Thursday, February 20, 2014

How to Disassemble Vita Game Cartridges, by Yifan Lu

By wololo

A useful piece of advice for the hardware tinkerers among us, directly from Yifan Lu.

If you’ve been following Yifan Lu’s work, or, more recently, the various ongoing hardware hacks by katsu (His HDMI output mod, his attempts to exploit the Vita NAND, his dual firmware boot prototype), you know we’re quite excited to see any progress on the hardware side of the force.
Opening a Vita cartridge in itself is not useful, but for those of you willing to dig deeper in the internals of the Vita, looking into the game cartridges is one more step you might want to take. Yifan Lu’s technique might be obvious to those who have been looking into these cartridges for a while, but if you’re curious and don’t want to permanently damage your game, you might want to follow his “how to”:

If you take a look at the top right or left corner of the game cart, you can see a line of where the two halves of the plastic was glued together. Locate the upper left corner and, with a sharp knife, push the blade into the line on the corner until you have a small dent. Then, move the knife downwards and wiggle the knife until you loosen the glue for the entire left side of the cart. Then keep moving the knife down and when you hit the bottom of the cart, turn and lose about half the bottom edge of the cart. Now you can use your fingers to spread the two halves apart (but be careful not to use too much force and tear the glue from the other two edges), and you can either shake the memory chip out or use a pair of tweezers.
As usual, Yifan Lu shares some cool pictures on his blog, where more details can be found (link below).
vita_cartridge
Source Yifan Lu
Based on the information from his blog, and Katsu’s recent work, Yifan also explains how games could potentially be dumped with standard NAND dumping techniques. He mentions this is probably as close to piracy as he’s ever gonna get, so I wouldn’t expect any additional information on that front from him.
If you were to follow the pinout, you can see that it appears to be a standard NAND pinout (not eMMC and not Memory Stick Duo). I have not tested this, but I believe this means you can use NANDWay or any other NAND dumping technique (there’s lots for PS3 and Xbox 360) provided you attach to the right pins. I suspect that the Vita communicates with the game cart through the SD protocol with an additional line for a security interface, but that is just speculation. If that were the case, having one-to-one dumps would not allow you to create clone games. Regardless, I will not be looking too much into game carts because they are so closely tied with piracy.
NANDWay can be downloaded here as part of the NORway tool.
vita_cartridge_structure
Pinout for Vita cartridge – Katsu
Source Yifan Lu

No comments:

Post a Comment

Spammers, stay out. Only political and video game discussion here.