Encrypted bootloader?

Search This thread

Ingvarr

Senior Member
Oct 14, 2006
279
15
Actually, regression is very rare when it comes to things like the bootloader that is actively being developed and tested. Like I said earlier, you'd have a better chance of attacking the baseband.
Sorry, I don't exactly see how baseband attack could help - and what to attack in the first place. Baseband processor core is completely separate and isolated - only data transmitted back & forth between baseband CPU and application CPU. And how in the world a hacked baseband could influence the signature checks during boot process?
 
Last edited:

Kingtech677

Member
Dec 19, 2009
6
0
Hey, I was wondering something. Now I dont really have any experience with hacking phones and finding sploitz. But, is it not possible to bruteforce through the code on the stock rom to find the key and then just inject it into a custom rom? I imagine its not, so that brings me to my next question, how come?
 

mrozzeh

Senior Member
Mar 16, 2010
97
7
Sorry, I don't exactly see how baseband attack could help - and what to attack in the first place. Baseband processor core is completely separate and isolated - only data transmitted back & forth between baseband CPU and application CPU. And how in the world a hacked baseband could influence the signature checks during boot process?

Take a look at the s-off hack we'll be releasing in a few days and then ask yourself the same question.

The radio has a much larger part in enforcing security than the bootloader does.

...only data transmitted back & forth between baseband CPU and application CPU...

Ah, so that means that RIL's and AT interpreters obviously cannot exist.
 
Last edited:

drewden123

Senior Member
Mar 8, 2008
661
11
Take a look at the s-off hack we'll be releasing in a few days and then ask yourself the same question.

The radio has a much larger part in enforcing security than the bootloader does.



Ah, so that means that RIL's and AT interpreters obviously cannot exist.
Excuse me for my ignorance, but does this mean you have cracked/made progress on the bootloader/custom roms?!?! Sorry if im jumping the gun...i just want my cyanogenmod!


Sent from my DROIDX using Tapatalk
 

mrozzeh

Senior Member
Mar 16, 2010
97
7
Excuse me for my ignorance, but does this mean you have cracked/made progress on the bootloader/custom roms?!?! Sorry if im jumping the gun...i just want my cyanogenmod!


Sent from my DROIDX using Tapatalk

Sorry, no. Its for the current generation of HTC devices. I'm waiting for my X to be shipped.
 

evilsai

Member
Jul 23, 2010
6
0
Lol I'm having fun with my Rooted Eris running xtraSense1.1 woot horray for speed.
Sent from my Eris using XDA App
 

drewden123

Senior Member
Mar 8, 2008
661
11
Lol I'm having fun with my Rooted Eris running xtraSense1.1 woot horray for speed.
Sent from my Eris using XDA App

Ha speed+eris in one sentence? That's funny... What's it like having a tiny, discontinued phone? :) and why would you post from such a phone in the X forum?

Sent from my DROIDX using Tapatalk
 

c0uRtJe$t3r

Senior Member
Jul 23, 2010
58
0
Asheville, NC
All I heard was him coming in to the room saying" hey guys, look at my tiny ****!!!!Ain't it cool???"

Fast Eris.... wtf lmao

Sent from my DROIDX using XDA App
 

karnovaran

Senior Member
Jul 27, 2009
598
71
PDX
There's really no such thing as progress on something like this; its either done or it's not.
Can you speculate on whether a potential Droid X crack will be applicable to the upcoming Droid 2? Or is that impossible to tell at this point. I ask because it seems the dev support will be much greater on the DX than the D2.
 

drew630

Senior Member
Feb 18, 2010
171
7
New Jersey
Birdman (mrweeeedbirdman on twitter) said the exploit is patched in froyo. So if the d2 is shipping with froyo i would guess the exploit will not work.

Sent from my DROIDX using XDA App
 

karnovaran

Senior Member
Jul 27, 2009
598
71
PDX
Birdman (mrweeeedbirdman on twitter) said the exploit is patched in froyo. So if the d2 is shipping with froyo i would guess the exploit will not work.

Sent from my DROIDX using XDA App
Right, but we're talking about the bootloader here. I'm wondering if all of this effort that will be put toward cracking the bootloader or achieving 2nd boot on the Droid X will be applicable to the Droid 2. Since it's likely far fewer devs will be working on that device, any crack will likely have to come from the progress made on the DX or Milestone.
 

drewden123

Senior Member
Mar 8, 2008
661
11
All I heard was him coming in to the room saying" hey guys, look at my tiny ****!!!!Ain't it cool???"

Fast Eris.... wtf lmao

Sent from my DROIDX using XDA App

^^ lol exactly. Customize your little Eris all you want...it's just putting lipstick on a pig. I don't care what you say..no customized eris can even compare to an all-stock X...just sayin'. And then once we get custom roms on the X we'll see who is really laughing...or lagging in your case, with your cute little 528mhz processor.
 

randallman

Member
Jul 28, 2010
43
6
Hey, I was wondering something. Now I dont really have any experience with hacking phones and finding sploitz. But, is it not possible to bruteforce through the code on the stock rom to find the key and then just inject it into a custom rom? I imagine its not, so that brings me to my next question, how come?

a 2048 bit key has 2^2048 possible combonations or 3.2317*10^616 or:

32317006071311007300714876688669951960444102669715484032130345427524655138867890893197201411522913463688717960921898019494119559150490921095088152386448283120630877367300996091750197750389652106796057638384067568276792218642619756161838094338476170470581645852036305042887575891541065808607552399123930385521914333389668342420684974786564569494856176035326322058077805659331026192708460314150258592864177116725943603718461857357598351152301645904403697613233287231227125684710820209725157101726931323469678542580656697935045997268352998638215525166389437335543602135433229604645318478604952148193555853611059596230656 combonations

This is, of course, an oversimplification of the issue - but as you can see there are a great deal of possible combonations making a brute force attack quite unreasonable.
 

ramseyja

Senior Member
Mar 19, 2010
138
0
^^ lol exactly. Customize your little Eris all you want...it's just putting lipstick on a pig. I don't care what you say..no customized eris can even compare to an all-stock X...just sayin'. And then once we get custom roms on the X we'll see who is really laughing...or lagging in your case, with your cute little 528mhz processor.

eris easily overclocks to 768, some to 825, still no where near the power of the ti omap's
 

spazzxb

Member
Jun 7, 2010
29
0
^^ lol exactly. Customize your little Eris all you want...it's just putting lipstick on a pig. I don't care what you say..no customized eris can even compare to an all-stock X...just sayin'. And then once we get custom roms on the X we'll see who is really laughing...or lagging in your case, with your cute little 528mhz processor.

I am an incredible owner with trade in options, however i have an eris in a drawer that is still a very nice device. My eris ran stable at 810mhz and was rocking Froyo. I am just saying don't pick on the phone that never claimed to be anything better than the best 100 dollar phone you could get at release.
 

drewden123

Senior Member
Mar 8, 2008
661
11
I am an incredible owner with trade in options, however i have an eris in a drawer that is still a very nice device. My eris ran stable at 810mhz and was rocking Froyo. I am just saying don't pick on the phone that never claimed to be anything better than the best 100 dollar phone you could get at release.
Not dissing but when someone comes in the X dev forum to brag about his eris it's kinda pathetic...


Sent from my DROIDX using Tapatalk