Introducing XDA:DevCon – A Conference For Developers By Developers
XDA Developers Android and Mobile Development Forum
Forgot your password?
 
Post Reply+
Tip us?
 
gdeeble
Old
#11  
Member
Thanks Meter 7
Posts: 95
Join Date: Oct 2011
Rzrbck, how so, if it could be retrieved from the phone? Maybe I'm not understanding, but if we had that bootloader is it not like the normal S model with full permissions to the phone?
 
dewhashish
Old
#12  
Member
Thanks Meter 6
Posts: 97
Join Date: Jan 2012
Location: Dracut, MA
what makes it an engineering model? are the physical components the same, or is it a software setting that if we changed could unlock the phone?
Motorola Droid: Unofficial CM9 1GHz (retired)

Motorola Droid 4: Unofficial CM10 4.1.1 (stock ICS kernel)

HP Touchpad: AOKP 4.0.4
 
niai_mack
Old
#13  
niai_mack's Avatar
Member
Thanks Meter 1
Posts: 64
Join Date: Feb 2011
would it be possible via hardware to dump an SE bootloader, and flash it to a S devic? I would be willing to give this a go if its possible.
 
rightonred
Old
(Last edited by rightonred; 28th June 2012 at 07:19 AM.)
#14  
Member
Thanks Meter 34
Posts: 99
Join Date: Jun 2012
if we could get the bootloader images off that phone an unlock for the Droid 4 might be possible. Assuming, of course that both the S and the SE model use the same keys.
 
mxgoldman
Old
#15  
mxgoldman's Avatar
Member - OP
Thanks Meter 3
Posts: 32
Join Date: Apr 2009
Tell me what I can do to help.
Steve - "Damn. That girl is so fine that I wish she would scratch my car so she'd have to leave her phone number..."

Me - "You really are a lonely bastard, aren't you?"

Steve - "Yup..."
 
rightonred
Old
(Last edited by rightonred; 28th June 2012 at 06:23 PM.)
#16  
Member
Thanks Meter 34
Posts: 99
Join Date: Jun 2012
I wish I knew what to do, but in the mean time, here's some literature on how the lock works (it's for the milestone, but the d4 might use the same infrastructure).

The bootchain:
http://www.droid-developers.org/wiki/Booting_chain
The mbmloader: this loads the bootloader, if this is replaced with a version that doesn't check signatures, the bootloader can be permanently replaced:
http://www.droid-developers.org/wiki/Mbmloader
The mbm (bootloader) does it's own signature check of the kernel before booting it.

If either the key burned into the phone's fuse, or the key the mbmloader uses to check the mbm are the same on both devices, one or both of those partitions can be flashed with with the unlocked version. If they're both different, this is a dead end.

The only other option after this (aside from espionage)would be to crack the signature system directly by either creating an unlocked version of the bootloader and patching it in a way that it generates the same hash, or discover a new way to factorize large (2048 bit) numbers, and reverse engineer motorola's private signing key. (If you were to discover this factoring method, nearly every security company would have to retool.)

edit: careful updating your phone, an OTA can relock your phone. The more I read, it seems less likely that the bootloader is encrypted. Dumps should be made, but this is going to require someone with greater knowledge than I.
 
dewhashish
Old
#17  
Member
Thanks Meter 6
Posts: 97
Join Date: Jan 2012
Location: Dracut, MA
how would we go about doing this?
Motorola Droid: Unofficial CM9 1GHz (retired)

Motorola Droid 4: Unofficial CM10 4.1.1 (stock ICS kernel)

HP Touchpad: AOKP 4.0.4
 
rightonred
Old
#18  
Member
Thanks Meter 34
Posts: 99
Join Date: Jun 2012
Quote:
Originally Posted by dewhashish View Post
how would we go about doing this?
It seems like you load a special kernel module to unhide the bootloader partitions then simply use the dd command to make an image copy onto the sdcard.

iow, we need a dev.
 
dewhashish
Old
#19  
Member
Thanks Meter 6
Posts: 97
Join Date: Jan 2012
Location: Dracut, MA
well the only ones i know might be kholk, hashcode, and p3droid
Motorola Droid: Unofficial CM9 1GHz (retired)

Motorola Droid 4: Unofficial CM10 4.1.1 (stock ICS kernel)

HP Touchpad: AOKP 4.0.4
 
gdeeble
Old
#20  
Member
Thanks Meter 7
Posts: 95
Join Date: Oct 2011
This got quiet. No news on this yet?

 
Post Reply+
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Go to top of page...

XDA PORTAL POSTS

Side-Swiping Multitasking with Kakudo

Recovering iPad users may still remember the multitasking function where you can swipe left or right to … more

Learn to Edit Graphics for your Development Work

The importance of good and appropriate graphics for your development work is undeniable. Be … more

Tasker Alternative: AutomateIt, Automates Your Device Tasks – XDA Developer TV

XDA Developer TV Producer Kevin wants to help make your … more