<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title>non-fake signing for content instalation idea</title>
<description> a simple solution would to get Nintendo&amp;#039;s private key! (like the solution is &quot;to kill the Batman&quot;)

I remember that in order to get Nintendo&amp;#039;s private key, that either Nintendo would give it away (NOT likely), a disgruntled employee would leak it( also not likely, but then we would just have to wait) or we could brute force it (more feasible)

So here is my idea... we have A LOT of people using wiibrew, we could code an app that would try and brute force find Nintendo&amp;#039;s private key. If enough of us used the app, we could get it done in much less time. to prevent overlapping, the app could connect to a server and would receive instructions on where to start testing, and after it finishes those, it would connect again to get new instructions. I know I could just let the app run whenever I am not using my Wii... then, in the eventuality that someone finds it, it would send a message with the private key to team twiizers and maybe do a congratulations bit on the person&amp;#039;s screen, like in Windows solitaire or something, haha...

besides the few stupid puns, I am serious..this could be quite feasible I think.</description><link>http://forum.wiibrew.org/read.php?27,6976,6976#msg-6976</link><lastBuildDate>Wed, 22 Jul 2026 22:41:53 +0200</lastBuildDate>
<generator>Phorum 5.2.23</generator>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,7845#msg-7845</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,7845#msg-7845</link><description><![CDATA[ <blockquote class="bbcode"><div><small>Quote<br /></small><strong>HyperHacker</strong><br /><blockquote class="bbcode"><div><small>Quote<br /></small><strong>bushing</strong><br />Discover the 2048-bit private RSA key, which is probably stored in a locked room inside of a <a href="http://en.wikipedia.org/wiki/Hardware_Security_Module" rel="nofollow">Hardware Security Module</a></div></blockquote>I dunno, from what I&#039;ve seen from Nintendo, I wouldn&#039;t be surprised if it&#039;s scribbled on a sticky note on some guy&#039;s monitor. ;-)</div></blockquote><br />hahaha<br /><br />so we just need to tap into their video monitoring devises and look at all of the cuticles...]]></description>
<dc:creator>DrLucky</dc:creator>
<category>Software</category><pubDate>Tue, 13 Jan 2009 22:52:14 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,7755#msg-7755</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,7755#msg-7755</link><description><![CDATA[ <blockquote class="bbcode"><div><small>Quote<br /></small><strong>bushing</strong><br />Discover the 2048-bit private RSA key, which is probably stored in a locked room inside of a <a href="http://en.wikipedia.org/wiki/Hardware_Security_Module" rel="nofollow">Hardware Security Module</a></div></blockquote>I dunno, from what I&#039;ve seen from Nintendo, I wouldn&#039;t be surprised if it&#039;s scribbled on a sticky note on some guy&#039;s monitor. ;-)]]></description>
<dc:creator>HyperHacker</dc:creator>
<category>Software</category><pubDate>Tue, 13 Jan 2009 04:45:41 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,7073#msg-7073</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,7073#msg-7073</link><description><![CDATA[ ahh, this is all a very interesting read...<br /><br />I might get that book you linked, bushing...]]></description>
<dc:creator>DrLucky</dc:creator>
<category>Software</category><pubDate>Tue, 06 Jan 2009 15:58:31 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,7054#msg-7054</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,7054#msg-7054</link><description><![CDATA[ <blockquote class="bbcode"><div><small>Quote<br /></small><strong>whodares</strong><br />The only way I can think of, is that the development machines have a different "Nintendo" key, and they get that private key (knowing it would be useless to non-development Wii&#039;s).</div></blockquote>
Yes, this is standard practice when doing development on embedded systems -- you have a "development" keypair vs a "production" keypair. There is a bit in the "Starlet" OTP that specifies which one a Wii will accept, I believe.<br /><br /><blockquote class="bbcode"><div><small>Quote<br /></small><strong></strong><br />BTW - My MD5 reference was purely about using distributed computing in consoles, and not comparing MD5 to RSA and SHA1.</div></blockquote><br />It was a poor choice of comparison, because MD5 is uniquely vulnerable.]]></description>
<dc:creator>bushing</dc:creator>
