It seems that the developer behind antid0te, the future jailbreak solution based on ASLR (Address Space Layout Randomization), has secretly been working on an iOS 4.3 untethered jailbreak. His name is Stefan Esser aka @i0n1c who has just released a demo video on YouTube showing his success in discovering a new untethered exploit. However, Stefan plans to save it until Apple releases iOS 4.3.1. He tweeted the following:
“iOS 4.3 *untethered* Alpha Jailbreak Video (sorry camera suxx) https://www.youtube.com/watch?v=71boAlfZIiU “
“With Apple already baking 4.3.1 the first one releasing an iOS 4.3 jailbreak will pretty much burn the exploit :P”
“Well Apple should release 4.3.1 very soon, because tomorrow everybody knows that @0xcharlie popped an iPhone 4 at #pwn2own through Safari.”
Meanwhile, the unlock solution for iPhone 4 on iOS 4.3 which was in the works by iPhone Dev-Team for basebands 2.10.04, 3.10.01 and 4.10.01 hasn’t turned out to be good enough. However, yet another (even better) exploit is being worked on by the Dev-Team which supposedly will unlock the iPhone 4 forever. Check out the following Q&A related to this new iPhone 4 unlock’s progress (via @veeence) :
Since there is a lot of confusion out there, and since I’m repeating myself all the time (which I do not really like), I made this little write up of questions that are continuously being asked (my personal FAQ). Please not that this is a global explanation. Don’t try to argue with me on specific details.
1. What happened?! I thought the unlock for basebands 02.10.01 & 03.10.01 would be released within the next 2 weeks?
As you know the Dev-Team (MuscleNerd) have been working on the unlock for quite a while now. They were making great progress on the unlock, but they found out that they (accidentally) unlocked “one particular SIM card” instead of the baseband itself. Which means that the unlock would only be an unlock you could use with MuscleNerd’s T-Mobile SIM. So, useless. If the unlock would unlock the baseband instead of “the SIM”, it’d probably be out within 2 weeks (reasonable timeframe which they had hoped). But things turned out to be different. Basically these <2 weeks predictions were a lack of information.
2. What is this NCK-key cracking? How does it work?
The NCK-key is the key generated by Apple if you’d officially unlock you iPhone, and with officially I mean, via your carrier. This “NCK-unlock” method is known over a few years now, actually since geohot started working on unlocking the iPhone 2G. He developed a program that could “crack” this 15 digits long key and unique for every device. Geohots NCKBF program could do around 100,000 keys/second which would produce a hit in many years, or complete a search in 317 years. To get to a point where this is actually doable we would need many orders of magnitude of improvement. Even if you use a PS3 (would we still want to use this??) or special hardware (within 1,000 US$ range) you will only get an improvement of 20-100 times.. which doesn’t help much.
Now, luckily, with the exploits they have now, they can’t unlock your baseband, but they *can* capture more information from the baseband to speed up this cracking process. Since the NORID and CHIPID (unique for every device) are known, you’d apparently only have to check 40 more bits (5 digits). A 40 bits key is theoretically crackable on “home hardware” within a week (24/7). The downside of this approach is that you’ll have to keep your computer turned on, and your iPhone has to be connected. And that is the reason why they never tried it before. Please note that this method is completely theorical and has been NOT tried at all till this moment.
3. Now what? Should I sell my locked iPhone 4?
I’d wait for more information on this “NCK-unlock”. Right now it’s pretty vague what timeframe we’re talking about. If the Dev-Team can pull this method off, it’d be very promising for those waiting for an unlock. If this method turns out to be not doable, I’d consider selling your iPhone 4 and save up for a factory unlocked iPhone 5.
4. Do you think there is every going to be an unlock?
Of course. But that’s unlikely to be any time soon (with soon being <1 month).
5. If the NCK method fails, how long do you think it will take for the Dev-Team to unlock the iPhone 4?
No ETA at all. Could be a few weeks, but it could easily be a few months as well.
Stay tuned for more unlock and jailbreak updates for your iPhone on iOS 4.3 / 4.3.1.