<phh>
f_: to be sure i understood it all, you have a xiaomi tv stick, vulnerable to the usb dl flaw, which you used to dump the AES key from efuses. Only AES key is used for secure boot, so that's enough for you to boot your own bootloader. Is that correct?
<f_>
phh: Basically. Except all the firmware is encrypted and the key I dumped is only for BL2
<f_>
And I can already boot my own bootloader via USB thanks to the vuln.
<f_>
I haven't tested replacing BL2 on the eMMC, and I don't think it'll work.. it's signed
<f_>
I mostly did my best to not touch anything on the eMMC. So only the vendor u-boot env has been altered, to boot postmarketOS from it
<f_>
But it print "USB boot" nor "resetting ...". I suppose DRAM init fails which is to be expected.. that binary uses lepotato's config and lepotato uses DDR3 while the stick uses DDR4
<Danct12>
i should do something to my beelink gt-king again
<Danct12>
my first idea is going to build a replacement shell for it and custom cooling
<Danct12>
there's apparently a lot of space for a custom cooling
<Danct12>
even screw holes for that
luka177 has joined #linux-amlogic
<f_>
Danct12: who's stopping you from doing it? :)
luka177 has quit [Ping timeout: 245 seconds]
hexdump0815 has quit [Quit: WeeChat 3.8]
hexdump0815 has joined #linux-amlogic
psydroid2 has joined #linux-amlogic
luka177 has joined #linux-amlogic
<f_>
edit: "But it" doesn't "print..."
<Danct12>
f_, nothing but.. i'm having trouble finding the exact cooler
<Danct12>
and also it seems like beelink has several revisions of the board
<Danct12>
some with mounting holes and other without them??
<Danct12>
it also has a unpopulated usb port
<Danct12>
so if i would go and adapt a custom case, i'd probably solder a usb port to that and enable it