Key to Motorola's locked bootloaders found - Milestone 2 General

Does it apply to our MS2?
http://www.androidcentral.com/has-motorolas-bootloader-encryption-been-cracked

I'd be very surprised if it didn't. I don't believe they'd use a separate signing process for MS.
And all I have to say about this is: :3
Edit: Reading on their site (http://freemymoto.com/Documentation) it seems it was initially developed for the first Milestone. So I think we're in luck. At the moment it specifically relates to the Droid X which is basically... the same. So yeah. We should be good.
Edit #2: it's for anything with the SHOLES bootloader. So, if I understand correctly, that's all the current handsets excluding the very newest releases (Atrix et all).
Edit #3: We don't have a key for MS2 yet. The keys seem to be per device, but the process for finding the key appears to be the same. The key was originally discovered for the Milestone. However, it's trivial to calculate it, as the process for signing each of the phones is the same.
Edit #4: Talked to Nenolod. As I expected, the above is correct. Just gotta calculate the key for each handset, but it is for every sholes handset. This will allow us to create our own SBFs for flashing and not have them rejected. So we can theoretically replace the kernel. And not need to use the kernels that moto provided. In short: AWESOME
It seems like this is Kexec project.
FURTHER VERY IMPORTANT EDIT:
This means do not update with anything that Moto may release in the future for MS2. They can patch this problem away!

It will apply to our device, he provided an formula to get the code for our device. I'm no math-person though so don't ask me

This is the best news I've received all year
http://nenolod.net/~nenolod/sholes-keyleak-explained.html

Yesssssss this is the best news

Amazing?
I'm not afraid of Motorola patching this loophole away...they hardly ever release updates haha!

Oo !
That's just incredible, we absolutely need to test if the same key is used for milestone2.
How are we supposed to do this? What about eFuse?
If it works, champagne !

folks at MS1 forum have been talking a lot about it
http://forum.xda-developers.com/showthread.php?t=1001352

I don't agree with the people discounting the finding. I've dug through what is the theory behind it. Basically, if they used the same random integer (as sony did) and we can get more than one SHA1 codee (we can! each of the official roms has one!) you can directly solve X (let x = private key, used to sign the roms). If it's zero, it's even easier to solve.
That is, if it really is this cypher (elgamal) and they really did re-use the key for signing (it's not unheard of! look at sony! they did both of these things using the same cypher.) then we are home free. All that remains is to work out the process for signing the roms, and we can SBF to our hearts content.
Basically, the cypher used breaks down ultra simplistically to this:
SHA1 key = randInt (masterKey - 1)
It's very simply, but you'd have to know what you were looking for to get it. It's likely that Moto was just going for security by obfuscation, not -actual- security. Otherwise they would have used a real random integer.

the feedbacks are pretty negative. this is from kabaldan, who ported CM6 and 7 to MS1, http://forum.xda-developers.com/showpost.php?p=12261553&postcount=113

so? when will we know if it's fake or not? any O.T.A. of a clean .sbf??

Mikevhl said:
<nenolod> i think the bootloader signature verification is still worth looking into, even if my guess of what was going on was false
<nenolod> because that made motorola jump in a way i have never seen them jump before
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Therefore proven fake. I will release CM using the 2nd-init method so don't worry
Click to expand...
Click to collapse
At least we got a new ROM (Cyanogen!!)...

Absolutely confirmed as false.
http://pastebin.com/Y6J4fCQK
Guy was trolling. For no apparent reason other than to get people to pay attention to him.
*sigh* Back to the drawing board! At least we have kexec and 2ndinit

I really want to kick his ass now!
Sent from my MotoA953 using Tapatalk

Related

Is this Windows mobile 7?

