"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?
Apple T2 Security Chip: Security Overview [pdf]
11–20 of 99 posts
Re: Apple T2 Security Chip: Security Overview [pdf]
#12One interesting point in the discussion of UEFI secure boot: it appears there is no way to boot OSes other than Mac OS and Windows without disabling secure boot entirely. > By default, Mac computers supporting secure boot only trust content signed by Apple. However, in order to improve the security of Boot Camp installations, support for secure booting Windows is also provided. The UEFI firmware includes a copy of th…
That seems like a very reasonable ability considering that "Full Security" mode says, "This mode requires a network connection at software installation time."
I'd guess it's a challenge/response deal with the T2 in your Mac issuing a challenge to Apple. The response could be as simple as Apple signing the signature of its software with the challenge, i.e. response = sign(challenge + sign(MacOS))
Presumably it's whatever Apple currently does for iOS, as my understanding is that it has the same downgrade protection feature and that is part of what makes jailbreaking so precious, you need to be on the vulnerable version of iOS in the relatively short window it's still being served by Apple (aka before Apple patches some or all of your exploit chain).
Re: Apple T2 Security Chip: Security Overview [pdf]
#13"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?
I wonder how that works for the Mac Mini. I'm honestly not sure if it even has a microphone built in or not.
Re: Apple T2 Security Chip: Security Overview [pdf]
#14"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?
I wonder how that works for the Mac Mini. I'm honestly not sure if it even has a microphone built in or not.
Re: Apple T2 Security Chip: Security Overview [pdf]
#15One interesting point in the discussion of UEFI secure boot: it appears there is no way to boot OSes other than Mac OS and Windows without disabling secure boot entirely. > By default, Mac computers supporting secure boot only trust content signed by Apple. However, in order to improve the security of Boot Camp installations, support for secure booting Windows is also provided. The UEFI firmware includes a copy of th…
> As I understand it, Apple claims that by simply changing its online service to deny signing certain boot loaders, it can prevent many OS downgrades to versions with known vulnerabilities. That seems like a very reasonable ability considering that "Full Security" mode says, "This mode requires a network connection at software installation time." I'd guess it's a challenge/response deal with the T2 in your Mac issuin…
Re: Apple T2 Security Chip: Security Overview [pdf]
#16One interesting point in the discussion of UEFI secure boot: it appears there is no way to boot OSes other than Mac OS and Windows without disabling secure boot entirely. > By default, Mac computers supporting secure boot only trust content signed by Apple. However, in order to improve the security of Boot Camp installations, support for secure booting Windows is also provided. The UEFI firmware includes a copy of th…
Aren't there various linux bootloader shims signed by the MS key to workaround exactly this sort of regressive thinking ?
Re: Apple T2 Security Chip: Security Overview [pdf]
#17> line-speed encrypted storage What does this mean? > The Mac unique ID (UID) and a device group ID (GID) are AES 256-bit keys fused (UID) or compiled (GID) into the Secure Enclave during manufacturing. No software or firmware can read the keys directly Does anyone know the details underlying this?
> With the exception of the Apple A8 and earlier SoCs, each Secure Enclave generates its own UID (Unique ID) during the manufacturing process. Because the UID is unique to each device and because it’s generated wholly within the Secure Enclave instead of in a manufacturing system outside of the device, the UID isn’t available for access or storage by Apple or any of its suppliers.
> Software running on the Secure Enclave takes advantage of the UID to protect device-specific secrets. The UID allows data to be cryptographically tied to a particular device. For example, the key hierarchy protecting the file system includes the UID, so if the memory chips are physically moved from one device to another, the files are inaccessible. The UID isn’t related to any other identifier on the device. The GID is common to all processors in a class of devices (for example, all devices using the Apple A8 processor).
https://www.apple.com/business/site/docs/iOS_Security_Guide....
Re: Apple T2 Security Chip: Security Overview [pdf]
#18"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?
I worked on some old networking equipment a while back that had a physical fail over switch. If you opened the cover you could watch the connection switch, fun stuff. Also very effective.
Re: Apple T2 Security Chip: Security Overview [pdf]
#19> line-speed encrypted storage What does this mean? > The Mac unique ID (UID) and a device group ID (GID) are AES 256-bit keys fused (UID) or compiled (GID) into the Secure Enclave during manufacturing. No software or firmware can read the keys directly Does anyone know the details underlying this?
Re: Apple T2 Security Chip: Security Overview [pdf]
#20"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?
I don't have a Mac so maybe that isn't a valid use anyway, but I do that with PCs all the time.