Getting JTAG on the iPhone 15

Поделиться
HTML-код
  • Опубликовано: 30 сен 2023
  • In this video we explore how to get access to the JTAG interface on the new iPhone 15!
    Special thanks to aunali1 & h0m3us3r, the Asahi Linux Project and Marc Zyngier!
    Sign-up to the hextree.io waiting list here: hextree.io/
    Links:
    - Twitter: / ghidraninja
    - Patreon: / stacksmashing
    - Modified Chip Scrutinizer Firmware: github.com/stacksmashing/cs-s...
    - macvdmtool patched for the iPhone 15: github.com/stacksmashing/macv...
    - My DEF CON talk on Tamarin Cable: • DEF CON 30 - stacksmas...
    - The secrets of Apple Lightning: • The secrets of Apple L...
    - Central Scrutinizer Hardware: git.kernel.org/pub/scm/linux/...
    - Central Scrutinizer on Tindie (does not work with iPhone 15 without modifications): www.tindie.com/products/aaafn...
  • НаукаНаука

Комментарии • 276

  • @muditbatra1681
    @muditbatra1681 9 месяцев назад +438

    Working in a semiconductor company myself, it’s really nice to see how much effort you put in this with literally 0 official documentation available with you. Please do a follow up as well on your progress.

    • @bassyey
      @bassyey 9 месяцев назад +2

      @@shueibdahir Pay is better in software lol. I left embedded field myself.

    • @janossydnepthalipao4277
      @janossydnepthalipao4277 9 месяцев назад

      I mean, I was about to say the same to him.

    • @shueibdahir
      @shueibdahir 9 месяцев назад +1

      @@bassyey How about hardware? Like sysadmin or some sort of it engineer? Do they pay aswell as software?

    • @farawayskies
      @farawayskies 8 месяцев назад +1

      @@bassyey Did the same. Worked in embedded a couple years and switched to software. Didn't do it for the money, although I did immediately get a six figure salary.

    • @farawayskies
      @farawayskies 8 месяцев назад +1

      @@shueibdahir I'd argue sysadmin does not pay nearly as well as software on average. I think you'd need to be a senior sysadmin to make what an entry level software engr can make.

  • @SomeDork353
    @SomeDork353 9 месяцев назад +648

    It's not even been 2 weeks, give poor Tim Cook a break lmao. Very cool work!

    • @djispro4272
      @djispro4272 9 месяцев назад +28

      Ah yes, Tim Cook is poor!

    • @Adolf1Extra
      @Adolf1Extra 9 месяцев назад

      Mr Tim Apple is merely an expendable pawn partaking in techno-feudalism to please his anti-capitalist shareholder lords.

    • @JPS13Laptop
      @JPS13Laptop 9 месяцев назад +21

      @@djispro4272 It's a figure of speech...

    • @Corei14
      @Corei14 9 месяцев назад +20

      *Tim Apple

    • @HyperVectra
      @HyperVectra 9 месяцев назад +2

      @@Corei14 lol you beat me too it!

  • @r.g.thesecond
    @r.g.thesecond 9 месяцев назад +214

    Amazing! Kudos to Asahi project as well for their dedication. Have a happy and productive hacking time!

    • @realcartoongirl
      @realcartoongirl 9 месяцев назад +2

      can you speak regular people language

  • @aettic
    @aettic 9 месяцев назад +33

    Interesting stuff. It's always so cool to me to see folks who have specialized knowledge in the areas where hardware and software meet. Even just reading those notes from the documentation (From the Texas team, if I understood correctly?) about the 206 maybe being SWD is so cool to see: Playing around with hardware and probing it for signs of how it might work. Very cool.

  • @majdps995
    @majdps995 9 месяцев назад +9

    Very well put video, straight to the point and no music. +1 sub.

  • @CyReVolt
    @CyReVolt 9 месяцев назад +7

    Well done! 🥳 It's so cool to see the community succeed together.
    Also I know that today is a holiday. I expect a breakthrough later tonight. :D
    Cheers ausm Pott! :)

  • @crusher70
    @crusher70 9 месяцев назад +32

    Fascinating work, well done getting this far. Can’t wait to see how far you can go. Good luck

    • @stacksmashing
      @stacksmashing  9 месяцев назад +8

      Thank you! :)

    • @crusher70
      @crusher70 9 месяцев назад

      @@stacksmashingI feel a visit to DigiKey is imminent 😂

  • @charon7320
    @charon7320 8 месяцев назад +2

    u are doing amazing work with so little documentation, literally a tech detective.

