![]() |
|
|
Thread Tools | Display Modes |
|
![]() |
#1 |
Meow Meow MEOW!
Join Date: Apr 2020
City & State: USA 🇺🇸
My Country: United States
Line Voltage: 120VAC 60hz
I'm a: Hardcore Geek
Posts: 491
|
![]() I was curious if the T2 chip serial being changed would allow cracking the Firmware lock and icloud lock of a device? We came across the T2 Rom Tool and this allows the use of changing the serial which in our experience would allow removal of MDM on older models (2017-and older). Would that isolate the icloud bypass since it is married to the serial of the T2 chip? Curious since we are close to pulling the trigger on a wholesale lot and we anticipate iCloud devices in MacBooks etc. Piernov or anyone have thoughts on this?
Update: People are saying yes and no. If you change the serial you would have to change the UUID? Apple looks at the serial and the UUID in the rom. I know we could figure this out some how some way.
__________________
MEOWING IN THE IMPOSSIBLE UNIVERSE! Last edited by Stephen; 03-14-2021 at 06:56 PM.. |
![]() |
![]() |
#2 |
Super Moderator
Join Date: Jan 2016
City & State: Valbonne, 06
My Country: France
I'm a: Knowledge Seeker
Posts: 3,998
|
![]() The serial can be changed in the T2 ROM without too much trouble. It's a 25-series 1.8V SPI ROM so a decent programmer can deal with it (it's a 3x4mm package so smaller than usual though). Serial number should show up in the dump after "mNrS" string.
I don't know what are the repercussions. I'm probably at least 5 years away from seeing a T2 machine in front of me.
__________________
OpenBoardView — https://github.com/OpenBoardView/OpenBoardView |
![]() |
![]() |
#3 |
TrumanHW
Join Date: Jun 2021
City & State: Los Angeles
My Country: United States
Line Voltage: 120VAC 60Hz
I'm a: Knowledge Seeker
Posts: 52
|
![]() Fixing [ONLY] the MDM management issue can be done via T2's ROM (SN): •*Desolder ROM •*Dump ROM BIN •*Find SN: after string mNrS THE QUESTION: Does ONLY eliminating MDM from T2 (Intel obviously) require steps beyond modifying the SN? Exemplars of my preferred character-revision: - C02 --> CO2 ...or... C02 --> C0Z ... 6 --> G ... G --> Q - Retain the letter-qty - Validate: Fsys @ 0x590000 ... via Medusa v2.7 (SO convenient!!!) IS a valid SN FORMAT (naming convention) now required? If so, can we: - Could we not change the WEEK of mfr to 53..? - Reuse a SN that was made in one country-code (Czech?) for China? - Reuse a SN from a unit which is no longer reparable? - Is there something analogous to the 0x590000 ..? Thanks!!! [/SIZE][/B]IE, following Stephen's STICKIED: T2 Unlocking Method (Hardware) (Obviously all other info posted stands + I already have the T203) •*Pkg kind: 25-series SPI ROM •*Pkg size: 3x4mm (smaller than ≤ 2017 ROM) •*ROM volt: 1.8v (Requires a 'level shifter' to use a CH341a) •*Simple: T203 = CH341a with integral 1.8v level shifter + 3x4mm fixture. |
![]() |
![]() |
#4 |
Meow Meow MEOW!
