Author Topic: Bypassing TI-Nspire RSA signatures now possible?  (Read 33575 times)

0 Members and 3 Guests are viewing this topic.

Offline compu

  • LV5 Advanced (Next: 300)
  • *****
  • Posts: 275
  • Rating: +63/-3
    • View Profile
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #15 on: March 29, 2011, 03:53:38 pm »
And how do you run 2.1 on 2.0.1?  O.O

Offline Goplat

  • LV5 Advanced (Next: 300)
  • *****
  • Posts: 289
  • Rating: +82/-0
    • View Profile
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #16 on: March 29, 2011, 03:55:47 pm »
And how do you run 2.1 on 2.0.1?  O.O
Same way I do all these hacks - modified nspire_emu.

Edit: You could theoretically do this on calc by using Home-Enter-X and sending the OS over RS232; it runs the received OS without installing it (since this has an 8MB limit, you would have to TNOC the OS)
« Last Edit: March 29, 2011, 04:00:43 pm by Goplat »
Numquam te deseram; numquam te deficiam; numquam circa curram et te desolabo
Numquam te plorare faciam; numquam valedicam; numquam mendacium dicam et te vulnerabo

Offline apcalc

  • The Game
  • CoT Emeritus
  • LV10 31337 u53r (Next: 2000)
  • *
  • Posts: 1393
  • Rating: +120/-2
  • VGhlIEdhbWUh (Base 64 :))
    • View Profile
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #17 on: March 29, 2011, 03:57:53 pm »
Nice pics Goplat!  I remember I got OS 1.1 running on OS 2.0 (both non-CAS) by replacing the image present on the calc.  The results were the same - the text was all messed up!


Offline DJ Omnimaga

  • Clacualters are teh gr33t
  • CoT Emeritus
  • LV15 Omnimagician (Next: --)
  • *
  • Posts: 55943
  • Rating: +3154/-232
  • CodeWalrus founder & retired Omnimaga founder
    • View Profile
    • Dream of Omnimaga Music
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #18 on: March 29, 2011, 04:00:06 pm »
Nice. I wish somehow it was possible to just launch an Ndless program that overwrites the entire OS content and bypass the protections...

Offline critor

  • Editor
  • LV11 Super Veteran (Next: 3000)
  • ***********
  • Posts: 2079
  • Rating: +439/-13
    • View Profile
    • TI-Planet
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #19 on: March 29, 2011, 04:01:01 pm »
Goplat, I think the "idea" is to launch a basic OS from an Ndlessed CAS OS.
Assuming we could launch the basic 1.7 OS over an Ndlessed CAS 1.7 OS, would we still have some strings problems? (the OS versions are the same... they should be very similar...)

And how do you run 2.1 on 2.0.1?  O.O

But using the Home+Enter+X combo and sending the 2.1 OS as a test image in RS232.
« Last Edit: March 29, 2011, 04:01:28 pm by critor »
TI-Planet co-admin.

Offline Goplat

  • LV5 Advanced (Next: 300)
  • *****
  • Posts: 289
  • Rating: +82/-0
    • View Profile
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #20 on: March 29, 2011, 04:02:15 pm »
Nice. I wish somehow it was possible to just launch an Ndless program that overwrites the entire OS content and bypass the protections...
Overwriting the OS in memory is easy. What do you mean by "bypass the protections"?
Numquam te deseram; numquam te deficiam; numquam circa curram et te desolabo
Numquam te plorare faciam; numquam valedicam; numquam mendacium dicam et te vulnerabo

Offline DJ Omnimaga

  • Clacualters are teh gr33t
  • CoT Emeritus
  • LV15 Omnimagician (Next: --)
  • *
  • Posts: 55943
  • Rating: +3154/-232
  • CodeWalrus founder & retired Omnimaga founder
    • View Profile
    • Dream of Omnimaga Music
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #21 on: March 29, 2011, 04:03:09 pm »
I mean RSA signatures and the like. I do not know how that stuff works, but I assume the calc checks if the OS signature is valid upon booting, right?

