Thanks EM and Scotty.
Scotty that really did clear a few things up for me, I didn't realize S-OFF allowed you to lock and still run custom. I guess I thought of it as hboot not checking any further with a locked bootloader, never occurred to me S-ON would be necessary as well to get you stuck.
Really just a point of curiosity, is the tampered flag tripped during checks when booting, or is it immediate in an S-ON device. Really can't see how it matters, I'm just curious what is doing the checking for "tamperationing" the bootloader, or some real time security?
Scotty (and others who know as well), if you're cool with it, I'm going to edit this and answer from my point of view.
Not because it's better - but because I've found that multiple points of view help with the understanding of odd bodkins and other orthodontia.
So - stand by - as you read this, I'm editing in my version of the answer(s).
~~~~~~ And the edit follows below this line

~~~~~~~~~
So - I'm not going to say the same things in different ways, that's often helpful and often just silly.
I am going to recap some of what scotty said
from a different point of view and that will help with my way of adding on answers to your questions.
I've written firmware, scotty has not. But in this case, scotty has a firmware developer's understanding of hboot - and I do not. I do have a systems programming understanding of it, so between the two points of view, I think we'll get close to a good picture.
I'm not going to talk about tampered and so forth - I turn to scotty for that anyway and have nothing to add.
I want to take a moment and take about cyber security.
Stock hboot has very good cyber security. It frustrates us, but it really protects users more than HTC or carriers.
I'm almost unique in that I *always* use the phrase "encrypted signature security" when talking about s-on/s-off and here's the story on that.
All crypto systems have locks and keys. The front door to your house is a crypto system. Your car ignition is a crypto system.
Anything with a lock and a key is a crypto system.
When we think about good locks and bad locks - and that's how we've all discussed the subject all our lives (this is a good combination lock for my locker, that brand sucks) - we say we're talking about the lock - but - we're really talking about the strength of key system.
Can the lock be fooled easily by a key not its own? Can it be forced open? Can it be picked?
If you think about it - those are descriptions of the key quality of the lock, not the lock per se.
Here's why that's important:
You can steal my keys and figure out that I drive a Ford and have a house or apartment. But you don't know which one. And if I make the key really complicated, you're going to fail making an unauthorized copy. (I'm thinking of that $250 Ford wants for my combination mechanical/computer chip key lmao!)
Got it? Sure you do - it's what you know, just with the crypto point of view.
If you want, take a second, meditate on that, so you got it. If you really already got it, meditate on being cool enough to get it that quickly.
If you grok what I just laid down about car and house keys and locks being crypto systems, something you already know all about - then you're ready to grok the HTC hboot (and virtually all others - HTC was here first ok

).
So - I like to start with the basics - your bootloader is locked. Forget rooting - savor the idea - your bootloader is locked.
So what happens with a stock phone and an OTA???

:dontknow:
Actually - the answer is really simple - it isn't that the bootloader is just locked - the bootloader contains all of the firmware management junk - and the bootloader CONTAINS THE LOCK.
That's so big, I'll repeat it - THE BOOTLOADER CONTAINS THE LOCK.
But what's behind the lock? Read on, this is the good part.
So - how can you even boot up your phone? How can you get an OTA update?
Just like your car or front door - a lock implies a key.
The OTA zip files that we warn people to be careful about - devs only, wait for your version - those are zip files of the bytes that streamed in during the OTA - and that stream, whether over the air or in a PC zip file -
contains the key.
If it didn't, the bootloader would not let the new bytes in -
the door is locked.
And - it's a software key - meaning - it's not a program, it's a stream of bits that the bootloader either plays bad-part-of-town-bouncer with - or it hears,
Open sez-a-me!
You know from flashing - check the MD5 value before installing new goodies. If they don't match, you had a bad download, don't goof with it, download again. In fact, we can even say that
the MD5 value is the key to good flashing.
So - what's an MD5 value? Quite simply (because it is quite simple), it's a way of counting ones and zeros in a file so that you get a number. It's not normal counting, it's actually a kind of moron counting. Normal counting would be "189,342 ones and 167, 289 zeros." So you could change one bit and the count would fail. But with real counting, you can change two bits, get the same counting, and have a messed up file. Or a thousand changes - with normal counting, any even number of screw ups would give you the same count. But no one can out-think what a moron will do next - so with moron counting, change anything and the MD5 total fails.
