00:02
naoki has quit [Quit: naoki]
00:03
naoki has joined #linux-amlogic
00:04
naoki has quit [Read error: Connection reset by peer]
00:04
naoki1 has joined #linux-amlogic
00:06
naoki1 has quit [Client Quit]
00:06
naoki has joined #linux-amlogic
00:11
naoki has quit [Ping timeout: 272 seconds]
00:18
djrscally has quit [Ping timeout: 252 seconds]
00:34
vagrantc has quit [Quit: leaving]
01:44
Danct12 has joined #linux-amlogic
01:47
Daanct12 has joined #linux-amlogic
01:49
naoki has joined #linux-amlogic
02:45
f_[x] has quit [Remote host closed the connection]
02:45
exkc has quit [Remote host closed the connection]
03:17
zxdd_ has joined #linux-amlogic
03:18
zxdd has quit [Ping timeout: 252 seconds]
03:51
hexdump0815 has quit [Ping timeout: 248 seconds]
03:54
hexdump0815 has joined #linux-amlogic
03:54
jacobk has joined #linux-amlogic
04:24
Daanct12 has quit [Quit: WeeChat 4.5.1]
04:35
konsgn has joined #linux-amlogic
04:36
luka177 has joined #linux-amlogic
04:38
chewitt has joined #linux-amlogic
04:57
Daanct12 has joined #linux-amlogic
05:28
buzzmarshall has quit [Quit: Konversation terminated!]
06:12
gabes22 has joined #linux-amlogic
07:07
luka177 has quit [Ping timeout: 248 seconds]
07:14
ldevulder has joined #linux-amlogic
08:05
djrscally has joined #linux-amlogic
08:33
naoki has quit [Quit: naoki]
08:33
naoki1 has joined #linux-amlogic
08:35
naoki1 is now known as naoki
09:04
jacobk has quit [Ping timeout: 260 seconds]
09:05
jacobk has joined #linux-amlogic
09:28
ldevulder has quit [Quit: Leaving]
09:54
ldevulder has joined #linux-amlogic
10:56
<
f_ >
What I find a bit strange is everything is encrypted. There is absolutely no AMLC header after BL2.
10:56
<
f_ >
Nothing except gibberish.
10:57
<
f_ >
Just curious, has anyone seen this behaviour before?
11:16
naoki has quit [Quit: naoki]
12:00
<
chewitt >
I thought the whole point of 'secure boot' was to encrypt everything, no?
12:20
<
f_ >
chewitt: I think it might be optional for secureboot
12:22
<
f_ >
At least for BL2
12:24
<
f_ >
chewitt: Though I would've expected the AES key for the rest to also be stored in efuses or something, but that's only the case for BL2
13:17
Daanct12 has quit [Quit: WeeChat 4.5.1]
13:34
f_[x] has joined #linux-amlogic
14:18
f_[x] has quit [Ping timeout: 260 seconds]
16:01
f_[x] has joined #linux-amlogic
16:23
mripard has quit [Quit: WeeChat 4.5.1]
17:00
vagrantc has joined #linux-amlogic
17:12
buzzmarshall has joined #linux-amlogic
17:29
anessen973383701 has joined #linux-amlogic
17:49
chewitt has quit [Quit: Zzz..]
17:50
chewitt has joined #linux-amlogic
18:10
hexdump0815 has quit [Quit: WeeChat 3.8]
18:10
hexdump0815 has joined #linux-amlogic
18:13
<
f_ >
hexdump0815: You can get the AES key for BL2 decryption if your box does not lock USB mode behind a password
18:15
<
f_ >
A vulnerability in the bootROM makes dumping whatever you want in SRAM easy. Specifically, there's a copy of OTP memory (efuse) at 0xd9013c00. So: The key is at 0xd9013c50 and the IV is just after, at 0xd9013c70
18:15
<
f_ >
so you can simply dump that, then feed those to openssl to decrypt BL2 :)
18:16
<
f_ >
I think I should document that clearly. Second.
18:27
psydroid2 has joined #linux-amlogic
18:30
anessen973383701 has quit [Ping timeout: 252 seconds]
18:42
chewitt has quit [Quit: Zzz..]
21:12
djrscally has quit [Quit: Konversation terminated!]
21:21
djrscally has joined #linux-amlogic
21:48
djrscally has quit [Ping timeout: 252 seconds]
21:49
djrscally has joined #linux-amlogic
23:03
konsgn has quit [Ping timeout: 248 seconds]
23:15
djrscally has quit [Quit: Konversation terminated!]
23:51
chewitt has joined #linux-amlogic