  • @blackhorseteck8381
    @blackhorseteck8381 9 месяцев назад +8

    Man, you brought me back memories of JTAG on the PS2 and X360, cool video though!

  • @saschakaupp
    @saschakaupp 9 месяцев назад +94

    Now I want a new iPhone, just to be able to use JTAG via USB-C. No clue what to do with it, though.

    • @fffUUUUUU
      @fffUUUUUU 9 месяцев назад +7

      But maaaam!😢 It's for the homework!

    • @alfaxgo
      @alfaxgo 9 месяцев назад +3

      It's for getting some of the Android features without having to wait for Apple to announce the same features as great improvements on iPhone 17.

    • @a17waysJackinn
      @a17waysJackinn 9 месяцев назад

      idk im noob too no idea what hes talking, but "jailbreak" control hardware and overclocking chips or smth I GUESS..

  • @StormBurnX
    @StormBurnX 9 месяцев назад +27

    Excellent work. I was curious how long it would be, since the Macbooks and iPads are M1/etc rather than A-series chips. Quite interesting all the same!

  • @duckydude20
    @duckydude20 9 месяцев назад +3

    so facinated by you guys. its my dream to do something like this someday. but i lack so much in everything...

  • @pikniknyok9203
    @pikniknyok9203 9 месяцев назад +1

    omg i never think usb c so complex like this 😮 thanks mate for the video

  • @csbluechip
    @csbluechip 9 месяцев назад +197

    There seems to be virtually zero courses on hardware hacking and reversing. I really hope your hextree project changes this :)

    • @stacksmashing
      @stacksmashing  9 месяцев назад +28

      We hope so too! :)

    • @prakharmishra3000
      @prakharmishra3000 9 месяцев назад +17

      its actually pretty diverse depending on what you want to hack, so its difficult to make a generalised tutorial for hardware hacking and most people just learn it themselves

    • @jameshatton4405
      @jameshatton4405 9 месяцев назад +4

      Yes I agree. I think that's the highlight of this video actually, not the iPhone 15 hacking itself (which is still awesome)

    • @phr3ui559
      @phr3ui559 9 месяцев назад

      yes

    • @mattmurphy7030
      @mattmurphy7030 9 месяцев назад +5

      There are entire university degrees dedicated to embedded engineering lol

  • @TheTarrMan
    @TheTarrMan 9 месяцев назад +1

    Awesome work you guys are doing.

  • @bekircandal3528
    @bekircandal3528 9 месяцев назад

    dude that was awesome. cant wait for another videos!

  • @thomasandrews9355
    @thomasandrews9355 9 месяцев назад

    LOL lot of comments which seem to have the "oh iphone owned" vibe... great work as Always

  • @rickoneill4343
    @rickoneill4343 9 месяцев назад

    Just joined the channel. Can't wait to see what you have been up to!

  • @f.d.9326
    @f.d.9326 9 месяцев назад +1

    Insane stuff man! I wonder how one can know so much!

  • @Eaton.
    @Eaton. 9 месяцев назад +5

    i barely understand this stuff but im forever interested and grateful for the work you put in discovering these things.

  • @vassoharalambous5982
    @vassoharalambous5982 9 месяцев назад +3

    This is brilliant work!! Bravoo

  • @deez6005
    @deez6005 9 месяцев назад

    I love your channel. Keep up the good work

  • @nicknorthcutt7680
    @nicknorthcutt7680 4 месяца назад

    Wow you are seriously talented, very interesting man!

  • @imawesome580
    @imawesome580 9 месяцев назад

    I jtaged my xbox off youtube tuttorials so this is extremely interesting and I hope you get the Jtag!

  • @NeverGiveUpYo
    @NeverGiveUpYo 9 месяцев назад

    Yes! What a video! Thanks for this!!

  • @user-lo4er8wy9l
    @user-lo4er8wy9l 9 месяцев назад +1

    fantastic work.

  • @justHeisen
    @justHeisen 9 месяцев назад +2

    I am very interested in these kinds of videos.

  • @sneauxburrow
    @sneauxburrow День назад

    Great video, thank you 🙏

  • @hyperkiko
    @hyperkiko 9 месяцев назад

    FINALLY, a new video!!!!

  • @WhoaMykey
    @WhoaMykey 9 месяцев назад +1

    Tim Cook is filthy rich and needs no breaks! This needs to happen for research and repair purposes! To the people! Bless you for your hard work! I thank you 🙏

  • @jsandppr
    @jsandppr 9 месяцев назад

    Love the Zappa reference!

