#tvos-jailbreaks

1 messages · Page 6 of 1

keen vessel
#

Can I get the app by using that?

ionic copper
#

yes

keen vessel
#

Ahh

ionic copper
#

helping someone pirate.. fr

keen vessel
#

I’m not gonna pirate🤫

#

It costs?

ionic copper
#

developer certificates aren't free

keen vessel
#

Is it the right site?

ionic copper
#

imagine owning an iphone 14 and apple tv 4k and yet pirating fr

keen vessel
#

Imagine paying

ionic copper
odd stone
#

how do i update my apple tv 4k to tvos 16.1 not 17.1 (latest) ?

wooden summit
#

apple tv 3rd gen

#

recovery loop after blackbox

#

even after futurerestore --exit-recovery

#

I'm just gonna itunes restore

#

anyway I have this apple tv 4k that I got a while ago sealed

#

what do I have to do to make sure it doesn't update

#

when I open

wooden summit
#

lol

ionic copper
ionic copper
wooden summit
#

how

#

lolxd

uneven wraith
#

Spartan development is on hold until OCLP supports macOS 14.2 because of a stupid bug in 14.1b1

odd stone
gritty hamlet
uneven wraith
#

It hangs infinitely on a screen complaining about AppleKeyStore things

#

The font changes too, I think it fails to load WindowServer due to Metal stuff

ionic copper
keen vessel
#

Any way you can sideload wirelessly without Apple configurator?

trim wagon
#

@keen vessel no afaik, sideloadly makes use of Apple configurator as well

#

if you are jailbroken, you can copy files over via ssh and install via appinst

violet wharf
#

Anyway to jailbreak an Apple TV 3rd gen on 7.9 without a mac or is it not possible?

wooden summit
#

Need mac

violet wharf
# wooden summit Need mac

Ouch alright. Is it possible to do it via emulator or no? I’d run hackintosh but my pc sadly does not support it

wooden summit
#

You can try but I doubt it'll work

violet wharf
#

Alright thanks

violet wharf
gaunt basalt
wooden summit
#

Alright

ionic copper
wooden summit
#

Howw dfu restore

keen vessel
#

How can i sideload to my Apple TV without cable or apple configurator? I have a registered UUID

cyan veldt
#

I've written a change to blackb0x to disable the usb port after jailbreak, should avoid that recovery mode issue once I post it

odd stone
ionic copper
ionic copper
jaunty rune
odd stone
uneven wraith
#

I got another TV HD that I'll be using for tvOS 13 testing

#

The tvOS 13 app interface is different enough now that I need a device for it

#

Should get here end of the week

uneven wraith
#

It's now saying next Monday despite being a 3-hour drive from my house? I love the United States Postal Service

uneven wraith
#

it arrived and it's on 14.7 ralseisplat

#

has the tv 4k 13.4.8 ipsw been released?

uneven wraith
#

@jaunty rune i dont know what to tell you... I tested Spartan on my HD on 14.7 and the top bar works just fine...

#

Some text and images are weirdly small so I'll be if #available some settings

#

but it works...

uneven wraith
#

Hmm

#

It works fine on 14.7 i'm not sure what to tell you

#

I have another idea maybe can try when I get home

jaunty rune
#

No biggie either way. Thanks for trying

open mauve
#

can you run macos on Apple TV

#

The new ones

uneven wraith
#

No, only the TV 1

#

only the TV 1 is x86

unreal sand
#

!t whyjbtv

boreal monolithBOT
# unreal sand !t whyjbtv
whyjbtv

Why jailbreak an Apple TV?

Tweaks and features such as:

AirMagic - Control your Apple TV via any web browser.
DalesDeadBug - Spoof your firmware version.
AppStore++ - Downgrade Apple TV apps from the AppStore.
nControl - Use other controllers for your Apple TV.
TVControlCenter - Install control center tweaks for ease of access. (13+ only)
Breezy - AirDrop files to and from your Apple TV from any device.
SnowBoardTV - Decorate your Apple TV homescreen with awesome themes!
Doom & Quake - Play the classics from your childhood right on the big screen!

emulators, multimedia, code execution, custom respring animations/wallpapers/ screensavers and so much more!

unreal sand
#

this list is old af but its a start

strong vault
#

You know what I have an Apple TV I’m going to have to look into this more. Kinda has me curious now

trim wagon
#

i'll never understand this type of question, same reason you need jailbreak on an iphone

strong vault
trim wagon
#

I would argue the same about iphones tho

#

just because you personally don't see a point, others might

strong vault
trim wagon
#

godspeed

marsh rune
#

Hello! Is there any beta jb compatible with tvOS 17.1 for the ATV HD 4?

#

I know I could be using tvOS 13.4.8 but I would like to use the newer features on tvos17

marsh rune
#

alright thanks

ionic copper
distant fox
#

tvOS 13 does need the older remote that they stopped shipping with newer ATV 4th gens.

marsh rune
#

also is there someone who can help me install an ipa on my apple tv? i already jailbroke it but idk how to directly install ipas

#

and i dont want to use resigning apps i want it to be permanent

marsh rune
#

Pop corn time

ionic copper
marsh rune
#

well what if it was another app

trim wagon
marsh rune
trim wagon
#

you copy the ipa via scp onto the atv, connect via ssh and run appinst to install the ipa

marsh rune
#

alright thank you!

uneven wraith
marsh rune
#

the repo is to install the appinst tweak

#

oh wait nvm it seemed to work now

trim wagon
#

and then it should work

#

nitoTV is completely fucked lately

marsh rune
#

well I don’t know what I did wrong but the app doesn’t want to open

ionic copper
trim wagon
#

depends where he lives

humble cairn
#

Is there a way to sideload apps to an Apple TV on the latest version

uneven wraith
#

sideloadly

sudden viper
#

Applets 4K 2nd gen (14.7) requires a breakout with micro usb to lightning or USB-C ?

trim wagon
#

it works for 2nd gen 4k as well?

uneven wraith
#

@jaunty rune Figured it out, it's a tvOS bug

#

apparently tvOS 14.1-14.4(?) has issues with sheets

#

Ok I fixed it

#

You have to attach the sheet to whatever button calls it? It also doesn't like @ViewBuilders.

#

Fun!

uneven wraith
#

It also doesn't seem to like any sheet with an onDismiss section

#

What

subtle swan
#

what are you working on

uneven wraith
#

This will fix some things for tvOS 14.1-14.4(?)

#

It also adds some nice speed improvements and the bug to which my nick is a reference to

subtle swan
#

neat

#

my tv is on tvOS 16 tho

jaunty rune
uneven wraith
jaunty rune
#

@uneven wraith everything works on the top bar, or at least they all do something now!

uneven wraith
#

nice!

