Live data from Hacker News

Apple's T2 Will Block Linux from Booting

phoronix.com

11–20 of 22 posts

Re: Apple's T2 Will Block Linux from Booting

#11

Earlier quoted context omitted.

It’s kind of funny that Apple-land now gets to see the same uninformed hysteria that the PC world has been rolling its eyes at for the past decade or so. Every year like clockwork I see alarmist articles about how “SecureBoot/EFI/Windows/TPM/whatever is going to block installing Linux!” and it never happens. Just tune it out; eventually you realize it’s just a way to get clicks and boost your nerd cred on Linux-cente…

It's a justifiable concern, that somehow hardware companies will wall off high-end hardware from Linux because of the industry pressure behind ill-fated ventures like pervasive DRM and Windows piracy protection. I'm glad that Apple still has the "fine, but it's your funeral" option that lets users do what they want. Secure by default, open if you want/need it.

Don't really think Apple cares much about you doing whatever you want with the hardware as long as you've paid for it.

Re: Apple's T2 Will Block Linux from Booting

#12
post #2

The article is incorrect. You can disable secure boot as simply as clicking an option in a dialog box. https://support.apple.com/en-us/HT208330

It’s kind of funny that Apple-land now gets to see the same uninformed hysteria that the PC world has been rolling its eyes at for the past decade or so. Every year like clockwork I see alarmist articles about how “SecureBoot/EFI/Windows/TPM/whatever is going to block installing Linux!” and it never happens. Just tune it out; eventually you realize it’s just a way to get clicks and boost your nerd cred on Linux-cente…

There's a small difference in this case -- I believe PCs with UEFI do have a certificate that allows some Linux distributions to boot.

Apple chose to exclude that certificate.

Re: Apple's T2 Will Block Linux from Booting

#13
post #11

Earlier quoted context omitted.

It's a justifiable concern, that somehow hardware companies will wall off high-end hardware from Linux because of the industry pressure behind ill-fated ventures like pervasive DRM and Windows piracy protection. I'm glad that Apple still has the "fine, but it's your funeral" option that lets users do what they want. Secure by default, open if you want/need it.

Don't really think Apple cares much about you doing whatever you want with the hardware as long as you've paid for it.

Apart from warranty issues, yeah, they really don't care.

Re: Apple's T2 Will Block Linux from Booting

#14
post #2

The article is incorrect. You can disable secure boot as simply as clicking an option in a dialog box. https://support.apple.com/en-us/HT208330

I'm curious how this plays out in the long term.

Apple seems very aggressive about blocking 3rd party code from running on their hardware.

I think the goal of the T2 is to block Hackintosh and also to block hardware upgrades.

At some point Apple is going to lock this down. They have a history of doing so and giving them the benefit of the doubt is probably a bad call.

Re: Apple's T2 Will Block Linux from Booting

#15
post #2

The article is incorrect. You can disable secure boot as simply as clicking an option in a dialog box. https://support.apple.com/en-us/HT208330

I'm curious how this plays out in the long term. Apple seems very aggressive about blocking 3rd party code from running on their hardware. I think the goal of the T2 is to block Hackintosh and also to block hardware upgrades. At some point Apple is going to lock this down. They have a history of doing so and giving them the benefit of the doubt is probably a bad call.

> I think the goal of the T2 is to block Hackintosh and also to block hardware upgrades.

Although there's no way for us to really know, I don't really think that's their priority. Sounds more like a side-effect. Consumers capable of assembling, installing and updating a Hackintosh are probably less than 0.1% of the entire Apple user-base. They are peanuts, from a merely commercial point of view.

They also don't really need to prevent hardware upgrades with an enforcing chip. They are already preventing hardware upgrades by releasing hardware that physically cannot be upgraded. Just think about their laptops released in the last 5 years, with RAM blocks and SSDs soldered to the motherboard...

Re: Apple's T2 Will Block Linux from Booting

#16
post #2

The article is incorrect. You can disable secure boot as simply as clicking an option in a dialog box. https://support.apple.com/en-us/HT208330

I'm curious how this plays out in the long term. Apple seems very aggressive about blocking 3rd party code from running on their hardware. I think the goal of the T2 is to block Hackintosh and also to block hardware upgrades. At some point Apple is going to lock this down. They have a history of doing so and giving them the benefit of the doubt is probably a bad call.

I don't think that's the goal of T2 any more than the goal of the TPM is to block alternate OS or hardware upgrades.

Apple lays out pretty well what the T2 chip does in their documentation.

Re: Apple's T2 Will Block Linux from Booting

#18
post #15

Earlier quoted context omitted.

I'm curious how this plays out in the long term. Apple seems very aggressive about blocking 3rd party code from running on their hardware. I think the goal of the T2 is to block Hackintosh and also to block hardware upgrades. At some point Apple is going to lock this down. They have a history of doing so and giving them the benefit of the doubt is probably a bad call.

> I think the goal of the T2 is to block Hackintosh and also to block hardware upgrades. Although there's no way for us to really know, I don't really think that's their priority. Sounds more like a side-effect. Consumers capable of assembling, installing and updating a Hackintosh are probably less than 0.1% of the entire Apple user-base. They are peanuts, from a merely commercial point of view. They also don't reall…

Adding to this - Apple manufactures new products with both upgradable hardware and T2 chips (well, product - the Mac Mini with the T2 chip and upgradable memory), and the long-awaited Mac Pro refresh will be an upgradable computer and presumably will have a Tx chip.

Re: Apple's T2 Will Block Linux from Booting

#19
post #12

Earlier quoted context omitted.

It’s kind of funny that Apple-land now gets to see the same uninformed hysteria that the PC world has been rolling its eyes at for the past decade or so. Every year like clockwork I see alarmist articles about how “SecureBoot/EFI/Windows/TPM/whatever is going to block installing Linux!” and it never happens. Just tune it out; eventually you realize it’s just a way to get clicks and boost your nerd cred on Linux-cente…

There's a small difference in this case -- I believe PCs with UEFI do have a certificate that allows some Linux distributions to boot. Apple chose to exclude that certificate.

Some Linux bootloaders such as RHEL's are signed by Microsoft to avoid having to manually enter a new trusted cert into the EFI.
Post reply on HN