Monday, 30 August 2010

Downgrade 4.0.2 -> 4.0.1: Of Myths and SHSHs

EDIT: Given the sheer number of people that are getting lucky with having their SHSH's on file with Cydia, I cannot stress enough how important it is to at least try to save your SHSH for 4.0 and 4.0.1. Remember to make sure Cydia is selected because Cydia is where your SHSHs would be. Who knows? You might be one of the lucky ones :)





There is much discussion on many blogs about a potential means of downgrading iOS 4.0.2 to 4.0.1 by simply changing a couple values in the buildmanifest.plist and copying all of the images from 4.0.1 into 4.0.2 and then deleting the files ending with 002. Following all of this, perform a DFU restore and somehow you will be on 4.0.1. 





There is a perfectly logical explanation for all of this and I will lay out exactly what is happening and explain why it is working for the folks that are the lucky ones.





Let me get this out first. 



  1. This is not a miracle, at least not in the sense you all hope for

  2. SHSHs are STILL required for any iPhone 4, iPhone 3GS, iPad, iPod Touch 3G, and iPod Touch 2G (MC Model)

  3. There is NO way around this... unfortunately this method included.

Let me start by explaining something very important. The buildmanifest is used by iTunes to build much of the TSS request that is used to obtain your SHSH for any given firmware revision. Unfortunately, the BuildNumber has no part to play in the request for SHSH. All that you ended up doing in following these directions is request 4.0.1 SHSH blobs. THAT IS ALL. Since every single one of you that got this to work changed your hosts file to point to Cydia, Cydia responded to the TSS request with an SHSH blob that was ALREADY "on-file". There was no magic. There was no miracle, apart from the lucky break that your device had been put on Cydia's SHSH request list at some time in the distant past.





That's it in a nutshell folks. There was no amazing technique for bypassing Apple's TSS. There was no amazing exploit that exists in DFU mode allowing for 4.0.2 -> 4.0.1 downgrading. It's simple; Cydia had your SHSH because at sometime in the past either:



  • Someone saved your SHSH with that device using TinyUmbrella and the default options

  • Someone restored that device with Cydia in the hosts pointing to gs.apple.com

  • Someone jailbroke the device and pressed 'Make my life easier'

That's it folks. Sorry to be a buzzkill but there was much confusion about this issue and many blog posts that simply didn't give the full story of what exactly was going on.

No comments:

Post a Comment