Badcaps.net Forum
Go Back   Badcaps Forums > Troubleshooting Hardware & Devices and Electronics Theory > Troubleshooting Laptops, Tablets, and Mobile Devices > BIOS Requests ONLY!
Register FAQ Calendar Search Today's Posts Mark Forums Read

 
Thread Tools Display Modes
Old 03-14-2021, 06:33 PM   #1
Stephen
Meow Meow MEOW!
 
Stephen's Avatar
 
Join Date: Apr 2020
City & State: USA 🇺🇸
My Country: United States
Line Voltage: 120VAC 60hz
I'm a: Hardcore Geek
Posts: 491
Default T2 Chip Programmer Tool

I was curious if the T2 chip serial being changed would allow cracking the Firmware lock and icloud lock of a device? We came across the T2 Rom Tool and this allows the use of changing the serial which in our experience would allow removal of MDM on older models (2017-and older). Would that isolate the icloud bypass since it is married to the serial of the T2 chip? Curious since we are close to pulling the trigger on a wholesale lot and we anticipate iCloud devices in MacBooks etc. Piernov or anyone have thoughts on this?

Update: People are saying yes and no. If you change the serial you would have to change the UUID? Apple looks at the serial and the UUID in the rom. I know we could figure this out some how some way.
__________________

MEOWING IN THE IMPOSSIBLE UNIVERSE!

Last edited by Stephen; 03-14-2021 at 06:56 PM..
Stephen is offline  
Old 03-15-2021, 02:43 PM   #2
piernov
Super Moderator
 
Join Date: Jan 2016
City & State: Valbonne, 06
My Country: France
I'm a: Knowledge Seeker
Posts: 3,998
Default Re: T2 Chip Programmer Tool

The serial can be changed in the T2 ROM without too much trouble. It's a 25-series 1.8V SPI ROM so a decent programmer can deal with it (it's a 3x4mm package so smaller than usual though). Serial number should show up in the dump after "mNrS" string.
I don't know what are the repercussions. I'm probably at least 5 years away from seeing a T2 machine in front of me.
__________________
OpenBoardView — https://github.com/OpenBoardView/OpenBoardView
piernov is offline  
Old 04-08-2022, 04:11 PM   #3
TrumanHW
TrumanHW
 
Join Date: Jun 2021
City & State: Los Angeles
My Country: United States
Line Voltage: 120VAC 60Hz
I'm a: Knowledge Seeker
Posts: 52
Default Re: T2 Chip Programmer Tool

Quote:
Originally Posted by piernov View Post
Changing T2 SN


Fixing [ONLY] the MDM management issue can be done via T2's ROM (SN):

•*Desolder ROM
•*Dump ROM BIN
•*Find SN: after string mNrS

THE QUESTION:
Does ONLY eliminating MDM from T2 (Intel obviously) require steps beyond modifying the SN?
Exemplars of my preferred character-revision:
- C02 --> CO2 ...or... C02 --> C0Z ... 6 --> G ... G --> Q
- Retain the letter-qty
- Validate: Fsys @ 0x590000 ... via Medusa v2.7 (SO convenient!!!)

IS a valid SN FORMAT (naming convention) now required? If so, can we:
- Could we not change the WEEK of mfr to 53..?
- Reuse a SN that was made in one country-code (Czech?) for China?
- Reuse a SN from a unit which is no longer reparable?
- Is there something analogous to the 0x590000 ..?

Thanks!!!

[/SIZE][/B]IE, following Stephen's STICKIED: T2 Unlocking Method (Hardware)


(Obviously all other info posted stands + I already have the T203)
•*Pkg kind: 25-series SPI ROM
•*Pkg size: 3x4mm (smaller than ≤ 2017 ROM)
•*ROM volt: 1.8v (Requires a 'level shifter' to use a CH341a)
•*Simple: T203 = CH341a with integral 1.8v level shifter + 3x4mm fixture.
TrumanHW is offline  
Old 03-15-2021, 03:07 PM   #4
Stephen
Meow Meow MEOW!
 
