• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

NVIDIA BIOS Signature Lock Broken, vBIOS Modding and Crossflash Enabled by Groundbreaking New Tools

Joined
Apr 14, 2023
Messages
36 (0.09/day)
Does this mean that eBay sellers will have it easier to start selling GTX 970s as RTX 4090s?
What dumbass could possibly fall for that? You say this like it's already happened tho. I can't even imagine.
 
Joined
Dec 25, 2020
Messages
4,954 (3.93/day)
Location
São Paulo, Brazil
System Name Project Kairi Mk. IV "Eternal Thunder"
Processor 13th Gen Intel Core i9-13900KS Special Edition
Motherboard MSI MEG Z690 ACE (MS-7D27) BIOS 1G
Cooling Noctua NH-D15S + NF-F12 industrialPPC-3000 w/ Thermalright BCF and NT-H1
Memory G.SKILL Trident Z5 RGB 32GB DDR5-6800 F5-6800J3445G16GX2-TZ5RK @ 6400 MT/s 30-38-38-38-70-2
Video Card(s) ASUS ROG Strix GeForce RTX™ 4080 16GB GDDR6X White OC Edition
Storage 1x WD Black SN750 500 GB NVMe + 4x WD VelociRaptor HLFS 300 GB HDDs
Display(s) 55-inch LG G3 OLED
Case Cooler Master MasterFrame 700
Audio Device(s) EVGA Nu Audio (classic) + Sony MDR-V7 cans
Power Supply EVGA 1300 G2 1.3kW 80+ Gold
Mouse Microsoft Ocean Plastic Mouse
Keyboard Galax Stealth
Software Windows 10 Enterprise 22H2
Benchmark Scores "Speed isn't life, it just makes it go faster."
What dumbass could possibly fall for that? You say this like it's already happened tho. I can't even imagine.

Unfortunately, it has. Counterfeit GPUs are a gigantic business. At the low end the market is swamped with fake cards (and they usually circulate in low income countries), in the midrange, counterfeiters have dedicated themselves to shifting e-waste Radeon RX 400 and 500 series GPUs from Chinese Ethereum farms, and at the high-end you usually see some frankenbuild GPUs but they're rarer because end of the day, the genuine components to make the unlicensed garbage such as a mobile GPU's core are still required.

But how exactly is it possible, since there is no any bios editing software. Don't get it.

I have an Asus RTX 2080 super blower edition card. It's terrible. Blower spins on 40% no matter what. The temperature literally goes up to 90 degrees. The card gets 65 degrees max with a little of undervolt and locking the blower on 50 %. So I was wondering if there is any way to edit bios at least to set the rpm correctly.

No, a BIOS editor has not been developed for Turing and newer. Furthermore, the folks who made these modified versions of nvflash have disappeared (for example, Veii deleted their TPU account), whether that was due to pressure from Nvidia or because they did not want publicity, we'll never know

I suppose all threads could be locked by now, I doubt there will be any further development on this
 

nicetigo

New Member
Joined
Apr 20, 2024
Messages
2 (0.04/day)
Unfortunately, it has. Counterfeit GPUs are a gigantic business. At the low end the market is swamped with fake cards (and they usually circulate in low income countries), in the midrange, counterfeiters have dedicated themselves to shifting e-waste Radeon RX 400 and 500 series GPUs from Chinese Ethereum farms, and at the high-end you usually see some frankenbuild GPUs but they're rarer because end of the day, the genuine components to make the unlicensed garbage such as a mobile GPU's core are still required.



No, a BIOS editor has not been developed for Turing and newer. Furthermore, the folks who made these modified versions of nvflash have disappeared (for example, Veii deleted their TPU account), whether that was due to pressure from Nvidia or because they did not want publicity, we'll never know

I suppose all threads could be locked by now, I doubt there will be any further development on this
Thank you very much for an answer.
 
Joined
Apr 14, 2023
Messages
36 (0.09/day)
Unfortunately, it has. Counterfeit GPUs are a gigantic business. At the low end the market is swamped with fake cards (and they usually circulate in low income countries), in the midrange, counterfeiters have dedicated themselves to shifting e-waste Radeon RX 400 and 500 series GPUs from Chinese Ethereum farms, and at the high-end you usually see some frankenbuild GPUs but they're rarer because end of the day, the genuine components to make the unlicensed garbage such as a mobile GPU's core are still required.
I guess I just don't know how the scam works. I'm picturing someone looking at a photo of a 970 and a screenshot of gpuz or something similar. Worse yet, buying it sight unseen. If you're that dumb, you deserve what you bought. Maybe, hopefully it's more clever than that and people aren't that stupid

No, a BIOS editor has not been developed for Turing and newer. Furthermore, the folks who made these modified versions of nvflash have disappeared (for example, Veii deleted their TPU account), whether that was due to pressure from Nvidia or because they did not want publicity, we'll never know

I suppose all threads could be locked by now, I doubt there will be any further development on this
Wait a min. Are you saying this article is basically mute? That the code was cracked yet unusable and there prob won't be any tools that take advantage of it? If so, I guess I'm way too behind. I was very intrigued to read this and figured I'd wait a little bit to see how it goes with the backup tool and other tools before trying it out myself. Seems it's passed its moment, and I missed it already.

After reading more comments from the creator, it doesn't look like this will except bios created from other programs that you yourself could create and tweak. Only other official nvidia bios. Weren't we already able to take, for example, a pny 4080 and flash it with a gigabyte 4080's bios. I don't understand what we're gaining here.
 
Joined
Dec 25, 2020
Messages
4,954 (3.93/day)
Location
São Paulo, Brazil
System Name Project Kairi Mk. IV "Eternal Thunder"
Processor 13th Gen Intel Core i9-13900KS Special Edition
Motherboard MSI MEG Z690 ACE (MS-7D27) BIOS 1G
Cooling Noctua NH-D15S + NF-F12 industrialPPC-3000 w/ Thermalright BCF and NT-H1
Memory G.SKILL Trident Z5 RGB 32GB DDR5-6800 F5-6800J3445G16GX2-TZ5RK @ 6400 MT/s 30-38-38-38-70-2
Video Card(s) ASUS ROG Strix GeForce RTX™ 4080 16GB GDDR6X White OC Edition
Storage 1x WD Black SN750 500 GB NVMe + 4x WD VelociRaptor HLFS 300 GB HDDs
Display(s) 55-inch LG G3 OLED
Case Cooler Master MasterFrame 700
Audio Device(s) EVGA Nu Audio (classic) + Sony MDR-V7 cans
Power Supply EVGA 1300 G2 1.3kW 80+ Gold
Mouse Microsoft Ocean Plastic Mouse
Keyboard Galax Stealth
Software Windows 10 Enterprise 22H2
Benchmark Scores "Speed isn't life, it just makes it go faster."
I guess I just don't know how the scam works. I'm picturing someone looking at a photo of a 970 and a screenshot of gpuz or something similar. Worse yet, buying it sight unseen. If you're that dumb, you deserve what you bought. Maybe, hopefully it's more clever than that and people aren't that stupid


Wait a min. Are you saying this article is basically mute? That the code was cracked yet unusable and there prob won't be any tools that take advantage of it? If so, I guess I'm way too behind. I was very intrigued to read this and figured I'd wait a little bit to see how it goes with the backup tool and other tools before trying it out myself. Seems it's passed its moment, and I missed it already.

After reading more comments from the creator, it doesn't look like this will except bios created from other programs that you yourself could create and tweak. Only other official nvidia bios. Weren't we already able to take, for example, a pny 4080 and flash it with a gigabyte 4080's bios. I don't understand what we're gaining here.

I mean, in most of the world, we don't have physical computer shops, we just order GPUs from the internet. Of course every country has its reputed stores, but due to the higher prices on genuine goods, a lot of people turn to AliExpress and other online marketplaces. There they're susceptible to buying things like this, and recently, even reputable e-commerce websites have been selling these things...


A common step in the counterfeiting process is editing the GPU's BIOS to change the model that it reports to the system, without regard for stability, if there's enough physical memory present or even if it works at all. BIOS signature restrictions have essentially made this impossible.

Unfortunately you'll find people are more than willing to buy these counterfeits and they won't hesitate to litter tech forums like TPU with their threads demanding BIOS thinking it'll magically fix their scam cards just because they "saved $50 buying this (insert comically bizarre Chinese name) RX 470" and "we shouldn't judge".

As for the article being basically mute, yep. These modified nvflashes can't do much on their own, not all restrictions were removed and with a distinct lack of an editor available, there's not that much you can do with them right now... and it seems everyone involved in developing these tools has disappeared.
 
Joined
Apr 14, 2023
Messages
36 (0.09/day)
As for the article being basically mute, yep. These modified nvflashes can't do much on their own, not all restrictions were removed and with a distinct lack of an editor available, there's not that much you can do with them right now... and it seems everyone involved in developing these tools has disappeared
That really sux these people working on it vanished. I guess they got tired of answering questions. Not sure why it was put out before 5000 either. That was never addressed in any detail that I could find. I'm sure whatever breakthrough was made here nvidia will surely lock it down on the 5000 cards forcing us to start all over with those. Another thing I just a moment ago realized is that the email I got from tpu was a notification. My dumbass didn't read the whole thing and thought that this was a new article. Until I went back and started reading the op comments. All in all, thx for the info. Have a great day/night, wherever you are.
 
