Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

11–20 of 393 posts

Re: Apple’s T2 security chip jailbreak

#11
The fact that Apple uses this chip to, among other things, block "unauthorized repair" (can't change a freaking SSD in 2020, really), makes me very happy that people are finding ways to break this chip to make repairs more accessible.

On the other hand, this could have serious implications on the iOS security model for example.

And I'm pretty sure someone is gonna run Doom on the touchbar in some months.

Re: Apple’s T2 security chip jailbreak

#12
post #7

If you follow the links you'll find https://checkra.in/ which gives you a dmg download - however the release notes don't mention anything about a T2 jailbreak. I would treat this with skepticism.

It does claim “partial bridgeOS support” which is the OS that runs on the T2. So maybe not as crazy. Good call though, it’s good to be aware of that sort of thing

Re: Apple’s T2 security chip jailbreak

#13

The fact that Apple uses this chip to, among other things, block "unauthorized repair" (can't change a freaking SSD in 2020, really), makes me very happy that people are finding ways to break this chip to make repairs more accessible. On the other hand, this could have serious implications on the iOS security model for example. And I'm pretty sure someone is gonna run Doom on the touchbar in some months.

Doom on touchbar (2016) https://www.theverge.com/circuitbreaker/2016/11/21/13697058/... https://twitter.com/b3ll/status/800472338496036864?s=20

Re: Apple’s T2 security chip jailbreak

#14
post #8

I wonder if this has security implications. The T2 houses the "secure enclave" and that's where your private keys, certificates and passwords are stored.

of course. Previously your keys are stored securely in a vault in a security facility but now the doors to the security facility is blown wide open. They still need to figure out the Secure Enclave though, which is no easy feat

Re: Apple’s T2 security chip jailbreak

#15

This is huge! Does anyone know if Apple is able to ship updated software to patch this? I thought the T2 was fairly isolated from the rest of the system. If it’s not easy to fix OTA, this will be really painful for security. Excited to see what sorts of things people build from this though! Would be cool to run a mini OS on the touch bar when the rest of the system is powered off.

They cannot. Both the AP and the SEP ROMs are hacked on the T2.

Re: Apple’s T2 security chip jailbreak

#16

The fact that Apple uses this chip to, among other things, block "unauthorized repair" (can't change a freaking SSD in 2020, really), makes me very happy that people are finding ways to break this chip to make repairs more accessible. On the other hand, this could have serious implications on the iOS security model for example. And I'm pretty sure someone is gonna run Doom on the touchbar in some months.

Doom on touchbar (2016) https://www.theverge.com/circuitbreaker/2016/11/21/13697058/... https://twitter.com/b3ll/status/800472338496036864?s=20

That's running purely in usermode, and nothing was broken in this demonstration, the touch bar is being used "as intended"

Re: Apple’s T2 security chip jailbreak

#17
post #8

I wonder if this has security implications. The T2 houses the "secure enclave" and that's where your private keys, certificates and passwords are stored.

The things stored in the enclave are encrypted with a key derived from, among other things, your device password so no jailbreak is going to provide access to them.

It would be a big deal if one could, say, run 'offline' dictionary attacks against secure enclave content.

Re: Apple’s T2 security chip jailbreak

#20

The fact that Apple uses this chip to, among other things, block "unauthorized repair" (can't change a freaking SSD in 2020, really), makes me very happy that people are finding ways to break this chip to make repairs more accessible. On the other hand, this could have serious implications on the iOS security model for example. And I'm pretty sure someone is gonna run Doom on the touchbar in some months.

True, but to be fair, the same mechanism also blocks thieves from using and/or selling stolen Macs.
Post reply on HN