Thanks for hanging in - that's not a tangent, it's really central ok, and here's why:
How do you use an MD5 value?
The dev makes a count and prints it. You make a count. You compare the dev's printed count with your own. If they match, you let the new file into your TWRP installer. If they don't - you stop it right there. But if it's good, you tell TWRP and everything with you new package,
Open sez-a-me!
That is a crypto key process.
How does it relate to the bootloader lock?
Simple.
The bootloader expects to get any number of updates over the phone's life.
And it's the bootloader.
When you or the phone is in the bootloader - who is it going to ask, "Hey - wth is the correct number over here?"
You could do that with you web page and your brain - but the poor little bootloader is all alone.
So - how do deal with that?
You could just make that a constant number. And tell the bootloader at the factory what that number is.
And any fool could find and copy that number - in other words, any fool could find and copy that key.
That's no lock at all. Someone malicious or an out of control download would let a really bad OTA in with that and brick your phone. The constant key would say - Use me! - but the following bits could be completely hosed.
So - you need a new and unique key each time, but you cannot let the bootloader know all the possible keys.
If that sounds impossible, you're following along perfectly.
For decades, it was impossible. Until one day, a cryptanalyst solved it.
And it's a parlor trick.
Suppose Granite and I come to you in chains, locked and say - unlock us. And we each have different locks needing different keys.
We want to be unlocked - but only by you because we only trust you.
So when we were all together at the factory, you were issued a master key. Just one. And some keymaking tools. Very secret keymaking tools. Only you know about them - not us.
And when Granite and I come to you - we're carrying little locked boxes in our hands. His is blue. Mine is blue. And we don't have the key for them. And Scotty pops out with the same deal. And so does... KOLIO.
And so we say - "Hey bud! It's Granite and Early and KOLIO and Scotty! Hooray!

"
And you say, with a really stern face and tone of voice - "Show me your boxes!"
And Scotty and Granite do, along with KOLIO.
But I don't have one. Or it's the wrong color. Or it's bent. So you say to me, "Get lost hoser! You big fakir, you're not Early. Early carries the One True Blue Box!"
I'm gone, done, erased.
So then you say, "Wow, hi guys! You might be Granite and Scotty and KOLIO - let's check!"
And you take out your master key - it does not fit Granite's box. You eject him from the game as a total fakir, right there.
You try your master key in Scotty's box and you say, "It works! Holy cow! Let's look inside!"
Inside - you find instructions on how to make the key to break Scotty's lock, free him from his chains, and let him past you.
You take the instructions, use your secret tool, make the key - and try it on Scotty's chain locks.
But uh oh, it doesn't work. So you say, "I'm not fooled. You might have started out as Scotty but you're all screwed up now! None shall pass!"
Finally - you get to KOLIO. He has a box. Your key works on it. Inside are key making instructions. You put them into your Acme Secret Keymaker by HTC - and you get a key. You put that key into the lock on KOLIO's chains, and it works!
You unchain him and say, "You are the one I have been set to await. You are now the master. Pass the gate with my blessing - change whatever you like on the other side - even me! You have said and I have heard,
Open sez-a-me!"
Now - you are the bootloader, and Granite, Scotty, KOLIO and I claimed to be good HTC software and firmware that were downloaded correctly, contained no malware from the process and could be entrusted to change the phone you guarded.
Even though you didn't have the one true key - you had the secret process to create, verify, and use the one true key, and let only the good one of us pass.
And we didn't know our own keys. We didn't even know the key to unlock the box we carried. And we don't know what our key instructions mean. We don't know what's in that box.
So you can't ask us.
And one of us can visit you as often as necessary, each time with different contents in that box - in other words - a different actual key.
And that is a better crypto system done with a parlor trick.
You, the bootloader don't have our key, but you have the key to our key. We don't have the key to our key or know the instructions inside the box, and we don't even know what The Secret Key Maker is.
The One True KOLIO update could visit you a hundred times, with a different key instruction each time - therefore - needing a different key each time.
And you would not need to know his key.
And an outsider could watch everything except your secret key making process - because that's behind your locked door - and never see the pattern to figure how to make counterfeit key-making instruction.
And in the crypto world, governed by maths both geniused and moroned, we call that system of numerical master keys, key-making instructions, and final keys -
Encrypted signature security.
And instead of metaphors like people and boxes and brass keys, we call the keys -
signatures. And we scramble them like eggs so they can't be figured out. And we call the scrambled numbers -
encrypted signatures.
Of course, we're going to encrypt (scramble) the signature - so we can leave that word out and agree that the important part is Signature.
And as long as you, the bootloader, are commanded to be ON the job by HTC, then HTC, we, you, and the users say - you are S-ON.
You only permit things that pass the encrypted signature security (I'll show you mine if you show me yours parlor trick) things to operate.
So what does that all mean?
I don't know how many people here remember the old days of Windows and DOS and hard drives.
Easy to lose everything, everything was the C: drive. Today we're back to that because it's pretty safe - but not in the early days.
So - in the early days - you took your new PC with it's Windows C: drive and you did the Super Expert Cool Really Expert Trick - you separated that one disk into C: and D: drives.
OMG PWNIES - there's only one disk! But it's like there's two. It's like - all - all - WOW!
And then if your Windows got borked or you accidentally erased your C: drive - you did not care. Because using the Super Expert Cool Really Expert Trick you went and put all of your documents and spreadsheets on the D: part of the hard disk drive. You reformat and reinstall your Window to C: and presto! Your files were still there, safe and sound!
Majicks! Majicks!
But with a borked C: part of the disk, the D: part was useless ones and zeros.
You have to be a little bit old to remember that.
So my point - your stuff was divided into two parts on one thing.
Don't worry - I didn't lose you, here it comes -
Android = embedded (no disk, just flash storage), real-time
Linux + Dalvik Virtual Machine (soon to become ART) + apps that run inside the Dalvik or through the ART, and use Linux system services
^Important
So - what is
Linux? It's exactly like Windows or Mac OS X - an operating system, meaning libraries (with services) (maybe you've heard of DLL files for Windows - OS X and Linux has the same deal, different names) and
a REALLY TINY piece of software.
You have a computer, a phone, a toaster, a fridge, I don't care - and it has hardware and software.
What is the bridge? It's easy to say "hardware and software" - see, I just did it again - but how do you make them come together?
A
special piece of tiny software called a kernel ties software and hardware together.
Without the kernel - you got nothing.
So - the freaking point already?
Your phone doesn't have an old school hard disk.
But it does have flash storage that does the same job - storage.
So - let's split it up, just like the old school Really Expert Trick - and make the one thing two, just like C: and D: on one hard disk.
Of course we're all cool and stuff, so we'll call them images and partitions and whatnot.
So - even though the kernel is part of the operating system - we can put it in its own deal.
We put it in the boot image area (because the first thing that the kernel does tying the hardware and software together is to boot up the operating system on the hardware).
And so - here's the next parlor trick - the boot image area (fancy name for the kernel C: drive

) - has an encrypted signature.
If you don't open its locks, you don't boot.
You can lock down a 1 or 2 GB Android operating part by just putting the
encrypted lock on the area where the kernel is.
And you can lock down installing things on a stock phone by putting an
encrypted lock on the update stream, whether OTA or zip file.
You can brute force things and copy whatever you like wherever you like.
No lock is perfect.
But if the keys fail, the keeper of the secrets - the bootloader - shuts itself down permanently so you can never get the key making secret.
And that is called a hard brick.
Or you can brute force a little and it'll send the phone into an endless loop of try to boot - fail - try to boot - fail - etc etc - until you fix the problem.
It's such a good idea that you put that scheme onto other parts of the storage as well - where the radio stuff is - where the bootloader itself is - the whole enchilada.
But once the phone passes all of the locks and boots up, you, the bootloader, can get out the way and not slow anything down.
You trust it. It gets to run.
So - HTC used to sorta lock things but turned a blind eye to all of our rooter antics. Even though they had s-on, they did it enough to save bad downloads and fooling it was no big deal. Getting unlocked and s-off was just tedious work but that's all. (My first unlock/s-off took 78 precise steps. I am not making that number up.)
But one day - they changed they minds and really went to Crypto Town.