#

i just put sheets on various non-wrapper elements and tested them and they seemed to mostly work

#

let me know if you find something that doesnt

jaunty rune
#

Found a few things. Just feedback not complaints btw.
Seems info, rename, open in, move/copy to, dont do anything. Move to trash and add to favorites work

#

Also in the select top bar the copy/paste and zip dont seem to work

#

In the create file menu, that and create directory arent working. Can create symbolic links though im a bit confused on what to do exactly

uneven wraith
#

Hmmm

#

I can use fullScreenCovers, but those dont have a background and so it looks really bad

#

Plus that'd require a lot of if #available everywhere

#

hate this bug

sudden viper
ionic copper
#

the second gen 4k cannot use checkra1n

sudden viper
ionic copper
simple wadi
#

Is it currently possible to jailbreak tvOS 17.1

ionic copper
marsh rune
#

@uneven wraith sorry for the ping but i tried to install the spartan app on my Apple TV running 13.4.8 and it doesn’t open. I installed it downloading the .deb file from the GitHub repository and then installed it with dpkg -i. Is there something i am doing wrong?

uneven wraith
#

I'm trying to find an HD for a decent price so I can put it on 13.4.8

#

I did buy one for that purpose, but it came on 14.7 and as my TV 4k on 14.3 won't enter DFU (so I can't jailbreak it) I'm using it as my tvOS 14 test device

marsh rune
#

ohh well don’t worry, thanks for the answer though!

#

does anyone now how to use appsync unified on an Apple TV?

uneven wraith
uneven wraith
uneven wraith
#

I am unsure when the problem started

marsh rune
uneven wraith
#

Just install apps with sideloadly

#

they'll work

#

it patches the codesign requirements

marsh rune
#

ohh so it’s that simple

#

thanks

humble cairn
#

anyone know what this means? ```Error installing '/Users/voids/Downloads/org.xbmc.kodi-tvos_20.2-tvos.ipa', ERROR: Error Domain=com.apple.dt.CoreDeviceError Code=3002 "Failed to install the app on the device." UserInfo={NSURL=file:///Users/voids/Downloads/org.xbmc.kodi-tvos_20.2-tvos.ipa, NSUnderlyingError=0x6000182709c0 {Error Domain=com.apple.dt.CoreDeviceError Code=3000 "The item at org.xbmc.kodi-tvos_20.2-tvos.ipa is not a valid bundle." UserInfo={NSURL=file:///Users/voids/Downloads/org.xbmc.kodi-tvos_20.2-tvos.ipa, NSLocalizedFailureReason=Failed to read the bundle., NSLocalizedDescription=The item at org.xbmc.kodi-tvos_20.2-tvos.ipa is not a valid bundle.}}, NSLocalizedDescription=Failed to install the app on the device.}
Domain: com.apple.dt.DVTCoreDevice
Code: -1
User Info: {
DVTErrorCreationDateKey = "2023-11-30 01:51:22 +0000";

humble cairn
uneven wraith
#

I'm not sure it works that way

humble cairn
#

Then how can I install the deb on my Apple TV

uneven wraith
#

Install it via dpkg

jaunty rune
#

Or airdrop

humble cairn
uneven wraith
#

dpkg -i debfile

#

ssh

steep halo
#

Is TV OS 17 jailbreakable on an Apple TV with USB C port?

#

from 2015

ionic copper
steep halo
ionic copper
ionic copper
#

Requires pc

steep halo
#

which is the highest version?

steep halo
ionic copper
#

Pc requires live booted Linux

steep halo
#

which tool?

ionic copper
#

Checkn1x

steep halo
#

But 13.4.8 is very outdated isn’t it?

ionic copper
#

It is but it's all you have for now

humble cairn
steep halo
#

how do you downgrade it?

ionic copper
ionic copper
#

Just download the ipsw

steep halo
#

ah i see

#

but is it worth it?

ionic copper
#

Don't know what you plan to do

steep halo
#

don’t even know whats possible on AppleTV haha

ionic copper
#

Lots of things are but the majority of folks will pirate by streaming movies and TV shows via kodi

#

It's unfortunate but true

steep halo
#

okay i see

#

if i have some time, ill try it
thank you :D

humble cairn
ionic copper
humble cairn
#

Yes

dusky imp
tiny dust
unreal sand
#

for the ATV? probably just checkm8

ionic copper
ionic copper
dusky imp
ionic copper
dusky imp
#

Ok

tiny dust
#

Does tvOS 16 beta profile work to block updates on tvOS 17.1?

ionic copper
uneven wraith
#

It will just give you tvOS 17 beta updates

tiny dust
#

how can I block ota them

uneven wraith
#

What I did is I booted an ssh ramdisk and told it to search for watchOS updates but can't easily do that on tv 4ks

jaunty rune
#

@uneven wraith on spartan in the “create new symlink” page, whats the correct process?

uneven wraith
#

Name of the symlink = the name of the symlink that will be created
Destination of the symlink = what the symlink will point to

jaunty rune
#

Ah ok yah wording confused me but thats what i figured ok thanks

uneven wraith
#

Yea sorry

#

Im working on info button stuff next

#

First im fixing compression

jaunty rune
#

Nice! No rush. Thanks for the hard work as always

#

@uneven wraith just curious can the sorting of directories be changed? ie date/name? What is it set to btw, cant tell

uneven wraith
#

It's currently alphabetical

#

Capital letters get priority over lowercase letters because that's how SwiftUI does it

jaunty rune
#

Hmm must be another tvos14 thing

#

Its totally random

uneven wraith
#

Wtf

#

I don't think I'm reading file date anywhere but I can add a sort option

#

I didnt even think about that

jaunty rune
#

Again its no biggie i figured it was something with 14. But yah definitely not alphabetical or anything else seemingly ha

uneven wraith
#

For me it sorts numbers, then punctuation, then capital letters, then lowercase letters

#

so .data takes precedence over Data

#

but Data is above data

jaunty rune
#

@uneven wraith

uneven wraith
#

Hmmm

#

That might be a bug actually

#

Thanks for letting me know

jaunty rune
#

Yup. And got the symlinks working! Only prob is i cant access the ROMs directory above… which is where id be using the function the most hah

#

Crashes spartan

#

Also, Kirbistan?

uneven wraith
#

I wonder what would be causing a crash

uneven wraith
jaunty rune
#

Ah

jaunty rune
#

Hmm another folder does the same. They are both fairly large. Could that be it?

uneven wraith
#

The latest one has a caching feature for speed improvements but that build has a few issues that could be causing it

jaunty rune
sweet flame
#

hello, does anyone know any tip how to fix on appletv 4k 1st generation, when at startup flashes fast diode and the screen does not show anything. Some de-brick device ? thx

ionic copper
#

would love to know how it got to that

trim wagon
#

sounds like it's bricked

#

you can get a replacement unit by apple if you ask nicely even if you are out of warranty

#

not sure if they still do that though with all those new models in place

#

see this

sweet flame
#

apple tv is out of warranty.

ionic copper
ionic copper
#

You'll be forking over the first gen for the 3rd at 300 bucks

sweet flame
uneven wraith
ionic copper
#

Reason for asking because your device is in a DFU state which could indicate hardware damage

uneven wraith
#

Hmm

jaunty rune
uneven wraith
#

It shouldn't

#

I was not having that issue

jaunty rune
#

Yup think it pertains to this specific issue? Seems to crash whenever there is a large file present in the directory

#

Moved a 300mb file to a directory that was opening fine and now it crashes spartan

#

As well as closing the ssh connection

ionic copper
#

A crash log would help

jaunty rune
#

@uneven wraith

uneven wraith
#

Large files? I will investigate

#

I am thinking it's a bug with my caching system

#

Wait what

#

EXC_BREAKPOINT?

