Today I have unpacked a brand new Nokia 4110 4G still lying around somewhere.
Before turning it on I decided to dump the pristine state of eMMC with EDL.
What I found interesting:
Waiting for the device
Device detected :)
Mode detected: Sahara
------------------------
HWID: 0x000940e100000000 (MSM_ID:0x000940e1,OEM_ID:0x0000,MODEL_ID:0x0000)
PK_HASH: 0xcc3153a80293939b90d02d3bf8b23e0292e452fef662c74998421adad42a380f
Serial: xxxx
SBL Version: 0x00000000
Successfully uploaded programmer :)
TargetName=MSM8909
MemoryName=eMMC
Version=1
Looking at PK_HASH - it seems that secure boot is not enabled at all.
Unfortunately, after the first boot the PK_HASH changes:
HWID: 0x000940e100420050 (MSM_ID:0x000940e1,OEM_ID:0x0042,MODEL_ID:0x0050)
PK_HASH: 0x1357fdaeabb7becbe49095f000d9d3dadf198885106d98598cac6d1b9b2edb3a
Does this mean that this hardware could run anything provided eMMC is flashed before KaiOS for a first time?