Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

61–70 of 393 posts

Re: Apple’s T2 security chip jailbreak

#61

The fact that Apple uses this chip to, among other things, block "unauthorized repair" (can't change a freaking SSD in 2020, really), makes me very happy that people are finding ways to break this chip to make repairs more accessible. On the other hand, this could have serious implications on the iOS security model for example. And I'm pretty sure someone is gonna run Doom on the touchbar in some months.

Sorry, but the only rational consumer response to a device that actively works against you is not to purchase it, not hack it. Once millions of people pay to be imprisoned on their own devices, the long game is lost no matter how good the hackers are, the firm has the upper hand and the resources to prevail in the long run.

And I am perfectly happy to assert this as a political preference, and vote in office people that vow to protect consumers from this kind of racketeering. I understand this might not be your cup of tea, and that some people prefer unfettered capitalism, its your political right. However I fell that allowing this in our society limits my freedom and choices, because the things you buy affect me too.

Re: Apple’s T2 security chip jailbreak

#62
post #58

I'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to cra…

So, if only Apple didn't tie the ability to repair and extend the device you purchased from them to the security of your own data, you would be able to feel a more consistent emotion with regards to interest in a fix; that seems all on Apple being a bit evil :/.

Can you describe a scenario where Touch ID is safe against evil maid attacks (say, a chip is installed allowing anyone to transmit a certain signal that spoofs Touch ID) while also allowing unrestricted modifications by someone with physical possession of the device (as this T2 rooting post celebrates)?

Right now, that security is provided by Apple crypto-locking the Touch ID sensor to the T2 chip so that it cannot be modified to allow unauthorized access without being disabled altogether.

With the ability to bypass the restrictions of the T2 OS, that protection is stripped away, and replaced by .. nothing, as far as I can determine.

This is akin to removing your car’s electronic anti-theft system because it requires OEM keys. Sure, you can do so, but your car is a lot easier to steal, too. Only it’s not your car here, it’s your computer and all personal data on it, and all SSH keys you use to access remote servers, too.

I’m all for repairability but it’s worrying that the tech community is so invested in removing a padlock that offends them that they set aside security and risk issues in favor of rooting without addressing it at all. If this complete lack of interest in device security is the best we can do, we don’t deserve repairability, and we don’t deserve root.

Re: Apple’s T2 security chip jailbreak

#63
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

Can we make the embarrassing emoji bar useful now?

Like turning it into a giant Delete key (since Apple idiotically omits a real Delete key from its keyboards).

Re: Apple’s T2 security chip jailbreak

#64
post #48

Earlier quoted context omitted.

> The goal was to aim for perfection, a machine that is so reliable it wouldn't need to repair in the first place. You will have to excuse me, but that is a load of bullcrap. Let's take the case that irritates me the most: The SSD. By definition of the technology that is NAND storage, an SSD will be able to operate "within norm" and without bit errors for so long. Rewrite for long enough and you'll see your data wavi…

Who is Linus Sebastian, why should I care about him, and why I should consider his case typical?

[deleted]

Re: Apple’s T2 security chip jailbreak

#65
post #61

The fact that Apple uses this chip to, among other things, block "unauthorized repair" (can't change a freaking SSD in 2020, really), makes me very happy that people are finding ways to break this chip to make repairs more accessible. On the other hand, this could have serious implications on the iOS security model for example. And I'm pretty sure someone is gonna run Doom on the touchbar in some months.

Sorry, but the only rational consumer response to a device that actively works against you is not to purchase it, not hack it. Once millions of people pay to be imprisoned on their own devices, the long game is lost no matter how good the hackers are, the firm has the upper hand and the resources to prevail in the long run. And I am perfectly happy to assert this as a political preference, and vote in office people t…

Many people buy iPhones / Macs because of the (intended) security provided by things like the T2 chip.

Re: Apple’s T2 security chip jailbreak

#66
post #51

Earlier quoted context omitted.

>By definition of the technology that is NAND storage, an SSD You see, I dont disagree. Apple was striving for an ideal that is not achievable. What they are aiming , trying and actually doing are three different thing.

> Apple was striving for an ideal that is not achievable They are aiming for planned obsolescence. The biggest competitor for new MacBooks are old MacBooks.

> The biggest competitor for new MacBooks are old MacBooks.

Maybe true 5-10 years ago, but not true now.

Re: Apple’s T2 security chip jailbreak

#67
post #58

I'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to cra…

So, if only Apple didn't tie the ability to repair and extend the device you purchased from them to the security of your own data, you would be able to feel a more consistent emotion with regards to interest in a fix; that seems all on Apple being a bit evil :/.

AFAIK, it's not just about the security of your data (you don't need a T2 chip to encrypt data), but also about discouraging theft of the hardware itself.

In light of that, how do you allow for components to be swapped out wholesale without breaking the security model?

Isn't the entire point that you can't just steal a Macbook, swap out the SSD, and now you have a functioning (stolen) laptop?

Re: Apple’s T2 security chip jailbreak

#68
post #58

Earlier quoted context omitted.

So, if only Apple didn't tie the ability to repair and extend the device you purchased from them to the security of your own data, you would be able to feel a more consistent emotion with regards to interest in a fix; that seems all on Apple being a bit evil :/.

Can you describe a scenario where Touch ID is safe against evil maid attacks (say, a chip is installed allowing anyone to transmit a certain signal that spoofs Touch ID) while also allowing unrestricted modifications by someone with physical possession of the device (as this T2 rooting post celebrates)? Right now, that security is provided by Apple crypto-locking the Touch ID sensor to the T2 chip so that it cannot b…

Allow the users to install their own keys. Changing keys invalidates all encrypted/secured data. Which means you have to export the data if you do hardware changes and reimport it after supplying your own. Once you have your own keys installed you could sign additional hardware with them.

If apple is a viable root of trust then you yourself should be too. There's nothing magical that only apple can do.

Re: Apple’s T2 security chip jailbreak

#69
post #58

Earlier quoted context omitted.

So, if only Apple didn't tie the ability to repair and extend the device you purchased from them to the security of your own data, you would be able to feel a more consistent emotion with regards to interest in a fix; that seems all on Apple being a bit evil :/.

AFAIK, it's not just about the security of your data (you don't need a T2 chip to encrypt data), but also about discouraging theft of the hardware itself. In light of that, how do you allow for components to be swapped out wholesale without breaking the security model? Isn't the entire point that you can't just steal a Macbook, swap out the SSD, and now you have a functioning (stolen) laptop?

The initial transition from the apple root of trust to your own root (which you would then use to install new hardware) could require being authenticated, this way a thief couldn't do it while the legitimate owner could.

Re: Apple’s T2 security chip jailbreak

#70
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

You guys are fighting the good fight for everything that owning hardware and being a user used to mean. Thank you.
Post reply on HN