Live data from Hacker News

Apple EFI firmware passwords and the SCBO myth

reverse.put.as

21–30 of 38 posts

Re: Apple EFI firmware passwords and the SCBO myth

#21
This article is the kind that makes me sit down with a cup of coffee and read it top to bottom, even though I don't understand all of the low-level assembler details (but it's understandable without that). Security is important for everyone, not just security researchers.

Re: Apple EFI firmware passwords and the SCBO myth

#22
post #2

TLDR? EFI password protection broken or not?

Apple has a backdoor for resetting firmware passwords via a special unlock file that must be cryptographically signed using Apple's private key(s).

In theory only Apple employees can sign the unlock files. How many employees have access to sign these unlock files? 10? 100? Every low-level employee? There may be some "bad apple" employees selling the signing of unlock files, some social engineering to trick Apple into providing signed files they shouldn't be, or a vulnerability the researcher has not found that allows attackers to bypass the public-key crypto implementation.

Re: Apple EFI firmware passwords and the SCBO myth

#24
post #17
post #5

Apple is doing a much better job than all the rest of the PC vendors. Even those vendors that I haven't published keygens for [1] have just stupendously unsound bypass mechanisms for BIOS passwords. [1] https://dogber1.blogspot.com/2009/05/table-of-reverse-engine...

Your list is 7 years old and relates to non-EFI bios implementations. It's hardly a valid comparison to a modern Apple bios as looked at here.

The bypass algorithms have largely remained unchanged when the industry moved to EFI. Most vendors (Lenovo, Dell, Acer, Asus, Toshiba, Fujitsu, ...) simply wrapped their bypass algorithms into some DXE driver and called it a day.

Re: Apple EFI firmware passwords and the SCBO myth

#25
post #5

Apple is doing a much better job than all the rest of the PC vendors. Even those vendors that I haven't published keygens for [1] have just stupendously unsound bypass mechanisms for BIOS passwords. [1] https://dogber1.blogspot.com/2009/05/table-of-reverse-engine...

Nevertheless, physical access still means it's game over; and I consider that a feature, not a bug. Given that, it's actually a little amusing that Apple went to all that effort for something that can be defeated with nothing more than a full BIOS reflash.

Maybe not so amusing! As far as I know, you’ll need to take the machine apart to reflash it, plus special hardware — because when a firmware password is set, a Mac requires the password to choose a different boot disk.

with this feature, Apple HQ can give a service center the ability to clear a particular firmware password without giving them a universal backdoor (hardware or software).

Re: Apple EFI firmware passwords and the SCBO myth

#26
post #2

TLDR? EFI password protection broken or not?

Apple has a backdoor for resetting firmware passwords via a special unlock file that must be cryptographically signed using Apple's private key(s). In theory only Apple employees can sign the unlock files. How many employees have access to sign these unlock files? 10? 100? Every low-level employee? There may be some "bad apple" employees selling the signing of unlock files, some social engineering to trick Apple into…

Since it's likely that every apple care center can perform this unlock there is a very good chance that there is a machine in virtually everyone of them that also has a service lab that makes these files.

The number of people that can unlock it is probably quite high, this isn't that different than removing an apple id from the device you need to go to the apple store with the device and proof of purchase and they do it for you.

Re: Apple EFI firmware passwords and the SCBO myth

#27

Earlier quoted context omitted.

Apple has a backdoor for resetting firmware passwords via a special unlock file that must be cryptographically signed using Apple's private key(s). In theory only Apple employees can sign the unlock files. How many employees have access to sign these unlock files? 10? 100? Every low-level employee? There may be some "bad apple" employees selling the signing of unlock files, some social engineering to trick Apple into…

Since it's likely that every apple care center can perform this unlock there is a very good chance that there is a machine in virtually everyone of them that also has a service lab that makes these files. The number of people that can unlock it is probably quite high, this isn't that different than removing an apple id from the device you need to go to the apple store with the device and proof of purchase and they do…

Last I heard, service centers have to request these files from Apple on a case-by-case basis, so that only a small number of people need the ability to generate them. All of the complexity (writing a nonce to flash when the firmware password is changed, etc.) exists to make it easy for a service provider to apply an unlock when authorized.

