![]() |
|
|
Thread Tools | Display Modes |
|
![]() |
#1 |
Member
Join Date: Nov 2015
City & State: bucharest
My Country: romania
Line Voltage: 380V 50Hz
I'm a: Knowledge Seeker
Posts: 31
|
![]() Here we try to figure out a way to bypass activation lock (FMM) and password lock. Until now there is no method available, but we're working to figure it out.
What we know so far: 1. There is a W25Q64 8Mb 3x4mm wson8 chip on the back of the board with part of NVRAM ( some strings can be seen in its dump, eg: iBoot-6723.50.2, boot-args=.nonce-seeds=, luetoothInternalControllerInfo= bt mac, InstallPhase -> Boot 1 ) but no serial number in clear. Other strings: Apple Secure Boot Root CA - G21.0, AppleStorageProcessorANS2-1161.40.21~221 2. Some suggest SN might be stored in ssd first nand, on hidden partition, some say it is tied to M1 processor itself ( which I doubt ). 3. Checkra1n / MinaTool / CheckM8 solution does not work on these devices, as there is newer iBoot version (T2 bios chip is just 4Mb vs M1 8Mb). An idea would be to downgrade iBoot so can be accessed on ssh. Good dump would be required here, maybe there are older versions we can use. 4. I have discovered a way to browse with safari if you boot into diagnostics mode ( hold on power until startup option is shown then press and hold Command-D, let it finish checking then click on find out more ), but from here you can't run any app, even if you can see it on usb mass storage attached. You can also download app but couldn't find a way to run it. 5. Now I have W25Q64 outside of locked macbook, wired to the board with long cable, so tests can be performed easier. If you have dumps for 13"/14"/15" ( locked /unlocked ) please share them here for testing and comparation. Dump with secureboot disabled might help. 6. Other way around can be writing SN from locked M1 into unlocked T2 mac, register it to mdm/icloud then get code. Looking for volunteers. Once we find out more interesting things will edit this first post to keep it simple. There is no doubt we'll find solution soon. ![]() Last edited by betonel; 01-31-2022 at 09:57 AM.. |
![]() |
![]() |
![]() |
#2 |
Member
Join Date: Apr 2021
City & State: Lagos
My Country: Nigeria
I'm a: Knowledge Seeker
Posts: 49
|
![]() Do you have boardview file/schematics for any 13" M1? I need to know where the w25q64 is located and how did you manage to read it?
Last edited by SMDFlea; 01-31-2022 at 01:30 PM.. |
![]() |
![]() |
![]() |
#3 | |
Super Moderator
Join Date: Jan 2018
City & State: York
My Country: UK
I'm a: Knowledge Seeker
Posts: 10,744
|
![]() Quote:
|
|
![]() |
![]() |
![]() |
#4 | |
Member
Join Date: Nov 2015
City & State: bucharest
My Country: romania
Line Voltage: 380V 50Hz
I'm a: Knowledge Seeker
Posts: 31
|
![]() Quote:
If you wonder what kind of wires I've used.. it's old pc IDE cable ![]() Instead of wasting money on T203 (~$200) and get stuck with uson4*3 or DS809SE (~$200) which is exactly an R809F i use this: 64$ RT809F + 15 adapters ( 1.8V adapter required!) https://s.click.aliexpress.com/e/_A6uAnD Programmer ( same as DS809SE ) 25$ MacBook Apple Notebook Maintenance Serial Number Modification Tool T2 Chip Unlock BIOS Read Adapter Board https://s.click.aliexpress.com/e/_ApVJfz Let us program USON2*3 U3750+U3710 Wifi+BT ROM, XSON4*4, Apple T2 ROM USON 4*3 and Macbook M1 SOC, WSON6*5, WSON**6 and WLCSP 16 ball used on A1534 bios or SSD rom. $52 Sam Connector with Seat Socket Serial Line for DS809SE https://s.click.aliexpress.com/e/_A0aPKx Small mod is required to work with RT809F: undo all pins from connector and put it reverse way -> red will be on opposite side , and run a wire from PIN 8 (+) to pin 8 on the board , which you can hold it by hand, without needing to power on MB machine. Last edited by betonel; 02-01-2022 at 03:10 AM.. |
|
![]() |
![]() |
![]() |
#5 | |
Member
Join Date: Apr 2021
City & State: Lagos
My Country: Nigeria
I'm a: Knowledge Seeker
Posts: 49
|
![]() Quote:
|
|
![]() |
![]() |
![]() |
#6 | |
TrumanHW
Join Date: Jun 2021
City & State: Los Angeles
My Country: United States
Line Voltage: 120VAC 60Hz
I'm a: Knowledge Seeker
Posts: 42
|
![]() Quote:
Very good advice: If the M2012 - 2013 Retina 13"+15" isn't needed, would this be a good deal? $38 www.aliexpress.com/item/201005003289066054.html - Includes the CH314a - The PCB to solder the T2 ROM (4x3mm) - Includes J6100 connectors for Late-2013 - 2017 (excludes M12-E13 retina) - Negates any need for getting the VCC, CLK, wiring (already done). Already Includes the: $20 - T2 board $45 - "SAM connectors" (just not the M12 - E13, looks but ≠ L13-M14) $ 5 - Includes CH314a plus the 'DIL' adapter interface to the cables... (not as good a programmer but can be okay) The attached annotated image shows Betonel's suggested means of reading the T2 with the Level Shifter and, by soldering it on a 4x3 reader. (which he suggests bc 'clamshell' adapters are all a FORTUNE for 4x3mm). Betonel: I found a "3mm x 3mm" that's 1/3rd the price ... think it'd fit..? https://www.aliexpress.com/item/1005001510434419.html (I ask bc it looks like the width of the chip is 'unconstrained' in the holder..?) Last: You wired the board analyzer (Zaleae) where the T2's ROM mounts... Are you really decoding the SINGALS that way ..? (reverse engineering it?!) The M1 looks RIDICULOUSLY difficult :'( (see animated GIF) |
|
![]() |
![]() |
![]() |
#7 | |
New Member
Join Date: Feb 2022
City & State: Hanoi
My Country: Vietnam
I'm a: Knowledge Seeker
Posts: 10
|
![]() Quote:
sorry for dumb question because im a newbie and I'm a knowledge seeker ![]() Sr english not my main language, Hope you reply me soon |
|
![]() |
![]() |
![]() |
#8 |
Member
Join Date: Jun 2013
City & State: Lancs
My Country: England
I'm a: Hobbyist Tech
Posts: 38
|
![]() A DIP8 to SOP8 won't work.
