Long Road Ahead for Windows Phone 7 ROM Builders

| November 22, 2010 | 2 Replies

Building a custom ROM for that Windows Phone 7 device of yours? Looks like you might have a long road ahead of you according to wpcentral.com.  Apparently there are some very low-level authentication keys called PVK that the OS and most of the cloud based services look for in order to function.  If it cannot find those keys, the hardware has to be replaced.  This can be seen as a nice security measure for end users or as a wall, blocking customizations.  Not to say that this won’t be overcome, but hackers will have another obstacle in their way while working on modifying the platform.  This is certainly a different approach than Google with its Android platform but not that far off from what Apple does with iOS.  Planning on working through it and making some custom ROMs or will this push you off to an easier-to-hack platform? Let us know what you think in the comments!

Although there have been reports of people porting over WP7 to the HTC HD2 and some chatter of people being able to make ROMs  (though not load them), there may yet be one final hurdle that could be very difficult to overcome: PVK.

PVK are the private keys Microsoft evidently uses to sign off on the OS that is also tied to the hardware. Specifically, some aspect of the OS looks for and then pulls these keys from the device motherboard for verification. If the keys cannot be found, the motherboard must be replaced or serviced. While elements of the phone/OS might still work without the PVK key, core elements such as Xbox, Marketplace, Windows Live or Zune…basically any “cloud service” will not.

The challenge to developers/hackers would be to circumvent this security, much like folks have managed to get around Microsoft’s Genuine Software checker for Windows 7 and Office products. No easy task, we imagine.

In addition to  the above image,  there is an accompanying “Service Advisory” on one of the HTC internal sites that reads:


This Service Advisory aims to resolve invalid PVK or PVK missing issue for any returned WP7 units

Condition(s) to follow this service advisory:

1. When customer complains about can not access Microsoft services such as XBOX, Marketplace, Windows Live and Zune on the WP7 devices.

2. When ASP performs diagnostic program test, ASP needs to follow the below repair actions if the diagnostic program detects invalid or missing PVK.

If the PVK is invalid or missing, there will be message on device as following when user try to login to Windows Live service

To all of this we say good on Microsoft for throwing down some serious security, but alas, the ROM community now has a challenge ahead of itself. Of course, this is probably more motivated by piracy concerns than ROM cookers, but we imagine Microsoft welcomes that as a wanted side effect as well. Combined with the Xbox Live security (see earlier coverage), cracking this OS wide open may be far off.

Source: WPCentral

Tags: , , , , , , , , , , , , , , , , , , , , , ,

Category: Mobile News

About the Author ()

I am a tech and gadget nut who loves talking about and debating new technology. I love learning about how tech can change and shape our lives in today’s society.

  • Anonymous says:

    Needless to say, Blair will be pissed!