Shsh Blobs Direct
Wise travelers know they must "save their blobs" while the window is still open. They use specialized tools to trick the server into giving them a signature even if they aren't ready to use it yet:
A blob saved for your iPhone 13 will not work on another iPhone 13. shsh blobs
This is the most common method, allowing you to save blobs from your phone directly. 1conan.com Wise travelers know they must "save their blobs"
To kill this exploit, Apple introduced a (a random, single-use number) into the handshake. Now, during a restore, the device generates a brand-new random nonce. The SHSH blob returned by Apple must match that exact nonce. Because the nonce changes every time, old cached blobs generally cannot be replayed directly unless the device can be forced to generate the specific matching nonce (a process known as nonce-setting, which requires a jailbroken state or an exploit). The Concept of the "Signing Window" 1conan