i was reading a tech blog and found this:
Link to the gallery
Link to the article
might be intrersting for the xda community
EDIT: 2nd link fixed
looks more like its showing off future smartphone and ppc phone technology. cant really tell
why couldn't it be wm7?
If they want to have an operating system that can compete with apple's then this looks promising to me.
..................
cacca said:
i was reading a tech blog and found this:
Link to the gallery
Link to the article
might be intrersting for the xda community
EDIT: 2nd link fixed
Click to expand...
Click to collapse
Yes its wm7 that will come out in 2009
xvicx said:
Yes its wm7 that will come out in 2009
Click to expand...
Click to collapse
how do you know that?
Check this out http://microsoft.blognewschannel.co...bile-7-to-focus-on-touch-and-motion-gestures/
mushipkw said:
Check this out http://microsoft.blognewschannel.co...bile-7-to-focus-on-touch-and-motion-gestures/
Click to expand...
Click to collapse
Thanks for the link. Interesting read so far. I'm not done with the Blog.
I'm just wondering though. It says that the camera will be used to calcullate certain activities (which may include gestures such as shake, twist, etc.) instead of using gyroscopes and accelerometers.
While it is too early to tell, it seems that this approach (already attempted with current devices in field) would have a negative impact on battery drain since the camera would have to be "always on" in order to comprehend your movements.
Secondly, what if someone came up with a camera hack? Could you imagine having your camera phone hacked and just being on all the time, displaying your personal life to some freak? I don't know if that is possible or not, but, it would be kinda scarry for me.
The article contradicts itself in a few areas; such as saying scroll bars will be done away with, then later stating that the scroll bars can be dynamically resized. LOL.
Still, it's fun for me to read about forthcoming technology - vaporware or not.
Dim-Ize said:
Thanks for the link. Interesting read so far. I'm not done with the Blog.
I'm just wondering though. It says that the camera will be used to calcullate certain activities (which may include gestures such as shake, twist, etc.) instead of using gyroscopes and accelerometers.
While it is too early to tell, it seems that this approach (already attempted with current devices in field) would have a negative impact on battery drain since the camera would have to be "always on" in order to comprehend your movements.
Secondly, what if someone came up with a camera hack? Could you imagine having your camera phone hacked and just being on all the time, displaying your personal life to some freak? I don't know if that is possible or not, but, it would be kinda scarry for me.
The article contradicts itself in a few areas; such as saying scroll bars will be done away with, then later stating that the scroll bars can be dynamically resized. LOL.
Still, it's fun for me to read about forthcoming technology - vaporware or not.
Click to expand...
Click to collapse
Dude these are all just things Microsoft are thinking of. Im pretty sure many features will cut down from this as MS does it always.
tomazez said:
how do you know that?
Click to expand...
Click to collapse
here all the full images and specs:
http://microsoft.blognewschannel.co...bile-7-to-focus-on-touch-and-motion-gestures/
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
hey! That's great...
I wonder if it still would be possible to get wm7 roms for our devices...
raizaM said:
hey! That's great...
I wonder if it still would be possible to get wm7 roms for our devices...
Click to expand...
Click to collapse
In theory, yes. It will most likely not need different hardware than it needs today.
From the looks of it, WM7 will be a lot more powerful that WM6 and require a lot more processing power. I'm sure there are a few HTC devices which will be able to run it, but I don't think I waoul want to run it on my Touch since it can barely handle WM6.
I don't think there's been any official announcement about the date of release, but end of 2008 or beginning of 2009 sound like the right time frame for Microsoft to roll this out. http://htcsource.com