#

Did I accidentally enable a breakpoint somewhere

#

Ok, it seems to be crashing while trying to call some process

#

I'm guessing my root helper

#

That, or async stuff is breaking

#

Because the dying thread is thread 5 which is all libdispatch related

#

ok that should not be it

#

hmmm m

uneven wraith
jaunty rune
#

It crashes when clicking

uneven wraith
#

It doesn't show the directory and then break?

jaunty rune
#

However i put a large file in /var/ and it takes a second after going to a black screen to crash

uneven wraith
#

So it's an updateFiles() issue

#

Thank you

jaunty rune
#

But the original directories i tried crash instantly

uneven wraith
#

Yeah, it's not an issue with displaying the loaded files

#

Something about the files is causing it to break

sudden viper
ionic copper
#

and sure, but there's no data on the apple tv

sudden viper
ionic copper
sudden viper
#

Ok hardware patch. Thanks for clarifying that point.

ionic copper
#

the local storage is on the same PCB, just another chip attached to the nand and the SOC

sudden viper
#

I’m interested in using device to look into this further. I never updated it not knowing it wasn’t compatible. The second chip should be able to be bypassed in some way.

#

Soc bypass is manageable

#

@ionic copper any NPU on that device?

ionic copper
ionic copper
sudden viper
sweet flame
ionic copper
limpid salmon
#

How to jailbreak Apple TV 4K with tvOS 17?

ionic copper
analog elk
#

Hi, is there a way to delayOTA a AppleTV 4k?

lucid falcon
#

I cant find the tvOS jailbreaks

ionic copper
lucid falcon
ionic copper
#

you can downgrade it to 13.4.8 and jailbreak via checkra1n

lucid falcon
lucid falcon
#

I don’t know how it updated

#

Or when

ionic copper
#

you just need a computer and a usb-c cable

lucid falcon
lucid falcon
#

Wait, you’re able to downgrade on tvOS?

#

That’s cool

ionic copper
#

yes

lucid falcon
#

I hope you could on iPhone lol

ionic copper
#

iphone is more complex

#

but apple tv is easy

lucid falcon
#

So which version should I downgrade to?

lucid falcon
lucid falcon
lucid falcon
ionic copper
#

no

#

only when you reboot or unplug

#

sleep is just not active

#

jailbreak still works

lucid falcon
ionic copper
lucid falcon
#

And there is some “guide” on how to do it or i have to find out how? Haha

lucid falcon
lucid falcon
#

An error?

ionic copper
#

so if you have an apple tv on tvos 9

#

then you can get to 10.3.3 since that's still signed too

#

and from there, to 13.4.8

lucid falcon
ionic copper
# lucid falcon Oooh

it wouldn't make sense to get an old apple tv with tvos 9 or 12 and not be able to update it to the latest because 13 is unsigned

ionic copper
# lucid falcon Of course

granted you could via a computer and the wire but folks don't know how and would rather just simply click "check for update" on the apple tv

ionic copper
#

but again, OTA updates would break since the latest wants 13 and you're on anything lower

lucid falcon
#

Like the downgrade and jailbreak?

#

Or source where I can search?

shell plume
#

any apps worth installing once JB? ive got nitoTV & kodi

ionic copper
lucid falcon
#

I’ll figure it out

uneven wraith
#

I'm not working on it much rn but it's not super broken afaik

#

If you build it from the current source it is though

fallen nexus
#

When on 15.4.1?

analog elk
sand sparrow
#

Would there be any reason why DelayOTA wouldn’t work on a ATV4K 1st Gen. I have a Goldeneye cable connecting my ATV4K to my MacBook, with Apple configurator app, I have followed the tutorials to ‘prepare’, and place in supervised mode, then install the delayota 90 day profile for tvOS. On the system settings it says the latest update is 17.0 (as expected - not 17.1!) but it fails every time. It’s currently on tvOS 16.6 but in the hope of trollstore possibly being ported to tvOS 17 I wanted to try and ship one of my 1st gen 4Ks to 17. Any advice I would appreciate!

ionic copper
sand sparrow
#

I know. I’ve got a fair few first gen’s 4Ks on various tvOS versions. I was just going to play devils advocate and just put one on 17.0 while the 90 day window was still open given some of the tvOS trollstore snippets released on twitter

subtle swan
#

i tried going from 13.4.8 -> 16.4 on my HD 4th gen, it also failed

#

i had to manually do some stuff in order to get it to work (not feasible for you, needs a jailbreak + needs special dev stuff)

#

i wonder if it has ever worked

sand sparrow
#

I also have the DCSD cable and once upon a time had this particular ATV jailbroken. Looking through the failed 17.0 update logs on the ATV there seems to be a lot of flags referring to incorrect partition mounts and authentication errors. Happy to upload them here if they make any sense to anyone. Always happy to contrived. DCSD. Cable and goldeneye plug with 1st gen ATV4K

subtle swan
#

if you can upload the log it'll be helpful, but if it's the same issue i had there's nothing you can do about it

ionic copper
subtle swan
#

???

ionic copper
#

delayota doesn't work for apple tv

subtle swan
#

it is supposed to

ionic copper
#

their certificates are different

subtle swan
#

what?

fleet flame
#

I’ve got a HD on 17.2, what can I do?

unkempt falcon
cyan veldt
jolly tendon
subtle swan
#

@uneven wraith what tvOS are you on

uneven wraith
#

and also soon 14.5 maybe

#

Why

uneven wraith
#

@subtle swan ?

subtle swan
uneven wraith
#

oh

subtle swan
#

but i'm on 16.5

uneven wraith
#

i dont have anything

subtle swan
#

i don't think smith was in tvOS

#

so no kfd

uneven wraith
#

smith?

subtle swan
#

exploit

uneven wraith
#

oh

#

i just use appsync on my hd on 14.7

#

and palera1n kpf via pongoterm on my hd on 15.0

#

combined with WDBThreeAppLimit on 15.0 i get the effects of trollstore without having to go through it to install

subtle swan
#

understandable

ionic copper
analog elk
#

Giving Away my Car And more i have a lot of stuff IF YOU WANT SOME JUST DM ME

green basalt
raven verge
#

Hi I’m poor anyone got old stuff they don’t need please help

dark current
#

Hello ya’ll I’m new to this group and I’m not that good at jailbreak

distant fox
#

What is the latest tvOS that can be jailbroken?

uneven wraith
distant fox
#

Dang tvOS jailbreaks really fell off

tight kindle
#

There’s not much use for one other than permasideloading. I never really saw anything that would tweak the UI, functionality, etc

#

Which is a mega bummer. I’ve always wished for a way to close all apps from multitasking, even if it’s a jb solution

tight kindle
#

That’s dope. I’ve literally never seen anything like that before

ionic copper
analog elk
#

what

#

r

#

the

#

effect

#

of jailbraiking

#

a apple tv

#

😭

ionic copper
#

indeed you can't trol

raven verge
ionic copper
dusty kelp
#

Ooh tvOS jailbreak

analog elk
#

huh ?

sweet flame
#

Hello, does anyone have the firmware to restore appletv 4K A1842 ? Is there any other possibility to use the idevicerestore? Does anyone have any instructions ?

ionic copper
#

Also, why do you want to restore it?

sweet flame
#

ihave goldeneye and dcsd cable, itunes detect in DFU mode, but when i select ipsw show mwé not compatible for device. My device in fast blinking light

ionic copper
#

Do you have an apple tv remote?

sweet flame
#

yes

#

siri remote

ionic copper
# sweet flame siri remote

Try this, point the remote at the apple tv and hold down menu and tv buttons together until light rapidly flashes

