+ Reply
Page 1 of 2 12 LastLast
Results 1 to 20 of 24
  1. #1
    iPhone? More like MyPhone
    Join Date
    Mar 2008
    Posts
    169
    Thanks
    21
    Thanked 13 Times in 11 Posts

    Default Current State of the Unlock

    The current state of the unlock seems to be different than different methods before. Based on tweets what I've gathered is that the crash found, while exploitable, isn't nessecarily perfect as an injection vector.

    The traditional method was code injection via a loader and a start up daemon. As musclenerd tweeted this wasn't working with all the SIMs tried.

    Instead he mentioned that the NCK is just 40 bits. What this means is that it can be easily bruteforced, by an average household computer in just a few days max. That is to say attempting to encrypt every possible combination and comparing the encrypted strings to verify a match.

    To do this though the NOR and SGOLD ID's are needed, this is where the current crash comes in. It is used to retrieve these and make the bruteforce attack possible.

    This seems to be roughly confirmed by what sherif_hashim has tweeted and as a backup he mentioned he is looking into new crashes.

    If this new method appears it could be different from any unlock before. It still would require a baseband exploit but the advantage of cracking the NCK is the phone would behave as a standard factory unlocked phone would.

  2. The Following 2 Users Say Thank You to alex1015 For This Useful Post:

    RIKKI123 (03-10-2011), Simon (03-10-2011)

  3. #2
    Green Apple
    Join Date
    Jun 2010
    Posts
    67
    Thanks
    5
    Thanked 0 Times in 0 Posts

    Quote Originally Posted by alex1015 View Post
    The current state of the unlock seems to be different than different methods before. Based on tweets what I've gathered is that the crash found, while exploitable, isn't nessecarily perfect as an injection vector.

    The traditional method was code injection via a loader and a start up daemon. As musclenerd tweeted this wasn't working with all the SIMs tried.

    Instead he mentioned that the NCK is just 40 bits. What this means is that it can be easily bruteforced, by an average household computer in just a few days max. That is to say attempting to encrypt every possible combination and comparing the encrypted strings to verify a match.

    To do this though the NOR and SGOLD ID's are needed, this is where the current crash comes in. It is used to retrieve these and make the bruteforce attack possible.

    This seems to be roughly confirmed by what sherif_hashim has tweeted and as a backup he mentioned he is looking into new crashes.

    If this new method appears it could be different from any unlock before. It still would require a baseband exploit but the advantage of cracking the NCK is the phone would behave as a standard factory unlocked phone would.
    Thank you VERY much for putting things into perspective and making it easier for us laymans to understand the whole unlock situation. I'm still a bit agitated, but hey, call me an optimist... or an idiot, i still have faith in the devs'

  4. #3
    iPhone? More like MyPhone
    Join Date
    Mar 2008
    Posts
    169
    Thanks
    21
    Thanked 13 Times in 11 Posts

    I don't have much background with unlocking, but I know that with modern programs and CPU power 40 bits is trivial. Now CPU and GPU power can be used by programs.

    The NCK bruteforce attempt geohot created for the original iPhone would have taken years as it did not use the NOR and Sgold chip id (unique per phone)

  5. #4
    Green Apple
    Join Date
    Jun 2010
    Posts
    67
    Thanks
    5
    Thanked 0 Times in 0 Posts

    Sorry, just to clarify, does this mean MORE time needed, but its possible?
    I'm completely oblivious to tech talk
    Thanks again for the time and effort in writing up this information, this forum needs more people like you rather than the DRONE of people writing their complaints.

  6. #5
    iPhone? More like MyPhone
    Join Date
    Mar 2008
    Posts
    169
    Thanks
    21
    Thanked 13 Times in 11 Posts

    Well yes more time definitely needed. The exploit will be used to retrieve the sgold and nor ids. These will then be used in conjunction with a bruteforce program on the computer (presumably).

    The uses for the exploit (sglod and nor id's) should be relatively simple. The bruteforce program and testing should take the most time. This general procedure is entirely new. As for a timeframe...your guess is as good as mine. As we know unexpected roadblocks are...expected.

    The more that is known about the NCK the better. If it is all a certain type of characters etc. this will all reduce the cycles needed to bruteforce the key

  7. #6
    Green Apple
    Join Date
    Jun 2010
    Posts
    67
    Thanks
    5
    Thanked 0 Times in 0 Posts

    Right okay thanks for the third time at least we know its a painfully complex procedure and that the dev's are working hard.

  8. #7
    iPhone? More like MyPhone
    Join Date
    Mar 2008
    Posts
    169
    Thanks
    21
    Thanked 13 Times in 11 Posts

    The nice thing is if this works then once the NCK is obtained from a vulnerable baseband it could presumably be used on subsequent basebands even if they are not vulnerable. Therefore even with an iOs update you'd maintain the unlock if you obtained it once.

    On a side note, I was a bit leery of this after 4.3 as there was never any explicit dev team confirmation like we typically see. Musclenerd only just announced that the attempted code injection wasn't working. We have no idea how long ago he discovered that. Odds are it wasn't just yesterday when it was tweeted. I only know as much as the tweets and the rest is speculation and minor knowledge from a background with encryption and decryption

  9. The Following User Says Thank You to alex1015 For This Useful Post:

    RIKKI123 (03-10-2011)

  10. #8
    What's Jailbreak?
    Join Date
    Jul 2009
    Posts
    24
    Thanks
    2
    Thanked 1 Time in 1 Post
    Do you think it would be possible in about 2 ~ 3 weeks or so?
    Or will it take longer than that?
    Just wondering .

  11. #9
    Super Penguin Mod i.Annie's Avatar
    Join Date
    Jun 2009
    Location
    Ohio
    Posts
    15,297
    Thanks
    124
    Thanked 2,067 Times in 1,800 Posts

    I am guessing it would take a bit of time. Longer than usual maybe, but maybe not. Those devs are smart.

    Alex, does this mean they have to start all over or just adjust what they have now?

  12. #10
    Superbad Moderator Simon's Avatar
    Join Date
    Nov 2007
    Location
    Bermuda
    Posts
    38,301
    Thanks
    1,933
    Thanked 5,991 Times in 4,294 Posts

    This brute force method is a whole different ballgame which sounds to be in its infancy so it could be a ways off, but could potentially be a much better means of unlocking. Thanks alex1015 for the post

  13. #11
    iPhone? More like MyPhone
    Join Date
    Mar 2008
    Posts
    169
    Thanks
    21
    Thanked 13 Times in 11 Posts

    It's better in the sense that it would allow a permanent solution.

    The exploit already exists to obtain the keys so it's not exactly starting from scratch. If musclenerd knows the keys can be obtained via the exploit then odds are he's done it before.

    But at the same time, it is an entirely different method of unlock. Instead of sneaking in through a crack in the door, we're looking through to see what the lock looks like and fashioning our own key.

    Ultrasn0w methods before always used the exploit to load custom code. This time the exploit is being used for keys. It's interesting to note that exploits can usually only allow a very small amount of arbitrary code to be executed, so a loader is created which allows much more code to be run. I believe in the last version of ultrasn0w this was planetbeings work, and he seems to have gone back to the real world for now.

    Again I have no experience with iPhone or baseband hacking, just a marginally related field so this is pure speculation.

    The iPhone wiki has a page related to this (we'd be class 1 instead of class 2 this time)

    http://theiphonewiki.com/wiki/index....old_608_Unlock
    http://theiphonewiki.com/wiki/index....old_618_Unlock
    Last edited by alex1015; 03-10-2011 at 06:37 PM.

  14. #12
    Super Penguin Mod i.Annie's Avatar
    Join Date
    Jun 2009
    Location
    Ohio
    Posts
    15,297
    Thanks
    124
    Thanked 2,067 Times in 1,800 Posts

    I'm understanding this better now, thank you.

  15. #13
    Superbad Moderator Simon's Avatar
    Join Date
    Nov 2007
    Location
    Bermuda
    Posts
    38,301
    Thanks
    1,933
    Thanked 5,991 Times in 4,294 Posts

    Ya, planetbeing being MIA is a big reason there is no unlock yet IMO. Honestly I don't think there will be another one unless him or someone else in the same league as him steps to the plate. The only people I think that are in the same league as him are geohot and maybe comex.

  16. #14
    Super Penguin Mod i.Annie's Avatar
    Join Date
    Jun 2009
    Location
    Ohio
    Posts
    15,297
    Thanks
    124
    Thanked 2,067 Times in 1,800 Posts

    Too bad GeoHot is a bit busy right now. Hopefully he gets out alive. I think we should be looking at Comex then?

  17. #15
    Theme Creator Raptors's Avatar
    Join Date
    Mar 2009
    Posts
    2,413
    Thanks
    145
    Thanked 478 Times in 348 Posts

    I don't see comex making an unlock & geo has problems of his own right now. We'll see

  18. #16
    Superbad Moderator Simon's Avatar
    Join Date
    Nov 2007
    Location
    Bermuda
    Posts
    38,301
    Thanks
    1,933
    Thanked 5,991 Times in 4,294 Posts

    Ya, I dont think comex will either, but I think he could if he wanted too.

  19. #17
    Super Penguin Mod i.Annie's Avatar
    Join Date
    Jun 2009
    Location
    Ohio
    Posts
    15,297
    Thanks
    124
    Thanked 2,067 Times in 1,800 Posts

    Wah this looks like bad news then. This is why I chose to go to an official carrier. No more worries about unlocking. It was so stressful before when I was on T-Mobile.

  20. #18
    Superbad Moderator Simon's Avatar
    Join Date
    Nov 2007
    Location
    Bermuda
    Posts
    38,301
    Thanks
    1,933
    Thanked 5,991 Times in 4,294 Posts

    It's bad news, but with a silver lining.

  21. #19
    Super Penguin Mod i.Annie's Avatar
    Join Date
    Jun 2009
    Location
    Ohio
    Posts
    15,297
    Thanks
    124
    Thanked 2,067 Times in 1,800 Posts

    I hope it turns out well though. I get excited for unlocks so I can copy an paste this response: "upgrade to 4.3 in iTunes, Jailbreak with XXXX, and install unlock from Cydia" lol.

    No bb preservations, no custom firmwares, the joy!

  22. #20
    Superbad Moderator Simon's Avatar
    Join Date
    Nov 2007
    Location
    Bermuda
    Posts
    38,301
    Thanks
    1,933
    Thanked 5,991 Times in 4,294 Posts

    Ya, always good when that happens, although it is rare for the stars to align like that.

+ Reply
Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts