#Question for the SHSH system

19 messages · Page 1 of 1 (latest)

sly nest
#

I am trying to make sense out of the SHSH system so bear with me

Suppose an obscure scenario where the GID key for a set of devices was leaked and a way to extract the UID key from said devices was found. Would that make the entire system collapse for those devices?

sly nest
#

Bump
Geniuses enlight me with your knowledge

plush vine
#

those are used to decrypt firmware, not sign them

#

shsh blobs are captured responses using sha-1 (a9 and older) or sha-384 (a10 and newer)

sly nest
#

Isn't that TOO many keys?

plush vine
#

each device series has a private key

#

iphone 11, 11 pro, 11 pro max, etc

sly nest
#

Ah alright

#

If that private key was to get leaked in some way, would that make the system collapse for a device series?

plush vine
#

yes

sly nest
#

Alright thanks

tame rock
sly nest
tame rock
#

I know.🥲 But I wonder what the shsh System has to do with security. I mean it just prevents the user from installing a custom os or an old version of ios. An attacker couldn't make use of it if it was possible because one would need physical access and the data would probably get wiped and the owner would notice. On Android it is possible to modify the system if you unlock the bootloader but that would result in a warning message on every bootup so you will notice that someone modified your phone when you left it alone.

plush vine
#

it would be fun for downgrading but you would not be able to store any sensitive data on your phone