Droid 2 versus Droid Incredible

Well, the D2 came out today, and I'm still within my 30 days return window... I'm wondering what people think about swapping the Dinc out for the new D2? I like the Incredible because of its screen, but the bump-charge battery and lack of QWERTY slider is a bit suckage. What would you do?
The d2 has a 720 mhz processor...thats a downgrade.
Sent from my ADR6300 using XDA App
jdkoreclipse said:
The d2 has a 720 mhz processor...thats a downgrade.
Sent from my ADR6300 using XDA App
Click to expand...
Click to collapse
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
That shows it as a TI OMAP 1ghz.
partizan81 said:
Well, the D2 came out today, and I'm still within my 30 days return window... I'm wondering what people think about swapping the Dinc out for the new D2? I like the Incredible because of its screen, but the bump-charge battery and lack of QWERTY slider is a bit suckage. What would you do?
Click to expand...
Click to collapse
Camera > downgrade
Processor > extremely slight upgrade
Keyboard > Hate the physical keyboard causing the device to be larger
Root / Roms > nobody knows if this will be possible to unlock (like the droid x) and you also have to wait for root now, if it's even possible
It's also worth noting that the Droid 2 has a much better GPU then the Incredible. If flashing ROMs is important to you I'd think long and hard before switching. If not I'd say go for it.
Yeah, it really comes down to what you like more. Also I don't know if you've had experience with Motoblur before, but since the Droid 2 is not an HTC phone, you will be getting Motoblur instead of Sense as the UI. I have a good feeling it will be rooted in time, as I'm sure it's going to be a popular product so lots of devs will be playing with it.
The Droid 2 GPU smokes the DInc, however there really aren't a lot of applications that can take advantage of that right now and I can't tell you if that is going to change in the future or not. Also do you care about having a hardware keyboard vs a soft kb? If you plan on texting, e-mailing, inputting a lot of data then that should seal the deal.
If you are looking for an answer like "Which phone is better?", then I can't give you that since it's mostly based on personal preference. Yes the Droid 2 has come out later so it is more advanced (except for the fact that I haven't heard a lot of positive feedback about Motoblur) and even though the camera might have a fewer MP count, based on the data I've read you will still be able to achieve the same if not better quality pictures than with the DInc (which requires a lot of manual option settings to get an optimal picture in most cases), plus it comes with some cool video features =).
I would skim over the differences between the two and not focus so much on statistics and more of how you would use the phone on a daily basis, then decide based on that which phone allows you to do such things the easiest.
the Dinc is the best and last of the fully NAND unlocked 1 ghz androids (for VZ anyway). It would take a serious hardware upgrade like a 1.5 ghz process with Wi-Di or HDMI output without discrimination against DRM protected material to get me to make a switch. But that's largely because I value having a fully unlocked OS over most anything else. I also had the option to get the Droid X and didn't get it if that tells you anything.
Incredible all the way; Motorola doesn't know how to make quality phones. http://www.engadget.com/2010/08/13/droid-2-review/

Done.....

Petition has been mailed.
csseale said:
http://www.PetitionOnline.com/4268499/petition.html
Voice your concerns there.
Click to expand...
Click to collapse
Your drive is admirable however, you need to correct your grammar in that petition for sure. I am not trying to insult you, but that is a mess. I think (my opinion) you need to word it so that it is not so threatening in an al-Qaeda sorta way. If you need help with that, PM me.
I signed!!!
..........
e.mote said:
I think it's fine as is. Humor is oftentimes an effective persuasion.
In the realm of attention-getting, however, images are really worth a thousand words. Hence my suggestions for one of these below to be added to the voices of the hoi polloi:
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Click to expand...
Click to collapse
holy cow she is scary.
keitht is right though. If you want to be taken seriously by Motorola or potential adult signatories then you need to clean up the grammar. Additionally, in my opinion, It would be more effective if you phrased it to seem less petulant.
Yea...sorry frustrated. The site wont let me update it though. Stuck with it now.
I don't know how that petition site works so not sure if you can edit your existing text, but it should only include the facts of the issue which are:
- microSD card support does not work 4 months after release
- no word on when 4G support will be available 4 months after release
As we wait, neither of the above features work as we watch other tablets release with fully functional microSD slots and 4G support.
My opinion (and is only my opinion) at this point, I have lost 1/2 the value of the tablet for the features that should have already been implemented. Maybe even more since the Xoom was already priced more than any tablet that released with these features working.
keitht said:
I don't know how that petition site works so not sure if you can edit your existing text, but it should only include the facts of the issue which are:
- microSD card support does not work 4 months after release
- no word on when 4G support will be available 4 months after release
As we wait, neither of the above features work as we watch other tablets release with fully functional microSD slots and 4G support.
My opinion (and is only my opinion) at this point, I have lost 1/2 the value of the tablet for the features that should have already been implemented. Maybe even more since the Xoom was already priced more than any tablet that released with these features working.
Click to expand...
Click to collapse
Put that in the comments of the petition that way when I print it out they see all that.
I just see all these concerns being wasted in this forum when they could be put there and printed out and mailed ya know.
So please don't waste those great thoughts in here anymore
A petition can't be changed once it's live, else people can sub X for Y and subvert the original premise.
BTW,
http://www.snopes.com/inboxer/petition/internet.asp
I signed! . . .
I signed it although I think it should have been proofed better. But that does not take away the fact that we have been screwed with the microSD card and 4G issue four months later. Xoom 2 talk already? Are you kidding me? Xoom 1 was never finished.
I am liking the comments. More of that said and we got something.
Signed!!!!
+1 sign
i just sign it..Chris.
signed...i need that damn sd card slot to work...dang it !!!
Op updated
I signed.
signed up hope you get somewhere with this.
i sign it, the link it's on my Facebook and Twitter.
cpam said:
i sign it, the link it's on my Facebook and Twitter.
Click to expand...
Click to collapse
Awesome thank you. We need the support.

