Minor Research

Xihexa.io

Member
Jul 25, 2018
18
10
0
Idk if this is anything of value, I extracted the OTACERTS.zip from /system/etc/security/ folder, and copied it to my home directory.
releasekey.x509: Apparently I could add it to user certificates?
It has SHA-256 & SHA-1 fingerprints, as well as a serial number and it's a Google certificate, which I strangely don't see in the trusted certs.
ALSO the Pixel 2 XL for Verizon is entirely encrypted using Roman coding.
I've been poking around the root system with Ubuntu and termux for awhile, to see if there's any sort of possibility of bypass Verizon's UEFI bootloader.
It's possible that by dual booting both the Pixel 2 XL and windows and running a few scripts while making a new boot config file and running couple more scripts, could bypass the bootloader via throwing it in a bootloop, to which the rescue system would kick in after awhile to ask us, the users, for a pin number before it kills itself. Idk if it changes much, but I found the Verizon SIM pin to be 1234, and changed it to 0666, and I've noticed a lot of the xml files show my new pin number.
.
.
.
This is all just prowling through code and Google itself that I've found this info.
If it's useless, I'll delete my post but I'm hoping someone that knows something about these things and could use this information.
I'm a total noob at coding, and hacking in general but I've been learning things because I cannot stand not being in control of my entire phone.
Idk tho, maybe it's pointless ?
 
Last edited:
  • Like
Reactions: siggey

slogar25

Senior Member
May 19, 2012
387
121
73
Could be something there. It's nice find. Been awhile since someone has found a fresh idea on this regardless of the outcome.

Edit: Just remembered that the otacert.zip is just the public key that matches Google's private key, which we don't have
 
Last edited:
  • Like
Reactions: Xihexa.io

Xihexa.io

Member
Jul 25, 2018
18
10
0
Huh, so the fact that we can obtain this key is a step forward? I read somewhere that it's used to sign OTA updates.
I'm doing more key digging and seeing what comes out of it as well.
 
Last edited: