Live data from Hacker News

Apple T2 Security Chip: Security Overview [pdf]

apple.com

61–70 of 99 posts

Re: Apple T2 Security Chip: Security Overview [pdf]

#61
post #59
post #18

Earlier quoted context omitted.

I wish we had a physical switch that cut power to the camera and mic... I worked on some old networking equipment a while back that had a physical fail over switch. If you opened the cover you could watch the connection switch, fun stuff. Also very effective.

They say that "The camera is not disconnected in hardware because its field of view is completely obstructed with the lid closed."

And since the webcam in Macs electrically can't get power without also powering the green notification LED, it's impossible for malicious actors to activate the webcam silently while the lid is open.

Re: Apple T2 Security Chip: Security Overview [pdf]

#62

What happens if the T2 Chip fails? Is it possible to recover data on the disk? Or do we have to recover data from the last backup?

As an example, the current gen Macbook Pro has an SSD that is soldered to the motherboard (so you obviously can't remove it and cable it up to USB via an adapter to extract data).

Apple installed a port on the motherboard that their techs can use to recover data if the motherboard fails. But sure enough it didn't work with my 11 month old Macbook Pro.

Moral of the story... even if Apple has a mechanism for hardware failures, there's a chance it won't work.

Re: Apple T2 Security Chip: Security Overview [pdf]

#63

What happens if the T2 Chip fails? Is it possible to recover data on the disk? Or do we have to recover data from the last backup?

I'm just waiting for the Rossmann video when someone manages to spill some Coke on their T2 chip...

Shit like this is why I will never buy another Apple product. With my encrypted drives I can pull them out, put them in another machine and decrypt them no issues.

Re: Apple T2 Security Chip: Security Overview [pdf]

#64
post #29
post #3

"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?

Why you need security chip to ensure that?

So no malware can be installed to override a software based interlock. No malware can alter the contents of the T2 chip so code there cannot be changed, altered or mitigated.

Re: Apple T2 Security Chip: Security Overview [pdf]

#65
post #18

Earlier quoted context omitted.

I wish we had a physical switch that cut power to the camera and mic... I worked on some old networking equipment a while back that had a physical fail over switch. If you opened the cover you could watch the connection switch, fun stuff. Also very effective.

Newer Thinkpads have a shutter to cover the camera, but mic still works when covered. https://www.businessinsider.com/lenovo-thinkshutter-laptops-...

Yeah I got some handy shutters from some conferences, not a bad solution.

Re: Apple T2 Security Chip: Security Overview [pdf]

#66

What happens if the T2 Chip fails? Is it possible to recover data on the disk? Or do we have to recover data from the last backup?

Unless they let you export the keys, difficult conversation time.

I did some support for some encryption devices a long time ago.

If someone was having that difficult conversation (you could just tell it was about to happen) we would all silently gather around to hear how it went...

Re: Apple T2 Security Chip: Security Overview [pdf]

#67

Earlier quoted context omitted.

>One interesting point in the discussion of UEFI secure boot: it appears there is no way to boot OSes other than Mac OS and Windows without disabling secure boot entirely. Aren't there various linux bootloader shims signed by the MS key to workaround exactly this sort of regressive thinking ?

> NOTE: There is currently no trust provided for the the Microsoft Corporation UEFI CA 2011, which would allow verification of code signed by Microsoft partners. This UEFI CA is commonly used to verify the authenticity of bootloaders for other operating systems such as Linux variants.

Thank god - you wouldn't want that enabled by default.

Some people might want secure boot with their own certs to work with Linux, but I don't see the gain in security if you are using a generic boot loader.

Re: Apple T2 Security Chip: Security Overview [pdf]

#68

Earlier quoted context omitted.

It is a valid use case, and no it seems like it won't work.

>seems like it won't work Are you speculating here or do you have some kind of insight?

I have a T2-equipped MacBook Pro and when in clamshell mode the input monitor for the mic is dead.

Cracking it open makes it spring back to life.

So yes, the microphone is disabled in clamshell mode if connected to displays.

Re: Apple T2 Security Chip: Security Overview [pdf]

#69
post #59
post #18

Earlier quoted context omitted.

I wish we had a physical switch that cut power to the camera and mic... I worked on some old networking equipment a while back that had a physical fail over switch. If you opened the cover you could watch the connection switch, fun stuff. Also very effective.

They say that "The camera is not disconnected in hardware because its field of view is completely obstructed with the lid closed."

I wonder how long it will be until someone manages to figure out how to use image processing to read the noise seen by the camera sensor while the lid is closed and turn it into audio.

Kind of like this: http://news.mit.edu/2014/algorithm-recovers-speech-from-vibr...

Re: Apple T2 Security Chip: Security Overview [pdf]

#70
post #26

What happens if the T2 Chip fails? Is it possible to recover data on the disk? Or do we have to recover data from the last backup?

It's probably impossible if the T2 itself fails; I imagine the encryption keys are in there. Data recovery is possible if the T2 is working: https://9to5mac.com/2018/09/20/apple-t2-data-recovery-transf...

With multiple points of failure, backups become so much more important.
Post reply on HN