<category>Software</category><pubDate>Tue, 06 Jan 2009 12:19:52 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,7053#msg-7053</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,7053#msg-7053</link><description><![CDATA[ Does anybody know how licensed developers test their games?<br /><br />I doubt Nintendo would give them the private key, and I would imagine the test platform would still implement the security (in order to prove it meets the security standard). The only way I can think of, is that the development machines have a different "Nintendo" key, and they get that private key (knowing it would be useless to non-development Wii&#039;s).<br /><br />BTW - My MD5 reference was purely about using distributed computing in consoles, and not comparing MD5 to RSA and SHA1.]]></description>
<dc:creator>whodares</dc:creator>
<category>Software</category><pubDate>Tue, 06 Jan 2009 11:57:26 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,7044#msg-7044</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,7044#msg-7044</link><description><![CDATA[ Thank you for clearing that up joedj. Im still relatively new to this.]]></description>
<dc:creator>Arikado</dc:creator>
<category>Software</category><pubDate>Tue, 06 Jan 2009 03:46:34 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,7040#msg-7040</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,7040#msg-7040</link><description><![CDATA[ For the part with the heuristics: Forget it.<br /><br />Yes, you are dealing with primes.<br />Yes, they are big.<br />No, the private key does not have to be a prime.<br /><br />In fact the public exponent e is 65537 most of the time and you need a private exponent d so that e*d is congruent to 1 modulo (p-1)*(q-1), where p and q are two large primes. This means d can be as large as (p-1)*(q-1), so forget brute force. Knowing (p-1)*(q-1) is equal to knowing p and q.<br /><br />Good news: The primes are stored in both the private and the public key.<br />Bad news: I lied. Only the product of them is stored. To get (p-1)*(q-1) from p*q you need to know p or q.<br /><br />When dealing with numbers that large there are no “rainbow tables” of primes. I think it is faster to try out a number, if you&#039;ve guessed one, than to first test if it is prime. In fact you would never really test if it&#039;s a prime but test if it&#039;s probably a prime a few times.<br /><br />Long story short: Forget it.<br /><br />P.S: You can write the keys alphanumeric, hexadecimal or in hieroglyphs. They still will be random bits. And by random i mean random as in radioactive decay, not as in least significant bit of your mouse movement.]]></description>
<dc:creator>Krstfrs</dc:creator>
<category>Software</category><pubDate>Tue, 06 Jan 2009 02:16:44 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,7039#msg-7039</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,7039#msg-7039</link><description><![CDATA[ This question doesn&#039;t make sense - hexadecimal is just a representation of a number in base 16.<br /><br />2048-bit keys can be represented as:<br /><br />- 2048 binary digits<br />- 617 decimal digits<br />- 512 hexadecimal digits<br />- 256 ISO8859-1 characters<br />- An 8x8 RGBA image<br />- 1/64 seconds of 128kbit/s MP3 audio<br /><br />(The numbers might be wrong, but hopefully you get the picture - keys are just data, you can represent this data however you like, including in hex...)]]></description>
<dc:creator>joedj</dc:creator>
<category>Software</category><pubDate>Tue, 06 Jan 2009 02:13:48 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,7036#msg-7036</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,7036#msg-7036</link><description><![CDATA[ <blockquote class="bbcode"><div><small>Quote<br /></small><strong>bushing</strong><br />* Discover the 2048-bit private RSA key, which is probably stored in a locked room inside of a <a href="http://en.wikipedia.org/wiki/Hardware_Security_Module" rel="nofollow">Hardware Security Module</a><br /><br />* Calculate the 2048-bit private key by some means</div></blockquote>
Are the keys hexadecimal (I&#039;m assuming they are)?]]></description>
<dc:creator>Arikado</dc:creator>
<category>Software</category><pubDate>Tue, 06 Jan 2009 01:46:07 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,7033#msg-7033</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,7033#msg-7033</link><description><![CDATA[ Without meaning to be condescending, please go read a good book on crypto before trying to speculate on breaking cryptosystems. I highly recommend Applied Cryptography, which is surprisingly readable, and pretty cheap to find used: <a href="http://www.amazon.com/gp/offer-listing/0471117099/ref=sr_1_olp_4?ie=UTF8&s=books&qid=1231200432&sr=1-4" rel="nofollow">Applied Cryptography on Amazon.com</a>.