6 059
Подписчики
+424 часа
+857 дней
+26830 день
Архив постов
6 057
DK can be referred as this, after this patch you may seek for CDI, like i have tried with some friend on Lenovo device and that still worked, but with sharp eyes you'll quickly notice that it's not very good for use. getting this requires patching over a "fused" partition, without such vulnerability, it's impossible.
moreover CDI derives with KDF over signature of the partition, the signer is on higher boot stage than the one compromised (you cannot intervene), the value is then corrupted.
Google RKP does not verify this yet, which explains my attempts on that Lenovo device succeeding, if this is enforced correctly, this solution is killed.
getting UDS is better it allows to spoof down stages with Secure Boot enforced values (extracted by Gen CSR v3 (must be with no EEK to get decrypted state)).
Farewell ~
6 057
R0rt1z2 confirmed that the vulnerability i was confused about regarding extraction of DK has been patched in June 2026 by Android Security Bulletin
With user consent, you'd still need to figure if ARB was enforced, if correct, you definitely should be sure that you can no longer perform it.
You can say goodbye to Google RKP in SW & kbx extraction.
6 057
Google has no plans to phase out factory keys after reading the update from https://developer.android.com/privacy-and-security/security-key-attestation#expired_factory_keys
6 057
it has been known in foreign countries that china sells things very cheap aboard, does this include rtx 5090 too?
6 057
I can say this is very effective actually after testing, consider giving it a try, also don't update ccode too often, i smell the safeguards are match("security", "cve", "vulnerability")
because the way it answers with this is like there are no safeguard rails at all