Stephen's Avatar
 
Join Date: Apr 2020
City & State: USA 🇺🇸
My Country: United States
Line Voltage: 120VAC 60hz
I'm a: Hardcore Geek
Posts: 491
Default Re: T2 Chip Programmer Tool

Yeah I feel thats the difficult part...taking that risk on . T2. I mean worst case scenario we just have to RUN DFU lol
Stephen is offline  
Old 04-14-2021, 02:11 AM   #5
Nico Latour
Banned
 
Join Date: Sep 2019
City & State: nice
My Country: france
I'm a: Hobbyist Tech
Posts: 75
Default Re: T2 Chip Programmer Tool

change serial on a t2 machine only works for mdm, mdm is linked on serial and icloud is linked on serial, wifi adres,bleutooth adres, so change serial not solved the problem, even the serial is not stored in the t2 chip and cant change it with software, the serial is in a small chip (4mb) and need to solder before can read write
Nico Latour is offline  
Old 07-13-2021, 06:46 AM   #6
curiositymaster
Member
 
Join Date: Apr 2021
City & State: Lagos
My Country: Nigeria
I'm a: Knowledge Seeker
Posts: 68
Default Re: T2 Chip Programmer Tool

Quote:
Originally Posted by Nico Latour View Post
change serial on a t2 machine only works for mdm, mdm is linked on serial and icloud is linked on serial, wifi adres,bleutooth adres, so change serial not solved the problem, even the serial is not stored in the t2 chip and cant change it with software, the serial is in a small chip (4mb) and need to solder before can read write

Of course you need to remove the chip to reprogram it. I have used this to change the serial number on T2 twice. The programmer I used was purchased on aliexpress and it came with the bin file and bypass software.
curiositymaster is offline  
Old 07-13-2021, 07:41 AM   #7
sanmlis
New Member
 
Join Date: Jan 2020
City & State: Таганрог
My Country: Россия
I'm a: Knowledge Seeker
Posts: 2
Default Re: T2 Chip Programmer Tool

Please share bin files, it would be interesting to study them
Quote:
Originally Posted by curiositymaster View Post
Of course you need to remove the chip to reprogram it. I have used this to change the serial number on T2 twice. The programmer I used was purchased on aliexpress and it came with the bin file and bypass software.
sanmlis is offline  
Old 07-13-2021, 08:00 AM   #8
curiositymaster
Member
 
Join Date: Apr 2021
City & State: Lagos
My Country: Nigeria
I'm a: Knowledge Seeker
Posts: 68
Default Re: T2 Chip Programmer Tool

Quote:
Originally Posted by sanmlis View Post
Please share bin files, it would be interesting to study them
I hope it helps
Attached Files
File Type: zip A2179 BIN.zip (2.25 MB, 745 views)
curiositymaster is offline  
Old 01-24-2022, 10:01 AM   #9
M4n0l0307
Member
 
Join Date: Nov 2020
City & State: Manizales
My Country: Colombia
I'm a: Knowledge Seeker
Posts: 48
Default Re: T2 Chip Programmer Tool

Quote:
Originally Posted by curiositymaster View Post
I hope it helps
Thank You Friend !
M4n0l0307 is offline  
Old 07-14-2021, 06:22 AM   #10
RethoricalCheese
Badcaps Veteran
 
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,497
Default Re: T2 Chip Programmer Tool

Quote:
Originally Posted by curiositymaster View Post
Of course you need to remove the chip to reprogram it. I have used this to change the serial number on T2 twice. The programmer I used was purchased on aliexpress and it came with the bin file and bypass software.

Hey! Could you upload the whole USB stick content? Software and other files.
RethoricalCheese is offline  
Old 03-27-2022, 06:05 AM   #11
bluestar77
Member
 
Join Date: Apr 2015
City & State: khartoum
My Country: sudan
I'm a: Knowledge Seeker
Posts: 54
Default Re: T2 Chip Programmer Tool

Which programmer bro you have to change the serial that come with software
bluestar77 is offline  
Old 07-13-2021, 10:12 PM   #12
andriyd1
New Member
 
Join Date: Dec 2013
City & State: new york
My Country: USA
I'm a: Knowledge Seeker
Posts: 7
Default Re: T2 Chip Programmer Tool

Quote:
Originally Posted by Nico Latour View Post
change serial on a t2 machine only works for mdm, mdm is linked on serial and icloud is linked on serial, wifi adres,bleutooth adres, so change serial not solved the problem, even the serial is not stored in the t2 chip and cant change it with software, the serial is in a small chip (4mb) and need to solder before can read write
How do you identify WiFi address and Bluetooth address in the dump read from small bt and WiFi rom chips?
andriyd1 is offline  
Old 07-14-2021, 10:19 AM   #13
imranromi
Badcaps Veteran
 
Join Date: Jan 2015
City & State: Rawalpindi
My Country: Pakistan
Line Voltage: 240Hz
I'm a: Knowledge Seeker
Posts: 1,216
Default Re: T2 Chip Programmer Tool

