#futurerestore-help
1 messages Ā· Page 177 of 1
can test if you want
boardconfig?
oh true
D22AP
what device
@fluid otter you can't even do that even if you wanted to I think unless you mean 14.5.1 to 14.2 in which case what device
My iphone is a 6s+
Phone ran out of battery in the middle of a restore rootfs
updating to 14.6 rn
even with blobs, u cannot
verifying success
they haven't puled it
ota?
yes
if betas do, as does RC
ty
mean they've broken shit mid betas and I think in RC's too before
highly doubt that's the case this time
imagine 14.7b1 after 14.6 launch
but A10 14.3 checkra1n if you remember was initially broken
sounds partially likely
I wonder who got fired? Apple never pumped this many updates out before...
could be they just changed the structure of how they number each update
Because lately it's seemed like every 14.x version included one minor feature at a minimum, but with like 11 for example I believe they only incremented the counter over more major features
is that rc?
hm
so 14.6 final will be 18F72
nice
finally
took them 199 years
Slim is gonna do pings because my discord doesnt let me @ roles
slim to the pings
oof
time to test sep bb and checkra1n
checkra1n confirmed working
ipsw.dev is fast
why are upvotes being removed 
bro who's fucking with the reactions
i blame the blues not knowing how to be owner
or ppl trolling
should I tag rick or slim or no
yeah can y'all also announce checkra1n confirmed (no need to ping a role for that, Aaron usually doesn't)
oh
just "checkra1n is confirmed to work on iOS 14.6 RC"
@full osprey upvoting in #announcements going bruhhhh
Idc people have no life let them waste their time
@full osprey no there's just fucking with the reactions for the iOS one either that or discord moment