  • @v1x4z
    @v1x4z 9 месяцев назад

    Pretty neat stuff!

  • @MediaCollection
    @MediaCollection 9 месяцев назад +2

    Love the zappa reference👌🏼

    • @stacksmashing
      @stacksmashing  9 месяцев назад

      Which Zappa reference? 😅 you are the second person mentioning it

    • @MediaCollection
      @MediaCollection 9 месяцев назад +1

      @@stacksmashing “The Central Scrutinizer”

    • @stacksmashing
      @stacksmashing  9 месяцев назад

      Ahhhhh thank you

  • @RazgrizDuTTA
    @RazgrizDuTTA 9 месяцев назад +1

    Hardware hacking is so fun! I have never done things that complex but even small hacks are fun!

  • @Unbaguettable
    @Unbaguettable 8 месяцев назад

    I understood absolutely nothing but looked interesting, cool video

  • @betogamer08
    @betogamer08 8 месяцев назад

    Good work!

  • @prateekSpace
    @prateekSpace 9 месяцев назад

    very in-depth video! get new subscriber 🎉

  • @lucasimark7992
    @lucasimark7992 9 месяцев назад

    Oh wow, that was nice!

  • @xenozelda0102
    @xenozelda0102 9 месяцев назад

    Awesome man!

  • @BAAAM101
    @BAAAM101 8 месяцев назад

    Amazing work. I’d like to see if youre able to jtag the new iPad with usb c. It offers more features with the usb port than the iPhone so you just might get a different result

  • @randallbro6749
    @randallbro6749 9 месяцев назад +1

    Nice didn't think it was possible

  • @johnnykernel4557
    @johnnykernel4557 9 месяцев назад +1

    Amazing work done!

  • @hanspeter24
    @hanspeter24 9 месяцев назад

    stacksmashing the best!!!

  • @vxrlorxnxrreal
    @vxrlorxnxrreal 9 месяцев назад

    sehr interessantes video!

  • @ArthurKhazbs
    @ArthurKhazbs 9 месяцев назад

    Good luck exploring the possibilities hidden inside the fruits of this corporation!

  • @Magnom365
    @Magnom365 9 месяцев назад

    You are quick!

  • @kwiky5643
    @kwiky5643 9 месяцев назад

    Great stuff

  • @ACiDFiRE
    @ACiDFiRE 9 месяцев назад

    Cool keep grinding lad

  • @dhruvgulati1667
    @dhruvgulati1667 9 месяцев назад

    Hey could you please explain more about debugging and exploiting.

  • @limebulls
    @limebulls 8 месяцев назад

    What do you recommend for beginners to start learning electronics?

  • @piholino
    @piholino 9 месяцев назад

    I have no idea what the hell you are doing but it was interesting to watch.

  • @kritikusi-666
    @kritikusi-666 9 месяцев назад

    this is awesome.

  • @XCTDEV
    @XCTDEV 9 месяцев назад

    Already knew it! but may brick after flash Jtag

  • @ErtugrulOzdemir-mf1gl
    @ErtugrulOzdemir-mf1gl 9 месяцев назад

    really cool!

  • @iamfinky
    @iamfinky 9 месяцев назад

    Very exciting! I'd be interested to know what is possible with JTAG.

    • @csbluechip
      @csbluechip 9 месяцев назад

      JTAG generally: You get direct control of the CPU, so your imagination is the limit... Specifically here: Who knows how open/crippled it is yet ;)

  • @Marvinzock34
    @Marvinzock34 9 месяцев назад

    YOOOO NEW VIDEO

  • @filipenicoli_
    @filipenicoli_ 9 месяцев назад

    Amazing!

  • @jerromerro9405
    @jerromerro9405 9 месяцев назад +1

    Good to know that you didnt finish the work , i have to know that checkm8 didnt work on the “newer“ iphones
    But i thought for the Usb-c “problem“ on the TamarinCable FW where only changing the cables and changing some code .. ok Its Not so easy
    But on iPhone 15 swd is Open i think thats a good Start ..

