❤8😐2👍1
Tadi Channel
Okay, I've been pinged that there are edits going on in the original post, good to see. The vibe loss can't be corrected tho, Google caused a lot of trouble, so people expect a cascade, let's not hasten it. This is the last message about that post.
I'm breaking my promise, but fr, they actually pushed an additional post to milk it further instead of editing, at the time I was writing this. They know exactly what they're doing, I overcredited the page and the author. Gotta get these liras.
But to be a little more detailed than salty (initial channel audience would already be aware of it), a reminder:
Secure boot off phones are exceptionally rare, unlockable bootloader is a bit of an ugly artifact, in a better world you'd be able to choose your own bootloader despite (and in compatibility with) secure boot, just like it is the case on desktops. The regulation refers to modems.
If some day in a better world the EU law actually starts demanding smartphone vendors to give you the same flexibility as proper laptops do, we'd be in a much better world. It wouldn't solve all of the anticompetitive measures that we're seeing, but at least you could do something you can on desktop: dual boot.
You can enable secure boot and still natively run Linux and Windows. To run anything that isn't stock Android on smartphones, you have to knowingly resign from the "perks" given to you by compliance of the stock ROM.
Yes, it'd be quite frustrating to reboot your phone every time you need to use a bank app, but honestly, it'd be a much better position than we are in right now.
And no, Snapdragon laptops with integrated modem won't force secure boot on you, they'll still be better than phones. If not for the panic, even a theoretically hostile EU stance would stop whenever the desktop equivalence is boldly pointed out. Smartphones are mini PCs.
But to be a little more detailed than salty (initial channel audience would already be aware of it), a reminder:
Secure boot off phones are exceptionally rare, unlockable bootloader is a bit of an ugly artifact, in a better world you'd be able to choose your own bootloader despite (and in compatibility with) secure boot, just like it is the case on desktops. The regulation refers to modems.
If some day in a better world the EU law actually starts demanding smartphone vendors to give you the same flexibility as proper laptops do, we'd be in a much better world. It wouldn't solve all of the anticompetitive measures that we're seeing, but at least you could do something you can on desktop: dual boot.
You can enable secure boot and still natively run Linux and Windows. To run anything that isn't stock Android on smartphones, you have to knowingly resign from the "perks" given to you by compliance of the stock ROM.
Yes, it'd be quite frustrating to reboot your phone every time you need to use a bank app, but honestly, it'd be a much better position than we are in right now.
And no, Snapdragon laptops with integrated modem won't force secure boot on you, they'll still be better than phones. If not for the panic, even a theoretically hostile EU stance would stop whenever the desktop equivalence is boldly pointed out. Smartphones are mini PCs.
❤8👍1😐1
Tadi Channel
I'm breaking my promise, but fr, they actually pushed an additional post to milk it further instead of editing, at the time I was writing this. They know exactly what they're doing, I overcredited the page and the author. Gotta get these liras. But to be…
The one thing that ARM laptops share with phones is keeping everything on a single storage chip to cut the costs. Modem firmware (protected), UEFI (protected). Yes, the latter sucks compared to usual x86 devices and it's a shame that you can't casually format everything as easily, but this state would already be a huge improvement for phones, completely in reach.
🔥7😐1
I understand that people are happy about it, but I'm not.
The monopoly state of GMS Android means it needs to be just "good enough" to serve serious blows to any alternatives. Position of Windows on desktop is completely incomparable to Android on smartphones. On desktop, you may even say that Linux started thriving. On smartphones, the consolidation into the garden of stock GMS Android seems to only increase.
Say you want Linux and Android on a single device. You may rely on projects like UBPorts, Waydroid, Droidian, PostmarketOS and do whatever you want with drivers or even whole kernel of your own device, make them more efficient and up-to-date in plenty of ways.
Google offers an alternative: you get to also have Android and Linux on a single device. But now, you'll do nothing with your hardware, even if it's EOL, even if something obvious sucks about it and can be easily fixed. [1/2]
The monopoly state of GMS Android means it needs to be just "good enough" to serve serious blows to any alternatives. Position of Windows on desktop is completely incomparable to Android on smartphones. On desktop, you may even say that Linux started thriving. On smartphones, the consolidation into the garden of stock GMS Android seems to only increase.
