ALERT: Droid X FroYo OTA - new bootloader uses new signing keys

MotoCache1

Chief Droid Scientist
Joined
Jun 30, 2010
Messages
530
Reaction score
1
[I posted this earlier this morning but I put it in the wrong sub-forum. Someone was trying to clean that up and move it and it accidentally got destroyed. I'm re-creating it. I don't know if the other posts that were in it will be salvaged or not, but here's the OP.]

I got brought in on this by someone who hit my Gtalk on my phone at 4:30a to let me know that the world was coming to an end -- more or less.

In the last couple hours we've sorted out a lot and the deal is, in the new Droid X OTA it appears that they have replaced the entire HAB chain from the mbmloader (the loader for the boot loader) on forward. The keys that were used to sign the prior HAB components are no longer trusted by the new HAB components. What that means is that if you take the current OTA, and then subsequently use an SBF (or any other method) to replace a signed code group (which is just about every code group on a DX) that signature will not be valid and the boot process will halt when that CG is encountered. Since pretty much every SBF contains the "boot" and "recovery" code group, as well as the very-critical "CDT" code group, this means if you apply an SBF to your OTA'd phone (that is now running the 30.03 bootloader) your phone is toast. But not permanently.

In the above scenario you will still be running the new mbmloader (GC63) and mbm (CG30), so as long as you put code groups back on that are signed with the new signatures, you'll be back in business. None of the prior SBF's are going to help you -- they are invalid as of this OTA.

I'm sure Verizon is expecting this and has the 2.3.13 SBF standing by in the retail stores so they can flash you back to stock and get you working again (and give you the evil eye when you lie about how your phone got this way -- because I'm sure they have been warned about this happening in advance).

That's all for now. Hopefully this helps avoid too much unnecessary confusion, so you can just concentrate on dealing with the necessary confusion.

Oh, and to all the people who mocked when the idea of a hostile bootloader via OTA came up in the Droid 1 topic, well...
 

Corinacakes

Super Moderator
Theme Developer
Joined
Nov 17, 2009
Messages
4,942
Reaction score
3
Location
Maine
I want to apologize to everyone that posted in this thread earlier. I screwed up and lost all of it. You guys can be mean if you want....I deserve it!!!! :icon_censored:
 

jntdroid

Super Moderator
Premium Member
Joined
Nov 18, 2009
Messages
6,436
Reaction score
312
Location
TX
So, what we were a little worried they might do with the Droid 1 OTA, they did do with the Droid X OTA, essentially. Interesting... I wonder if they would ever dare to try this on the Droid 1 - though, who knows when the next OTA will be for ol' faithful.
 
OP
MotoCache1

MotoCache1

Chief Droid Scientist
Joined
Jun 30, 2010
Messages
530
Reaction score
1
Just some updated information. We've been doing continued testing and while the OTA does contain mbmloader and mbm, it appears that this lockdown may be occurring later than that in the boot cycle. We're not sure how just yet -- but we were able to reproduce the issue without updating the bootloader. More information as we have it.
 

stevesimmons

New Member
Joined
Aug 16, 2010
Messages
11
Reaction score
0
I have the OTA zip file and I have not allowed it to install on my DX.

Is it possible to modify the zip file so that it does not install the new boot loader, yet still get froyo and the other patches?
 

furbearingmammal

Super Moderator
Joined
Jun 16, 2010
Messages
11,081
Reaction score
363
Location
Anywhere you're not
Website
swdouglas.blogspot.com
Current Phone Model
32GB Moto X Developers Edition
Twitter
furryvarmint
I'm going to go ahead and say no. If you're going to root, root now -- otherwise you'll have to wait to see what can be done later... and that's potentially NOTHING. If they come out with a rooted version of the update you'll be gold then. Otherwise... Keep in mind this is merely coming from an understanding of the corporate psychology, not any actual knowledge of the process involved. :)

I'll lay a large bet that the D2 is right around the corner for the same thing.
 

furbearingmammal

Super Moderator
Joined
Jun 16, 2010
Messages
11,081
Reaction score
363
Location
Anywhere you're not
Website
swdouglas.blogspot.com
Current Phone Model
32GB Moto X Developers Edition
Twitter
furryvarmint
I'm going to take a stab and say we'll have to wait for someone in a store who got it to leak it, and if Motorola and Verizon are as serious about stopping hacking as they've made themselves out to be, that file may never hit the stores.
 

teddyearp

Senior Member
Joined
Jan 13, 2010
Messages
1,816
Reaction score
12
Location
Pinetop, AZ
Current Phone Model
Motorola Razr 5g Rooted
AFIK, all the leaks we've been getting come from WAY higher up the food chain than a lowly VZW store . . .;)
 
Top