Skip to main content

Apple to block firmware downgrades with APTicket?

posted onMarch 28, 2010
by hitbsecnews

As many of you have noticed, the new shsh files contain a new key named APTicket. I still need to do a more thorough investigation of this key but my gut tells me that it is an indication that Apple intends to try to stop us from bypassing their TSS server for local restores.

My guess is that in future versions of iTunes, Apple will probably handle the TSS request/response and later this year implement the code to process the response in the actual bootrom of the device. Here's what I mean:

1.) The newer iTunes versions will send a certificate request in the TSS request by adding a new key to the TSS request.

2.) Their TSS server will create a new certificate with an effective date attached to it. (Making it invalid if used after that date)

3.) Until the new bootrom rolls out, iTunes will handle the decrypting of the response blobs using the nifty new signed certificate response ala APTicket.

4.) Once Apple ships new devices with the bootrom capable of validating the new APTicket (or whatever they call it in the future) they can add logic to check the bootrom of the device and conditionally process the response from the TSS server(for old bootroms) or allow the device to process it(for new bootroms).

Source

Tags

Apple

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th