Say you want Linux and Android on a single device. You may rely on projects like UBPorts, Waydroid, Droidian, PostmarketOS and do whatever you want with drivers or even whole kernel of your own device, make them more efficient and up-to-date in plenty of ways.
Google offers an alternative: you get to also have Android and Linux on a single device. But now, you'll do nothing with your hardware, even if it's EOL, even if something obvious sucks about it and can be easily fixed. [1/2]
❤1
Why would anyone choose the latter? The answer is already there: Play Integrity and free app licensing (aka sideloading restriction). Measures that make sure to put difficulty onto any alternatives, especially commercial.
How popular would a mobile OS project have to be to get millions of users and hyped up investors in current state of the market? Whenever GMS Android makes a step forward, it pushes the rest five steps back.
[2/2]
How popular would a mobile OS project have to be to get millions of users and hyped up investors in current state of the market? Whenever GMS Android makes a step forward, it pushes the rest five steps back.
[2/2]
👍9😐3
OnePlus is switching to Realme unlocking scheme, NOT closing down bootloader unlock procedure. The real questions become:
1. Will there be a quota?
2. Will there be a week wait?
1. Will there be a quota?
2. Will there be a week wait?
😐14
Tadi Channel
OnePlus is switching to Realme unlocking scheme, NOT closing down bootloader unlock procedure. The real questions become: 1. Will there be a quota? 2. Will there be a week wait?
Actually, have translation of the whole original post on Chinese OP forum:
Good luck!
In order to protect the security of users' devices and data, and enhance system stability, we will adjust the bootloader unlocking method on ColorOS 16. Developers and users with specific needs can apply to join the in-depth testing program through the official channel if they are fully aware of the risks associated with unlocking and brushing and can bear the risks.
Specific application rules and operational procedures are as follows.
1)【Application Requirements
All of the following conditions must be met in order to apply to join the Deep Test Program:
ColorOS 16.0 and above models
No account abnormality or violation
No application record within 30 days
Non-government-enterprise and carrier-customized cell phones and tablets
Mobile phones and tablets listed in mainland China
2)【Application Instructions
1、After joining the test program, unlocking Bootloader privileges, modifying system files and other behaviors may cause unpredictable effects on the device, including but not limited to:
The three-party firmware may make some functions of the device can not run normally, such as the camera to take pictures. This may result in damage to the device.
Personal security and private information on the device may be leaked, and security is not guaranteed.
Some system functions may be modified, affecting system version upgrades and preventing you from experiencing the latest ColorOS services.
The data on the device may be damaged or lost, and cannot be recovered, so it is recommended to back up the data in advance.
2. After joining the test program, if the product is caused to have a functional failure, it will not be ennoscriptd to the return and exchange service, but will be ennoscriptd to the original warranty. If you can successfully recover to the official system by brushing, you can still enjoy the three packages normally, if the recovery fails, you can only enjoy the warranty.
3) How to apply for in-depth testing?
1、Please make sure that:
1) The phone and tablet meet the application conditions and support in-depth testing
(2) The system version type is the official version, and upgraded to the version that supports in-depth test when OTA detects the latest version (Viewing method: Settings > About this machine > Version information).
2. Follow the instructions to complete the application process at the in-depth test application portal.
3、After submitting the application, please wait patiently for the review, which is expected to be completed within 1~2 working days.
4、Related announcements will be released in the official account of OnePlus Community [ColorOS Upgrade Assistant], please pay attention to get relevant information in time.
QA
1、Is the Bootloader unlocking policy of previous ColorOS version affected?
For previous ColorOS versions, Bootloader unlocking is not affected.
2、When will this Bootloader unlocking policy be enforced?
The policy will be applied to the first batch of ColorOS 16-powered OnePlus phones and tablets in the second half of the year.
3. When can I apply to join the in-depth testing?
Relevant announcements will be released on the official account of ColorOS Upgrade Assistant in the OnePlus community, so please pay attention to get the relevant information in time.
4、Do I need to answer questions to apply for the in-depth test?
