#HITB2012AMS D1T2 - MuscleNerd - Evolution of iPhone Baseband and Unlocks
Sign in to YouTube
Sign in to YouTube
Sign in to YouTube
Published on Jun 16, 2012
----------------------------------------
#HITB2012KUL (OCT 10-11) REGISTRATION NOW OPEN
http://conference.hitb.org/hitbseccon...
----------------------------------------
Presentation Materials: http://conference.hitb.org/hitbseccon...
Since the first iPhone in 2007, the baseband that Apple uses for cellular communications has evolved in terms of both hardware and software. Some of the changes were minor but others were quite drastic and obviously aimed at deterring carrier unlocks. This paper details the most interesting of the changes and what effects they've had on both software-based unlocks and hardware-based SIM interposers. In addition to comparing the most recent baseband against its own earlier hardware and software incarnations, we compare it to other current Qualcomm handsets and discuss the ramifications of changes Apple has made to the traditional Qualcomm baseband boot sequence. This presentation will cover:
Baseband ROP: Overview of the role ROP plays in software unlocks like yellowsn0w and ultrasn0w. Comparison to ROP on the main Application-side CPU (jailbreaks). Why ROP wasn't even necessary on the first generation of iPhones.
Software Unlocks vs. Hardware Unlocks: How iPhone software unlocks differ from those using hardware SIM interposers. Which layers of the baseband are exposed to each, and how the exploit development environment differs. Description of even more radical hacks like baseband chipset retrofitting and what Apple has done to prevent them.
iPhone4 DEP: How Apple implemented DEP with specific hardware changes on the iPhone4 baseband, and what went wrong. How ultrasn0w was made to work despite aggressive hardware-based DEP.
Operating Systems: So far, Apple has used 3 completely different baseband operating systems in the iPhone line. Description of which parts Apple tends to customize and why. Comparison of past and present custom command parsing.
Infineon vs. Qualcomm: Discussion of the transition from Infineon baseband chipsets to Qualcomm chipsets. Comparison of the older serial-based AT interface (still used on many other handsets) to the USB-based QMI used by the iPhone4S.
Activation Tickets: Detailed description of the "activation ticket" Apple uses to authorize use with specific (or all) carriers. How activation tickets interact with the traditional PIN-based NCK codes. Contrasting activation tickets and baseband tickets.
Baseband Tickets: Details on how Apple authenticates software updates to the baseband. Comparison of baseband tickets to "ApTickets" that Apple now uses on the main Application CPU to control software changes. Why baseband tickets provide even strong protection than ApTickets. The role of nonces in both the baseband and main application CPU.
iPhone4S: What we've learned so far about the iPhone4S baseband. Overview of changes Apple has made to the original Qualcomm bootrom. How the iPhone4S baseband boot process differs from most other Qualcomm-based handsets. Which features the iPhone4S baseband has in common with other handsets and which have been removed. Description of the current attack surfaces, and comparing iPhone4 vs iPhone4S hardware-based protection mechanisms.
ABOUT MUSCLENERD
Member of the iPhone Dev Team, providing free jailbreaks and carrier unlocks since 2007. Our most popular programs have been redsn0w and PwnageTool for jailbreaks, and AnySim, yellowsn0w, and ultrasn0w for unlocks.
-
Category
-
License
Standard YouTube License
Loading...
Loading...
Loading...
Loading...
Loading...
