Live data from Hacker News

Apple's T2 chip will prevent hackers from eavesdropping on your microphone

techcrunch.com

151–159 of 159 posts

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#151

I'm really wondering if there even was 1 customer request for this.

My company (major telecom) literally gives away camera covers. Surely they'd do same for mics if there was a convenient cheap way. There's plenty of rumors about mics & cameras being commandeered by hackers & secret agencies. Apple gets ahead by actually securing mic access. Lots of people want it.

Camera covers yeah, but mic?

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#152
post #5

Earlier quoted context omitted.

Who controls the switch? You need an entire secure system distinct from the untrusted CPU - or a manual switch on the side. The latter goes against everything Apple believes in design wise.

I'm suggesting the lid could control the switch, physically, as in when you close it the mic's circuit is broken.

[sarcasm="true"]bit-bangs the lid servo [/sarcasm]

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#153
post #86

Earlier quoted context omitted.

There are people out there that hook up their laptop to an external display and then use it with the lid closed. Wouldn't be surprised if some of them want to use the mic with that configuration as well.

It's a shame. It's a damn fine third or fourth screen (I'm writing this on it).

I dock because I only like one screen. My workflow is already optimized for my laptop screen (I'm on it 60% of the time). So my ideal setup is one massive screen when I have the choice.

I could credentialize in multimonitor usage (I have before), but now I'm getting used to something that's incompatible with portability.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#154

> The chip comes with a hardware microphone disconnect feature that physically cuts the device’s microphone from the rest of the hardware whenever the lid is closed Why do you need a chip for this? Can't you just break the circuit with a regular dumb physical switch? Or is this a much more complex problem than it first appears?

Why not just give users a physical switch to turn on power to the mic when they require it?

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#155

Earlier quoted context omitted.

My company (major telecom) literally gives away camera covers. Surely they'd do same for mics if there was a convenient cheap way. There's plenty of rumors about mics & cameras being commandeered by hackers & secret agencies. Apple gets ahead by actually securing mic access. Lots of people want it.

Camera covers yeah, but mic?

Video may be embarrassing, audio more likely actionable.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#156

Earlier quoted context omitted.

My company (major telecom) literally gives away camera covers. Surely they'd do same for mics if there was a convenient cheap way. There's plenty of rumors about mics & cameras being commandeered by hackers & secret agencies. Apple gets ahead by actually securing mic access. Lots of people want it.

Rip the mic out Plug in USB mic when you need one.

As though $BIGCOMPANY would approve of people tearing laptops open to tear out hardware. Or $JOEUSER could do without voiding the warranty, assuming he had a clue how.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#157

> The chip comes with a hardware microphone disconnect feature that physically cuts the device’s microphone from the rest of the hardware whenever the lid is closed Why do you need a chip for this? Can't you just break the circuit with a regular dumb physical switch? Or is this a much more complex problem than it first appears?

Extra physical switches on an Apple product?

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#158
post #117

Earlier quoted context omitted.

Physical switch could be done with a very small magnet behind the lid surface and an opposed micro-reed switch (or other magnetically actuated on/off device) buried behind the body surface. No surface penetrations, no exposed moving parts (reed relays are hermetically sealed).

Reed switches are pretty damned huge when working at the scale of a laptop. Not to mention it would make the case of the computer microphonic — bump it hard enough and that’ll be transmitted through the reed relay.

Yeah, I agree. Reed switches might even resonate with music played through laptop speakers. This needs a no-moving-parts magnetic sensor.

Re: Apple's T2 chip will prevent hackers from eavesdropping on your microphone

#159

Earlier quoted context omitted.

You don't need a chip for this. And to their credit Librem laptops have offered such a hardware switch for a while now (perhaps since they began selling laptops) with (as I understand it) no chipset involved. Putting this functionality into a computer chip is ridiculous and unnecessary partially because there's no clear way for ordinary non-technical users to control that, and partially because this suggests that sof…

If your threat model includes "I don't trust Apple", then all discussion is moot. You could provide all the hardware killswitches you want. Apple could still design a way around them to get your data while the laptop is active. Now, if you trust Apple, the T2 chip is perfectly secure for this use case. Apple claims this serves as a hardware disconnect baked into the silicon, in which case it is no different from a me…

You're missing the point (as are the moderators, apparently): trust is a factor only when it comes to proprietary software. If you have to "trust Apple" to deal with Apple software, then you've lost any reason to trust them as they've already shown that they ought not be trusted -- both in principle (by distributing proprietary software) and in specific examples as per https://www.gnu.org/proprietary/malware-apple.html (only some of which aren't Apple's fault but merely run on Apple-made OSes, and some of which include bad business practices by Apple). Buying into claims ought not be needed and isn't needed except for proprietary software where such trust is apparently often misplaced. You can't tell if "the T2 chip is perfectly secure for this use case" because you don't know what runs on it. Apple claims a lot of things and one had good reason to believe Apple wouldn't, for instance, leave a remotely-exploitable vulnerability in iTunes unfixed for years after being notified about that vulnerability while governments exploited that vulnerability. But according to http://www.telegraph.co.uk/technology/apple/8912714/Apple-iT... that's what Apple did.

If Apple distributed free software trusting Apple wouldn't enter into the discussion. We could inspect what Apple distributed, we'd be allowed to change what we don't like about the software Apple distributed to us, and we could distribute improved versions of that software to help others. No need to buy into uninspectable code we're not allowed to change or distribute further.

And the answer to the question you didn't answer which the original poster asked -- do you need a chip to do this task -- remains "no". Purism's hardware is proof by existence. With Purism's hardware switch there's no software involved to accomplish this feature and they (as far as I know) distribute a free software distro called "PureOS" (a GNU/Linux system) which also happens to have earned an FSF-approved distro entry.

Post reply on HN