Join Date: Apr 2020
City & State: USA 🇺🇸
My Country: United States
Line Voltage: 120VAC 60hz
I'm a: Hardcore Geek
Posts: 491
|
![]() Yeah I feel thats the difficult part...taking that risk on . T2. I mean worst case scenario we just have to RUN DFU lol
|
![]() |
![]() |
#5 |
Banned
Join Date: Sep 2019
City & State: nice
My Country: france
I'm a: Hobbyist Tech
Posts: 75
|
![]() change serial on a t2 machine only works for mdm, mdm is linked on serial and icloud is linked on serial, wifi adres,bleutooth adres, so change serial not solved the problem, even the serial is not stored in the t2 chip and cant change it with software, the serial is in a small chip (4mb) and need to solder before can read write
|
![]() |
![]() |
#6 | |
Member
Join Date: Apr 2021
City & State: Lagos
My Country: Nigeria
I'm a: Knowledge Seeker
Posts: 68
|
![]() Quote:
Of course you need to remove the chip to reprogram it. I have used this to change the serial number on T2 twice. The programmer I used was purchased on aliexpress and it came with the bin file and bypass software. |
|
![]() |
![]() |
#7 |
New Member
Join Date: Jan 2020
City & State: Таганрог
My Country: Россия
I'm a: Knowledge Seeker
Posts: 2
|
![]() Please share bin files, it would be interesting to study them
|
![]() |
![]() |
#8 |
Member
Join Date: Apr 2021
City & State: Lagos
My Country: Nigeria
I'm a: Knowledge Seeker
Posts: 68
|
![]() I hope it helps
|
![]() |
![]() |
#9 |
Member
Join Date: Nov 2020
City & State: Manizales
My Country: Colombia
I'm a: Knowledge Seeker
Posts: 48
|
![]() |
![]() |
![]() |
#10 | |
Badcaps Veteran
Join Date: Mar 2013
City & State: Tartu
My Country: Estonia
I'm a: Knowledge Seeker
Posts: 1,497
|
![]() Quote:
Hey! Could you upload the whole USB stick content? Software and other files. |
|
![]() |
![]() |
#11 |
Member
Join Date: Apr 2015
City & State: khartoum
My Country: sudan
I'm a: Knowledge Seeker
Posts: 54
|
![]() Which programmer bro you have to change the serial that come with software
|
![]() |
![]() |
#12 | |
New Member
Join Date: Dec 2013
City & State: new york
My Country: USA
I'm a: Knowledge Seeker
Posts: 7
|
![]() Quote:
|
|
![]() |
![]() |
#13 |
Badcaps Veteran
Join Date: Jan 2015
City & State: Rawalpindi
My Country: Pakistan
Line Voltage: 240Hz
I'm a: Knowledge Seeker
Posts: 1,216
|
![]() |
![]() |
![]() |
#14 |
New Member
Join Date: Dec 2013
City & State: new york
My Country: USA
I'm a: Knowledge Seeker
Posts: 7
|
![]() Activation locks
|
![]() |
![]() |
#15 |
Member
Join Date: Apr 2021
City & State: Lagos
My Country: Nigeria
I'm a: Knowledge Seeker
Posts: 68
|
![]() |
![]() |
![]() |
#16 |
Member
Join Date: Mar 2020
City & State: auckland
My Country: New Zealand
I'm a: Knowledge Seeker
Posts: 78
|
![]() What programmer interface for reading the chip please? Is the a socket for tl866 thanks
|
![]() |
![]() |
#17 |
New Member
Join Date: Jul 2017
City & State: Durban
My Country: South Africa
I'm a: Knowledge Seeker
Posts: 10
|
![]() |
![]() |
![]() |
#18 | |
Senior Member
Join Date: Sep 2016
City & State: Canberra ACT
My Country: Australia
Line Voltage: PPBUS_G3H
I'm a: Knowledge Seeker
Posts: 104
|
![]() Yes I believe so but AFAIK, T2 ROM are only 1.8v so you need the right adapter that supplies that voltage to the chip
Quote:
Yes correct. Some people just want to take, take take and never give diddly squat. Luckily there are many people here not like that. Last edited by Pedro147; 12-12-2021 at 08:01 PM.. |
|
![]() |
![]() |
#19 |
TrumanHW
Join Date: Jun 2021
City & State: Los Angeles
My Country: United States
Line Voltage: 120VAC 60Hz
I'm a: Knowledge Seeker
Posts: 52
|
![]() You a MacOS user ... ? Able to read CH341x (ROMs) via MacOS ..?
If not, I finally figured out how (after 7 years) and can help (free obviously) As far as dealing with T2 (Intel + M1) ... I have: •*T203 •*Medusa 2.6 / 2.7 / 3.1 •*DS809 •*RT809F + Level Shifter I'm determined to figure iC locked + MDM issue (intel + M1) asap. Back to reading the remainder of this thread) |
![]() |
![]() |
#20 |
TrumanHW
Join Date: Jun 2021
City & State: Los Angeles
My Country: United States
Line Voltage: 120VAC 60Hz
I'm a: Knowledge Seeker
Posts: 52
|
![]() Cool, would you be willing to provide a copy of the SW which came with the T200 ..? I'm thinking the only difference between the T200 and T203 is the software, no ...? PS, You can read a CH341x on MacOS (as can the T203, - also a CH341a) |
![]() |
![]() |
Thread Tools | |
Display Modes | |
|
|