Offline critor

  • Editor
  • LV11 Super Veteran (Next: 3000)
  • ***********
  • Posts: 2079
  • Rating: +439/-13
    • View Profile
    • TI-Planet
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #22 on: March 29, 2011, 04:03:54 pm »
Nice. I wish somehow it was possible to just launch an Ndless program that overwrites the entire OS content and bypass the protections...

You can overwrite and might be able to run it by the same time...

But you'll have problems during the next reboot.
TI-Planet co-admin.

Offline DJ Omnimaga

  • Clacualters are teh gr33t
  • CoT Emeritus
  • LV15 Omnimagician (Next: --)
  • *
  • Posts: 55943
  • Rating: +3154/-232
  • CodeWalrus founder & retired Omnimaga founder
    • View Profile
    • Dream of Omnimaga Music
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #23 on: March 29, 2011, 04:06:12 pm »
Hmm I see... x.x

Offline apcalc

  • The Game
  • CoT Emeritus
  • LV10 31337 u53r (Next: 2000)
  • *
  • Posts: 1393
  • Rating: +120/-2
  • VGhlIEdhbWUh (Base 64 :))
    • View Profile
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #24 on: March 29, 2011, 04:07:01 pm »
Using the same principles as 1337mod, it should be fairly simple to replace the language/text files.  It just might be a bit of annoying work, but I think it would be doable.


Offline critor

  • Editor
  • LV11 Super Veteran (Next: 3000)
  • ***********
  • Posts: 2079
  • Rating: +439/-13
    • View Profile
    • TI-Planet
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #25 on: March 29, 2011, 04:08:54 pm »
Overwriting is not a good idea, untill we can flash modified boot1/boot2.

But launching an OS without installing it, assuming it is "similar enough" with the installed OS might be the way.
That's why my example was launching the 1.7 basic OS from an Ndlessed 1.7 CAS OS.
« Last Edit: March 29, 2011, 04:09:15 pm by critor »
TI-Planet co-admin.

Offline DJ Omnimaga

  • Clacualters are teh gr33t
  • CoT Emeritus
  • LV15 Omnimagician (Next: --)
  • *
  • Posts: 55943
  • Rating: +3154/-232
  • CodeWalrus founder & retired Omnimaga founder
    • View Profile
    • Dream of Omnimaga Music
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #26 on: March 29, 2011, 04:18:01 pm »
Yeah true. I guess in that case Goplat might be right about third party OSes: it might just be best to make them as regular ASM/C programs.

Offline mikehill2003

  • LV5 Advanced (Next: 300)
  • *****
  • Posts: 279
  • Rating: +13/-4
    • View Profile
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #27 on: March 29, 2011, 04:48:49 pm »
Trying to load an nspire CAS image on a regular nspire just locked it up(both were OS 2.1). Does it work the other way around?
« Last Edit: March 29, 2011, 04:53:26 pm by mikehill2003 »

Offline critor

  • Editor
  • LV11 Super Veteran (Next: 3000)
  • ***********
  • Posts: 2079
  • Rating: +439/-13
    • View Profile
    • TI-Planet
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #28 on: March 29, 2011, 04:56:08 pm »
Trying to load an nspire CAS image on a regular nspire just locked it up(both were OS 2.1). Does it work the other way around?

It depends upon the way you're trying to load the OS.
If you're using the original boot2, of course it's checking the model type and won't load a CAS OS on a basic Nspire.
TI-Planet co-admin.

Offline mikehill2003

  • LV5 Advanced (Next: 300)
  • *****
  • Posts: 279
  • Rating: +13/-4
    • View Profile
Re: Bypassing TI-Nspire RSA signatures now possible?
« Reply #29 on: March 29, 2011, 04:58:02 pm »
Trying to load an nspire CAS image on a regular nspire just locked it up(both were OS 2.1). Does it work the other way around?

It depends upon the way you're trying to load the OS.
If you're using the original boot2, of course it's checking the model type and won't load a CAS OS on a basic Nspire.

Hmm. That figures. I'm too new to this to know how to modify the boot2 on my image right now. Any suggestions on where to start?

Edit: And before anyone asks, no it's not for cheating. A non-cas nspire was all I could find. I don't really need the cas os, I just don't like having the calculator not be as powerful as it can be.
« Last Edit: March 29, 2011, 05:01:28 pm by mikehill2003 »