How did it get corrupted? FTL issue in an aging eMMC? Bug in linux kernel block device driver? Malicious code? Sheer dumb misfortune? Who knows...
How did it get corrupted? FTL issue in an aging eMMC? Bug in linux kernel block device driver? Malicious code? Sheer dumb misfortune? Who knows...
I don't know how it is now, but my almost-decade-old generic Mediatek Android smartphone (still working, although seldom used) lets you access the whole eMMC in a special recovery mode using SPFlashTool, and there's no signing required. Looks like they have locked down things since then, ostensibly for security but more likely for corporate control and planned obolescence...
If the flash bootloader is failing to verify, I should be able to send a new one over the USB port, even if that requires wiping the device for security purposes. Defending against an evil maid attack doesn't explain why I can't do that.
More details: https://blog.quarkslab.com/analysis-of-qualcomm-secure-boot-...
I get that, but there should be something in the ROM that can reflash the device.
It already has signature verification code, which is the hard part to fit into a tiny ROM.
> Without a signed firehorse binary you can't do anything, because EDL just won't talk to you.
So... either they should release a firehorse binary that can wipe devices, or they should add a small bit of code that can wipe and flash without needing a firehorse binary.
As I read it, dmitrygr was saying that the ostensible reason you can't do anything is fear of evil maid attacks, but that ostensible reason doesn't explain why there isn't a wipe+access mode. And "the bootloader is corrupt" isn't the reason, because this is about the pre-bootloader code.
And how should they add code to a ROM of yet bricked devices?
> As I read it, dmitrygr was saying that the ostensible reason you can't do anything is fear of evil maid attacks, but that ostensible reason doesn't explain why there isn't a wipe+access mode. And "the bootloader is corrupt" isn't the reason, because this is about the pre-bootloader code.
Well, ask Google? :-)
I'm criticising the original design. Read that "should" as talking about the past.
> Well, ask Google? :-)
Why? I don't care what they have to say (unless they have something surprisingly interesting to contribute), I'm just accusing them of doing this wrong.