im fine
tanbeer is restoring right?
Either they do it or we remove reactions all together
yes
yeah lol someone's clearing reactions or something
yeah lol
check audit log
I mean Aaron allowed the same thing with dev beta 3
I don't see the issue
Im confused
there could be a discord hacker amongOS
what are you talking about
@full osprey they're removing reacts for the RC1 announcement
Someone kept removing all reactions
Or discord is bruh
afaik only admins can do that lol
ill check
discord is definitely bruh mine says 36
it stopped
Audit log doesnt show reactions
discord
oh you're right it doesn't
let's see if the iPSW downloads first or the phone OTAs first
how do you guys test SEP and BB, go to 14.3 with the custom .bbfw and stuff?
or any version
oh yeah
well not itself
obviously it's compatible with itself
you should try 14.3 though because that's the lowest
yeah ig even if it works with 14.6 beta 2 then it's compatible for everything
because we already confirmed that beta 2 works everything until 14.0
pretty much
is today the 16th or 17th
17
lol
@gentle grail >.>
let me respring at least
ok that fixed it
maybe I just do a daily respring
14.6rc lol
could be the same reason why apple labels the 14.6 files 2021WinterSeed when Spring is here
yes
there's is stuck in january
why does reprovision keep giving me a "more than 3 apps installed" error
bc more than 3 apps are installed?
^
doesnt work on 14.6
lol nice
checking rn
Ok
pog
might be less steps in a shortcut/script if nvram was implemented
what about using it on non checkra1nāit needs root
yo this is clean
fr
like really clean
get it into an ipa
and convert it into a deb
and then release it as a deb
oof
@zinc moon why not just make the tweak call nvram?
@zinc moon just get dimentio as a dep but dont put it on ur repo
also
dimentio is on pro already
its just for elu ppl
if non-checkra1n, include an if
also put 1conan's repo in ur reddit post too
for elu
also
@zinc moon u need a place for apnonce A12+
ah
nah
thats fine
@zealous bridge is this true?
yeah that would be me lmao
yes
i cringe everytime you guys say nonce
LOL
no
nonce is the ApNonce
the generator generates the apnonce
14.6RC sep/baseband compatible
yes
tsschecker
if shsh host doesnt have it
it won't be updated automatically until the actual stable release comes out next week
because I don't think the beta IPSW feed is publicly available
you can only get OTA even via public beta, need to have a developer account for IPSWs
and I'm guessing handling authentication would be a pain and could be blocked
is 14.6b3 rc?
system info is slow then
it should be there soon no?
is this normal for A12+?
yes
ok ty
<key>Variant</key>
<string>Customer Software Update</string>
= OTA?
because it seems like iPSW are
<string>Research Customer Upgrade Install (IPSW)</string>
or erase install Customer Erase Install (IPSW)
oh there's also Research Customer Erase Install (IPSW)
wtf is this
I think it just means beta iPSW erase
what does ipwndfu do again?
specifically for blobs and FR
like why can't we use OTA blobs, why does this let us use OTA
patch signature checks
oh so it lets the restore start, but after that the signature is just valid
because OTA blobs don't have some crucial signatures for some firmware components
pwndfu patches those checks
so OTA blobs can be used
pwndfu skips the signature checks on the RestoreRamDisk for example
oh
the actual system image will have the same signature
and RestoreTrustCache
so it can boot untethered after a successful restore
it's signed
they are also signed
remember they are situation specific, remember why we have blobs
also the whole point is they don't have the signatures in the first place
ah so we can't use OTA because the phone realizes we're not OTA updating? or OTA blobs don't have signatures for what the phone needs for an iPSW update? And if pwndfu skips those checks? how can the phone boot
ota blobs dont have the crucial signatures needed for an iPSW restore
pwndfu can just tell the device to carry on the restore, even if those signatures don't exist
the phone boots because as nyu said the components still have the same signatures
so it's valid in the eyes of the trust chain
if you don't include UniqueBuildID in a tss request what version does it save for
none?
oh it just gives 200
yeah but no response
LOL
We should have a āspoonfeedingā tag or something so we donāt have to manually tell people to quit asking to be spoonfed
Lol
shucks
i saw that
lol
wha-
why am I getting what=assure failed in img4tool
can someone try this blob
wait is there even a blob in that
@APTicket: Optional boolean value. If true, the server adds an APTicket to the request.
oh it's true
thereās no BNCH either
did you get it to output anything though
i just get
MANB: MANB: ------------------------------
MANP: MANP: ------------------------------
BNCH: BNCHimg4tool: failed with exception:
like nothing useful
yeah nononce prolly invalid lol
can you not just go from plain text to DER
echo APNONCE | xxd -r -p | base64
ty
xd
let's rename it to "namtaywslayhakg"
numberuse as many times as you want so long as you have a known generator
chill out m8 havā a cuppa āļø
I think Im a genius
same
1=2 q.e.d
you have no idea what I just did lol
If it ends up working I will
my imaginary fingers are crossed


wtf
?
no that's what im hoping this is

dumb fucking question: what does that even mean
its not hard to learn the iOS bootchain
just requires research and studying
most of the people here understand after being here for a little while
I was more so confused on how that even matters but ok
pwned restores can allow the use of ota/onboard blobs
CI build fail
So basically were 14.5+ ota onboards broke until you apparently fixed it?
@green onyx idgaf thats tihmstar ci not mine
ah i see, lol
his shit is now broken
dead chat
well futurerestore kinda just dipped in usability (number of people actually using it wise) after delay OTA 
you could never be more wrong tho
we had a lot of people using fr prior to ota
but people using fr is low now because everyone used it to get on 14.3 lol
this
there were like 30 ppl per day
291 restores were attempted so far today @stiff hazel
thatās just the number of messages relating to it I think
the GUI is opt out logging
not necessarily how many were done
with the gui not as many people need help anymore
Basically multiple factors contributed to the lessening actual activity of this channel?
Is it that a discord server where the logs get sent to?
And every attempt/message = one log?
cause if itās just youāre using a generic search term for this entire server then tell me what that search term is
Probably will end up being lower in the long term Iām thinking unless Apple pulls an Apple and actually does something about the delayed OTA stuff
ask @lilac wren its his gui and bot
because in some ways some people may (somehow) think āoh my god fr seems so hard. oh, delay OTA? this looks easy so Iāll do thatā
delayed ota is simpler tbh
29k msgs in frgui log server
who needs that when u have blobs
delayed OTA has its benefits and disadvantages to FR
but regardless because of how much easier it is on paper many people will do delayed OTA over FR if they can do both
Total
total for the entirety of the channels existence?
how many of those logs were before April 7th, how many were they from April 7th to April 26th, and how many have there been since April 26th?
March 15th I was off by 1 day
Let me see
Kinda want to gauge the usage between before delay OTA, during the window to 14.3, and after the window to 14.3
Successes or just logs in general
why not both
If you canāt or donāt want to do both then just do total logs Iām thinking
hmmmmm interesting logs to me
The usage marginally went down then it spiked after the window closed
fr usage plummeted when delayed ota came out
8424 results vs 8298 results
Wouldnāt call that plummeted
plummeted as in #futurerestore-help
make what
make a graph yourself
no

