Live data from Hacker News

Apple T2 Security Chip: Security Overview [pdf]

apple.com

21–30 of 99 posts

Re: Apple T2 Security Chip: Security Overview [pdf]

#21
post #20
post #3

"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?

Does this mean you can't use it in a configuration with say one laptop, two external monitors, and lid closed... and still use the mic? I don't have a Mac so maybe that isn't a valid use anyway, but I do that with PCs all the time.

It is a valid use case, and no it seems like it won't work.

Re: Apple T2 Security Chip: Security Overview [pdf]

#23
post #20

Earlier quoted context omitted.

Does this mean you can't use it in a configuration with say one laptop, two external monitors, and lid closed... and still use the mic? I don't have a Mac so maybe that isn't a valid use anyway, but I do that with PCs all the time.

It is a valid use case, and no it seems like it won't work.

TY, interesting.

Granted, I get that for security ... can't be bending the rules or it would just be the method use to circumvent it.

Re: Apple T2 Security Chip: Security Overview [pdf]

#24

One interesting point in the discussion of UEFI secure boot: it appears there is no way to boot OSes other than Mac OS and Windows without disabling secure boot entirely. > By default, Mac computers supporting secure boot only trust content signed by Apple. However, in order to improve the security of Boot Camp installations, support for secure booting Windows is also provided. The UEFI firmware includes a copy of th…

>One interesting point in the discussion of UEFI secure boot: it appears there is no way to boot OSes other than Mac OS and Windows without disabling secure boot entirely. Aren't there various linux bootloader shims signed by the MS key to workaround exactly this sort of regressive thinking ?

> NOTE: There is currently no trust provided for the the Microsoft Corporation UEFI CA 2011, which would allow verification of code signed by Microsoft partners. This UEFI CA is commonly used to verify the authenticity of bootloaders for other operating systems such as Linux variants.

Re: Apple T2 Security Chip: Security Overview [pdf]

#25
post #12

Earlier quoted context omitted.

> As I understand it, Apple claims that by simply changing its online service to deny signing certain boot loaders, it can prevent many OS downgrades to versions with known vulnerabilities. That seems like a very reasonable ability considering that "Full Security" mode says, "This mode requires a network connection at software installation time." I'd guess it's a challenge/response deal with the T2 in your Mac issuin…

Last time this came around I believe it was shown that the process was similar to the one used in iOS.

With the very important difference that on the Mac, it can actually be turned off.

Re: Apple T2 Security Chip: Security Overview [pdf]

#26

What happens if the T2 Chip fails? Is it possible to recover data on the disk? Or do we have to recover data from the last backup?

It's probably impossible if the T2 itself fails; I imagine the encryption keys are in there. Data recovery is possible if the T2 is working: https://9to5mac.com/2018/09/20/apple-t2-data-recovery-transf...

Re: Apple T2 Security Chip: Security Overview [pdf]

#27
post #20
post #3

"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?

Does this mean you can't use it in a configuration with say one laptop, two external monitors, and lid closed... and still use the mic? I don't have a Mac so maybe that isn't a valid use anyway, but I do that with PCs all the time.

I don’t think the audio quality of the mic on a closed laptop is going to be something you’d actually want. Plus it likely only applies when the machine is entering sleep?

Re: Apple T2 Security Chip: Security Overview [pdf]

#28
post #27
post #20

Earlier quoted context omitted.

Does this mean you can't use it in a configuration with say one laptop, two external monitors, and lid closed... and still use the mic? I don't have a Mac so maybe that isn't a valid use anyway, but I do that with PCs all the time.

I don’t think the audio quality of the mic on a closed laptop is going to be something you’d actually want. Plus it likely only applies when the machine is entering sleep?

Older MacBook Pros had their microphones on the exterior of the laptop, on the left side, so I'd imagine the sound from that would be pretty decent. Newer Macs put it inside the speaker grill, I think, so this wouldn't really work.

Re: Apple T2 Security Chip: Security Overview [pdf]

#29
post #3

"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?

Why you need security chip to ensure that?

Re: Apple T2 Security Chip: Security Overview [pdf]

#30
post #18
post #3

"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?

I wish we had a physical switch that cut power to the camera and mic... I worked on some old networking equipment a while back that had a physical fail over switch. If you opened the cover you could watch the connection switch, fun stuff. Also very effective.

The description makes it sound like Apple is using a hardware interlock that I'd assume cuts power to the microphone via a MOSFET when the lid is closed. That's pretty much the same thing, just with a solid state switch instead of a mechanical contact.
Post reply on HN