  • @nilsmertens6253
    @nilsmertens6253 9 месяцев назад

    Nice, keep going

  • @gamerstar8311
    @gamerstar8311 9 месяцев назад

    Cool stuff

  • @eyesoffloraandfauna8728
    @eyesoffloraandfauna8728 8 месяцев назад

    Make videos for best sideload method

  • @HoZyVN
    @HoZyVN 9 месяцев назад +1

    Amazing

  • @shortgrowinchannel101
    @shortgrowinchannel101 9 месяцев назад

    My dream iphone😊

  • @JonMasters
    @JonMasters 9 месяцев назад

    Excellent

  • @dcfix35
    @dcfix35 9 месяцев назад

    Excellent ✅✅

  • @jameshatton4405
    @jameshatton4405 9 месяцев назад +6

    This is so awesome. I would really like to be able to use hardware hacking as a business?
    So if you can get JTAG to iPhone 15, does that mean that the boot loader can be reverse engineered and the iPhone could essentially run non-apple or customised firmware?

    • @sol_xz
      @sol_xz 9 месяцев назад +1

      imagine this on ipad with windows for arm

    • @overPowerPenguin
      @overPowerPenguin 9 месяцев назад

      ​​@@sol_xzthis is not how it works. You need Windows drivers and a lot of patches to make everything run, even if you can load an custom EFI boot.
      It's insane amount of work and don't worth it, because, in the end, it's cheaper and faster to buy an Windows tablet that probably supports also Linux.

  • @timboffff
    @timboffff 9 месяцев назад

    amazing work

  • @atinder2006
    @atinder2006 9 месяцев назад +1

    When they added usb c and controller embedded into cpu i had feeling they are already worried about security.

  • @H8RSAPPRECIATE
    @H8RSAPPRECIATE 8 месяцев назад

    I know you said it’s not a exploit but I realized once they switched to USB C I assumed it might make it easier for someone to find a exploit that way and since you can connect to more devices than with a lightning cable ( not saying I know anything or claiming to be a expert)

  • @jarredallen
    @jarredallen 9 месяцев назад +18

    its not uncommon ( for my line of work) to see a jtag locked physically. maybe this is the case right here. some pull up resistor to some pads might be needed.

    • @stacksmashing
      @stacksmashing  9 месяцев назад +14

      Ah in this case it's a bit more complicated - you can read up on the demotion of the iPhone X using checkm8 :)

  • @Freedom-of-Thought
    @Freedom-of-Thought 9 месяцев назад

    Can you teach how to jailbreak iOS 17? Thank you

  • @jameshatton4405
    @jameshatton4405 9 месяцев назад +6

    I see you've done this with the iPhone 15, but I'm curious if JTAG can be found a similar way on Samsung Galaxy devices and if one could possibly access the KNOX e-fuse data store on a galaxy device? So essentially if the Knox bit has been tripped; that section in the boot loader can be reversed?
    This is currently the only thing stopping me from going to GraphineOS and being able to support encryption and have as much support with the boot loader security as say a supported Pixel device?

    • @trevorgray3681
      @trevorgray3681 9 месяцев назад

      I don't remember much about it and doubt it's relevant anymore, but I remember being able to not trip knox on my s6 edge. I'm sure whatever exploit was there has been fixed though.

    • @jameshatton4405
      @jameshatton4405 9 месяцев назад

      @@trevorgray3681 I would like to reverse the boot loader and how it trips the Knox because it's an implementation that's still in practice today? I've built ROMs and custom firmware for Android and have bucket loads of tools for just about any kind i of hacking and reversing software known? I've also got experiencing dumping binaries by direct chip reading and FlashROM using raspberry Pi SPI interface + voltage changer and read from diagnostic ports on MacBooks etc. Then Hex hacking the dumped binary and then writing my own stuff back on it to unblock a forgotten password? I can find out the voltages etc but if I could possibly talk between his created device and using USB-C then I can certainly attempt to play around? Have a little snoop & sniff and see what's up yo? See it could mean I could possibly make any Samsung a private phone like the Google Pixel with GrapheneOS. I can already rebuild and change the GrapheneOS to work on my Samsung or any Samsung even if the firmware doesn't support it? I know what partitions to write to, I can build a custom recovery. I can impart binaries etc etc and get what ever I need working? It's the being able to support encryption from recovery that is the most important? So it's worth sniffing even if not for Knox? It's just more enticing to offer should anyone be interested in using their Samsung as a private phone without needing to purchase a Pixel to so?
      In Australia Pixels are for fanatics and people who purchased it outright with money and not on a plan? That's a very very tiny slice of the Australian market unfortunately?
      Sorry but I figured I may as well spew my thoughts all over the RUclips comments cause I'm Autistic as fuck and have narcolepsy and you've got me on a medication is working don't know where to stop moment? So sucks to you if you've read this far 😛

  • @2.7petabytes
    @2.7petabytes 9 месяцев назад

    Zappa would be proud 😂

  • @jerromerro9405
    @jerromerro9405 8 месяцев назад

    I have a Short question , i Hope for an answer .
    The iPhone15 has 5g Right?
    Can i use this for sniffing 5g packets like osmocombb for gsm??

