• After 15+ years, we've made a big change: Android Forums is now Early Bird Club. Learn more here.

Root [CDMA] No need to panic about 'locked' bootloader - HTC listened

Personally, I don't have the answers (too busy with new staff - how about a big welcome to novox77 everyone! :)) - but I'm counting on the truth coming out pretty quickly on what's what on this beastie.
 
I thought rooting was not the issue, just custom ROMs, Kernels, NAND backups (not really necessary if no flashing), and Recoveries. Is this an inaccurate assessment?

If I can root and install apps that require superuser, then I'm good. Can do all the pruning of bloatware manually via ADB Shell or Root Explorer. Sense won't bother me so much if the hw is beefed up to support it, as the case w/ Evo 3D.

While a root exploit is never guaranteed (and therefore should never be taken for granted), it's likely that this phone will be at least "half rooted." This means you should be able to run rooted apps.

/system is a bit tricky. Although it's not signed, it might be a protected partition that is mounted read-only. This was the case with the original Evo. Unlocking the bootloader allowed you to mount it read/write. So... if the bootloader is unlockable, /system might remain read-only.

However, I also remember during unrEVOked.com's earlier days that they had an exploit where they could temporarily unlock NAND, and in that small window, you could make changes to /system. That exploit might have required a custom recovery, and since /recovery is now signed, this option may be off the table. I'm not really sure about this, since I don't really understand the nature of the exploit.

Bottom line: it's going to take a lot more effort on the devs' part to break the Evo 3D (unless the engineering HBOOT is leaked), and it may be a while until we know what we'll be able to do.
 
While a root exploit is never guaranteed (and therefore should never be taken for granted), it's likely that this phone will be at least "half rooted." This means you should be able to run rooted apps.

/system is a bit tricky. Although it's not signed, it might be a protected partition that is mounted read-only. This was the case with the original Evo. Unlocking the bootloader allowed you to mount it read/write. So... if the bootloader is unlockable, /system might remain read-only.

However, I also remember during unrEVOked.com's earlier days that they had an exploit where they could temporarily unlock NAND, and in that small window, you could make changes to /system. That exploit might have required a custom recovery, and since /recovery is now signed, this option may be off the table. I'm not really sure about this, since I don't really understand the nature of the exploit.

Bottom line: it's going to take a lot more effort on the devs' part to break the Evo 3D (unless the engineering HBOOT is leaked), and it may be a while until we know what we'll be able to do.

Good point about the bootloader and it's relation to mounting /system as r/w, I hadn't thought of that. Within Android, isn't system always a protected partition? This seems the case on my Heroc. For instance, every time I access it via Root Explorer, I have to mount it as writable in order to copy or move anything to it. I believe that same holds true via ADB via chmod.
 
Good point about the bootloader and it's relation to mounting /system as r/w, I hadn't thought of that. Within Android, isn't system always a protected partition? This seems the case on my Heroc. For instance, every time I access it via Root Explorer, I have to mount it as writable in order to copy or move anything to it. I believe that same holds true via ADB via chmod.

Yes, exactly. Just because you've unlocked the bootloader doesn't mean the bootup sequence doesn't place the default r/o privs on these partitions. We still have to manually remount the partition. However, there are a few ways to have this automatically done, either at phone bootup, or later. I use a bashrc file to do it. whenever I putty into the phone and call up bash, it auto-mounts system rw.
 
Anyone have an idea what it would take to brute force this? Could we do a shared computing system, like seti to do it. MODS delete this post if it is against the rules.

From my understanding, while the possibility exists, if possible, it would likely take years for this to be accomplished, even with brute-forcing, it has a 256-bit encryption which is a considerable road block.

There's a good chart in this wiki page that explains a bit further:

Brute-force attack - Wikipedia, the free encyclopedia
 
From my understanding, while the possibility exists, if possible, it would likely take years for this to be accomplished, even with brute-forcing, it has a 256-bit encryption which is a considerable road block.

There's a good chart in this wiki page that explains a bit further:

Brute-force attack - Wikipedia, the free encyclopedia

That's why she suggested to set up some type of network of computers to split the workload up. Still would take long, but from what I understand those time frames are worst-case, last-shot scenarios, no?

Do you really think HTC/Sprint is going to delay a phone for a few thousand people who are upset? There are way more people without rooted EVOs than there are people with rooted EVOs. More EVOs for the rest of us who don't care.

I'm going to quote a comment I saw when someone said that people who root their phones make only 1% of the total buyers.

 
That's why she suggested to set up some type of network of computers to split the workload up. Still would take long, but from what I understand those time frames are worst-case, last-shot scenarios, no?

I understand what she meant, but firstly, don't you think the same thing has been considered for the Droid X? I know most of us here are HTC or EVO users so we may not really pay much attention, but the Droid line is hugely popular as well and there are many Droid X users who want their phones unlocked but have not been able to do so.

Secondly, this sort of task would take tremendous, almost inconceivable amounts of of raw computing power,

This is just an except from the wiki I mentioned before:

"Breaking a symmetric 256-bit key by brute force requires 2128 times more computational power than a 128-bit key. A device that could check a billion billion (1018) AES keys per second (if such a device could ever be made) would in theory require about 3
 
after looking at HTC's facebook page, both their status update and their wall, I think they'd have to be batshit crazy to carry on w/ this plan in any meaningful way. :)
 
Frankly, I'm amazed that they even responded to it, regardless of whether their Facebook wall was getting crushed. The hopeful side of me wants to think that maybe we made a difference, but the realist side (or cynical you could say) thinks this is just PR to get the anger level checked, and to let it die down before they either never announce what their review process found, or quietly announce they're moving forward as planned.

Guess we'll see, if they move forward as planned, it's definitely going to weight heavily into my decision on whether I want to continue with my purchase or not.

Hopefully "soon" means actually means just that.

Oh, and a big welcome to novox as a new Mod. :D
 
256-bit is 2^256 combinations to try, which is about 11,579,208,923,731,619,542,357,098,500,869,000,000,000,000,000,000,000,000,000,000,000,000,000.

This is not the way to get around the problem :)
 
I'm also curious if the backlash was equally strong during the release of the recent HTC phones... I'd like to think that our active discussions here really fueled the fire in other places.
 
I am also pretty astounded that HTC even acknowledged the public outcry over this. However, given that it seems like it was really huge, it was probably warranted. ;)

I am going to go ahead and say that this was probably one of the largest instances of news of this kind causing a huge backlash like this. I have never seen the fires stoked so highly as they were on the Facebook page for HTC today. :D
 
HTC has a big fan event tonight (going on right now, in fact) in Vancouver. So they probably wanted to kill that outcry before their fan event started.
 
Even using theory, comparing the likelihood of it happening via a device which does not currently exist, it would take an insane amount of time. To the extent in which, if for example it is successful, no one would be using the phone anymore.

No one would be using anything period. Humanity will probably have done something foolish enough to bring about the apocalypse in that time. :D

Okay, okay, maybe that is a pretty dim view. However, either way, by then smartphones will be a thing of the past. ;)
 
256-bit is 2^256 combinations to try, which is about 11,579,208,923,731,619,542,357,098,500,869,000,000,000,000,000,000,000,000,000,000,000,000,000.

This is not the way to get around the problem :)

I will gladly donate my CPU cycles to get this decrypted.

I'm sure i'm not alone.
 
I wonder what will happen if in a few days they come out and say that they won't be making any changes.

Either all of the fire and anger will be gone and it'll die out, or could it be worse, since they pissed people off, quieted them with what will then be interpreted by many as a lie (they completely think that reevaluating is opening up), and then decided to stay the course.

Some will be doubly as mad, but will there still be the numbers to really make noise, and if they've already looked at the policy and not changed it, will there be any reason to continue complaining other than to voice your displeasure at something you know won't be changed, or maybe the cathartic effect it'll have?
 
I understand how big the problem is, but I also understand that nothing is unbreakable. Every encryption system used needs to have a key, which can be exploited one way or another. For the most part, it is getting the key you need to worry about, not getting false promises. In a brute force attack, you can cut the time down a huge amount, if you can set a list of rules. With passwords you start with a standard dictionary, you usually dont need to get pass the whole dictionary before you get the password. Most people use very simple passwords. What I was trying to ask, and missed the point, what do we know about the key, how long, what do they use, and how can we limit down the bruteforce attack. For example, we know that "password" will not work, in fact we can probably through out the whole dictionary. Of we know the key is is 100 letters long, of random numbers and letters, we can limit the brute force to that, saving us a huge amount of time. As for can it be done, yes it can, but the easiest way is to social engineer it.
 
I wonder what will happen if in a few days they come out and say that they won't be making any changes.

Either all of the fire and anger will be gone and it'll die out, or could it be worse, since they pissed people off, quieted them with what will then be interpreted by many as a lie (they completely think that reevaluating is opening up), and then decided to stay the course.

Some will be doubly as mad, but will there still be the numbers to really make noise, and if they've already looked at the policy and not changed it, will there be any reason to continue complaining other than to voice your displeasure at something you know won't be changed, or maybe the cathartic effect it'll have?
What would happen is I would not get the phone, and probably not get another HTC phone ever again. And I'm sure I'm not the only one.

It's really too bad that nobody has a phone that can match these specs. If there was a viable alternative, I would completely abandon this Evo 3D, even if it meant switching carriers. As it is I will hold out hope that HTC "leaks" a bootloader or whatever we need to unlock it. But I don't think I'm buying this phone until that happens. And if another phone gets announced that competes with the Evo 3D before the "leak" happens, then I'll drop all plans for the Evo 3D and preorder the other phone.
 
It's going to be impossible to brute force this :(. I hope we get a leak or htc does something about it. I for one just wrote on their facebook page and emailed htc venting my views :mad:. If the 3vo can't be rooted, I might as well get an Iphone, same difference really (I really won't be getting an Iphone).
 
Back
Top Bottom