Live data from Hacker News

Apple's T2 chip will prevent hackers from eavesdropping on your microphone

techcrunch.com

91–100 of 159 posts

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#91
post #60
post #41

Earlier quoted context omitted.

Except the magnet-actuated switch for each mic.

Why would that be more likely to fail than the lid-closed sensor which they are currently using for this application?

The lid sensor likely won't fail. What will likely fail is this T2 chip and/or its firmware. And it will fail in mysterious and unfixable ways.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#92

> The chip comes with a hardware microphone disconnect feature that physically cuts the device’s microphone from the rest of the hardware whenever the lid is closed Why do you need a chip for this? Can't you just break the circuit with a regular dumb physical switch? Or is this a much more complex problem than it first appears?

You can't patent a dumb physical switch. That and the fact that the tech industry has moved so far away from even caring about users problems that it's now busy devising cool new solutions to the problems it created for them.

Seriously, putting cameras and mics in every device and then creating web browsers which potentially have access to them at all times? Yeah, I'm most worried about what happens when I close the lid.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#93

Earlier quoted context omitted.

> While speakers can certainly be used as microphones, I doubt they'd be connected to an ADC so probably won't be useful In most modern PCs with two audio jacks software will ask you what kind of device you just connected and reconfigure the sound chip to treat it as input or output. I wouldn't be surprised if clever software was able to convince Apple hardware to treat the built in speaker as a microphone.

That hardware capability is exploited in the following paper, if you want to know the details: Mordechai Guri et al. (2016) 'SPEAKE(a)R: Turn Speakers to Microphones for Fun and Profit'. http://cyber.bgu.ac.il/advanced-cyber/system/files/SPEAKE(a)... By Mordechai Guri, Yosef Solewicz, Andrey Daidakulov, and Yuval Elovici.

I'm getting access denied on that link. Do you have a mirror?

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#94

Earlier quoted context omitted.

The camera already functions this way. The light is connected to the actual power of the camera and cannot be disabled unless the camera is also disabled. The microphone, to my knowledge, doesn't function like this but I don't think it makes sense for it to function like this as the microphone doesn't really need power outside of what's provided to the amps and DACs inside the machine. It would be too easy to work ar…

> The light is connected to the actual power of the camera and cannot be disabled unless the camera is also disabled. This was proven false when malware was discovered that accessed the camera on Mac laptops without activating the LED light. It's mentioned in the article.

Am I the only one who has tape over my laptop camera? (Specifically a peppa pig sticker)

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#95
While I'm glad this is the case, if my computer is compromised to the point where I can be spied on with the webcam/microphone, I'd be far more worried about my entire photo library, web browsing history, message history, email history, bank credentials, etc. being exposed.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#96
post #89

Earlier quoted context omitted.

Or, you know, they could use a chip that they're already putting into the device (like the T2) and not have to use additional components. Same end result without the extra parts.

And an unknown and unknowable attack surface. At least with the switch if the mic doesn't work you just check for magnets around it and that's it.

I'd argue the T2 chip is actually more secure than your method. Magnets can be removed. The T2 chip cannot. Not without rendering the computer unusable and the data irrecoverable.

The chip provides a hardware disconnect for the microphone, just like your idea. Except it's baked into the silicon instead of an additional large part in the body of the computer.

Regardless, if your attack model is "T2 chip is compromised", all bets are off. Worrying about the microphone would be the absolute least of your concerns. All your local and iCloud data can now be decrypted, your 2FA is compromised, so on and so forth.

The T2 chip and Secure Enclave provide the strongest security guarantees in today's computers and mobile devices respectively. I'm not worried about a compromise of the T2 chip, to be honest.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#97

Earlier quoted context omitted.

> The light is connected to the actual power of the camera and cannot be disabled unless the camera is also disabled. This was proven false when malware was discovered that accessed the camera on Mac laptops without activating the LED light. It's mentioned in the article.

Am I the only one who has tape over my laptop camera? (Specifically a peppa pig sticker)

I bought these for all the laptops being used by my family. Especially useful when you are in a group video conference and you need a quick and foolproof way to blank the video.

https://www.aliexpress.com/item/2018-WebCam-Cover-Laptop-Cam...

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#98
post #93

Earlier quoted context omitted.

That hardware capability is exploited in the following paper, if you want to know the details: Mordechai Guri et al. (2016) 'SPEAKE(a)R: Turn Speakers to Microphones for Fun and Profit'. http://cyber.bgu.ac.il/advanced-cyber/system/files/SPEAKE(a)... By Mordechai Guri, Yosef Solewicz, Andrey Daidakulov, and Yuval Elovici.

I'm getting access denied on that link. Do you have a mirror?

I was able to read it on Arxiv: https://arxiv.org/pdf/1611.07350.pdf

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#99
post #86
post #53

Earlier quoted context omitted.

Physical switch could be made INSIDE the laptop and would be automatically pressed by the lid itself - when the lid is closed. No sensors needed. No chip needed. When lid is closed - mic is disconnected. When opened - mic is connected... User does not need to do anything else then closing the lid...

There are people out there that hook up their laptop to an external display and then use it with the lid closed. Wouldn't be surprised if some of them want to use the mic with that configuration as well.

In my experience, it doesn't work very well with the lid-closed... therefore I (like many of my colleagues) tend to use external mics, too.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#100

> The chip comes with a hardware microphone disconnect feature that physically cuts the device’s microphone from the rest of the hardware whenever the lid is closed Why do you need a chip for this? Can't you just break the circuit with a regular dumb physical switch? Or is this a much more complex problem than it first appears?

You don't need a chip for this. And to their credit Librem laptops have offered such a hardware switch for a while now (perhaps since they began selling laptops) with (as I understand it) no chipset involved. Putting this functionality into a computer chip is ridiculous and unnecessary partially because there's no clear way for ordinary non-technical users to control that, and partially because this suggests that sof…

If your threat model includes "I don't trust Apple", then all discussion is moot. You could provide all the hardware killswitches you want. Apple could still design a way around them to get your data while the laptop is active.

Now, if you trust Apple, the T2 chip is perfectly secure for this use case. Apple claims this serves as a hardware disconnect baked into the silicon, in which case it is no different from a mechanical switch.

Finally, the whole argument about user control over various security features is interesting. I will say that Apple has, better than any other manufacturer, struck almost perfectly the balance between security and usability. Apple's software/hardware security does its job, does it well, and gets out of your way. Including 20 different hardware switches and 150 different security settings that mean nothing to the average user would not be in their design language.

It's all about your threat model. Perhaps yours is a bit too severe to use traditional consumer devices.

Post reply on HN