  • @robertclarkguitar
    @robertclarkguitar 8 месяцев назад

    Nice. ❤😮

  • @mattsold1267
    @mattsold1267 9 месяцев назад +1

    What do you need to study to learn all this stuff? The automotive field is heavy on this type technology and I want to get be able to heavily study these systems but there isn’t enough info online?? Some pls respond

    • @elbert5208
      @elbert5208 8 месяцев назад

      It's a secretive field

  • @cleardd
    @cleardd 9 месяцев назад

    Very cool

  • @ishdemon_
    @ishdemon_ 9 месяцев назад +1

    man's voice evolved around 6:48 lmao

  • @NieuNotNew
    @NieuNotNew 9 месяцев назад

    thats huge, the central scrutinizer. that pcbs purpose is to enforce all the laws that havent been passed yet

  • @KpFriendly
    @KpFriendly 9 месяцев назад +3

    It’s so simple I’m completely able to follow this with 5 years of experience
    Jk
    This stuff seems really complicated but interesting, as someone getting into cyber security, you definitely got me more interested in the hardware side of it all, I learned alot from this video!

  • @NewGroup78
    @NewGroup78 9 месяцев назад

    How and where do we learn hardware hacking and all these things?? please tell me.

  • @alvarotorijano
    @alvarotorijano 8 месяцев назад

    Upload more videos!!!

  • @YHK_YT
    @YHK_YT 9 месяцев назад

    You have to put the lightning port back

  • @kipchickensout
    @kipchickensout 8 месяцев назад

    Will 0xT have a free trial?

  • @Phrew
    @Phrew 9 месяцев назад +10

    Seen this video before it was cool. ;)

  • @Malibuthe6th
    @Malibuthe6th 8 месяцев назад

    Topic aside the presentation is good but I had to turn on subtitles

    • @stacksmashing
      @stacksmashing  8 месяцев назад

      Thank you - was the voice not clear enough for you? Too fast? Happy to learn what I can improve!

    • @Malibuthe6th
      @Malibuthe6th 8 месяцев назад

      @@stacksmashing Too fast, slow down by ~10%.

  • @kdtoystore7341
    @kdtoystore7341 8 месяцев назад

    I love how he says “Central Scrutinizer” 😅

    • @stacksmashing
      @stacksmashing  8 месяцев назад

      Am I mispronouncing it? :D

    • @AngelaTheSephira
      @AngelaTheSephira 3 месяца назад

      @@stacksmashing No, you're doing it right. (At least, to an American who's heard a hell of a lot of accents and pronunciations.) No clue what he's on about.

  • @ajmalaboobacker5110
    @ajmalaboobacker5110 8 месяцев назад

    Is he tree available for sign up?

  • @bloodaid
    @bloodaid 9 месяцев назад

    Is it possible to send data from an app to the JTAG with this?

  • @gabriledyt
    @gabriledyt 9 месяцев назад

    Maybe a new full jailbreak after this?

  • @ivoxii
    @ivoxii 9 месяцев назад

    The way you say macbook is the same as the "city people" episode in south park 😂😂😂

  • @aacc8466
    @aacc8466 8 месяцев назад

    is this a way to retrieve a lost password/iCloud ? asking for a friend

  • @b_1337
    @b_1337 9 месяцев назад

    You’re awesome

  • @bameninghong-chan
    @bameninghong-chan 8 месяцев назад

    Do you have a cheap way to read and Write Bricked android, it has 11 UFS debug pins but no public layout, it is surface duo with an SDR855 and there is no public EDl loaders available

  • @jerm_
    @jerm_ 9 месяцев назад

    so whats possible with JTAG? is it similar to jailbreak?

  • @randykitchleburger2780
    @randykitchleburger2780 9 месяцев назад

    Sweet

  • @hydro5168
    @hydro5168 8 месяцев назад

    will this let me get a mod menu for Black Ops 2?

  • @annekedebruyn7797
    @annekedebruyn7797 9 месяцев назад

    iPhone 15 lightning cable mod when>?

  • @lauaall
    @lauaall 7 месяцев назад

    insane

  • @SlavGee
    @SlavGee 9 месяцев назад

    Cool!