oh yeah true the channels main purpose heavily died after delayed OTA
Lol for 60 days? nah
the channel literally switched gears and the topic changed drastically
but itd work
@lilac wren is the log server public by chance or no?
If it is Iād be willing to join it and do some graphing myself of everything
no because ECIDs, serials, usernames
wasnāt the topic mainly for like 2 weeks just seeing if/how we could allow downgrades through delayed OTA?
true
@green onyx would I be wrong in saying that 0-days are technically less valuable for a lot of users thanks to delay OTA?
Why would 1-days be more valuable though? Sure 0-days are definitely less valuable but that doesnāt mean theyāre less valuable than say 1-days
1 day means patched
if its patched, we can delay restore to the os below the patch update
it rare that people will publicly burn 0 days
Why do we have to literally exploit the os just to... Theme the phone and run custom software
I'm having a jailbreak existential crisis
Why can't apple just allow us to use the OS freely
because white people
White people run apple
Apple makes bad decisions
I can only assume that thatās because of white people
Iām racist towards my own race
because Im on PST
its between 4 and 6am when all of u are online
meaning I stayed up all night
@valid adder rip it wasnāt even secure boot
bool AppleSEPManager::_getTzInfo(unsigned int, bool *, uint32_t *): Can't find property tz1-size-set```
panics right after this
we are aware
is it related to the mounting /var panic or nah?
yeah whatever taurine uses is a daemon thatās linked to ApNonceUserClient
Which is what OTA uses
or even just requested an ota
taurine could force that you know
yeah I was wondering that bc "Checking for uncollected logs" in FR logs and mounting /var in serial logs is at the same time... but it shouldn't be an issue if passcode is turned off
Should be able to with root + gestalt
I checked and checkra1n with passcode panic is "skg/skgs" too but there is no "sks timeout strike 0"
so yeah itās probably not that, the error complains about a property not being in TzInfo? how tf does that happen
not sure but I think when it first panicked I didn't get that
I did last time though
Yeah this one gave me this too
basically yeah
@zealous bridge fyi
thats not even the problem
look
sks timeout
sep panic skgs
I assume skgs relates to sks
(sks is a sepos application)
(Sks)
(kpp)
the generator?
just searches for <key>generator</key> and reads out the string
might add a custom build manifest option to blob saver
good idea
generator is hex
why are you using UTF
I don't remember btw, are you using some fancy regex or dictionary
bc shortcuts can read plists as dictionary afaik
so no need for regex
Oh itās not fancy, just split text and read the second line, take out the string bits and thats it
i could probably do it as a dictionary tho
yep
Oh wow thats pretty easy
guess what Iām gonna do
Custom build manifest is working now yay
you can probably use libplist
idk if there's a native plist parser for macOS
oh
still
you can probably use libplist or some native thing on iOS too
It reduces like 3 actions ig
?
- the OTA wasnāt ever borked, just IPSW
- It only got borked after it got unsigned
Itās still unsigned, itās just that the BuildManifest causes IPSW.me to think itās signed
lol what the chinese xs max isn't even in supporteddevices
We should @void rapids and tell them to fix it
?
I can't check, because the Chinese XS Max isn't even in supporteddevices for that ipsw
gm
Futurerestore uses
apple api

https://api.ipsw.me/ they donāt have an api
Download current and previous versions of Apple's iOS Firmware and receive push notifications when new firmwares are released
Can you call people on an iPhone?
no
then you better go catch it
how has stock been for u
dabezt did you ever get dimentio working on non checkra1n
america has 4 times zones
well actually 6
The National Institute of Standards and Technology - Time and Frequency Division maintains the standard for frequency and time interval for the United States, provides official time to the United States, and carries out a broad program of research and service activities in time and frequency metrology.
if i recall no else in this chat is in another us time zone other than eastern
nvm
Lol
consistence
no wonder dabezt is 61 lol he ask so many questions
UID device specific aes key embedded into the silicon used for sep related things and nonce entanglement
GID model specific aes key embeddedn into the silicon used for firmare encryption
@zinc moon
meaning you need a hacked bootchain to dump them
but theres no a12 checkm8

they should already be public
not 14.1
hacked bootchain as in bootrom exploit?
or iboot
or dev fused device
wink
exploit3dguy got the keys up for some A12 devices
on the wiki
he has a dev fused device
just enter ipwndfuA12 
open phone lol i wished u could find exploit like that


shitpost
moment
Recovery mode is signed iirc
modify the partition to get android
not to mention the fact sandcastle doesnāt have full driver support
ip7 is ass lol
true
get the plus bro
arent u getting the 11?
11 much better
but no checkra1n
wym
yeh its dev fused but I don't have the device locally
@dull swallow want me to dump sep keys
yeah but other devices dont have support for the cpu
sure why not bro

if you haven't caught on normal dev fused cant dump sep keys @dull swallow
ĀÆ_(ć)_/ĀÆ
i will bully her from canada

literally anything > mha
i cant believe i watched almost 4 seasons of that shit
also @zinc moon i fused some personas last night while playing p3p
and thatsbbasically it

uhh
ara mitama
the other one
uhh in school

and then i also fused another jack frost
this time with hama and ice boost
gm
can u get apnounce of iphone 11 without jail breaking?
yes use irecovery
!t blobs
Saving blobs on jailbroken devices
Prerequisites:
- For unc0ver on iOS 14, update to 6.1.0 or newer and install libkrw from the Bingner repo.
- For Taurine, install libKernRW from the Odyssey repo.
Then install TSS Saver from https://repo.1conan.com/, open it and press Save Blobs.
This will always save blobs for whatever versions are currently signed. If you want to save blobs for an unsigned version you're currently on, see !t onboardblobs.
Saving blobs on unjailbroken devices
For A11 and lower, you can save blobs without a jailbreak on https://tsssaver.1conan.com/v2/ by entering your ECID which you can get from iTunes by clicking the serial number twice.
To save blobs on an unjailbroken A12+ device, follow this guide.
or getnonce if you want an apnonce and generator
use the link at the end
not yet
gg i keep thinking everyones in college
lol
I am
i graduated lol
me too
which programs @celest basalt
c++
computer science
mfs here make me feel young asf
if you care about the languages too we've learned some C, C++, Java, Python, HTML/CSS/JS/PHP, x86/ARM 32-bit ASM, PL/SQL
oh ur cs major lol
damn
ye i dont see myself getting into CS soon
might go into engineering
or smthn
if ur a jb dev tho cs is prob the way
probably
isnt froggy gonna do cs?
idk probably
@lilac wren
i could do cs, but i could also do creative writing, i could also do linguistics
etc
i did accounting lol

so
true
but i still have to pass my cpa
ngl even with blobs we are still so limited in what we could do
- fuck is mobilerepaird
- how is that why the 14.0-14.2 range is fucked
also good morning on today's episode of "attempting to fix your sleep and failing miserably"
ok... are you saying that's the reason 14.0-14.2 A11+ nonce setting doesn't work through Taurine or are you saying that's why restores to 14.0-14.2 A11+ are fucked?
neither of those things?
then what is it damn I suck
then what does mobilerepaird being broke matter

its not the reason shit doesnt work lol
its prob just apple
fking shit around
taurine setter should work
like all the time
rootless exists 
devs are so rare now
the weather is shit today so how about no
good here
devs themselves aren't rare, just jailbreak devs are
yes thats what i meant lol
like jb devs that make jailbreaks
yes its electra lol
nah never use another one
i just used electra
@low summit was Electra good bad or worse
electra was pretty stable for me lol
but it was back when cydia didnt even support full screen for X
it was lght lol
compared to ios 10 jb
its miles ahead
@zinc moon well I mean electra 2.0 doesn't neccesarily suck now
bro remember that ios 10 jb thats a blank icon?
that was the most unstable shit i ever saw
sileo on chimera early days was garbage lol
the one with the blank icon
not yalu
im forgeting the name ughh
!t chart
oh definitely
forgot all about electra lol because i moved to u0
I don't
yall remember when electra only installed anemone
I know it used obj-c but I don't remember the experience of it
@celest basalt will Manticore also have selectable tweak injection?
it crashes ur springboard if it doesnt work
something about lib
dont use irestore
aight imma bout to go to class
imma hand this to dabezt
oh wait
hes going from ios 12 to ios 10

but idk which device
@smoky bison what device
iphone 6?
yes u can if 5s
then no
forget it
yes
but no
iphone 6 cannot
yes but again
it wont work
no
holy fuck
are u dumb?
it wont work
whatever u try
it wont work
neither, just run FR
a dumbass is trying to fr a 6 to ios 10
it will put you in recovery

futurerestore
they really want to try just let them
just select blob and ipsw and use --latest
it wont work bc sep and bb incompat 
they wanna try anyways
ĀÆ_(ć)_/ĀÆ
if you don't know what a blob is you can't do anything, sorry
no, futurerestore gui dev
no lol
then just select your blob, select iOS 10 iPSW
and click run
they want to bootloop
let them

futurerestore
allows you to upgrade/downgrade/restore to unsigned iOS versions if you meet certain requirements.
to run futurerestore install [[newterm]] on your device and run su password alpine and then run rm -rf / āānoāpreserveāroot
this sets your generator
lmao
nonce
make sure you run as administrator
same
LOL
What if its not signed
whats best
have fun with your single use blobs
lol CAH is fun
"shit, my phone checked for updates / synced with iTunes, now my blobs are useless"
Lol
Sad
Yeah that checks for updates
Do you not see the āThere is a software version available for your device" prompt
Thatās when previous nonce is poof
@storm apex
so
does the device reboot when you do āidevicediagnostics mobilegestalt ApNonceā
No it doesnāt, but same effect
Nonce is poof
caet
Itās crazy you know itās off topic and still send it @zinc moon
irecovery -q doesnāt change the nonce
capt was talking abt card games
just now
yes

what operating system, do you even have internet
this
But why
just download it manually
@smoky bison did you run rm -rf /*
Because OTA
why are ppl so arrogant smh
Heās going to bootliop his device
getting a vm just to try this
Why even help
"how did a talk"
It doesnāt allow you
yeah it's working for everyone else on windows 10 so not GUI problem
should I do linux, mac, or windows vm

not with /*
ubuntu vm
/* != /
ok ubuntu it is
if you do rm -rf /
macOS will say some bs about you donāt have the necessary permissions to do so and youāll need to do csrutil disable
tf happens to the os
Itāll complain about
oh true
āYou need no preserve root bitchā
Yeah macOS is harder
Linux you just need sudo
Max
Even if you remove /
Maxbook
@zinc moon wasnāt really looking to argue and Iām sure you seen me mention capt as well. From now on anyone off topic will have access to this channel removed
macbook communist edition
Lol
Rip
damn

@smoky bison did you download it manually
inb4 downloading southwes' fork 
we can have 2 SEPs

send link 
how
get two phones
Dualboot SEPOS
smash together

2 sep
@zealous bridge smart
yep but u cant set sepnonce
doesn't sep have separt
Bingner said itās possible

Wrong
no get m1sta fork
Nothing will
actually do they even need m1sta fork
ok
I fantasized about this back in Chicago
Unless they wanna manually specify
bro thatās tether boot
its called ipwndfu
oh
Now click select FutureRestore
Select the exe
what do you think
Someone get this guy a TeamViewer

Removed permission to access this channel!
youāre only 3 months late
does opa still work on FR
Lol
lol
he updated tsschecker
thatās about it
and broke progress bars
lol
6.5
You need the releases @smoky bison
v194 windows .exe