No. Users can finish the application process by following the prompts in the in-depth test application portal, and will be able to get the unlocked BL privileges after passing the audit in 1~2 working days.
5. Is there any limit on the total number of Bootloader unlocking applications and is there a limited number of unlocking quota?
No, there is no quota limit at present.
6、What is the after-sale policy after unlocking?
Good luck!
In order to protect the security of users' devices and data, and enhance system stability, we will adjust the bootloader unlocking method on ColorOS 16. Developers and users with specific needs can apply to join the in-depth testing program through the official channel if they are fully aware of the risks associated with unlocking and brushing and can bear the risks.
Specific application rules and operational procedures are as follows.
1)【Application Requirements
All of the following conditions must be met in order to apply to join the Deep Test Program:
ColorOS 16.0 and above models
No account abnormality or violation
No application record within 30 days
Non-government-enterprise and carrier-customized cell phones and tablets
Mobile phones and tablets listed in mainland China
2)【Application Instructions
1、After joining the test program, unlocking Bootloader privileges, modifying system files and other behaviors may cause unpredictable effects on the device, including but not limited to:
The three-party firmware may make some functions of the device can not run normally, such as the camera to take pictures. This may result in damage to the device.
Personal security and private information on the device may be leaked, and security is not guaranteed.
Some system functions may be modified, affecting system version upgrades and preventing you from experiencing the latest ColorOS services.
The data on the device may be damaged or lost, and cannot be recovered, so it is recommended to back up the data in advance.
2. After joining the test program, if the product is caused to have a functional failure, it will not be ennoscriptd to the return and exchange service, but will be ennoscriptd to the original warranty. If you can successfully recover to the official system by brushing, you can still enjoy the three packages normally, if the recovery fails, you can only enjoy the warranty.
3) How to apply for in-depth testing?
1、Please make sure that:
1) The phone and tablet meet the application conditions and support in-depth testing
(2) The system version type is the official version, and upgraded to the version that supports in-depth test when OTA detects the latest version (Viewing method: Settings > About this machine > Version information).
2. Follow the instructions to complete the application process at the in-depth test application portal.
3、After submitting the application, please wait patiently for the review, which is expected to be completed within 1~2 working days.
4、Related announcements will be released in the official account of OnePlus Community [ColorOS Upgrade Assistant], please pay attention to get relevant information in time.
QA
1、Is the Bootloader unlocking policy of previous ColorOS version affected?
For previous ColorOS versions, Bootloader unlocking is not affected.
2、When will this Bootloader unlocking policy be enforced?
The policy will be applied to the first batch of ColorOS 16-powered OnePlus phones and tablets in the second half of the year.
3. When can I apply to join the in-depth testing?
Relevant announcements will be released on the official account of ColorOS Upgrade Assistant in the OnePlus community, so please pay attention to get the relevant information in time.
4、Do I need to answer questions to apply for the in-depth test?
No. Users can finish the application process by following the prompts in the in-depth test application portal, and will be able to get the unlocked BL privileges after passing the audit in 1~2 working days.
5. Is there any limit on the total number of Bootloader unlocking applications and is there a limited number of unlocking quota?
No, there is no quota limit at present.
6、What is the after-sale policy after unlocking?
😐4❤2
Tadi Channel
OnePlus is switching to Realme unlocking scheme, NOT closing down bootloader unlock procedure. The real questions become: 1. Will there be a quota? 2. Will there be a week wait?
After unlocking the privileges, if the product is caused to malfunction, it is not ennoscriptd to return or exchange service, but can enjoy the original warranty. If you can successfully recover to the official system by brushing, you can still enjoy the three guarantees normally, if the recovery fails, you can only enjoy the warranty.
