vulnerable to this was quickly known on day 1 and shortly after posted all over the internet. I didn't leak something private.


I know, I wasn't referring to you in particular, it was no secret a while ago. I guess it was inevitable since it was so easy. I'm just sore that this will likely be patched in future updates now.


You're gonna have to be cleverer then.


Considering all the horror stories about Japan's IT industry, should this really come as a surprise?


What horror?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: