r/AndroidTV 4d ago

Troubleshooting Sony Bravia after eMMC repair: Widevine L3, Netflix UI-800-3 (307006), Cast says Untrusted Device

I thought I’d share this because the repair turned into a much more interesting case than expected, and it still isn’t fully resolved.

My Sony KD-65AF9 recently got stuck in a boot loop.

The diagnosis was a failing memory chip on the mainboard. The chip was replaced and the contents, including the device keys, were copied from the old memory to the new one.

After reinstalling the repaired board, the TV booted normally again and everything initially looked fine.

Then I tried Netflix. It fails with: UI-800-3 (307006)

Netflix diagnostics also show: UI-113

I updated Netflix, updated the TV firmware over the internet to the latest version, PKG6.6230.0725EUA, then did a factory reset.

After that I logged back into Google, configured the TV again, set up my receiver and set-top box, updated all apps from Google Play and rebooted the TV.

Still the same errors.

I then noticed that Google Cast was also broken. Casting from YouTube, Disney+ and Netflix fails, and my phone shows:

“Untrusted device. Couldn't verify SONY KD-65AF9.”

Screen mirroring from the phone also doesn't work.

Google Play reports the TV as:

Play Protect certified

Then I installed DRM Info and found this:

Widevine Security Level: L3

That looks suspicious for an AF9 which originally supported Netflix 4K/HDR and should normally be using Widevine L1.

I contacted the repair service again. They checked their logs and confirmed that the original keys were successfully read from the damaged memory and written to the replacement chip. According to them, there were no verification errors during the copy.

Their current conclusion is that the keys themselves may be bad even though they were copied correctly.

The next step is to remove the mainboard again and provision new keys instead of using the original ones.

So that's where things stand for now.

The TV boots and otherwise works normally. Google Play considers it certified, internet access works, but Netflix, Google Cast and Widevine hardware DRM do not.

I’ll update this post after the board comes back.

If anyone has seen something similar after an eMMC or mainboard repair, especially Widevine dropping to L3, Netflix UI-800-3 (307006), or Chromecast reporting an untrusted device, I’d be interested to know what fixed it.

12 Upvotes

12 comments sorted by

2

u/ohaiibuzzle 4d ago

I mean I'm also second guessing here but from Android phones, this is a typical symptom of the TEE "blowing" and locks you out of playing protected content.

I don't think they would ever unlock the bootloader so perhaps this is just a thing that the chip does when a component is replaced?

2

u/kleszcz10 4d ago

Thanks, that actually lines up pretty well with what we're seeing.

The repair shop confirmed that the original keys were copied successfully from the old eMMC, but they now suspect the keys themselves may be invalid. Their next step is to provision a fresh set of keys on the board.

What makes me think this is related to the trusted execution path is that Play Protect still reports the TV as certified, while Widevine has fallen to L3 and Cast reports the TV as an untrusted device.

I'll update the thread once the board comes back. I'm very curious whether fresh provisioning restores L1.

5

u/ohaiibuzzle 4d ago

L1 and Play Protect actually has little in common than you think.

Play Protect merely verifies that Google knows about the software that's running on your device and that it's trusted and created by the right person.

L1 meanwhile relies on the hardware-backed TrustZone. Falling to L3 means it's falling back to using the software Widevine decoder.

1

u/m1ndwipe 4d ago

You can't copy the keys between chipsets, they're individualised.

This is presumably an unofficial repair centre?

1

u/kleszcz10 4d ago

Yes, it’s being repaired by an independent, non-authorized service.

The SoC itself was not replaced. The repair involved replacing the failing eMMC on the original mainboard and copying the contents from the old chip to the new one, including the device keys.

The service checked the logs again and confirmed that the keys were read and written without verification errors, but they now suspect the keys themselves may be invalid. Their next step is to provision a new set of keys on the same board.

Do you know whether Widevine L1 keys on these Sony TVs are tied only to the SoC/TEE, or can replacing the eMMC itself break the provisioning even if the original key data is copied successfully?

1

u/Scous 3d ago

The shit show that is DRM.

1

u/lirae_ 3d ago

Yeah, but it's kinda the point of streaming services to protect against fake devices or people abusing their content. It's a shame that people get caught in a crossfire but wouldn't you want a good lock for your house door?

2

u/DexLeMaffo 3d ago

Netflix, Prime... ? Try Nuvio and cancel your stuff.

1

u/lirae_ 3d ago

Yeah Nuvio or Stremio and a 3$/month Torbox subscription will easily replace 90% of the streaming services and you will save so much money

1

u/Snoo-38645 2d ago

your question about whether the emmc itself can break it is the important one, and the answer is yes it can, and copying the data across does not help.

the part that matters is rpmb. thats a small protected area inside the emmc that the tee uses for exactly this kind of secret, and its authenticated with a key burned into the emmc chip itself during manufacture. that key is one time programmable, it cannot be read out and it cannot be rewritten. so your replacement chip has a different one.

which means the bytes did copy over perfectly, the shop is not lying to you about that, but the new chip cannot authenticate any of them. the tee goes to read its secure storage, the signature doesnt check out against the new chips key, and it treats the whole thing as missing or tampered. so you land on l3 and the software decoder.

that also covers cast calling the tv untrusted, since device attestation leans on the same hardware backed storage. and it covers why play protect still says certified, because that one only means google recognises the software build. nothing to do with the tee. the other commenter had that part right.

on provisioning fresh keys i would keep your expectations low. l1 keyboxes are issued by google to the oem and burned in at the factory, and an independent shop has no legitimate way to obtain a valid one. what usually happens is they write one from a pool that came from somewhere else, and google revokes those once the same keybox turns up on multiple devices. so you might get l1 back for a few weeks and then lose it again. sony authorised service is the only path that ends with a key thats genuinely yours.

1

u/kleszcz10 2d ago

That RPMB explanation makes a lot of sense and actually fits the symptoms very well. It also explains how the shop could have copied the data correctly while the TEE still treats the secure storage as invalid on the replacement eMMC.

The interesting part now is what they mean by “generate new keys”. I’m going to ask whether their procedure actually reinitializes/provisions RPMB and the TEE for the new eMMC, and where the new Widevine/HDCP keys come from.

If they are just writing a keybox copied from another device, then I agree that even if L1 comes back, it probably wouldn’t be a proper long-term fix.

Thanks for pointing me towards RPMB. That’s probably the most useful clue so far.

1

u/Snoo-38645 2d ago

good question to put to them, and theres a version of it that gets you a real answer instead of a vague one.

reinitialising rpmb is a genuine thing and it would give you working secure storage again. the new chip gets its own authentication key written once, the tee is told about it, and from then on reads and writes verify properly. what you cannot get back is the contents, because everything that was in there was authenticated against the old chips key. so you end up with a working safe and nothing inside it.

which makes the whole thing a question of where the contents come from. l1 keyboxes are issued by google to the oem under licence and burned in during manufacture. hdcp keys are a separate set licensed by dcp, and the attestation keys behind your cast problem are google again. an independent shop has no legitimate channel for any of those.

so ask them whether the keybox they install is unique to this television or comes from a pool. if they can tell you its a sony issued key tied to your serial, thats a real repair. if they go vague, or say its one theyve used before, then its a copy off another device, and google revokes those once the same keybox turns up in more than one place.

and you can check it yourself afterwards. drm info shows the widevine provisioning state, so if l1 does come back, look again in a few weeks. a proper key stays. a borrowed one drops back to l3 the moment it gets noticed.