https://bbs.oneplus.com/thread/1926504022886318086
https://bbs.oneplus.com/thread/1926504022886318086
一加社区
一加手机官方论坛。一加手机开箱体验、测评报告、玩机技巧、手游攻略。与你分享美图及摄影技巧,众多大神教你轻松刷机,并由丰富手机资源任由下载。百万加油大家庭,交流更随心,一加社区官方论坛
Tadi Channel
After unlocking the privileges, if the product is caused to malfunction, it is not ennoscriptd to return or exchange service, but can enjoy the original warranty. If you can successfully recover to the official system by brushing, you can still enjoy the three…
Tldr they say 1-2 working days and no quota, but the phrasing about account makes it sound like it may need to be a month old. I also suggest a little bit of caution about Chinese units, but for now, unlocking Chinese Realmes abroad wasn't a problem (and didn't need a month old account)
Tadi Channel
Tldr they say 1-2 working days and no quota, but the phrasing about account makes it sound like it may need to be a month old. I also suggest a little bit of caution about Chinese units, but for now, unlocking Chinese Realmes abroad wasn't a problem (and didn't…
So now from my understanding, as "deep testing" gives you bootloader access and by itself doesn't influence your later actions, even the normiest of normies should start applying for it.
For the sake of stats, and unironically also the resell value. By successfully applying, you're giving your unit the ability to unlock, so the value of your device increases compared to default state without sacrificing anything.
For the sake of stats, and unironically also the resell value. By successfully applying, you're giving your unit the ability to unlock, so the value of your device increases compared to default state without sacrificing anything.
👍7
Google is such a mess now about releasing security patches that they confused (a) Qualcomm (employee).
https://issuetracker.google.com/u/0/issues/436838167
https://issuetracker.google.com/u/0/issues/436838167
😐10😁6🔥2
Just setting the record straight about a somewhat dated topic (I'm far from happy that a state before this commit managed to be real for any period of time):
https://github.com/eu-digital-identity-wallet/eudi-app-android-wallet-ui/commit/9367289f3da1abd7f2cff0e7e05d67a95f4fdf60
https://github.com/eu-digital-identity-wallet/eudi-app-android-wallet-ui/commit/9367289f3da1abd7f2cff0e7e05d67a95f4fdf60
GitHub
Update README.md · eu-digital-identity-wallet/eudi-app-android-wallet-ui@9367289
EUDI Wallet Prototype. Contribute to eu-digital-identity-wallet/eudi-app-android-wallet-ui development by creating an account on GitHub.
❤3😐3👍2
Forwarded from R0rt1z2’s Dumpster
Since Nothing decided to ignore my report, after waiting for about a month I decided to release it publicly :)
You can find the source code and full details here: https://github.com/R0rt1z2/fenrir. Currently, it only supports the Nothing Phone 2a but it should apply to more MediaTek devices from what I've seen on
You can also test the patched LK image from the releases section. It should spoof the bootloader state as locked while it’s actually unlocked, allowing you to pass strong integrity anywhere (as shown in the pictures I shared a few months ago).
Have fun, and sorry for the messy repo. I wish I had more time to write a proper guide and clean things up.
You can find the source code and full details here: https://github.com/R0rt1z2/fenrir. Currently, it only supports the Nothing Phone 2a but it should apply to more MediaTek devices from what I've seen on
expdb dumps.You can also test the patched LK image from the releases section. It should spoof the bootloader state as locked while it’s actually unlocked, allowing you to pass strong integrity anywhere (as shown in the pictures I shared a few months ago).
Have fun, and sorry for the messy repo. I wish I had more time to write a proper guide and clean things up.
🔥14😐1
R0rt1z2’s Dumpster
Since Nothing decided to ignore my report, after waiting for about a month I decided to release it publicly :) You can find the source code and full details here: https://github.com/R0rt1z2/fenrir. Currently, it only supports the Nothing Phone 2a but it should…
Obviously, it's an example of an exploit that could be further utilized for PIA proxying. Google knows they can't really keep up with banning and the vulnerable build will keep passing strong for a significant time, hence:
https://news.1rj.ru/str/TadiBlog/547
https://news.1rj.ru/str/TadiBlog/547
Telegram
Tadi Channel
So Google already acknowledges the feasibility of proxying PIA results to/from (a good linguistic question...) vulnerable devices
😐2
The future is proxying PIA from your own vulnerable ewaste device that won't ever be downgraded to no integrity because of coming from a major OEM (assuming it'll be secured enough to make secret extraction impossible but unpatched enough to be fine with proxying)
🤯9😐2❤1🥰1