|
|
#21 |
|
Member
![]() Join Date: Jan 2012
Posts: 40
Likes: 15
Liked 15 Times in 7 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
|
Its almost like the dongles contain the keys to 3.6+ ...they decrypt eboot- rencrypt with 3.55 key....plus w.e drm bs TB adds.
And everyone thought @enosrasun was a fool. Now if we can just figure out how TB decrypts the 3.6+ eboots we may just be in luck. Hopefully its as easy as 3.6+ keys sitting on the dongle :P The more realistic scenario is that they decrypt the 3.6+ eboots externally to the dongle (hence why the are always releasing eboots all the time). Then encrypt with their drm keys. If we can crack their dongle at the very least we can get the eboots signed via 3.55 key that have been released thus far by TB Short term fix.... long term would actually be getting 4.11 keys, so we can actually sign our own and have homebrew again Last edited by No_0ne; 04-05-2012 at 01:34 PM. |
|
|
|
|
#22 |
|
Member
![]() Join Date: Dec 2011
Posts: 364
Likes: 282
Liked 861 Times in 189 Posts
Mentioned: 190 Post(s)
Tagged: 0 Thread(s)
|
Im also looking into the dongle, but i have to see what it does with the cfw also.How they communicate., els we crack the dongle they just change key and cfw. We have to cover all parts.
I have seen indications of master keys not just 3.6+ many have talked about it before. But have seen alot of it mention digging into dongle stuff. Off cause i cant find or prove it 100% .but it says on the first post master key.And it also tell me thats why trueblue are still here after alot of OFW updates from sony
__________________
![]() Last edited by zadow28; 04-05-2012 at 01:35 PM. |
|
|
|
|
#23 |
|
Member
![]() Join Date: Feb 2011
Location: Germany
Posts: 279
Likes: 374
Liked 81 Times in 59 Posts
Mentioned: 9 Post(s)
Tagged: 0 Thread(s)
|
you ,gumbie and gravox ==== Freedom
|
|
|
|
|
#24 | |
|
Member
![]() Join Date: Jan 2012
Posts: 40
Likes: 15
Liked 15 Times in 7 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
|
Now what this means is, what keys are actually on the dongle? I would guess they would be as dumb as leaving say 4.11 private/master key on the dongle. If this is the case then there would be no real need to release eboots regularly. You could have the dongle take care or decrypting with 3.6+ key and re-encrypting with 3.55 keys. Its most likely the case that they decrypt the 3.6+ eboots on a computer. then encrypt them with there TB encrypt keys(possible the "master key" from your dumb). This is essentially the drm, so if we were able to get the actual keys from the dongle, we could decrypt the eboots, and sign them with 3.5 keys so they would work with current cfw. The problem with that is that they can update the TB and the keys would have to be retrieved again. So we really would still need 3.6+ keys themselves. At that point we can have our new cfw(in which case the eboots would really matter) |
|
|
|
|
Likes: (1) |
|
|
#25 |
![]() ![]() Join Date: Jun 2009
Location: up sh*t creek without a paddle
Posts: 7,674
Likes: 2,771
Liked 5,292 Times in 2,530 Posts
Mentioned: 360 Post(s)
Tagged: 1 Thread(s)
|
if they had 3.6+ keys then the eboots wouldnt need patching. they would be the same as retail eboots thats correct.
dont forget there is a master dongle key which the one you found reference to could be |
|
|
|
Likes: (1) |
|
|
#26 | |
|
Member
![]() Join Date: Jan 2012
Posts: 40
Likes: 15
Liked 15 Times in 7 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
|
The only other explanation would be that they found a way to create eboots from scratch/reverse engineered eboots. And I think its fair to say that getting debug eboots has been ruled out a while ago Last edited by No_0ne; 04-05-2012 at 01:53 PM. |
|
|
|
|
|
#27 | |
|
Member
![]() Join Date: Dec 2011
Posts: 364
Likes: 282
Liked 861 Times in 189 Posts
Mentioned: 190 Post(s)
Tagged: 0 Thread(s)
|
by the way its not that hard to find debug eboots, if i can, so can they. and no i would not say how. but lets gues there are pasties out there that tell. anyway the debugging of the cfw clearly indicates tampering with the lv1 so its not just pure 3.55 ill will look at the rest and post more findings.we are getting closer. trueblue knows these, and try scre tactics. regards
__________________
![]() |
|
|
|
|
Likes: (1) |
|
|
#28 | |
![]() ![]() Join Date: Jun 2009
Location: up sh*t creek without a paddle
Posts: 7,674
Likes: 2,771
Liked 5,292 Times in 2,530 Posts
Mentioned: 360 Post(s)
Tagged: 1 Thread(s)
|
i wouldnt say "ruled out" lol.
dont forget its hard to know who to trust in these times. we have been misdirected and trolled by "respectable" people before. there is no way they created eboots from scratch, not without the source code for the game at least now my guess is that as we have heard chatter about a special TB debug fw is that they have a fw (like rebug) and gained access to dev network again. again, this was "ruled out" but again, who do you trust? we as a scene put faith in that french troll for a long time and he turned out to be more harmful than good there was always the PNM project which was supposed to enable new things but vanished right before TB rose its but ugly head. it seems to me though that sadly too many people coincidentally stopped work when tb was released and vanished / changed stance etc
if it was true and you held the info back then you would be no better than any of the corrupted who play god with the scene |
|
|
|
|
Likes: (3) |
|
|
#29 |
|
Member
![]() Join Date: Dec 2011
Posts: 364
Likes: 282
Liked 861 Times in 189 Posts
Mentioned: 190 Post(s)
Tagged: 0 Thread(s)
|
well that is stealing and i dont do that, still and its not that hard to find unsecured section of the debug eboot .
and Huufff upload an shell dont really fall into there level. but thats just me.
__________________
![]() Last edited by zadow28; 04-05-2012 at 02:10 PM. |
|
|
|
|
#30 |
|
Member
![]() Join Date: Jan 2012
Posts: 40
Likes: 15
Liked 15 Times in 7 Posts
Mentioned: 3 Post(s)
Tagged: 0 Thread(s)
|
The more and more I look at
@zadow28
's dumps the more its revealing. There are a lot of references to dongle key. And one mention of a masterKey field. I think its simply the dongles master key.
Now to confirm this, we need to gain access to the so called "masterkey". From here we can attempt to decrypt a eboot released from TB, and see what happens. If we are successful in doing so, then we at least know what key (3.55 or 3.6+) was used to sign it. If there is something more complex going on (they have 3.6+ private keys) then perhaps we would have to dig further into the dongle |
|
|
![]() |
| Bookmarks |
| Thread Tools | |
|
|