Re: Microsoft Surface Book 3 UEFI locked (AMITSESetup missing)
Hi.
Yes, you are right. NV bios area is all FF. After some time I am pretty sure that it is because RPMC (Replay Protection Monotonic Counter). It is new NOR flash W25R128JW and if I understood it well, there is saved HMAC SHA-256 security key inside the NOR flash. Without knowing it, and without executing "Increment Monotonic Counter" instruction, the protected area cannot be accessed.
How can I read this stupid chip please W25R128JW? ...
Announcement
Collapse
No announcement yet.
User Profile
Collapse
-
Microsoft Surface Book 3 UEFI locked (AMITSESetup missing)
Hello.
I have completely locked 15" Microsoft Surface Book 3 (windows password, UEFI password + USB boot disabled). So I dissasembled it, desoldered Winbond W25R128JW NOR flash, read it with CH341 (with 1.8V converter) and now I am trying to find encrypted password (with UEFITool / HxD). But there is no patterns like this:
65 74 75 70 00 (AMITSESetup.)
01 4E 56 41 52 (.NVAR)
I am confused... Is there some kind of new protection mechanism?
...
Leave a comment:
-
No activity results to display
Show More
Leave a comment: