Some update on the SEP tool I’ve promised:
Tethered blackbird downgrades: ✅
Untethered blackbird downgrades with SHSH blobs: ✅
Decrypt SEP KBAGs: ✅
What’s left: fix up A10 support, optimise exploit on A9 to be more reliable and clean up the code.
ETA: when it’s done, 🔜
@serhatisb Tethered only, if you don't have saved blobs for the relevant versions.
But if you saved blobs from way back when, this will now (with a lot of work) effectively allow downgrading permanently untethered, for those APTicketed versions only.
#checkm8 in two moves: iBSS/iBEC/iLLB/iBoot are effectively same image. What's needed now is to dump/decrypt each device class (A7-11)'s iBoot and patch out the part which verifies APTicket/IMG4 signatures, or
(Better yet) create a dynamic pathfinder.
Then the real game begins.
@AppleDry05@zhuowei Have you ever tried to grab apticket using kloader64, like we do with shsh from 32bit devices? I wonder if anyone has accomplished this
@rA9_main@thejailbreakhub The gist is gone. Do you have info to share?
I have iOS 14 blobs for a couple devices. And a couple 5S on iOS 8.x I’d love to be able to restore.
Impossible has been done.
First successful blackbird downgrade on iPhone 6s to iOS 10.0.1 tethered without SHSH blobs. It was painful but it was worth it at the end :))
W/ passcode fully working.
Following instructions on https://t.co/KurqUamoYG, I could successfully convert dumped blobs into a .plist file that can *hopefully* be used with idevicerestore later to downgrade.