|
|
|
|
|
by cbsmith
3761 days ago
|
|
There is nothing in the digital signature check that allows it to be locked to a device, so that's logic that has to kick in AFTER the trusted layer has validated the code. At that point, it is a simple matter of altering the device ID check in unsecured RAM and you've now got another cracked phone. |
|
So by not signing any requests for that particular firmware hash, Apple can effectively neuter that firmware and make sure it's never installed anywhere but on the target phone.
The problem is though: If apple can be compelled to do this once, they can also be compelled to do this any other time.