Analyzes DH public key ↔ key 33.6 pairs from Netflix iOS appboot CBOR
captures, confirming the trivial block-XOR encoding and mapping plaintext
regions to static header, session-bound, and per-request zones.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Hooks HKDF_extract and HKDF_expand in the tweak for improved key derivation
logging and analysis. Removes Frida and Proxyman skills, references, and
documentation for a more focused Agent Team workflow.
Adds several Python tools for systematic HKDF and session key derivation
analysis, supporting ongoing reverse engineering and debugging efforts.
Switches all agent workflow documentation and prompts to English, clarifies
inter-agent communication constraints, and updates the workflow to reflect
current team structure and supported features.
Relates to the need for more accurate key extraction and simplified agent
usage.
Enhances iOS MSL CBOR decoder for multi-item parsing, iOS-specific payload
handling, and IV extraction from ciphertext. Updates NetflixCrypto to support
Tweak-format key JSON. Extends the Tweak to capture DH key exchange material
and session keys more reliably, saving full key histories and implementing
better appboot phase tracking. Adds scripts for DH-derived HKDF parameter
analysis and appboot key response investigation.
Improves documentation on iOS CBOR MSL protocol differences, decryption
pipeline, and key extraction workflow.
Relates to iOS MSL traffic analysis and decryption research.
Introduces detailed documentation for the iOS Netflix MSL client, including work plans and a comprehensive decryption pipeline, to support reverse engineering and protocol understanding.
Adds Python scripts that automate brute-force searching of HKDF parameters, support key derivation analysis across multiple encryption and HMAC key candidates, and verify DH parameter consistency.
Facilitates future development of a standalone iOS MSL client and aids in identifying the correct key derivation logic needed for cross-platform manifest decryption.