question to the hard bricked users

I'm wondering if you guys would ever buy a product from Motorola again? I will surely not. Also I now fully understand all the "haters" who said Motorola is crap, not only because their bootloader policy. It is just the truth, there are so much better phones out there. Maybe the brick was a sign.
One thread just to cry about you broke Your phone? LoL
Sent from my MB860 using Tapatalk
So you broke your phone because you can't follow simple directions and now you want to blame motorola? Sounds about right.
Sent from my MB860 using xda premium
meloy said:
I'm wondering if you guys would ever buy a product from Motorola again? I will surely not. Also I now fully understand all the "haters" who said Motorola is crap, not only because their bootloader policy. It is just the truth, there are so much better phones out there. Maybe the brick was a sign.
Click to expand...
Click to collapse
^^^^ This is why they are locking them. Don't want people blaming them for this .... -__-
Sent from AT&T SGS2
I concur with EVERYONE in this thread.
YOU (OP) took the chance at modifying YOUR phone. Moto didnt make you do this. If you had left it to a factory state it WOULD STILL BE WORKING. There is a disclamer on every mod that is out. It's YOUR responsibility to accept terms and void a warranty should you so choose.
Obviously mod/hacking hard/software is not for you. If you CANNOT read a simple warning that is all over the Atrix Subforum, you shouldnt be attempting anything as complex as flashing a firmware to a hardware device. I have been mod'n Moto's since the early RAZR days and have NEVER had a brick, but that is neither here nor there. Moto makes good quality phones and locks them down so hardcore cause of jacka$$es like yourself. /end rant.
Protip: Pack your NEW phone up in the box it came in, take it back to your carrier, and request a feature phone. I'm sure mom and dad will be much happier since you arent costing them $ by bricking another device.
Leave the modding for experienced users who can follow directions...
sorry for being that dude, just sick of these people.
malfuncion said:
...
Click to expand...
Click to collapse
Oh. It seems you are a bit upset. Why you are so upset?
The funny thing with other phones is, even if you are a j4cka$$ like me ( or this noobish kennethpenn, omfgz look at this j4cka$$ n00b, he bricked his device! ) and brick your device you're still possible to unbrick it. Look at Samsung for example. Or other companies who don't give a **** about their SBK and just release it, so you're able to unbrick your phone.
And please, don't be so butthurt because i'm saying something bad about your lovely phone. I understand it hurt your feelings ( ) ... but it is just my opinion.
I'm sure i'm not the only one who think so. I guess all the other bricked people are already using other phones though. So they not reading this thread. Or they are just afraid of the Motorola-Fanboys. ( Attention: This could be a provocation. Don't get mad. Calm down. )
meloy said:
The funny thing is, even if you are a j4cka$$ like me ( or this noobish kennethpenn[/COLOR] )
Click to expand...
Click to collapse
Mr. Penn the moderator will be along shortly to noobishly ban you! LOL
I <3 my mb860
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Have to admit, having owned two Samsung Android phones, they are very difficult to hard brick. I mean, you really gotta mess with bootloader, SBL (ABCs,123s, IDK. I forgot the acronym), to get hard bricked on those Samsungs.