We were screwed. There was much sadness in the land. We could not get around them.
We mounted a public petition and it went viral worldwide.
HTC's CEO stepped up to the plate and said -
"You want it? We listen. But here's the deal. We ship it our way so normal people are safe from malware and OTAs. But we let you come to us, get yet another secret key and unlock your bootloaders - so you can all go to Root City. If we do, you say good things about us. Do we have a deal?"
There was much rejoicing in the land.
We got what we asked for - precisely what we asked for - and we stood down the publicity attack, seeing their side of it too, to protect regular users. Anyone can get a bad download. And it's not a BlackBerry, so no, you do not get to erase whatever you like and get sympathy from us.
Enter the HTCdev program - and The Big Surprise.
We got EXACTLY what we asked for and they gave exactly what they promised - The Unlocked Bootloader.
But they revealed something we'd never seen and never dreamed of - The Unlocked Bootloader With S-On.
We didn't even know to imagine such a thing possible.
Be careful what you ask for, you just might get it.
So - with that - you can "unlock the bootloader" - but really, it simply says - hey, it's not one of the encrypted signature areas - you can flash and change there.
But the encrypted signature areas - those are still s-on - so you can do nothing there. Only our approved ones and zeros.
So, s-on unlocked means - no signature security on recovery, flash away - no encrypted signature security on the rest of the rom - flash away. Everything else. Ours. Not yours. Radios - ours. Kernels - ours (and by extension, what roms work with our kernels). And any other firmware - ours. And we'll just update the bootloader whenever we like so if you get close to the secret key maker, we'll distribute a new one.
And despite our whining, as we have scotty and a scant few like him, most HTC rooters really can get by with an s-on unlocked bootloader.
But the real deal - turn off the gatekeeper part of the bootloader altogether.
Put him on vacation.
Tell him that he is to no longer ever check an encrypted signature ever again.
Not even if he gets replaced by a new bootloader who thinks he can.
That is The Crypto Key Magic - that is permanent s-off.
The tampered flags, text, unlocked, locked, etc etc, all messages for the humans. You, so you know they'll know, and them, so they'll know.
You might fool a tech with changing the words on the hboot screen on that - but you can't fool the factory or software from the factory that can really check.
So, with s-off, yes, you can lock the phone again.
It won't mean anything because at the end of the day, the key maker says, "All shall pass."
Whether new hboot, recovery, whatever dude - with s-off, all shall pass.
And because other software - like, oh, I don't know, let's say an app like Drive - is flying at about 30,000 feet above the bootloader, it don't see so good. It can see the secret tampered and unlocked flags. But it won't see the s-off hiding below them.
Ok - I felt like it was all there and at the end, I felt like maybe I got obtuse again.
I'll stop here.
I hope that this point of view answers some questions, was actually understandable and as fun to read as it was to write.
In my fevered brain, you all got it and loved it.
If in reality you didn't, my bad.
If you did, my eternal thanks for reading - because writing this was not easy!
BTW - change brands, it's all still the same story. We have names for these things with HTC because HTC went the professional crypto route. It's not that other bootloaders don't do all this - they just do it with less discipline and more confusion.
HTCs are not weird in the world of bootloaders. In fact, only Nexi (lock or not without an encrypted signature key) and an HTC (next level up) really do any of this stuff correctly in the first place.
^Not an opinion even if it sounds like one. :rofl:
PS - for every rule there's an exception. The LTEvo could be s-on and still flash a non-HTC kernel. Doesn't misprove anything if you can think of an example here or there that go against what Scotty or I have said. Just means that HTC has made a lot of models, a lot of locks, a lot of keys - and for every rule, there's an exception.
But overall - that's the deal.
PPS - the whole HTC bootloader unlock did in fact center around our forums. Our mod at the time, and my pal, novox77 wrote up a clear analysis of how they did s-on with an unlocked bootloader. That removed the confusion and he was quoted far and wide - that's when the petition went from a niche story to viral, and only then did HTC respond.
So my telling of that story is as firsthand as you can get without being novox77. And like Steven58 in the epic GNex thread, novox77 and I talked real-time about that throughout.
I'm proud to have worked with novox77 - he may be gone from our rolls due to work, but he is not forgotten, and he is another unsung hero in the history of HTC rooting.