We've been working a lot on TI-Nspire ClickPad prototypes, which revealed to be very interesting models.
On the one hand, a very small hardware difference made their NOR Flash chip writeable:
Thanks to this, we were able to reprogram the boot1 contained in this chip,
turning prototypes into production models accepting the OS published by TI.
On the other hand, we noticed that the prototypes ASIC CAS/non-CAS flag wasn't set.
Thanks to this, we cound
turn non-CAS TI-Nspire prototypes into TI-Nspire CAS.
It seemed obvious to us, that on production models, there was probably no way to reprogram the ASIC.
But, somebody
(who apparently wants to remain anonymous) followed our work very seriously and decided to do the impossible: make NOR chips rewriteable on production TI-Nspire ClickPad!
Even if no flashing has been attempted yet to our knowledge, the NOR chip from this modified production TI-Nspire ClickPad now reports itself as writeable when asked for its properties through an Ndless program.
The Boot1 is the central piece in TI-Nspire models security.
It's the one to check Boot2 and diags checksums and RSA signatures before launching them or not.
Being able to reprogram the Boot1 means being able to run any original, modified or 3rd party diagnostic or boot2 image!
Those who think in the short term certainly have in mind installing a CAS OS on a non-CAS TI-Nspire, thanks to a modified or 3rd-party Boot2.
The others are probably allready thinking to installing Linux, thanks to the U-Boot launcher we dumped on some old TI-Nspire prototypes.
However, such mod if a comprehensive documentation is ever released for it, will only deal with TI-Nspire ClickPad models. TI-Nspire TouchPad have their NOR chip included in the ASIC: there is probably no way to open that chip without breaking everything.
Source:http://tiplanet.org/forum/viewtopic.php?t=10389&lang=enMore information: (fragmented and incomplete so far)http://tiplanet.org/forum/archives_voir.php?id=6835http://www.cemetech.net/scripts/countdown.php?/text/production_clickpad_information.tar.gz&path=archiveshttp://ourl.ca/16358/305205 (point 3)https://groups.google.com/forum/?fromgroups=#!topic/tinspire/GQJO45-kXyk (point 3)