Author

Topic: Blackberry Z10 Dev Alpha B Developers Device for sale (Read 4056 times)

sr. member
Activity: 455
Merit: 250
Sent you a AM. Please check.
newbie
Activity: 1
Merit: 0
Hi!

If this device is still available let me know!! I will buy it asap! I've had one previously but my friend lost it! Angry

Reply here and I will pay you to ship it to Sydney Australia.

Thanks mate!

Isaac
newbie
Activity: 7
Merit: 0
hello manekari,

greetings!

dont worry about my way of doing an operation. I never
get it right at first place, then i get up and learn from
my mistake and get it right.

cpu and system board? i am extremely well versed.
especially the blackberry ones. they are the most bastard
system boards i have ever seen.

they literally hide the debug ports except uart via usb
finding the traces on this system board is one heck of
a research project on its own.

there cpu has got 530+ pins/pads and those pads leads
to traces on board. and the TI (texas instrument) even
got pin muxing tool by which the jtag and other debug
ports can be completely shut off.

so you must attack the x-loader which is signed using
TI's m-shield and it stores the data in the cpu in a 128 bit
memory flash called e-fuse.

this cpu got an RTOS which kicks off the rom boot code,
which then kicks off the x-loader, where the signature
and/or authenticity is verified.

and after its verified it send the go signal to the
bootloader or secondary bootloader. this then initiates
the kernel and the OS loads off.

the e-fuse is a special memory cell present inside the
cpu which literally gets blown apart when a specific
voltage is passed say 12-15v dc and thus seals any
further mode or method of modifying the boot sequence.

e-fuse is present in omap3x and omap4x HS cpu chips and
in omap3x and omap4x GP chips this e-fuse is absent.

HS = high security and GP = general purpose. we can attack
the cpu code execution via jtag, but i am well versed with
blackberry and they remove all jtag professionally even
uart except uart via usb.

which leaves me with 2 methods which are SCA and DPA.
SCA is side channel attack and DPA is differential power
analysis.

sca and dpa are full proof method of cryptanalysis since
sca and dpa are known as the "achilles heel" ;-)

like how every strength has subtle weakness, so does
encryption, and SCA and DPA are the "achilles heel" of
encryption. xD!

so if i get this device from you? i will be pleased indeed.
and carry on with my research work.

so i will carry with my project anyway. if i dont get it from
you, i will get it from someone else. and i will eventually
break the encryption. its a matter of time. ;-)

hope i am crystal clear and transparent and i did explain
the method well enough.

thanks!
-paul
sr. member
Activity: 455
Merit: 250
As i don't know much about the hardware and CPU, i can not commit if you get success on your research or not.

Please check your PM.

Thanks. Smiley
newbie
Activity: 7
Merit: 0
Hello manekari,
greetings!

this is paul. I am extremely eagerly to get my get a grip on this device. why?

I am trying to port coreboot to blackberry playbook.
from crackberry forum i got 3 damaged playbook systemboards.
but i can never get hold of this device be it single piece
or systemboard as such.

i am working on trying to reverse engineer the bootrom.
which is a sha1 sum stored inside the omap4x cpu.

being this a developer edition i will expect it to have a jtag
interface. if it doesnt have a jtag atleast a serial interface.

yes i am well versed with this CPU and i am currently trying to
reverse the hash/key in omap3430 or omap3x which is
found is nokia n900.

i had some serious arguement with crackberry board members,
which is why i am avoiding the forum and slap them back the
decrypted code once i am done. (serious disgust against 
few forum members from crackberry forum)

this device can prove me very valueable insights on the
omap4x which here is omap4470.

i am not a criminal. i am a developer. all i am trying to do is
unlock the FFS locked OS and bootloader and bootrom.

blackberry OS and u-boot (bootloader) and signed bootrom
(x-loader). i think i can reverse engineer the bootrom, and
thus get rid of the FRIGGIN BLACKBERRY crippled handicapped
OS, which turds me to the corner of the dark dimlit room
in the distant galaxy million light year away.

if you or others need to know more let me know. but i will
for sure like to grab this device and start my development
work on omap4470 as well.

hope i will get a decent rate unless you have not sold it
already. the developer editions only got omap4x which
are of interest to me. the production units have qualcomm
which doesnt interest me.

if you still have it, let me know i am interested, i will never
use it but i am 100% sure i will sooner or later be able to
decrypt the private key hash stored in the cpu.

hoping against hope that you still got it and are willing to
sell it at a decent rate.

and once again, i may never use this device, main motive
is to obtain the .pem files which is present inside the CPU.

yes the OMAP4470 stores the signed m-shield x-load
binary key inside the cpu. and the bootloader houses the
validation key which is stored in the emmc nand flash. which
i need to recover since its very important for my project.

thanks!
-paul
p.s. sent you a p.m. kindly check it.
sr. member
Activity: 455
Merit: 250
I'll be interested in buying Blackberry Z10 quote with a decent price in BTC considering current rates also few pictures of your device to support. THanks Smiley

Just to confirm. I am selling "Blackberry Z10 Dev Alpha B" not the retail Blackberry Z10 phone.

More details about Dev Alpha B can be found here : http://www.engadget.com/2012/09/25/blackberry-dev-alpha-b-handset-bb10-hands-on/

Please confirm so i will send you the pics and price.

Thank you.
hero member
Activity: 714
Merit: 500
NEED CRYPTO CODER? COIN DEVELOPER? PM US FOR HELP!
I'll be interested in buying Blackberry Z10 quote with a decent price in BTC considering current rates also few pictures of your device to support. THanks Smiley
sr. member
Activity: 455
Merit: 250
Hi,

Offer valid.

Will ship outside but shipping and customs cost will be yours.
hero member
Activity: 714
Merit: 500
NEED CRYPTO CODER? COIN DEVELOPER? PM US FOR HELP!
offer still valid Huh also will you ship it outside Huh
sr. member
Activity: 455
Merit: 250
Hi,

I have received the device for testing purpose of my apps and i am done with it. The device is used for a month for just testing purpose.
Device is fully working without scratches.

Device : Blackberry Z10 Dev Alpha B
Details : http://www.engadget.com/2012/09/25/blackberry-dev-alpha-b-handset-bb10-hands-on/
Accessories : Original battery and Charger
Specifications :






I am currently using Blackberry Z10, Lumia 822, Galaxy S3, iOS(past), but so far i found Blackberry OS the best.

Interested people PM me, Selling it for $500 or eqi BTC.

Only Mumbai buyers, Meet me and get the device.
Jump to: