Today MuscleNerd of iPhone dev-team has unveiled some new update regarding iPhone 4 unlock project for basebands 2.10.04 / 3.10.01, the news are related to the iPhone 4 [You must be registered and logged in to see this link.] which they are now concentrated to crack the NCK's 40 bit code. MuscleNerd has confirmed via his Twitter account that he finally got the SecZone dumper working.
[You must be registered and logged in to see this link.]
[You must be registered and logged in to see this link.]
You may ask about the meaning of these tecky expressions:
Someone Asking MuscleNerd: Anything positive coming about your NCK attempts?
MuscleNerd Replying: finally got the SecZone dumper working (turns out it's very different than in 2G/3G/3GS, where SZ was simply memory mapped)
What is the [You must be registered and logged in to see this link.]?
This is the area in the baseband where the lock state is stored.
What is [You must be registered and logged in to see this link.] Brute Force?
MuscleNerd also noted that the iPhone 4's SecZone is very different and difficult than the one of iPhone 2G / 3G / 3GS. Today's progress is definitely a new milestone. Now dev-team is working on capture the official NCK code and finally capturing after SecZone then work out an offline BF flow
This is a theoretical exploit which involves brute forcing the NCK from the seczone the CHIPID and the NORID. So far no one has made public an instance of NCK discovery using this theoretical approach.
[You must be registered and logged in to see this link.]
so the idea is: capture (a) before-seczone, (b) official NCK code (c) after-seczone. Then work out an offline BF flow
[You must be registered and logged in to see this link.]
On the other hand, you have to know that there is another hardware solution for unlocking iPhone 4 basebands 2.10.04 / 3.10.01 with [You must be registered and logged in to see this link.] you can check out full details about it in [You must be registered and logged in to see this link.].
after those steps a,b,c, then get back to the SW-based hacked unlock (and revisit BF results when they're done)
[You must be registered and logged in to see this link.]