Live data from Hacker News

Apple T2 Security Chip: Security Overview [pdf]

apple.com

11–20 of 99 posts

Re: Apple T2 Security Chip: Security Overview [pdf]

#11
post #3

"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?

I wonder how that works for the Mac Mini. I'm honestly not sure if it even has a microphone built in or not.

Re: Apple T2 Security Chip: Security Overview [pdf]

#12

One interesting point in the discussion of UEFI secure boot: it appears there is no way to boot OSes other than Mac OS and Windows without disabling secure boot entirely. > By default, Mac computers supporting secure boot only trust content signed by Apple. However, in order to improve the security of Boot Camp installations, support for secure booting Windows is also provided. The UEFI firmware includes a copy of th…

> As I understand it, Apple claims that by simply changing its online service to deny signing certain boot loaders, it can prevent many OS downgrades to versions with known vulnerabilities.

That seems like a very reasonable ability considering that "Full Security" mode says, "This mode requires a network connection at software installation time."

I'd guess it's a challenge/response deal with the T2 in your Mac issuing a challenge to Apple. The response could be as simple as Apple signing the signature of its software with the challenge, i.e. response = sign(challenge + sign(MacOS))

Presumably it's whatever Apple currently does for iOS, as my understanding is that it has the same downgrade protection feature and that is part of what makes jailbreaking so precious, you need to be on the vulnerable version of iOS in the relatively short window it's still being served by Apple (aka before Apple patches some or all of your exploit chain).

Re: Apple T2 Security Chip: Security Overview [pdf]

#13
post #3

"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?

I wonder how that works for the Mac Mini. I'm honestly not sure if it even has a microphone built in or not.

The Mac Mini isn't a portable, so not at all?

Re: Apple T2 Security Chip: Security Overview [pdf]

#14
post #3

"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?

I wonder how that works for the Mac Mini. I'm honestly not sure if it even has a microphone built in or not.

AFAIK it doesn't. You need to provide your own microphone.

Re: Apple T2 Security Chip: Security Overview [pdf]

#15
post #12

One interesting point in the discussion of UEFI secure boot: it appears there is no way to boot OSes other than Mac OS and Windows without disabling secure boot entirely. > By default, Mac computers supporting secure boot only trust content signed by Apple. However, in order to improve the security of Boot Camp installations, support for secure booting Windows is also provided. The UEFI firmware includes a copy of th…

> As I understand it, Apple claims that by simply changing its online service to deny signing certain boot loaders, it can prevent many OS downgrades to versions with known vulnerabilities. That seems like a very reasonable ability considering that "Full Security" mode says, "This mode requires a network connection at software installation time." I'd guess it's a challenge/response deal with the T2 in your Mac issuin…

Last time this came around I believe it was shown that the process was similar to the one used in iOS.

Re: Apple T2 Security Chip: Security Overview [pdf]

#16

One interesting point in the discussion of UEFI secure boot: it appears there is no way to boot OSes other than Mac OS and Windows without disabling secure boot entirely. > By default, Mac computers supporting secure boot only trust content signed by Apple. However, in order to improve the security of Boot Camp installations, support for secure booting Windows is also provided. The UEFI firmware includes a copy of th…

>One interesting point in the discussion of UEFI secure boot: it appears there is no way to boot OSes other than Mac OS and Windows without disabling secure boot entirely.

Aren't there various linux bootloader shims signed by the MS key to workaround exactly this sort of regressive thinking ?

Re: Apple T2 Security Chip: Security Overview [pdf]

#17

> line-speed encrypted storage What does this mean? > The Mac unique ID (UID) and a device group ID (GID) are AES 256-bit keys fused (UID) or compiled (GID) into the Secure Enclave during manufacturing. No software or firmware can read the keys directly Does anyone know the details underlying this?

More information on the GID/UID can be found in the iOS Security Guide:

> With the exception of the Apple A8 and earlier SoCs, each Secure Enclave generates its own UID (Unique ID) during the manufacturing process. Because the UID is unique to each device and because it’s generated wholly within the Secure Enclave instead of in a manufacturing system outside of the device, the UID isn’t available for access or storage by Apple or any of its suppliers.

> Software running on the Secure Enclave takes advantage of the UID to protect device-specific secrets. The UID allows data to be cryptographically tied to a particular device. For example, the key hierarchy protecting the file system includes the UID, so if the memory chips are physically moved from one device to another, the files are inaccessible. The UID isn’t related to any other identifier on the device. The GID is common to all processors in a class of devices (for example, all devices using the Apple A8 processor).

https://www.apple.com/business/site/docs/iOS_Security_Guide....

Re: Apple T2 Security Chip: Security Overview [pdf]

#18
post #3

"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?

I wish we had a physical switch that cut power to the camera and mic...

I worked on some old networking equipment a while back that had a physical fail over switch. If you opened the cover you could watch the connection switch, fun stuff. Also very effective.

Re: Apple T2 Security Chip: Security Overview [pdf]

#19

> line-speed encrypted storage What does this mean? > The Mac unique ID (UID) and a device group ID (GID) are AES 256-bit keys fused (UID) or compiled (GID) into the Secure Enclave during manufacturing. No software or firmware can read the keys directly Does anyone know the details underlying this?

"line speed encrypted" ~= "encryption that goes as fast as the device would if not encrypting"

Re: Apple T2 Security Chip: Security Overview [pdf]

#20
post #3

"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?

Does this mean you can't use it in a configuration with say one laptop, two external monitors, and lid closed... and still use the mic?

I don't have a Mac so maybe that isn't a valid use anyway, but I do that with PCs all the time.

Post reply on HN