Quote:
Originally Posted by andriyd1 View Post
How do you identify WiFi address and Bluetooth address in the dump read from small bt and WiFi rom chips?
For which purpose you want to find?
imranromi is offline  
Old 07-14-2021, 12:21 PM   #14
andriyd1
New Member
 
Join Date: Dec 2013
City & State: new york
My Country: USA
I'm a: Knowledge Seeker
Posts: 7
Default Re: T2 Chip Programmer Tool

Activation locks
andriyd1 is offline  
Old 07-30-2021, 09:40 AM   #15
curiositymaster
Member
 
Join Date: Apr 2021
City & State: Lagos
My Country: Nigeria
I'm a: Knowledge Seeker
Posts: 68
Default Re: T2 Chip Programmer Tool

Quote:
Originally Posted by andriyd1 View Post
Activation locks

You can't unlock simply by changing values on the dump file.
curiositymaster is offline  
Old 10-18-2021, 10:14 AM   #16
paulyboy
Member
 
Join Date: Mar 2020
City & State: auckland
My Country: New Zealand
I'm a: Knowledge Seeker
Posts: 78
Default Re: T2 Chip Programmer Tool

What programmer interface for reading the chip please? Is the a socket for tl866 thanks
paulyboy is offline  
Old 10-19-2021, 01:14 PM   #17
Bb68
New Member
 
Join Date: Jul 2017
City & State: Durban
My Country: South Africa
I'm a: Knowledge Seeker
Posts: 10
Default Re: T2 Chip Programmer Tool

Quote:
Originally Posted by paulyboy View Post
What programmer interface for reading the chip please? Is the a socket for tl866 thanks
Hi

Ch340 programmer , like by-t200
Bb68 is offline  
Old 12-12-2021, 07:56 PM   #18
Pedro147
Senior Member
 
Pedro147's Avatar
 
Join Date: Sep 2016
City & State: Canberra ACT
My Country: Australia
Line Voltage: PPBUS_G3H
I'm a: Knowledge Seeker
Posts: 104
Default Re: T2 Chip Programmer Tool

Quote:
Originally Posted by Bb68 View Post
Hi

Ch340 programmer , like by-t200
Yes I believe so but AFAIK, T2 ROM are only 1.8v so you need the right adapter that supplies that voltage to the chip

Quote:
Originally Posted by anhbanxoi View Post
I cannot open minaT2Activator on Macbook M1. Anybody tested that file?
As suggested by others, all of this software for reading flashing BIOS etc is all Windows based

Quote:
Originally Posted by curiositymaster View Post
I'm very sure you've got a lot of free help on this forum, I mean from people who didn't get the knowledge/tools free of charge.
Yes correct. Some people just want to take, take take and never give diddly squat. Luckily there are many people here not like that.

Last edited by Pedro147; 12-12-2021 at 08:01 PM..
Pedro147 is offline  
Old 04-07-2022, 03:14 AM   #19
TrumanHW
TrumanHW
 
Join Date: Jun 2021
City & State: Los Angeles
My Country: United States
Line Voltage: 120VAC 60Hz
I'm a: Knowledge Seeker
Posts: 52
Default Re: T2 Chip Programmer Tool

Quote:
Originally Posted by Bb68 View Post
Hi
Ch340 programmer , like by-t200
You a MacOS user ... ? Able to read CH341x (ROMs) via MacOS ..?
If not, I finally figured out how (after 7 years) and can help (free obviously)


As far as dealing with T2 (Intel + M1) ... I have:
•*T203
•*Medusa 2.6 / 2.7 / 3.1
•*DS809
•*RT809F + Level Shifter

I'm determined to figure iC locked + MDM issue (intel + M1) asap.

Back to reading the remainder of this thread)
TrumanHW is offline  
Old 04-08-2022, 10:07 PM   #20
TrumanHW
TrumanHW
 
Join Date: Jun 2021
City & State: Los Angeles
My Country: United States
Line Voltage: 120VAC 60Hz
I'm a: Knowledge Seeker
Posts: 52
Default Re: T2 Chip Programmer Tool

Quote:
Originally Posted by Bb68 View Post
Hi

CH340 programmer , like by-t200

Cool, would you be willing to provide a copy of the SW which came with the T200 ..? I'm thinking the only difference between the T200 and T203 is the software, no ...?

PS, You can read a CH341x on MacOS (as can the T203, - also a CH341a)
TrumanHW is offline  
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump



Badcaps.net Technical Forums © 2003 - 2023
Powered by vBulletin ®
Copyright ©2000 - 2023, Jelsoft Enterprises Ltd.
All times are GMT -6. The time now is 02:06 PM.
Did you find this forum helpful?