You need a board from AliExpress called "serial number modification tool T2 chip unlocking BIOS reading adapter board" as posted by betonel. This has USON8 and other types of useful pinouts. |
![]() |
![]() |
![]() |
#9 |
New Member
Join Date: Feb 2022
City & State: Hanoi
My Country: Vietnam
I'm a: Knowledge Seeker
Posts: 10
|
![]() thanks for answer, but my Macbook in new version bridgeOS, hope checkra1n team do something
![]() |
![]() |
![]() |
![]() |
#10 |
New Member
Join Date: Feb 2022
City & State: Hanoi
My Country: Vietnam
I'm a: Knowledge Seeker
Posts: 10
|
![]() over 20$ in my country very expensive, what do you think when I use copper jump wire to connect T2 Rom chip in Adapter "DIP8 to SOP8"
|
![]() |
![]() |
![]() |
#11 | |
Meow Meow MEOW!
Join Date: Apr 2020
City & State: USA 🇺🇸
My Country: United States
Line Voltage: 120VAC 60hz
I'm a: Hardcore Geek
Posts: 412
|
![]() Quote:
![]()
__________________
MEOWING IN THE IMPOSSIBLE UNIVERSE! |
|
![]() |
![]() |
![]() |
#12 | |
Banned
Join Date: Sep 2019
City & State: nice
My Country: france
I'm a: Hobbyist Tech
Posts: 75
|
![]() Quote:
|
|
![]() |
![]() |
![]() |
#13 |
Master of thoug
Join Date: Jan 2019
City & State: Chisinau
My Country: Moldova
Line Voltage: 220VAC 60hz
I'm a: Knowledge Seeker
Posts: 21
|
![]() |
![]() |
![]() |
![]() |
#14 |
Badcaps Veteran
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,279
|
![]() Why would it be in the nand? Have you seen iPhones and iPads?
![]() |
![]() |
![]() |
![]() |
#15 |
Meow Meow MEOW!
Join Date: Apr 2020
City & State: USA 🇺🇸
My Country: United States
Line Voltage: 120VAC 60hz
I'm a: Hardcore Geek
Posts: 412
|
![]() |
![]() |
![]() |
![]() |
#16 |
New Member
Join Date: Apr 2020
City & State: CA
My Country: USA
I'm a: Knowledge Seeker
Posts: 10
|
![]() To add on this would be MDM locks with fmm off. Is there a bypass or full removal option. I wrote a script back for 2015-2017 models before the usb thing to bypass the mdm prompts upon boot. Will be looking into getting a M1 and tweaking to see if i can get it to work on a M1.
|
![]() |
![]() |
![]() |
#17 |
New Member
Join Date: Dec 2019
City & State: chiapas
My Country: tuxtla gtz
I'm a: Knowledge Seeker
Posts: 1
|
![]() It's the Nand. The info is in the nand. We have lowered the nand and tried to read with irrepair 12 but it does not let me read, it is hidden in some way. If you could access that hidden info, it would be there like the iPad info.
|
![]() |
![]() |
![]() |
#18 |
Member
Join Date: Nov 2015
City & State: bucharest
My Country: romania
Line Voltage: 380V 50Hz
I'm a: Knowledge Seeker
Posts: 31
|
![]() What if you remove nand and run diagnostic mode, I guess you will be able to see SN there. Funny will be that SN is generated from bt mac + wifi mac, and we're looking for something that doesn't exist.
Need to compare dumps from SOC rom of M1, @Stephen, can you share some? Will upload mine tomorrow. |
![]() |
![]() |
![]() |
#19 | |
Meow Meow MEOW!
Join Date: Apr 2020
City & State: USA 🇺🇸
My Country: United States
Line Voltage: 120VAC 60hz
I'm a: Hardcore Geek
Posts: 412
|
![]() Quote:
|
|
![]() |
![]() |
![]() |
#20 |
Member
Join Date: Nov 2015
City & State: bucharest
My Country: romania
Line Voltage: 380V 50Hz
I'm a: Knowledge Seeker
Posts: 31
|
![]() Attached is my SOC chip dump and multiple tests.
SN from this dump is FVFDV113Q05P. Please upload yours.. ![]() Unlocked with Secure boot disabled is wanted. ![]() btw: if you re not a bot, to get correct SN, xor all 1 with 1 Last edited by betonel; 02-01-2022 at 02:22 AM.. |
![]() |
![]() |
![]() |
Thread Tools | |
Display Modes | |
|
|