mirror of
https://github.com/qtmleap/revkit.git
synced 2026-10-03 08:21:50 +02:00
- apphmac は HMAC/SHA/HKDF ではなく [device deviceIdToken] (CDM由来の不透明トークン) - MslClient getAuthData() (0x284bc) の静的解析で this+0xe8 → CBOR "apphmac" の流れを確認 - setApphmac() (0x29930), 3つのコードパス (A/B/C) を特定 - HKDF(MGK, PSK, Nonce) は apphmac とは無関係 (Phase 3 KDF 初期化用) - entity_auth_data の全フィールド構造を確定 全未知値の解明が完了: - apphmac: deviceIdToken (キャプチャ必要) - appboot sign key: Keychain キャッシュ (初回は sign_key_1) - devicetoken: NRM トークン (キャプチャ必要) Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>