dmiller2007
Android Expert
I do not plan on doing any more work on this. But all information has been handed over to people who are working on this. Follow the FreeMyMoto people for their progress.
Advisory history
- December 20th, 2010
Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
I do not plan on doing any more work on this. But all information has been handed over to people who are working on this. Follow the FreeMyMoto people for their progress.
Advisory history
- December 20th, 2010
Sholes signing key leak explained
The Motorola(r) sholes platform uses a trusted bootloader environment. Signatures are stored as part of the CDT stored on the NAND flash. mbmloader verifies the signature on mbm before passing control. mbm verifies all other signatures before allowing the device to boot.
There is a vulnerability in the way that Motorola generated the signatures on the sections stored in the CDT. This vulnerability is very simple. Like on the PlayStation 3, Motorola forgot to add a random value to the signature in order to mask the private key. This allowed the private key and initialization vector to be cracked.
The keys can be cracked using Mathematica. Read up on how the Elgamal signature scheme works.
Ok, what does this mean?
Please refer to the following table:
Boot chain component Status OMAP secure bootrom secure Secure keystore replaceable mbmloader secure, but irrelevant, replaceable but unnecessary mbm secure, but irrelevant, replaceable but unnecessary recovery replaceable (providing new keys is recommended) system replaceable (providing new keys is recommended) bootimage replaceable (providing new keys is recommended) I do not plan on doing any more work on this. But all information has been handed over to people who are working on this. Follow the FreeMyMoto people for their progress.
Advisory history
- December 20th, 2010 Motorola notified of keystore vulnerability. No response received from Motorola.
- February 20th, 2011 Motorola notified again of keystore vulnerability. No response received from Motorola.
- February 27th, 2011 Motorola notified that keystore vulnerability will be disclosed to public on March 20th. No response received from Motorola.
- March 20th, 2011 Keystore signature generation vulnerability publically disclosed including private key leak. Response received from Motorola legal.
Do you really think Motorola will push the issue? Please correct me if I am wrong but I thought the encrytion was embedded with the processor which is now outdated. No new phones will be able to take advantage (Atrix, Bionic) because they used a different processor which would carry it's own encryption. Might have it all screwed up. Read up on it at 3 am during a bout of insomnia.
I think the problem is I don't know what I am talking about, hence the confusion. Lol
Went back and read up on it. I'm an idiot and will shut up now. I'll be here in the corner talking to myself...

Well they have the keys to something but I don't see anything about them saying its the keys to the efuse. hmm after reading a few more tweets it looks/sounds like they have cracked motomobiles custom encryption and found the keys
nenolod William Pitcock
props to @motomobile for cooking their own modified elgamal signature scheme and doing a bad job at it. no props to TBH.
1 hour ago
![]()
nenolod William Pitcock
frequently asked question: what are these keys for? answer: signing SBF update files for rsdlite.
![]()
nenolod William Pitcock
continuing... SBF files can be used to load a new recovery on the phone. or to flash entirely different software (e.g. non-android)
1 hour ago http://twitter.com/#http://twitter.com/#http://twitter.com/#http://twitter.com/#
![]()
Sounds good!
http://twitter.com/#http://twitter.com/#http://twitter.com/#http://twitter.com/#
Just out of curiousity, do we know why he seems to have "beef" with Team Black Hat?

Just out of curiousity, do we know why he seems to have "beef" with Team Black Hat?
The only thing that I am still unclear on is whether this will allow us to flash updated Kernals for new versions of Android (allowing us to update to all new versions of Android in the future).
I think its funny now that all the dev's dumped their Droid X's and now we will have true greatness on our phones... haahahahahahahahahaha... mainly at birdman and the early dumpers...
so as typical as life would have it; once it is out dated the possible big break comes out?
i got that right?
not that i really care as im gonna use this phone until it or the otterbox gives up on me....lol....

Loll I'm still a fan of the flyX boot ani.