I’d make a large bet that the same is true for removing Apple ID activation locks from devices.

Re: Apple EFI firmware passwords and the SCBO myth

#28

Earlier quoted context omitted.

Since it's likely that every apple care center can perform this unlock there is a very good chance that there is a machine in virtually everyone of them that also has a service lab that makes these files. The number of people that can unlock it is probably quite high, this isn't that different than removing an apple id from the device you need to go to the apple store with the device and proof of purchase and they do…

Last I heard, service centers have to request these files from Apple on a case-by-case basis, so that only a small number of people need the ability to generate them. All of the complexity (writing a nonce to flash when the firmware password is changed, etc.) exists to make it easy for a service provider to apply an unlock when authorized . I’d make a large bet that the same is true for removing Apple ID activation l…

I haven't removed an EFI password but I've removed an Apple ID from 2 devices and it was done in While It's likely that Apple has probably has some audit trail on these requests just the sheer amount of devices that are likely to need to undergo such procedure make it unlikely that there is some room in Apple HQ where 5 highly trusted engineers issue those files.

Even if you don't count all the end users that lock their devices and can't unlock them all the devices that are returned to apple, go in for a hardware replacement/fix or recycling need to undergo a similar procedure. So If I would be asked to wager on how this process is done it would be that it's an automated process with an audit trail just like what many organizations use to reset account details, passwords and other things.

Re: Apple EFI firmware passwords and the SCBO myth

#29

Earlier quoted context omitted.

I'm not so sure the people selling SCBO files are the ones we'd consider the good guys. Or at least not based on their most likely buyers.

Correct, they're most likely allowing stolen computers to be used Makes me wonder if their SCBO generating system is connected to their stolen serial number db (probably not)

they're most likely allowing stolen computers to be used

Also those which have been recycled, or which someone has locked out accidentally, or deliberately to scam someone ( https://news.ycombinator.com/item?id=7993435 ), etc. Used computers from companies often have BIOS passwords that no one bothered to clear before sending them off. Not every computer with a password its current owner doesn't know is a stolen one. That's why I think this is a good thing --- I believe in the fact that if you physically own something, regardless of how you came to own it, you should truly "own" it.

Re: Apple EFI firmware passwords and the SCBO myth

#30

Earlier quoted context omitted.

Nevertheless, physical access still means it's game over; and I consider that a feature, not a bug. Given that, it's actually a little amusing that Apple went to all that effort for something that can be defeated with nothing more than a full BIOS reflash.

Maybe not so amusing! As far as I know, you’ll need to take the machine apart to reflash it, plus special hardware — because when a firmware password is set, a Mac requires the password to choose a different boot disk. with this feature, Apple HQ can give a service center the ability to clear a particular firmware password without giving them a universal backdoor (hardware or software).

> As far as I know, you’ll need to take the machine apart to reflash it, plus special hardware

This doesn't take very long. Maybe 5 minutes to disassemble the machine.

As for hardware, you can flash SPI chips using a Teensy and a clip chip. [1] The total cost of parts is under $30.

Incidentally, I highly recommend investing in one of these if you're doing firmware development for routers. It's so much easier to flash a backup than muck around with TFTP.

> because when a firmware password is set, a Mac requires the password to choose a different boot disk.

This is hardly unique to Apple. Most PC laptop manufacturers also disable changing the boot device or choosing a temporary boot device when a setup password is enabled.

> with this feature, Apple HQ can give a service center the ability to clear a particular firmware password without giving them a universal backdoor (hardware or software).

Um, this is how it works for PC firmware passwords as well. Unless there is a keygen available, most modern implementations use a hashed value from the serial number or hard drive as the master unlock password. It's unique to the laptop being unlocked.

[1] https://trmm.net/SPI_flash

Post reply on HN