-
44:03
أم كلثوم - بعيد عنك - كاملةby ARABICS0NGSFeatured
1,820,621
-
55:50
#HITB2012AMS D2T2 - Dream Team - Part 1 - Corona for iOS 5.0.1by Hack In The Box Security Conference
14,122 views
-
MuscleNerd's channel
17 videos7K
-
32:58
Dream Team press conference at Hack in the Box 2012 Amsterdamby SoftpediaNews
9,984 views
-
1:03:57
Aalto Talk with Linus Torvalds [Full-length]by aaltouniversityace's channel
836,603 views
-
52:47
#HITB2012AMS D2T2 - Dream Team - Part 2 - Absinthe for iOS 5.0.1 (... and One More Thing)by Hack In The Box Security Conference
10,171 views
-
6:08
ChronicDevTeam + Musclenerd sneak peek!!by JailbreakCon
9,114 views
-
5:35
Why jailbreak? Demo by @saurikby MuscleNerd
87,933 views
-
59:40
#HITB2012AMS D1T2 - Itzhak Avraham and Nir Goldshlager - Killing a Bug Bounty Program TWICEby Hack In The Box Security Conference
564 views
-
1:07:36
#HITB2012AMS D2T1 - A. Bazhanyuk and N. Tarakanov - Automatically Searching for Vulnerabilitiesby Hack In The Box Security Conference
452 views
-
43:05
#HITB2012AMS D1T2 - Sebastien Renaud and Kevin Szkudlapski - WinRTby Hack In The Box Security Conference
282 views
-
4:22
How to Carrier Unlock iPhone 4 using Ultrasn0wby m4ttgr33n3
472,575 views
-
8:29
Apple iPhone 5 Unboxingby PhoneDog
393,846 views
-
4:14
Apple Smart Case for iPad REVIEW 9TO5MAC.COMby Jake Smith
26,806 views
-
9:41
NEW Jailbreak 6.1.3+ 6.1.2- iOS 6 UNTETHERED w/ sn0wbreeze iPhone, iPad, iPod Touchby iDevice Expert SUBSCRIBE═►
70,781 views
-
4:46
How to Factory Unlock iPhone's For Freeby iPhoneTy
218,732 views
-
3:56
Apple's Diabolical Plan to Screw your iPhoneby iFixit
221,689 views
-
13:05
FREE Unlock ANY iPhone 4 04.11.08/04.12.01, iPhone 4S and iPhone 3GSby OpinionativeReviewer
542,687 views
-
29:09
Airphone 4 Review (Fake iPhone 4)by Ashens
2,833,423 views
-
7:22
HOW TO OFFICIALLY UNLOCK THE iPHONE 4 (ANY BASEBAND, INCLUDING 4.11.08 or 4.12.01.!!!!) AT&Tby Joe Abate
155,792 views
-
8:02
How To Downgrade iPhone Baseband 06.15 To 05.13by D7 iPhone, iPad & iPod Touch Help▼
26,770 views
- Loading more suggestions...
Top Comments
Miketyler1015 11 months ago
An I was thinking this whole time he had a pineapple face
Sign in to YouTube
Sign in to YouTube
TechHigh24 1 month ago
His face is now UntetherdxD
Sign in to YouTube
Sign in to YouTube
All Comments (31)
danatopereira 2 months ago
are u paying his salary? is anybody paying him at all for that?
there u got ur jailbreak
because of ppl like u, sometimes i wish he actually stopped jailbreaking so he could "work out" more and there wouldnt be comments like this.
thank him for doing it, because its not his job, not his obligation
Sign in to YouTube
Sign in to YouTube
goforkranthi79 4 months ago
Looks like Musclenerd's focussing on working out than jailbreaking!! Where is iOS 6 jailbreak??!!
Sign in to YouTube
Sign in to YouTube
iamDani3l 5 months ago
looks like his face was booting tethered when he took that pic on twitter
Sign in to YouTube
Sign in to YouTube
iPhoneTy 5 months ago
I half expected a pineapple to give the speech.
Sign in to YouTube
Sign in to YouTube
Denis Le Court De Billot 6 months ago
He should do ASMR videos !
Sign in to YouTube
Sign in to YouTube
agentmax699 7 months ago
he is LEGEND :)
Sign in to YouTube
Sign in to YouTube
ILIK3HATERZ 7 months ago
his face has been jailbroken , no longer a pineapple !
Sign in to YouTube
Sign in to YouTube
blackw1z4rd 11 months ago
Maybe it's because they didn't want to let u hear something :(
Sign in to YouTube
Sign in to YouTube