Joined
Dec 25, 2020
Messages
4,954 (3.93/day)
Location
São Paulo, Brazil
System Name Project Kairi Mk. IV "Eternal Thunder"
Processor 13th Gen Intel Core i9-13900KS Special Edition
Motherboard MSI MEG Z690 ACE (MS-7D27) BIOS 1G
Cooling Noctua NH-D15S + NF-F12 industrialPPC-3000 w/ Thermalright BCF and NT-H1
Memory G.SKILL Trident Z5 RGB 32GB DDR5-6800 F5-6800J3445G16GX2-TZ5RK @ 6400 MT/s 30-38-38-38-70-2
Video Card(s) ASUS ROG Strix GeForce RTX™ 4080 16GB GDDR6X White OC Edition
Storage 1x WD Black SN750 500 GB NVMe + 4x WD VelociRaptor HLFS 300 GB HDDs
Display(s) 55-inch LG G3 OLED
Case Cooler Master MasterFrame 700
Audio Device(s) EVGA Nu Audio (classic) + Sony MDR-V7 cans
Power Supply EVGA 1300 G2 1.3kW 80+ Gold
Mouse Microsoft Ocean Plastic Mouse
Keyboard Galax Stealth
Software Windows 10 Enterprise 22H2
Benchmark Scores "Speed isn't life, it just makes it go faster."
Is there one for Pascal

No, not that I am aware of. That was when Nvidia introduced the signature keys for VBIOS, Maxwell (GTX 900 series) is the latest that can be freely edited.
 
Joined
Aug 27, 2023
Messages
153 (0.53/day)
From about 7 years ago
I don't really care about this anymore since I already have parser/builder library for Kelvin/Rankine/Curie/Tesla/Fermi/Kepler/Maxwell/Pascal (at least for most data relevant to overclocking) which can do everything KBT/MBT can do.


From even longer ago IIRC
tweak.png


Stopped about 5 years ago but still on Github if you want to fork. IIRC there's support for some Turing and a few desktop cards too but only seems functional on mobile which apparently allows broken vbios images as long as flashed by HW SPI programmer. 5$ SPI programmer was always a means to cross flash too and recover while the hacked nvflash being convenient might leave you bricked.
 
Joined
Sep 6, 2013
Messages
3,061 (0.78/day)
Location
Athens, Greece
System Name 3 desktop systems: Gaming / Internet / HTPC
Processor Ryzen 5 5500 / Ryzen 5 4600G / FX 6300 (12 years latter got to see how bad Bulldozer is)
Motherboard MSI X470 Gaming Plus Max (1) / MSI X470 Gaming Plus Max (2) / Gigabyte GA-990XA-UD3
Cooling Νoctua U12S / Segotep T4 / Snowman M-T6
Memory 16GB G.Skill RIPJAWS 3600 / 16GB G.Skill Aegis 3200 / 16GB Kingston 2400MHz (DDR3)
Video Card(s) ASRock RX 6600 + GT 710 (PhysX)/ Vega 7 integrated / Radeon RX 580
Storage NVMes, NVMes everywhere / NVMes, more NVMes / Various storage, SATA SSD mostly
Display(s) Philips 43PUS8857/12 UHD TV (120Hz, HDR, FreeSync Premium) ---- 19'' HP monitor + BlitzWolf BW-V5
Case Sharkoon Rebel 12 / Sharkoon Rebel 9 / Xigmatek Midguard
Audio Device(s) onboard
Power Supply Chieftec 850W / Silver Power 400W / Sharkoon 650W
Mouse CoolerMaster Devastator III Plus / Coolermaster Devastator / Logitech
Keyboard CoolerMaster Devastator III Plus / Coolermaster Devastator / Logitech
Software Windows 10 / Windows 10 / Windows 7
What dumbass could possibly fall for that? You say this like it's already happened tho. I can't even imagine.
You focus on the example and totally miss the point. So, let me do it a little easier. GTX 1070 selling as an RTX 4070.

To answer your question, anyone with lack of knowledge can be tricked. And no, they are not "dumbass" as you say, just people with better things to do in their lives than reading countless information before they buy something. A graphics card, a console, a TV, a vacuum cleaner, clothes, shoes, paint, meat....

shifting e-waste Radeon RX 400 and 500 series GPUs
At least those are sold as RX 580s and 480s, not as RX 6600s for example.

I'm picturing someone looking at a photo of a 970 and a screenshot of gpuz or something similar
That GPU-Z was usually the information proving something being fake on eBay. You where looking at a GPU-Z screen saying GTX 970 for example, and the firmware version was the one used on GTX 400 series, again, for example. That was proof that the seller was selling a GTX 400 series card as a GTX 900 series card.
 
Top