Live data from Hacker News

Apple's T2 chip will prevent hackers from eavesdropping on your microphone

techcrunch.com

41–50 of 159 posts

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#41
post #29
post #19

Earlier quoted context omitted.

Expensive and failure-prone!

Just put a magnet-actuated switch into the mic itself and a magnet in the corresponding place in the body - problem solved. Nothing to break, zero attack surface, what's not to like?

Except the magnet-actuated switch for each mic.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#42
The only reliable way to prevent eavesdropping is to physically break continuity of all voice coils in the device.

Entrusting a black box chip to do this on your behalf is more risky than there being a physical kill switch somewhere which all the voice coils pass through.

There's certainly going to be a way for the chip to be told via software to reconnect the coils, though you may not know how yourself.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#43
post #5

Earlier quoted context omitted.

Who controls the switch? You need an entire secure system distinct from the untrusted CPU - or a manual switch on the side. The latter goes against everything Apple believes in design wise.

What about a physical killswitch goes against Apple's design? The iPhone has always had a ringer/vibrate switch on its side since it was introduced. Obviously it doesn't do anything hardware-wise, but it's still a switch that disables some functionality.

It’s a part that when it fails is probably a motherboard replacement ($), and it fails often because people.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#44

Or they could do, you know, a simple $0.10 on-off slide switch.

And then they would have to endure 10 million support calls from users who didnt know they disabled the switch and cant make skype/facetime calls.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#45
post #39

Earlier quoted context omitted.

> I would love to see a light come on if the camera or microphone is receiving power, and then only turn on power to these devices when a program requests it. Isn't the microphone a simple passive device no different than a voice coil in a magnetic field? I don't think it's that simple, since it won't be powered. My understanding is that there's often a reconfigurable circuit in the sound chip which determines where…

There's at least a pre amp and a d/a converter that the mic needs to have powered up and running before any of it's signal can be used by the rest of the computer.

Which will all be inside an IC, away from the microphone.

So what, does the light turn on whenever the entire IC sees power? Because if it relies on a signal from within the software-controlled IC, that's not exactly trivial to audit.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#46
post #41
post #29

Earlier quoted context omitted.

Just put a magnet-actuated switch into the mic itself and a magnet in the corresponding place in the body - problem solved. Nothing to break, zero attack surface, what's not to like?

Except the magnet-actuated switch for each mic.

Those are rated for over hundreds of millions of switching cycles. They would be the last thing that breaks in a laptop.

But if you're so against moving parts, a hall sensor and a transistor would achieve the same result.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#47

> The chip comes with a hardware microphone disconnect feature that physically cuts the device’s microphone from the rest of the hardware whenever the lid is closed Why do you need a chip for this? Can't you just break the circuit with a regular dumb physical switch? Or is this a much more complex problem than it first appears?

You don't need a chip for this. And to their credit Librem laptops have offered such a hardware switch for a while now (perhaps since they began selling laptops) with (as I understand it) no chipset involved.

Putting this functionality into a computer chip is ridiculous and unnecessary partially because there's no clear way for ordinary non-technical users to control that, and partially because this suggests that software (as I presume the software on this new chip will be alterable by Apple) can still affect whether the mic is hot. The headline "Apple's T2 chip will prevent hackers from eavesdropping on your microphone" should probably be interpreted to mean that Apple won't be prevented from listening in.

Camera access and wireless network access should also be physically disconnectable via a simple user-controlled piece of hardware which electrically disconnecting the on-board webcam and wireless network device from the rest of the system -- a slider or rocker switch. This too is something I understand Librem laptops offer but is uncommon elsewhere.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#48

> The chip comes with a hardware microphone disconnect feature that physically cuts the device’s microphone from the rest of the hardware whenever the lid is closed Why do you need a chip for this? Can't you just break the circuit with a regular dumb physical switch? Or is this a much more complex problem than it first appears?

Because you may want to configure it. I close my laptop when it’s attached to an external monitor. The mic should stay on in that instance.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#49

> The chip comes with a hardware microphone disconnect feature that physically cuts the device’s microphone from the rest of the hardware whenever the lid is closed Why do you need a chip for this? Can't you just break the circuit with a regular dumb physical switch? Or is this a much more complex problem than it first appears?

Because you may want to configure it. I close my laptop when it’s attached to an external monitor. The mic should stay on in that instance.

That would defeat the purpose wouldn’t it? Malware would also configure it.
Post reply on HN