#

Then release

#

If the light goes back to rapid flashing, it's hardware damage

sweet flame
#

ok i try it

sweet flame
#

remote unresponsive, but idevicerestore recognize. But i don't have restore ipsw. is there any instruction how to edit the ipsw ota ?

ionic copper
#

Restoring it via software will not fix

waxen igloo
#

what devices are supported

ionic copper
waxen igloo
#

tvos jailbreaks 💀

ionic copper
waxen igloo
#

4k first gen and third gen

#

both tvos 17

ionic copper
#

first gen will be jailbreakable soon though

waxen igloo
#

ok

young shale
#

I had to update my ATV4K to use Infuse

vale yoke
#

Managed to snag a A2843 from FB marketplace on 16.5 😁 (I need 16.5 for the matter thread 1.3 support). Apparently the dude has like 40 more for sale on various versions from 16.0 to 16.5. Might pick up a few more before 16.5 becomes impossible to find and just hold onto them until something becomes available.

ionic copper
vale yoke
ionic copper
vale yoke
ionic copper
#

I don't even think you can block 'em nowadays seeing as they're all mainly expired

#

best to disconnect entirely from the internet

#

why Apple isn't sued for enforcing unwanted updates is beyond me

vale yoke
#

Ah. Yeah, I’ll just keep it unplugged for now I guess when I’m not using it.

analog elk
#

?

#

idkk

ionic copper
#

PSA

The Apple TV 4K 3rd gen (model number A2843) does *NOT* have a connection in the ethernet port unlike the first and second gen Apple TV 4K devices. Therefore purchasing the Goldeneye cable for this particular device will be useless.

hybrid rivet
#

Are any of these firmwares jailbreakable? I have 13.4.8 installed on my Apple TV right now

boreal harbor
#

I have no macs but an AppleTV 3. Is there any way to jailbreak?

I've tried https://etasonatv.tihmstar.net/ but it seems it's not working, also relies on services we have no control

golden depot
ionic copper
daring delta
lapis heath
#

not only that but a user should be allowed to choose to downgrade, even if you require a secure wipe to enforce security

ionic copper
lapis heath
#

sure give it out free then

#

don't sell me something that I can't own

#

like sony with selling movies then revoking access

ionic copper
lapis heath
#

like my 2000 civic

#

❤️

ionic copper
#

i do love the common misconception of buying a movie.. "oh, it's mine" no, you rented it.

#

you bought the privilege to use it for your personal use

lapis heath
#

until the disc breaks then "sorry you broke it buy another"

#

or want to watch it on a different platform/device

ionic copper
lapis heath
#

and a law that will destroy your life if you try

#

can't forget that

ionic copper
#

nah, half a million fine

#

they don't lock up anymore

lapis heath
#

i need your couch coins then cause mine is bare

ionic copper
#

I'm sure a part time job on minimum wage will pay the fine in 45 years

#

..after expenses

lapis heath
#

sure if someone is covering all your expenses

#

so we're back at life-destroying

ionic copper
#

i do feel bad for the elderly gent paying nintendo for modifying their console to sell piracy

lapis heath
#

🙂

ionic copper
ionic copper
# lapis heath so we're back at life-destroying

paying a big fine isn't really life-destroying, what is; is getting convicted, locked up and wasting time then being released on a tight leash with a criminal record with extremely limited resources

trim wagon
ionic copper
trim wagon
#

can we pin stuff like this?

ionic copper
vale yoke
ionic copper
vale yoke
#

Ah. So the only thing to support other versions is the offsets?

ionic copper
#

yes

vale yoke
#

Dang. I’m too stupid to find those 😞

ionic copper
#

i'd get them but i'm running into errors with obtiaining offsets

#

i tried to consult with the devs, but no answers

vale yoke
#

The Apple TV second and third generation don’t even have OTA updates for download either 😫

#

could they even be found for those?

vale yoke
#

Oh. I was just looking on IPSW me

ionic copper
#

but you can't install them

ionic copper
vale yoke
#

Well, I meant to find the offsets. You can use the OTA updates to find the offsets in IDA, right?

#

Or do you need a whole IPSW

ionic copper
vale yoke
#

Oh ok

#

I should get a Mac…

ionic copper
#

from there you run that on the kernel cache

vale yoke
#

I feel useless I want to contribute

ionic copper
#

and it'll display the kernel pointers for the exploit

#

they're very specific and there's over 20 of them

#

so just guessing will result in failure or kernel panic

vale yoke
#

Oh so that’s how they are doing it. I remember reading a tweet that all the offsets had to be found manually lol

ionic copper
#

you manually execute the lib that searches and outputs them

#

you need to do it for every version for every device

#

because the exploit isn't universal

#

universal meaning one or multiple attempts for x version on x device

vale yoke
#

Do you have to be jailbroken already in order to run the offset finder? Or can it just be sideloaded?

ionic copper
vale yoke
#

oh ok I thought it had to be run on the Apple TV lol

#

This is all very interesting but I feel dumb I want to learn how to do this.

stone crescent
ionic copper
stone crescent
#

So with offsetfinder i can provide them? My appltv is linked in xcode for sideloading.

ionic copper
#

Finding offsets has nothing to do with sideloading

stone crescent
#

Yeah i know. I just mentioned it to show my device is connected with Xcode

neat orchid
#

Dang, i thought tvOS jailbreak was dead and never bothered to block updates lol

stone crescent
#

Trollstore would be nice 🙂 sick of Yt ads

vale yoke
#

Same. YouTube Adblock and MAME 😁

stone crescent
#

Xcode Sideloaded apps on appletv have the same 7 day limit ?

unreal sand
#

yes

#

unless you have a dev account

stone crescent
#

No dev account.

unreal sand
#

then yes 7 days 3 app limit

stone crescent
unreal sand
#

its still being worked on

ionic copper
#

There's one that has no ads

somber slate
somber slate
#

I tried Blackb0x, but it didn't work.

storm ridge
#

@trim wagon
I have 4 first gen 4k's sitting on 16.5. Nice to hear some developments are in progress. Can we install Trollstore using Misaka as on iOS? Or, is it better to wait for a full jb?

ionic copper
#

blackb0x requires Arduino to pwn for your device

storm ridge
#

@ionic copper
If I can turn off the darn update nag I'd be on it.

storm ridge
#

with Misaka? ok, now I'm interested

#

I have an iPhone 12 on 16.3.1 and I installed the tvOS profile to stop the nags while I wait for the jb to land. Would like to do it on apple tv too

EDIT: According to this report Misaka works only up to 16.1.1 devices for now
https://www.idownloadblog.com/2024/01/03/misaka-apple-tv-support/

The Misaka package manager app has been updated to support the Apple TV, which means that it’s now possible to install hacks and add-ons.

trim wagon
#

does trollstore even work on tvOS?

