Tom Chai


From what I know the S/N is in the main NAND and there are tools to modify that. However it must match the IMEI on Apple activation server records in order for the phone to be activated.

The baseband is another story. The IMEI is either burned into the BB or encrypted and stored in the BB EEPROM. All content or at least sensitive information in the EEPROM is encrypted with a unique key in the BB. There is no way to alter or even readout the information as plaintext. The BB and BB EEPROM has to be present as a matching set, with BB destroyed there is no way to make it work.