Disabling RO firmware protection on Ti50
TIP
This is only applicable to devices with a Ti50 security chip, which is typically found in devices released during or after mid-2023.
TIP
If you disabled WP via CCD and reset your CCD flags with ccd reset factory
, you can skip this step.
Step 1: Verify the device has a Ti50
- Open VT-2 (
ctrl
+alt
+f2
(right arrow)). - Login as
root
. - Run
gsctool -a -I | grep AllowUnverifiedRo
. - If that command has any output, your device has a Ti50. If you get no output or an error, your device either has a Cr50 or no GSC at all.
Step 2: Disable RO verification
- Unlock the GSC by running
gsctool -a -o
. - Run
gsctool -a -I AllowUnverifiedRo:always
. - Press the power button when prompted.
WARNING
If your device has a Ti50 and you don't disable RO verification, flashing full rom will brick the device (can be recovered with steps listed below).
Recovering a device bricked due to RO verification
Chromebooks
- Press and hold the
Power
button. - Press the
Refresh
(arrow icon) button twice. - Release the
Power
button. - Repeat the above steps a second time.
Chromeboxes
- Press and hold the
Power
button. - Press the recovery pinhole button twice.
- Release the
Power
button. - Repeat the above steps a second time.
Tablets
- Press and hold the
Power
button. - Press and hold
Volume Up
for 10+ seconds. Release and repeat it a second time. - Release the
Power
button. - Repeat the above steps a second time.
This will disable RO verification for 15 minutes, allowing you to permanently disable it.