#

friendly reminder my 14.5 atv4k1 is jailbroken and I can't do jackshit on it cause half of the packages on it are broken

ionic copper
ionic copper
trim wagon
#

you might remember me bringing it up several times here and in nito's channel

ionic copper
#

as long as you sideload it and jailbreak, it'll work forever

trim wagon
#

like i said, either dumping the app doesn't work properly

#

or the installation

#

am I supposed to sideload ipas that I dump, why do I have to do that if I'm jailbroken tho

ionic copper
trim wagon
#

any

#

i tried stock youtube for example

storm ridge
#

@ionic copper
So does this mean that if we get a jb we can permasign the jb IPA as on iOS?

storm ridge
#

Great, just hoping they release a tvOS jb tool alongside the iOS one that is coming

ionic copper
#

Best to not have a jailbreak

somber slate
subtle swan
#

@uneven wraith what happens if i replace a daemon on tvos 16 and then boot stock

uneven wraith
#

the file?

subtle swan
#

no ssv, so the daemon will just crash right

#

yea

uneven wraith
#

once you rename snapshot it should just crash yea unless you've CT2'd it

#

i dont have any tvos 16 devices to test so there may be ssv on 16? but it definitely is not on 15

subtle swan
#

oh, tvos still does snapshot booting? woe

uneven wraith
#

yeah it got snapshot at same time as ios

#

but you can just rename it

subtle swan
#

trying to figure out how to get a CTv2 binary to run

uneven wraith
#

tvos 15 doesnt care

subtle swan
#

4k 2nd gen so no jailbreak

uneven wraith
#

oh

subtle swan
#

apparently there's no removable system apps on tvos

uneven wraith
#

correct

subtle swan
#

with mdc i have to overwrite something that hasn't been launched

#

so i guess podcasts

uneven wraith
#

install the twitter app

subtle swan
#

it has to be a system app

uneven wraith
#

oh

subtle swan
#

otherwise <whatever>board will verify it right

uneven wraith
#

idk i dont do much with that

subtle swan
#

hmpf

uneven wraith
#

i just boot my palera1n kpf, run WDBRemoveThreeAppLimit, and watch installd be unable to complain about the horrible things I do

subtle swan
#

ok well i guess i am going to have to write an mdc thing

ionic copper
#

There's no ssv on tvOS

#

🙄

ionic copper
bitter gull
#

is tvOS 16.6 on 4k gen 1 a possible candidate for misaka in the future?

vale yoke
#

I think they said they’re stopping development of misaka unfortunately and moving to something else 😦

gaunt basalt
#

is it possible to get kodi with misaka

ionic copper
gaunt basalt
#

cool just checked and my tv is on 16.6 anyway lol

#

is downgrading still not recommended

ionic copper
gaunt basalt
#

4k 1st gen

#

i did buy the goldeneye cable

ionic copper
#

i wouldn't downgrade. You'll be stuck on the latest

gaunt basalt
#

okay

#

its sucks they dont share ipsws really dumb

ionic copper
#

so buying the cable for that is useless

gaunt basalt
#

can apple store not even unbrick those then lol

ionic copper
#

they can but they do it via OTA

vale yoke
# gaunt basalt its sucks they dont share ipsws really dumb

It’s the same situation with the first gen HomePod. Apparently they had a habit of bricking themselves during an OS update, so there’s tons of people out there with HomePods that are unable to be restored, because there is no IPSW anywhere 😐

ionic copper
vale yoke
#

There is a guy out there that runs a HomePod repair business, and he has over 50 logic boards from HomePods that are bricked. He’s been trying for like 2 years to unbrick them and even has a bounty up for anyone who can build a working IPSW to restore them with, even with Checkm8. They don’t have a bootable IPSW. It’s pretty bullshit.

ionic copper
#

as possible as it was with the apple tv 4k

#

and since it's the first gen, it has checkm8 so restoring is entirely possible

#

you'd just need the ota zip (the largest one) and extract the pom files

#

from there, re-build the kernel cache, trust, ibss, llb, etc

#

make the buildmanifest, zip it together, then send it in via idevicerestore using patched method

vale yoke
#

If you do that, do you have to tether boot all the time? Or could you restore that IPSW and then do an OTA update to get the official firmware reinstalled?

ionic copper
#

you'd just need the blobs

#

then patch them in

#

the ipsw would be the latest firmware

vale yoke
#

Damn, that’s cool

ionic copper
#

Jonathan Levin built a tool for extracting OTA files

#

with them extracted, an ipsw can be built

#

and with checkm8, completely restored back to factory

vale yoke
#

Wow

ionic copper
#

you'd just have to modify the ipsw to add filler files

vale yoke
#

Well, if you’re interested in getting a free HomePod, this guy is offering one to anyone who can build an IPSW lmao

ionic copper
#

which requires some solder

vale yoke
#

Apparently you can open up the bottom and solder directly onto the logic board. macOS will see it, but cannot restore it, because there is no firmware available

ionic copper
#

and since homepod takes from tvOS software, I'm very well familiarized by it 😉

ionic copper
#

or do we need to make one?

#

i could probably make an ipsw.. would be difficult to test if I don't have the unit

vale yoke
#

Check this out. He is even offering anyone who thinks they can fix it complete remote access to a PC with a working HomePod and a bricked HomePod connected do it

#

This is his most recent update, and they are still at it Trying to fix the HomePods 😞

ionic copper
vale yoke
#

They don’t. As far as I can tell, they have no idea what is causing the brick. But pretty much all of them died during a firmware update.

#

So they think it’s software

#

There’s gotta be a way to like Console into it or something and get an output of the boot log and see where it is failing

ionic copper
#

Again, needs an ipsw

#

What I'd do, is make a ramdisk, install it then just overwrite the files

ionic copper
ionic copper
vale yoke
#

Hmm let me see if I can get him to join

#

Honestly, I’m surprised he’s not in here already if he does this kind of stuff lol

brazen niche
#

Im here

vale yoke
#

Are you Nic

brazen niche
#

frankly not 100%, still recovering from getting tboned at 40mph

vale yoke
#

Oh shit damn

#

I hope you are ok

brazen niche
#

walkin and talkin so meh. hope whatever was on her phone at the time was worth it

#

anyways,

#

Got this at the moment, not sure exactly how I ssh in to start

vale yoke
#

Have you ever tried to boot the SSH RAM disk with DFU mode?

brazen niche
#

no and that sounds pretty foreign to me, but Im willing to try whatever

vale yoke
#

The SSH RAMdisk script is here, but not sure how you would configure it for a HomePod

#

But if you can get this to boot, then you should be able to access the file system and get a log of the boot process and where it’s failing

brazen niche
vale yoke
#

Zenzeq would know more. I’ve only ever done it on an iPhone.

ionic copper
#

I have the script etc that should work for that particular device, just need to get some time to decrypt the files etc

brazen niche
#

take your time, ty

ionic copper
#

Do you by chance have the ECID for the affected HomePod?

#

Apple Configurator/Xcode would tell you

brazen niche
#

Yes but I won’t have a chance to grab it for a while, I’ll @ you when I do in the HomePod channel

vale yoke
#

I don't think we have a homepod channel

#

Although technically homepod runs a version of tvOS, so this channel is still appropriate lol

brazen niche
#

@ionic copper

ionic copper
brazen niche
#

No :( any way to get it?

ionic copper
#

The iboot/xnu version might give some light to knowing what its on

ionic copper
#

But that requires windows to run

brazen niche
#

I can dig windows up if needed nbd. Here's everything I got from irecovery when I connected earlier

::
::    Local boot, Board 0x38 (b238aap)/Rev 0xa
::
::    BUILD_TAG: iBoot-5540.120.17
::
::    BUILD_STYLE: RELEASE
::
::    USB_SERIAL_NUMBER: SDOM:01 CPID:7000 CPRV:11 CPFM:03 SCEP:01 BDID:38 ECID:001E5DD900D080A6 IBFL:1D SRNM:[CC4VQ```
vale yoke
#

Looks like 13.4

ionic copper
#

With that being said, we cab grab keys

ionic copper
ionic copper
#

I think gaster might work too? (Included inside SSHRD) but unsure

#

This would've been easier had keys been published but I guess no one cared enough to DFU a homepod and decrypt such

brazen niche
#

Are you saying it’s possible to get keys with different circumstances? Say, a sacrificial working HomePod? One in a particular OS? Just need DFU mode?

