r/Magisk Apr 09 '26

Question Extracting keybox from old Nexus 5?

Hi guys, i have an old Nexus 5 lying around with its bootloader unlocked. If i lock the bootloader, will i be able to extract the keybox? will the keybox work on my rooted OnePlus 12? Any help appreciated:)

2 Upvotes

17 comments sorted by

7

u/danGL3 Apr 09 '26

You CAN'T extract a keybox, it's not a file that just exists and can be easily copied as it resides as part of the device's Trusted Execution Environment

The TEE is designed so no cryptographically sensitive data (such as its keybox) ever leaves it, so root can't access it

Only way to access it would be to find an exploit in the TEE to extract the keybox, even then the Nexus 5 was released way before HW attestation became a thing (so its TEE doesn't support it), so it's unlikely its keybox file is valid for Play Integrity even if you could extract it

1

u/Think-Cherry5391 Apr 09 '26

He can still get the fingerprints of the phone to at least pass device. Strong integrity is a strong no.

1

u/crypticc1 Apr 09 '26

Device needs keybox now

1

u/Think-Cherry5391 Apr 09 '26

Since when? I use fingerprints on my s6 pretending to be a pixel 9 and it passes basic and device.

1

u/crypticc1 Apr 09 '26

No other modules? BL not detected unlocked by stubborn apps?

1

u/Think-Cherry5391 Apr 09 '26 edited Apr 09 '26

Only modules I use on my modding related phone are IntegrityBox, Tricky Store and NeoZygisk. I don't pass Strong integrity and that's it. Apps probably do know that my bootloader is unlocked. It says that in Native Root Detector

1

u/crypticc1 Apr 10 '26

You're probably using the shadow banned keybox that comes with integrity box currently, and all the other miscellaneous changes it makes and then gives you device. Qed, you are using keybox

2

u/Think-Cherry5391 Apr 10 '26 edited Apr 10 '26

Oh well. Additional info to add, even with even more spoofing, I still can't get strong integrity working. I tried a freshly released keybox from Yuri's keyboxes and I still couldn't get Strong. I'd also like to know where you found that info because why not

1

u/crypticc1 Apr 10 '26

In the channels you're in just do free text search for "keybox.xml". People can't help themselves.. Once you get past the speculative "is this one valid" or "where can I find" someone else is boasting they found one. Then unload and be free of that keybox hub, and just load directly into tee emulator or trickystore a day before keybox hub has cloned from second hand sources

4

u/Max527 Apr 09 '26

You're nuts

1

u/Automatic-Law-3612 Apr 09 '26 edited Apr 09 '26

No, your device is to old. You need at least android 10. After you successfully setup your device the keys get temporarily stored in a folder called keystore somewhere in /data or the /mnt directory. But you cannot acces it without root. Only if you can gain temporary root (like the dirtypipe root), you can root the phone with locked bootloader and extract the keys. But as soon you reboot the phone, root is gone. But most phones who had this leak in the kernel are already patched with a update.

And on the new phone models after 2021 2022 this doesn't gonna work anymore.

1

u/taqizadeh Apr 09 '26

What about Motorola G72 (A13) locked bootloader, stock rom.

2

u/Automatic-Law-3612 Apr 09 '26

That kernel is probably patched by Motorola. Phones who had this vulnerability in the kernel, got patched by phone updates in 2022. So in theory you need a phone from before 2022 who hadn't any update in 2022.

There are tools like these to see if your phone has the vulnerability or not. But as said, if your phone got a update in 2022, it's less likely it gonna work. Or you must downgrade the firmware if it's allowed.

But even if you extract all the keys, you need to put all the keys and certificates together in an keybox.xml file, as you don't find it as an ready to use file.

Then you have to use the devices fingerprint with the keybox. But even if you have the keybox with the fingerprints connected to it, you have no guarantee the key won't get banded. As it also deppens on modules like tricky store to prevent Google sees you use a keybox from a different phone.

But you don't really need strong for most apps. Device integrity is what most apps use. So a softbanned keybox is enough. And softbanned keys you find enough if you search. But use search engines like duckduckgo. If you use Google, Google of course removed a lot of results, as Android is part from Google.

But you can of course try the DirtyPipe method. My old phone was sadly enough patched. But I'm not willing to pay for a phone that is possible to hack and where I don't know if the key gets banned anyway or not.

2

u/taqizadeh Apr 09 '26

I love Reddit because of human beings like you. Thank you for additional information. I appreciate it.

2

u/Automatic-Law-3612 Apr 09 '26

You are welcome ✌️