Live data from Hacker News

Apple's T2 chip will prevent hackers from eavesdropping on your microphone

techcrunch.com

131–140 of 159 posts

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#131

What about a hardware switch? You know, a mechanical switch, like the one already used to detect whether the lid is closed? Besides, I also want the mic disabled when my laptop is open...

There's no mechanical lid switch.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#132

Earlier quoted context omitted.

Has Apple security record on electronics been ever broken? I don’t think so. If there is an exploit yet, at least it’s not publicly known and no-one has seen it for sale on the black market, so it would be in the millions. I’d say Apple is trustworthy as far as I’m concerned, perhaps not trustworthy enough if the threat model is Hillary-level politics, but trustworthy enough for a billion dollars business.

>Has Apple security record on electronics been ever broken Absolutely. It was possible to trigger the mic/camera on older Macbooks without turning on the green LED. This led to people being spied on without their knowledge (by script kiddies, not nation-states). More recently, there's the unlocking of the San Bernardino shooters' iPhones.

None of those devices have TPMs like these.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#133
post #96

Earlier quoted context omitted.

I'd argue the T2 chip is actually more secure than your method. Magnets can be removed. The T2 chip cannot. Not without rendering the computer unusable and the data irrecoverable. The chip provides a hardware disconnect for the microphone, just like your idea. Except it's baked into the silicon instead of an additional large part in the body of the computer. Regardless, if your attack model is "T2 chip is compromised…

I'd argue the T2 chip is actually more secure than your method. Magnets can be removed. The T2 chip cannot. Not without rendering the computer unusable and the data irrecoverable If someone can physically modify your laptop, you've already been hacked, T2 chip or not. if your attack model is "T2 chip is compromised" I think the more realistic attack model is "Apple enables the undocumented 'turn on mic while closed'…

Some repair shop or some repair guy could remove magnet for celebrity...

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#134

I'm shocked at how many defenders pop up here for a proprietary chip that cannot be audited. Sure, this hardware/firmware combo might be safe. It also might be terrible, but no one on this thread actually knows either way. It is also vulnerable in ways that a magnetic lid switch would never be. The T2 is the single most important attack target (for desktops) now for large budget attackers. I wonder how long until the…

Was also slightly bemused. Especially the comments saying a physical switch is too expensive?

An inlaid switch would cost a few cents and apart from physical tampering will always work. With Apple's design skills I doubt many would even see it.

People who boldly guarantee a products security are doomed to relearn history.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#135

> The chip comes with a hardware microphone disconnect feature that physically cuts the device’s microphone from the rest of the hardware whenever the lid is closed Why do you need a chip for this? Can't you just break the circuit with a regular dumb physical switch? Or is this a much more complex problem than it first appears?

So that they can trigger it to spy on you, duh

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#136

> The chip comes with a hardware microphone disconnect feature that physically cuts the device’s microphone from the rest of the hardware whenever the lid is closed Why do you need a chip for this? Can't you just break the circuit with a regular dumb physical switch? Or is this a much more complex problem than it first appears?

This might prevent Apple from eavesdropping on your microphone.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#137
post #56
post #24

Earlier quoted context omitted.

There is already a lid closed sensor. Adding another mechanical switch is more expensive, adds another point of failure, takes space, may interfere with the aesthetics, etc... The T2 chip probably also acts as a controller for a lot of the builtin sensors, including the microphone and lid closed switch. As a result, adding a feature to turn off the microphone when the lid is closed becomes trivial. Basically just add…

Why have the control go through a sophisticated programmable chip and not just use a simple transistor/relay directly connected to the sensor?

Even on programmable chips, not every part of the chip is programmable.

The goal is to make this so it cannot be overridden in software. By designing hard-coded logic in a chip that already exists, you can get the same level of security for essentially zero cost.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#138

This only protects when the lid is closed, but many people leave the lid open on their desk. I would love to see a light come on if the camera or microphone is receiving power, and then only turn on power to these devices when a program requests it.

The camera already functions this way. The light is connected to the actual power of the camera and cannot be disabled unless the camera is also disabled. The microphone, to my knowledge, doesn't function like this but I don't think it makes sense for it to function like this as the microphone doesn't really need power outside of what's provided to the amps and DACs inside the machine. It would be too easy to work ar…

[deleted]

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#139

I'm shocked at how many defenders pop up here for a proprietary chip that cannot be audited. Sure, this hardware/firmware combo might be safe. It also might be terrible, but no one on this thread actually knows either way. It is also vulnerable in ways that a magnetic lid switch would never be. The T2 is the single most important attack target (for desktops) now for large budget attackers. I wonder how long until the…

Was also slightly bemused. Especially the comments saying a physical switch is too expensive? An inlaid switch would cost a few cents and apart from physical tampering will always work. With Apple's design skills I doubt many would even see it. People who boldly guarantee a products security are doomed to relearn history.

> will always work

Unless the user forgets to use the switch. Cue the XKCD comic about $5 wrenches breaking strong crypto.

The deeper philosophical question is whether to build, to quote the Arch Way, user-friendly or user-centric products (and, consequently, security). It should surprise nobody that Apple values user-friendly design over user-centric design.

Fwiw I also would prefer an inlaid physical switch.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#140
post #56

Earlier quoted context omitted.

Why have the control go through a sophisticated programmable chip and not just use a simple transistor/relay directly connected to the sensor?

Even on programmable chips, not every part of the chip is programmable. The goal is to make this so it cannot be overridden in software. By designing hard-coded logic in a chip that already exists, you can get the same level of security for essentially zero cost.

Especially, even if this is programmable, this chip is probably not programmable from the point of view of the motherboard...

And if an attacker is able to connect a chip programmer on your motherboard, you have a totally different threat model and bigger problems to worry about.

Post reply on HN