#

I am well armed

ionic copper
#

DFU is required but you'll need to be pwned

#

Which is easy, it's just tedious

ionic copper
#

@brazen niche I need the keys for the following kbags:

80844783D569382B3EAC225C16480E1B15519C867EEE2B68E21D405F7AF3A934C1FE3469D36D8020D867E6C261823CE39B20F37DEB92D818474E868B5E0611DDC050D75BB43A72E9D9656DEA7F6A230D41B3B6A40A337C54EBDDA63FB5AA5ADA

and

9B00F97F65CC8BEE1A68E813771BA42B17792EEEBAC9E7C7FEFF4448A27E612C3D53AE8FFFA87EDE18484DAC279071D4E5AEFBC8BD5FFA6533A25CC737124F351C3A610D37AB4FB3B8C9B3CA7D2E348793FE8D65ABD0174159388F455F6EFCE2

#

you can use ipwndfu -p to place the HomePod in pwnedDFU mode

Then, execute: ipwndfu --decrypt-gid=80844783D569382B3EAC225C16480E1B15519C867EEE2B68E21D405F7AF3A934C1FE3469D36D8020D867E6C261823CE39B20F37DEB92D818474E868B5E0611DDC050D75BB43A72E9D9656DEA7F6A230D41B3B6A40A337C54EBDDA63FB5AA5ADA

and

ipwndfu --decrypt-gid=9B00F97F65CC8BEE1A68E813771BA42B17792EEEBAC9E7C7FEFF4448A27E612C3D53AE8FFFA87EDE18484DAC279071D4E5AEFBC8BD5FFA6533A25CC737124F351C3A610D37AB4FB3B8C9B3CA7D2E348793FE8D65ABD0174159388F455F6EFCE2

#

You'll get some type of code. I need both.

#

after that, then we're like more than half-way to getting it fixed (hopefully)

ionic copper
#

@brazen niche I also have the entire filesystem for HomePod 13.4.5 extracted

#

so any files that were damaged during the update to cause bootloop could be replaced

spiral patio
#

Piping in to show my ignorance here, but given that 13.4.5 is a very old version at this point, would we be able to revive a HomePod on say, os 17.0 with these files?

ionic copper
#

depends what HomePod it is

spiral patio
#

The infinite bootloop currently affects 1st Gen HomePods, not the minis or the second gens as far as we know

#

Same ones Nic is working with now

ionic copper
#

was it an update?

#

because there may be a way to revive it..

spiral patio
#

A bit of an unknown, we hear reports often that it happened during an update, but for other people it seems to be out of the blue. My money is on it being update related whether people realize it or not

vale yoke
#

Does the boot process write to a log anywhere? I would think you could look at the log file and see exactly what part it’s failing on

ionic copper
#

why apple continues to update old devices is beyond me

ionic copper
#

again why the homepod has sep in the first place much like the apple tv is beyond anyone other than thwarting downgrades

#

but the latest sep is compatible with 13.4

#

so with this in mind, downgrading a homepod back to 13.4 should be theoretically possible, that is if on-board blobs are obtained

vale yoke
spiral patio
vale yoke
#

I thought all the files on the file system was signed specifically for your device and using Files from a different device wouldn’t work. Apparently I’ve been really misunderstanding how that works lmao

ionic copper
ionic copper
ionic copper
#

they're all from the same, just a lower version

#

because technically, if it's bootlooped during an update, it hasn't installed the files yet

#

it's just transfered over, so anything that's corrupt can be replaced

#

(in theory)

#

what would be wise is to try out an idea I have, but I need the keys from @brazen niche if/when they can get time to obtain them

spiral patio
ionic copper
#

what Apple should do, is add a recovery mode for their devices

#

so the device can download the OTA and extract it and proceed with updating if it fails

#

I'm going to say it was the SEP

vale yoke
#

I wonder if it’s possible to do a factory reset from the command line, like wipe the user partition like an iCloud erase does and then try to boot

ionic copper
#

because everytime I do a routine update, it does fail and it's usually because the SEP isn't agreeing without the prerequisites in place

#

like to get to 17 you need 15

#

but if you're on 13 you need to get to 15, but 15 isn't signed

#

so it fails

ionic copper
#

just need a few things prior

vale yoke
#

Oh cool

ionic copper
#

i do know if it's the second gen or third gen homepods, then you're SOL

#

but first gens have a possibility

vale yoke
#

Ya cause no bootroom exploit 😞

ionic copper
#

and no software

vale yoke
#

I don’t think any of the HomePods have USB

#

you have to solder on the bottom of all of them

ionic copper
#

to make a device without such port as a way of an emergeny

#

terrible engineering

vale yoke
#

Oh, you mean like you can’t even solder onto the logic board? That’s dumb af

ionic copper
#

it's like constructing a building without a water line or another exit door

ionic copper
#

no soldering, just plug and play

#

they don't come on watches or homepods and apple tv's (4K) which is terrible

vale yoke
#

Eventually, they are going to remove the port from the phone

#

At that point, I feel like jailbreaking will be no more, as everyone will be too afraid of bootloop

brazen niche
spiral patio
brazen niche
#

ok figured, any particular version?

ionic copper
#

any

#

as long as it's installed

#

if you have it, you can do which python

#

it'll tell you where it is

#

then you can do sudo cp /location/of/python /usr/bin/

ionic copper
#

the idea is there to make, all you need are just a set of pins on a 3d-printed board connected to usb cables

brazen niche
#

fml

#

I installed python

#

which python
python not found

spiral patio
#

Depending on how you installed it it may not show that way, did you use a package manager or native?

brazen niche
#

I downloaded the pkg installer from their site

spiral patio
#

Reboot?

brazen niche
#

gfdi

#

ok one minute

ionic copper
#

install it via homebrew

#

/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"

#

then brew install python

brazen niche
#

reboot didnt help anyways
ok time to install homebrew too I guess

ionic copper
#

homebrew is the best for that

brazen niche
#

going to have an anurysm

#

zsh: command not found: brew

ionic copper
brazen niche
#

pip not found

#

brew fuckin installed just fine what is the deal

ionic copper
#

if you don't have pip: curl https://bootstrap.pypa.io/get-pip.py -o get-pip.py

#

python3 get-pip.py

brazen niche
#

Im going to have to wipe this computer after all this shit

#

holy shit we're moving forward

spiral patio
#

Homebrew is nice and contained usually, you can always uninstall just that

ionic copper
brazen niche
#

they should color that better, I'll accept 50% fault

#
Traceback (most recent call last):
  File "/Library/Frameworks/Python.framework/Versions/3.12/bin/ipwndfu", line 8, in <module>
    sys.exit(main())
             ^^^^^^
  File "/Library/Frameworks/Python.framework/Versions/3.12/lib/python3.12/site-packages/ipwndfu/main.py", line 117, in main
    pwn(device, match_device=args.match_device)
  File "/Library/Frameworks/Python.framework/Versions/3.12/lib/python3.12/site-packages/ipwndfu/main.py", line 179, in pwn
    device = dfu.acquire_device(match=match_device)
             ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/Library/Frameworks/Python.framework/Versions/3.12/lib/python3.12/site-packages/ipwndfu/dfu.py", line 40, in acquire_device
    for device in usb.core.find(
                  ^^^^^^^^^^^^^^
  File "/Library/Frameworks/Python.framework/Versions/3.12/lib/python3.12/site-packages/usb/core.py", line 1309, in find
    raise NoBackendError('No backend available')
usb.core.NoBackendError: No backend available```
ionic copper
#

go in sshrd and look for gaster

brazen niche
#

Im sorry for my ineptness but...huh?

