1. Finding the "True" Unlock method: Please contribute!
People this thread is for members to contribute to the decyphering of the NCK and NOT discussing Unlocking alternatives. If you are an AT&T customer, or have paid Apple or your carrier to unlock your phone via iTunes. Then please contribute your a.plist to this thread so that we can forward it to GeoHot!

Read the fine print below before replying to this thread. Any unwanted request or post will be deleted, this is to prevent un-necessary populating of this thread.

Sunday, December 16, 2007

NCK Pattern: 6 So Far: No German pattern

So far I have (see title) NCK <=> IMEI combinations. I can't post them, since they are sensitive data of the people who were kind enough to extract their a.plist for me. I have learned that the German ones use "SP" instead of "NO". Also the two German NCK's I have both start with the number 3. Coincidence? Keep these a.plists flowing, could people please posts requests on their respective language iPhone forums? Also the algorithm used to verify the NCK on the phone is known and is not even close to reversible. Brute force is capable at 100,000 k/s, so the initial idea of finding a pattern in the NCK's is to lower the time required for that brute force.

Also my theoretical NCK generation system; this has no basis in anything anyone has discovered but... IMEI^d mod n, where d and n are relatively prime and n is similar in size to the IMEI. If Apple keeps d and n secret, they could generate NCK's given an IMEI when no one else could.

Saturday, December 15, 2007

NCK Length=15

So thanks to the magic of an activation emulator and the original work of Dvd Jon, I got the activation/unlock record of a French unlocked iPhone. The field looks like

"UnlockCode" = "NO=111111111111111&";

with the 1's replaced by the code. "NO" is the lock type. There are fifteen digits, so I'm pretty sure the NCK length is 15. This is out of range of a bruteforcer, and I doubt, although its possible, that the NCK's are based off the IMEI/DevID. I would think Apple just has a big lookup table. Although any visible pattern would shorten the brute force time. So I still really need a.plists off legal unlocked phones.

Friday, December 14, 2007

Unlock ETA and NCK Length

Well I'm back to my original statement that we have to wait for a baseband update to finally unlock the new bootloader. The two exploits I posted have implementation problems. Once we get the new version, iEraser and iUnlocker will work as before. Still only hardware though. I spent the last week and a half of cold Swedish nights looking for more practical exploits, and found none. Perhaps someone cleverer than I will find one?
Also, anyone out there with a legally unlocked phone, either French or German? Could you do me a favor and download this and follow the enclosed instructions. Its a good way to get your name on the blog

Geohot

2. The only problem with that is that people who have a legit unlocked phone probably wouldn't be looking in these forums. So if anybody knows anyone who has a legit unlocked phone, send them this way.