<br /><br />If you want to modify data covered by a TMD, you have three choices:<br /><br />* Discover the 2048-bit private RSA key, which is probably stored in a locked room inside of a <a href="http://en.wikipedia.org/wiki/Hardware_Security_Module" rel="nofollow">Hardware Security Module</a><br /><br />* Calculate the 2048-bit private key by some means<br /><br />* Find a collision (not any collision, but one of 2 or 3 specific collisions) in SHA1<br /><br />svpe&#039;s math isn&#039;t quite right -- there are faster attacks than brute-force attacks to calculate the private part of an RSA keypair, given the public key. They involve factoring very large numbers, and the complexity of those algorithms doesn&#039;t quite double with each additional bit. Still, it&#039;s considered computationally infeasible. see e.g. <a href="http://www.rsa.com/rsalabs/node.asp?id=2004" rel="nofollow">http://www.rsa.com/rsalabs/node.asp?id=2004</a><br /><br />The presentation at 25C3 took advantage of a <a href="http://www.kb.cert.org/vuls/id/836068" rel="nofollow">known weakness</a> in MD5. SHA1 was developed, in part, to avoid that kind of weakness.]]></description>
<dc:creator>bushing</dc:creator>
<category>Software</category><pubDate>Tue, 06 Jan 2009 01:31:44 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,7027#msg-7027</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,7027#msg-7027</link><description><![CDATA[ The MD5 collision stuff was only possible due to weaknesses in MD5 itself.]]></description>
<dc:creator>comex</dc:creator>
<category>Software</category><pubDate>Tue, 06 Jan 2009 00:58:18 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,7022#msg-7022</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,7022#msg-7022</link><description><![CDATA[ <blockquote class="bbcode"><div><small>Quote<br /></small><strong>whodares</strong><br />Actually, if you look at the 25C3 event on MD5 collisions, they have a rig of 200 PS3&#039;s cracking the MD5 :-)</div></blockquote><br />yeah, I saw that too, I was trying to find the post of that again to link to here.<br /><br />perhaps I am using the wrong terminology (but I also do not know much about digital security)<br />isn&#039;t brute force checking just randomly trying a bunch of numbers?<br /><br />How many characters is Nintendo&#039;s key? is it only numbers or characters too?]]></description>
<dc:creator>DrLucky</dc:creator>
<category>Software</category><pubDate>Tue, 06 Jan 2009 00:46:08 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,7000#msg-7000</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,7000#msg-7000</link><description><![CDATA[ Actually, if you look at the 25C3 event on MD5 collisions, they have a rig of 200 PS3&#039;s cracking the MD5 :-)]]></description>
<dc:creator>whodares</dc:creator>
<category>Software</category><pubDate>Mon, 05 Jan 2009 20:49:27 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,6998#msg-6998</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,6998#msg-6998</link><description><![CDATA[ I&#039;m sure you could apply some heuristics that would reduce the amount of time slightly. Like, it&#039;s probable that the most significant bit is 1. And, since we&#039;re dealing with primes, the least significant bit is also going to be 1.<br />Even if we run through a list of only prime numbers, it&#039;s going to take a while.<br /><br />And as for your distributed search plan, realize that you&#039;d need (number_of_years_svpe_posted) computers doing it for a year to check all of those.]]></description>
<dc:creator>tona</dc:creator>
<category>Software</category><pubDate>Mon, 05 Jan 2009 20:45:17 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,6996#msg-6996</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,6996#msg-6996</link><description><![CDATA[ You could always try the random key approach, and hope you get lucky early on. hehe]]></description>
<dc:creator>whodares</dc:creator>
<category>Software</category><pubDate>Mon, 05 Jan 2009 20:34:11 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,6991#msg-6991</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,6991#msg-6991</link><description><![CDATA[ Let&#039;s assume we can break a 512bit key in about one week. This time will be doubled for each additional bit the key contains since we need to test all possibilities for the first 512bits again when we set the 513th bit to one.<br />The time it takes to bruteforce a key of arbitrary length n therefore is about 2^(n-512) weeks. We divide this by 52 since a year has about that much weeks. That yields the following results:<br />&gt;&gt;&gt; 2**(2048-512) / 52<br />46352162056173703626540703962082963709847947075878633679993750751254949838303<br />90770517471200206434710891247627463246163053581571113067227548018486515174566<br />63741387180650312543225150399599554134553239527526420734626461028049597038290<br />28103598501913614711496454641198089954412949140031104392534503153226651353276<br />326329023492152751042923299283816347703453612517326802209466989935512138106058<br />919324487984274240504749862267282807134856266217776946788208788553083448398L<br />Good luck...]]></description>
<dc:creator>svpe</dc:creator>
<category>Software</category><pubDate>Mon, 05 Jan 2009 18:59:48 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,6990#msg-6990</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,6990#msg-6990</link><description><![CDATA[ We will be able to do it at that speed in 2304 years != It will take 2304 years.<br />It&#039;s closer to 2^2304 years to do it at the current speed. Find a calculator that will tell you that.<br /><br />Edit: And once again, the Wii is not anywhere near the speed of computers they&#039;re talking about for "a few weeks" computation.]]></description>
<dc:creator>tona</dc:creator>
<category>Software</category><pubDate>Mon, 05 Jan 2009 18:52:15 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,6989#msg-6989</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,6989#msg-6989</link><description><![CDATA[ No, no no. what tona said. :-)]]></description>
<dc:creator>blasty</dc:creator>
<category>Software</category><pubDate>Mon, 05 Jan 2009 18:50:23 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,6988#msg-6988</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,6988#msg-6988</link><description><![CDATA[ I was also thinking of integrating it into the HBC, whodares.<br /><br />2304 years divided by an approximate 2 (because it is very unlikely that the final key we try is the right one) is<br />1152.<br /><br />divided by the number of Homebrew users times 2 (if they use their PCs too) =<br /><br />less than a year probably...]]></description>
<dc:creator>DrLucky</dc:creator>
<category>Software</category><pubDate>Mon, 05 Jan 2009 18:49:22 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,6987#msg-6987</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,6987#msg-6987</link><description><![CDATA[ Quite feasible. That&#039;s why all modern day security is based on RSA, and uses similar-length keys.<br />[<a href="http://en.wikipedia.org/wiki/RSA#Security" rel="nofollow">en.wikipedia.org</a>]<br /><br />Oh, and the PPC Gekko is nowhere near fast enough for brute force like this.<br />We&#039;re talking about brute forcing 2048 or 4098 bits. If you read that article, it says 512bit keys are factorable in a few weeks on common hardware. We&#039;re talking about 2048 bits means 2^(2048-512) more possibilities to bruteforce. If you follow Moore&#039;s law, which *generally* gives that computers will be twice as fast every 1.5 years, then we&#039;ll be able to bruteforce 2048 bit keys just about as fast as those 512bit keys in (1.5)(2048-512) years, or 2304 years.<br /><br />And, of course: &lt;pepsima1&gt; we&#039;ll have quantum computers before then<br /><br />Short answer: "No."]]></description>
<dc:creator>tona</dc:creator>
<category>Software</category><pubDate>Mon, 05 Jan 2009 18:09:14 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,6985#msg-6985</guid>
<title>Re: non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,6985#msg-6985</link><description><![CDATA[ I had also contemplated the distributed computing approach; although I think you&#039;d still be talking several years to crack the key, by which time most people will probably be on Wii2 or whatever it will be called<br /><br />I suppose if we could add it in the background of the HBC ;-) so while you&#039;re browsing your apps as well as a full processor version. Get desktops involved too...]]></description>
<dc:creator>whodares</dc:creator>
<category>Software</category><pubDate>Mon, 05 Jan 2009 17:30:33 +0100</pubDate></item>
<item>
<guid>http://forum.wiibrew.org/read.php?27,6976,6976#msg-6976</guid>
<title>non-fake signing for content instalation idea</title><link>http://forum.wiibrew.org/read.php?27,6976,6976#msg-6976</link><description><![CDATA[ a simple solution would to get Nintendo&#039;s private key! (like the solution is "to kill the Batman")<br /><br />I remember that in order to get Nintendo&#039;s private key, that either Nintendo would give it away (NOT likely), a disgruntled employee would leak it( also not likely, but then we would just have to wait) or we could brute force it (more feasible)<br /><br />So here is my idea... we have A LOT of people using wiibrew, we could code an app that would try and brute force find Nintendo&#039;s private key. If enough of us used the app, we could get it done in much less time. to prevent overlapping, the app could connect to a server and would receive instructions on where to start testing, and after it finishes those, it would connect again to get new instructions. I know I could just let the app run whenever I am not using my Wii... then, in the eventuality that someone finds it, it would send a message with the private key to team twiizers and maybe do a congratulations bit on the person&#039;s screen, like in Windows solitaire or something, haha...<br /><br />besides the few stupid puns, I am serious..this could be quite feasible I think.]]></description>
<dc:creator>DrLucky</dc:creator>
<category>Software</category><pubDate>Mon, 05 Jan 2009 16:45:58 +0100</pubDate></item>
</channel>
</rss>