ionic copper
brazen niche
#

Really my brain got rocked it's hard to think clearly. Thank you

#

Ok do I just ./sshrd.sh

ionic copper
#

no

#

find gaster in Darwin/

#

gaster -pwn

brazen niche
#
usb_timeout: 5
usb_abort_timeout_min: 0
Usage: env ./gaster options
env:
USB_TIMEOUT - USB timeout in ms
USB_ABORT_TIMEOUT_MIN - USB abort timeout minimum in ms
options:
reset - Reset DFU state
pwn - Put the device in pwned DFU mode
decrypt src dst - Decrypt file using GID0 AES key
decrypt_kbag kbag - Decrypt KBAG using GID0 AES key
#

Oh I see

#

is goin

ionic copper
#

whoops, no -

#

just gaster pwn

brazen niche
#
usb_timeout: 5
usb_abort_timeout_min: 0
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
ionic copper
#

homepod should be in dfu mode

brazen niche
#

ok sick so now I

ionic copper
#

if not, could be a usb issue

#

so then if you get you can run untrusted images

#

if done correctly

brazen niche
#

should it still be waiting at that by now?

ionic copper
#

if gaster is saying "REBOOT" "RESET"

#

then try rebooting homepod, reset in dfu mode

#

might need to power cycle the unit

brazen niche
#

why dont I just boot the thing upside down for dfu?

ionic copper
#

you could do that

brazen niche
#

🙃

ionic copper
#

hopefully gaster sees it and pwns it

brazen niche
#

oh shit gaster is gasterin

ionic copper
#

good

brazen niche
#

Found the USB handle.
Now you can boot untrusted images.

ionic copper
#

good

brazen niche
#

Yessurr

#

ok decrypt now?

ionic copper
#

gaster decrypt_kbag 80844783D569382B3EAC225C16480E1B15519C867EEE2B68E21D405F7AF3A934C1FE3469D36D8020D867E6C261823CE39B20F37DEB92D818474E868B5E0611DDC050D75BB43A72E9D9656DEA7F6A230D41B3B6A40A337C54EBDDA63FB5AA5ADA

brazen niche
#

hmm

#
usb_timeout: 5
usb_abort_timeout_min: 0```
ionic copper
#

yeah

#

power cycle, place back in dfu

#

then just type it as is

#

at least gaster works though

#

i think the way it works is it pwns and decrypts instead of pwn first, then decrypt

brazen niche
#

Sorry Im not clear what exactly I do next
boot it in dfu mode again
then just run the decrypt_kbag command?

ionic copper
#

yes

brazen niche
#

Im getting the same results as the last quote

ionic copper
#

try again

brazen niche
#
usb_timeout: 5
usb_abort_timeout_min: 0
nic@Nics-MacBook-Pro Darwin % ./gaster decrypt_kbag 80844783D569382B3EAC225C16480E1B15519C867EEE2B68E21D405F7AF3A934C1FE3469D36D8020D867E6C261823CE39B20F37DEB92D818474E868B5E0611DDC050D75BB43A72E9D9656DEA7F6A230D41B3B6A40A337C54EBDDA63FB5AA5ADA
usb_timeout: 5
usb_abort_timeout_min: 0
nic@Nics-MacBook-Pro Darwin % ./gaster decrypt_kbag 80844783D569382B3EAC225C16480E1B15519C867EEE2B68E21D405F7AF3A934C1FE3469D36D8020D867E6C261823CE39B20F37DEB92D818474E868B5E0611DDC050D75BB43A72E9D9656DEA7F6A230D41B3B6A40A337C54EBDDA63FB5AA5ADA
usb_timeout: 5
usb_abort_timeout_min: 0
nic@Nics-MacBook-Pro Darwin % ./gaster decrypt_kbag 80844783D569382B3EAC225C16480E1B15519C867EEE2B68E21D405F7AF3A934C1FE3469D36D8020D867E6C261823CE39B20F37DEB92D818474E868B5E0611DDC050D75BB43A72E9D9656DEA7F6A230D41B3B6A40A337C54EBDDA63FB5AA5ADA
usb_timeout: 5
usb_abort_timeout_min: 0
nic@Nics-MacBook-Pro Darwin % ./gaster decrypt_kbag 80844783D569382B3EAC225C16480E1B15519C867EEE2B68E21D405F7AF3A934C1FE3469D36D8020D867E6C261823CE39B20F37DEB92D818474E868B5E0611DDC050D75BB43A72E9D9656DEA7F6A230D41B3B6A40A337C54EBDDA63FB5AA5ADA
usb_timeout: 5
usb_abort_timeout_min: 0
nic@Nics-MacBook-Pro Darwin % ./gaster decrypt_kbag 80844783D569382B3EAC225C16480E1B15519C867EEE2B68E21D405F7AF3A934C1FE3469D36D8020D867E6C261823CE39B20F37DEB92D818474E868B5E0611DDC050D75BB43A72E9D9656DEA7F6A230D41B3B6A40A337C54EBDDA63FB5AA5ADA
usb_timeout: 5
usb_abort_timeout_min: 0
nic@Nics-MacBook-Pro Darwin % 
ionic copper
#

unplug usb, replug

brazen niche
#

hmm same so far

ionic copper
#

could be homepod in odd-ball state too

#

if still nothing, try

gaster decrypt_kbag 23134BBAA48F8EEC20565F31B87A8109440E624189591D32603C718BB27483CFD936857B9FBFF936D6E9EF2907C95FC6 843B854E32E249E22CF33ED3029D003DCCA70590F14066B3F5220D4DBA5F9A5DBF2B8210FBBBB60F0A041B77124649EC

#

or

#

gaster decrypt_kbag A6B04CA5452BDD31F3E6CF7114179AC53D0B65543B7E55D795B7A6F8BD3B158819845C285D3175C0D1246AFAB508D269 DFC385AAEEF2008EB469A23068DFC5C6C1B9B6DC6209D6E7E54CBFADE20687D0DDD21802014A26CDD123AC8592B41463

brazen niche
#

Ok got something new on this attempt

843B854E32E249E22CF33ED3029D003DCCA70590F14066B3F5220D4DBA5F9A5DBF2B8210FBBBB60F0A041B77124649EC
usb_timeout: 5
usb_abort_timeout_min: 0
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7000
Found the USB handle.
Stage: RESET
ret: true
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7000
Found the USB handle.
Stage: SETUP
ret: true
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7000
Found the USB handle.
Stage: SPRAY
ret: true
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7000
Found the USB handle.
Stage: PATCH
ret: true
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7000
Found the USB handle.
Now you can boot untrusted images.
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
Found the USB handle.
IV: ED8EAA4BD9D8DCB1F6B283594AFC03CD, key: CC2382FB803CFD11EF00A238D037B74B7B0E1D26D1DB4FE3D07B1D99D54D71FC
zsh: command not found: 843B854E32E249E22CF33ED3029D003DCCA70590F14066B3F5220D4DBA5F9A5DBF2B8210FBBBB60F0A041B77124649EC```
ionic copper
#