Twitter Social Media Campaign to Free the Bootloader

I propose we take this time to put some pressure on Samsung Mobile and Samsung Mobile US to Free the Bootloader for the Note 7. As faith in Samsung's products are waning do to multiple products having safety issues and new and old are losing perceptive value it may be time to put the social media pressure on them to unlock the Bootloader. I have started tweeting Samsung Mobile US with the attached.
{
"lightbox_close": "Close",
"lightbox_next": "Next",
"lightbox_previous": "Previous",
"lightbox_error": "The requested content cannot be loaded. Please try again later.",
"lightbox_start_slideshow": "Start slideshow",
"lightbox_stop_slideshow": "Stop slideshow",
"lightbox_full_screen": "Full screen",
"lightbox_thumbnails": "Thumbnails",
"lightbox_download": "Download",
"lightbox_share": "Share",
"lightbox_zoom": "Zoom",
"lightbox_new_window": "New window",
"lightbox_toggle_sidebar": "Toggle sidebar"
}
Totally agree. This would make me feel a lot better for all the crap they've put me through
Sent from my SM-N930T using XDA-Developers mobile app
Agree
Sent from my SM-N930T using Tapatalk
Let's make this device we don't want anyone using more enticing by unlocking the bootloader. Won't happen.
Ya, u might have more luck asking for the next device to have unlocked bootloader as they have written this one off. Still a long shot but better than doing nothing.
Sent from my SM-N930T using Tapatalk
kbtoy said:
Ya, u might have more luck asking for the next device to have unlocked bootloader as they have written this one off. Still a long shot but better than doing nothing.
Sent from my SM-N930T using Tapatalk
Click to expand...
Click to collapse
THIS is what everyone should be doing. Petition for the bootloaders BEFORE the phone is released.
The only message you will ever get from Samsung on this device is power down and return.
Samsung should make it so we have no desire to root our phones or need custom roms. By this point they need to work on the audio. There should be no reason why an app like viper cant be made. Instead they give us constantly crappy audio and laggy phones.
thegameksk said:
Samsung should make it so we have no desire to root our phones or need custom roms. By this point they need to work on the audio. There should be no reason why an app like viper cant be made. Instead they give us constantly crappy audio and laggy phones.
Click to expand...
Click to collapse
Thing is there will always be a reason to root and a lot of those reasons aren't a function of how samsung does business but rather a function of how android is designed, one example being adblocking. Even with those ones that route through a VPN that don't require root, they pale in comparison to Ad away.
DVS_Sokar said:
I propose we take this time to put some pressure on Samsung Mobile and Samsung Mobile US to Free the Bootloader for the Note 7. As faith in Samsung's products are waning do to multiple products having safety issues and new and old are losing perceptive value it may be time to put the social media pressure on them to unlock the Bootloader. I have started tweeting Samsung Mobile US with the attached.
Click to expand...
Click to collapse
Not going to happen. Phone is officially a write off so your chances of them pushing update to disable phone more likely than lobbying against unlocking broader on a recalled device. Furthermore to have one unlocked will hurt their bottom line, they only listen to the green backs. They always complain for security reasons for what they do but funny part is that custom roms (CM etc) don't have those security (stagefright) issues cause they are identified and patched before the masses sees it. They just want more from everyone and will always label us as pirates and hackers to keep the sheeple in line.

Categories

Resources