Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

101–110 of 393 posts

Re: Apple’s T2 security chip jailbreak

#101
post #8

I wonder if this has security implications. The T2 houses the "secure enclave" and that's where your private keys, certificates and passwords are stored.

of course. Previously your keys are stored securely in a vault in a security facility but now the doors to the security facility is blown wide open. They still need to figure out the Secure Enclave though, which is no easy feat

It’s been largely figured out already. The actual work is going into A11’s enclave at the moment.

Re: Apple’s T2 security chip jailbreak

#102
post #61

Earlier quoted context omitted.

Sorry, but the only rational consumer response to a device that actively works against you is not to purchase it, not hack it. Once millions of people pay to be imprisoned on their own devices, the long game is lost no matter how good the hackers are, the firm has the upper hand and the resources to prevail in the long run. And I am perfectly happy to assert this as a political preference, and vote in office people t…

How does me (or anyone else) buying a MacBook affect your freedom and choices? Was there some extinction of e.g. Linux-capable devices I didn’t hear about? And if I actually want the security features, who are you to say that’s not an option for me?

The more people use X, the more developers will focus on X and not on Y. From there, even fewer people will use Y and the downward cycle continues.

Re: Apple’s T2 security chip jailbreak

#103

I'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to cra…

If it really matters, Apple can bring an update that blocks these attacks. If the system depends on security through obscurity, sorry, that never lasts.

Apple cannot update this away; the vulnerability goes down to the very lowest levels of the software to the code burned into ROM.

Re: Apple’s T2 security chip jailbreak

#104
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

Incredible work. > It's a pretty peppy chip, at times coming close to my 8th gen i7...yikes. Have you got any benchmarks? It is passively cooled right? I am really surprised to hear a ~2016 arm64 CPU can can beat a 2019 Intel i7 in even synthetic benchmarks.

Not to be stickler but he said come close, not beat. Not that it's any less impressive.

Re: Apple’s T2 security chip jailbreak

#105
post #43

Earlier quoted context omitted.

The T2 was more or less a stopgap solution between their current Intel-based offerings and the AppleSilicon devices in regards to their security aspirations. My understanding is that there will be no T3, as evidenced in the DTK, which makes a lot of sense considering how identical these chips will be to their mobile counterparts.

I'm a user on a 2019 16-inch MBP (MacBookPro16,1) who hopes to move to Linux as my base OS on this hardware full-time over the next 12 months. ( https://github.com/Dunedan/mbp-2016-linux ) This is because I honestly cannot find a laptop with the combination of 64+ GB RAM, a non-NDIVIA GPU (edit: to clarify, this is because of NVIDIA's notoriously bad compatibility with Linux), and other premium hardware aspects like…

> I honestly cannot find a laptop with the combination of 64 GB RAM, a non-NDIVIA GPU, and other premium hardware like its market-leading trackpad at this time

Only 14”, and perhaps less performant, but here is this one: https://puri.sm/products/librem-14/.

Re: Apple’s T2 security chip jailbreak

#106

Earlier quoted context omitted.

How does me (or anyone else) buying a MacBook affect your freedom and choices? Was there some extinction of e.g. Linux-capable devices I didn’t hear about? And if I actually want the security features, who are you to say that’s not an option for me?

The more people use X, the more developers will focus on X and not on Y. From there, even fewer people will use Y and the downward cycle continues.

Okay, so why do your preferences for the device take priority over the majority of users who don’t care about what the T2 does and the ones who do and actually want it? Why should it be illegal for a company to make a product for us instead of you?

Re: Apple’s T2 security chip jailbreak

#107
post #18

Does the T2 have any secure storage like the A12 and newer, or are all boot ROM exploits essentially unpatchable? And do we know if this specific exploit is a boot ROM exploit?

It’s the checkra1n BootROM exploit, yes. T2 does have a SEP processor like every modern iPhone but that’s been recently cracked too (interestingly enough because Apple tried to run some trickery to “patch the unpatchable” using it).

Re: Apple’s T2 security chip jailbreak

#109

Earlier quoted context omitted.

My 2016 MBPr was of the first gen with all these changes and it's doing fine as I type this message.

My 2017 MBPr isn't quite the same -- I've had the keyboard changed 3 times so far due to the double key tap issue. I don't mind though; I'm actually happy when it happens because I get a new battery and top case for free.

How do I get a replacement though?

Re: Apple’s T2 security chip jailbreak

#110
post #77

Earlier quoted context omitted.

Such people would have no issue if they were to be provided with a 20 character secret code that allows rooting and fine grained security control. They would simply not enter it and rely on Apple's decisions for them. This pretty much kills the whole "intended" security line, the intent is user control.

Or perhaps Apple doesn’t want to have to build and support a complicated alternate signing mechanism that virtually none of their users want? I don’t see how a company should have an obligation to offer you exactly the product you want, particularly when there are tons of viable alternatives (which I’m guessing you’re using right now to type these messages).

Oh come on. It is a similar issue with network locked terminals - networks fought tooth and nail to keep the unlock codes away from the people who finished their contracts. In the end, it costs them nothing to provide the codes, but real money to lose customers.

The "none of the users want it" is circular reasoning. If unlock was possible on a mass scale, developers would build for the unfettered iDevices and a market would emerge separate from the one Apple controls. Then users would want it, since it provides value for them - cheaper apps, legal apps that are banned in the Store etc. Of course Apple will fight to the death to prevent such a thing.

Post reply on HN