BOOM!

vale yoke
#

Woo

ionic copper
#

so it's on 13.4.6

brazen niche
#

Im betting a lot of the bricked ones will be somehwere stuck between 13 and 14 since that's when most of the reports started

ionic copper
brazen niche
#
DFC385AAEEF2008EB469A23068DFC5C6C1B9B6DC6209D6E7E54CBFADE20687D0DDD21802014A26CDD123AC8592B41463
usb_timeout: 5
usb_abort_timeout_min: 0
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7000
Found the USB handle.
Now you can boot untrusted images.
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
Found the USB handle.
IV: DDE91F4891D8E670CCB0676D2153199B, key: 423464E66D5D664C012E3BF9554129E60A83CB700C9A08F71374B9FECEECAADB
zsh: command not found: DFC385AAEEF2008EB469A23068DFC5C6C1B9B6DC6209D6E7E54CBFADE20687D0DDD21802014A26CDD123AC8592B41463
ionic copper
#

cool, give me a sec

ionic copper
brazen niche
#

oohhhhh buddy

ionic copper
vale yoke
#

So that key allows you to decrypt the firmware OTA file? Cool

ionic copper
#

the key allows you to decrypt a file passed via dfu in order to upload as an unsigned image

#

this then allows you to get around signature checks

#

aka = install custom firmware

vale yoke
#

Ohhhh. Why doesn’t SSHRD have to do that for iPhones then? When I used it on my 6 I didn’t have to do any of this

#

Oh wait I get it now

#

People have already done it for the iPhone

ionic copper
#

i got ibss, but not ibec

#

so it's ./gaster decrypt_kbag 23134BBAA48F8EEC20565F31B87A8109440E624189591D32603C718BB27483CFD936857B9FBFF936D6E9EF2907C95FC6843B854E32E249E22CF33ED3029D003DCCA70590F14066B3F5220D4DBA5F9A5DBF2B8210FBBBB60F0A041B77124649EC

#

and

#

./gaster decrypt_kbag A6B04CA5452BDD31F3E6CF7114179AC53D0B65543B7E55D795B7A6F8BD3B158819845C285D3175C0D1246AFAB508D269DFC385AAEEF2008EB469A23068DFC5C6C1B9B6DC6209D6E7E54CBFADE20687D0DDD21802014A26CDD123AC8592B41463

#

just want to make sure, i downloaded too many otas and got 'em mixed up

brazen niche
#

neither of those worked

#

oh sorry

#

first one

#

./gaster decrypt_kbag 23134BBAA48F8EEC20565F31B87A8109440E624189591D32603C718BB27483CFD936857B9FBFF936D6E9EF2907C95FC6
843B854E32E249E22CF33ED3029D003DCCA70590F14066B3F5220D4DBA5F9A5DBF2B8210FBBBB60F0A041B77124649EC
usb_timeout: 5
usb_abort_timeout_min: 0
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
CPID: 0x7000
Found the USB handle.
Now you can boot untrusted images.
[IOKit] Waiting for the USB handle with VID: 0x5AC, PID: 0x1227
Found the USB handle.
IV: ED8EAA4BD9D8DCB1F6B283594AFC03CD, key: CC2382FB803CFD11EF00A238D037B74B7B0E1D26D1DB4FE3D07B1D99D54D71FC
zsh: command not found: 843B854E32E249E22CF33ED3029D003DCCA70590F14066B3F5220D4DBA5F9A5DBF2B8210FBBBB60F0A041B77124649EC

#

but second one not worky

#

when I copy your first one it doesnt work. the one I ran works, I cant tell whats different

#

mine
23134BBAA48F8EEC20565F31B87A8109440E624189591D32603C718BB27483CFD936857B9FBFF936D6E9EF2907C95FC6
843B854E32E249E22CF33ED3029D003DCCA70590F14066B3F5220D4DBA5F9A5DBF2B8210FBBBB60F0A041B77124649EC
yours
23134BBAA48F8EEC20565F31B87A8109440E624189591D32603C718BB27483CFD936857B9FBFF936D6E9EF2907C95FC6843B854E32E249E22CF33ED3029D003DCCA70590F14066B3F5220D4DBA5F9A5DBF2B8210FBBBB60F0A041B77124649EC

#

line break in mine

ionic copper
brazen niche
#

yeah fuck that

ionic copper
#

Think of it as unlocking a CD key for a game

brazen niche
#

the problem is the line break I think. my kbag has a line break yours is one string

brazen niche
#

thank god I was still typing one of them out SWEATSTINY

ionic copper
#

now we can have fun 👿

vale yoke
#

We should put that key in the wiki 😁

ionic copper
#

for those who don't know: these two files are required for sshramdisks

#

but i have something else in mind

spiral patio
#

So what are the unknowns at this point? At what point will we know if it’s possible or not?

spiral patio
#

Cool, I’m curious how the process works if and when it’s finished

ionic copper
#

Give me a few hours

brazen niche
#

do you even have a first gen homepod? is this really about to be fixed by someone that doesn't even own the thing??

ionic copper
#

It does however, work at the same principal of devices that I do own

#

So that works out imho

vale yoke
#

I don’t own any HomePods either… although if this works I’m gonna start searching EBay for some cheap ones with the same issue 🤔

#

I’ve heard they sound great but I haven’t been able to justify spending $300 on a speaker…

quiet sedge
#

is it possible to downgrade the firmware on an apple tv 4th gen?

ionic copper
quiet sedge
#

i have the usb port just not sure what i need to do

#

i'd like to get it jailbroken

ionic copper
#

what version are you currently on?

quiet sedge
#

17.2

ionic copper
#

ah okay

quiet sedge
#

wondering if there is an ad free youtube app

ionic copper
quiet sedge
#

whats the latest version of tvos i can install that i can jailbreak

ionic copper
#

using checkra1n

quiet sedge
#

and use itunes

ionic copper
quiet sedge
#

thanks for the help gonna give it a shot

#

whats the app store called trollstore or is it something else?

ionic copper
ionic copper
quiet sedge
#

yeah

ionic copper
#

nitoTV

quiet sedge
#

thx!

ionic copper
quiet sedge
#

just reading the install instructions on ipsw

ionic copper
#

are you using mac or pc

quiet sedge
#

mac

ionic copper
#

press options and click "restore"

quiet sedge
#

kk

#

i dont see it in finder

#

when i plug it into my mac and into usb-c

ionic copper
#

inside mac terminal

#

might have to install it

quiet sedge
#

Warning: No available formula with the name "idevicerestore". Did you mean ideviceinstaller?
==> Searching for similarly named formulae and casks...
==> Formulae
ideviceinstaller

To install ideviceinstaller, run:
brew install ideviceinstaller

#

is it ideviceinstaller

ionic copper