Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

121–130 of 393 posts

Re: Apple’s T2 security chip jailbreak

#121
post #32

Earlier quoted context omitted.

>The fact that Apple uses this chip to, among other things, block "unauthorized repair" I actually dont mind they block unauthorised repair, at least I believe in the Steve Jobs's Apple era he wanted the best customer experience. And they want the Data of what is failing in their Mac where their Genius Bar gain first hand experience and knowledge which leads to feedback to the Design team. ( They dont publicly announ…

> The goal was to aim for perfection, a machine that is so reliable it wouldn't need to repair in the first place. You will have to excuse me, but that is a load of bullcrap. Let's take the case that irritates me the most: The SSD. By definition of the technology that is NAND storage, an SSD will be able to operate "within norm" and without bit errors for so long. Rewrite for long enough and you'll see your data wavi…

Reliability never means "will last for ever". It only ever means "a certain percentage of devices will last for at least a certain number of years".

Re: Apple’s T2 security chip jailbreak

#122

Earlier quoted context omitted.

> Apple was striving for an ideal that is not achievable They are aiming for planned obsolescence. The biggest competitor for new MacBooks are old MacBooks.

> The biggest competitor for new MacBooks are old MacBooks. Maybe true 5-10 years ago, but not true now.

What has changed in the last 5 years? MacOS users have no legitimate alternative if they want to keep their desktop on macOS. If you want a macOS system legally, there's two options, either buy a new Mac, or an old one.

Re: Apple’s T2 security chip jailbreak

#123
post #4

And so the futility of captured computing continues. I would love to write software for the Touch Bar that runs when I shut the MacBook down .. it'd be quite useful for some things, I imagine - such as using it for a remote control for other equipment I own.

You could explain this a bit more? Not really understanding how this would be useful.

Just imagine opening your laptop without turning it on, and using it to unlock your front door without getting up, or turning off/on the TV, or the temperature of the house.

Re: Apple’s T2 security chip jailbreak

#124
post #58

Earlier quoted context omitted.

So, if only Apple didn't tie the ability to repair and extend the device you purchased from them to the security of your own data, you would be able to feel a more consistent emotion with regards to interest in a fix; that seems all on Apple being a bit evil :/.

Can you describe a scenario where Touch ID is safe against evil maid attacks (say, a chip is installed allowing anyone to transmit a certain signal that spoofs Touch ID) while also allowing unrestricted modifications by someone with physical possession of the device (as this T2 rooting post celebrates)? Right now, that security is provided by Apple crypto-locking the Touch ID sensor to the T2 chip so that it cannot b…

I do not understand why you find it worrying that the tech community is invested in removing a restriction IN THE OPEN. If it can be removed for nefarious purposes, eventually, someone will do so and sell the exploit on the zero-day market (probably to a state actor). The existence of the vulnerability is just a fact, it is reality. Why do you feel safer not knowing about it? Whether you know about it or not the vulnerability is still there.

Re: Apple’s T2 security chip jailbreak

#125

Earlier quoted context omitted.

Apple did actually screw the pooch on this one. Typically, it's criminally illegal to circumvent DRM in the US (and 99% of the rest of the world). However, there are also certain exemptions that have been granted, within the US only (other countries are not so lucky). The right to repair is one such exemption[1]. If Apple had separated security from first-party repair enforcement, then anyone found even attempting to…

I bet breaking DRM is legal in most parts of the world. Good luck to any company trying to sue an individual for breaking DRM. "Article 6.4 of the European Directive mandates Member States to ensure users can benefit from the copyright exceptions. This means that countries must have some kind of process in place to allow citizens to make copies of DRMed works." ( https://fsfe.org/news/2019/news-20191113-01.en.html )…

This is the first time I've heard about this, and quite interesting to me as Article 12 of WIPO Copyright Treaty specifically requires signatories make circumvention of DRM protection devices illegal. This would seemingly be in contradiction to that. However, seems as the US, who were the driving behind this treaty, also provide exceptions/exemptions, I can see how the EU were able to justify any such contradiction.

That said, from the EU directive:

> Member States shall take appropriate measures to ensure that rightholders make available to the beneficiary of an exception or limitation provided for in national law in accordance with Article 5(2)(a), (2)(c), (2)(d), (2)(e), (3)(a), (3)(b) or (3)(e) the means of benefiting from that exception or limitation, to the extent necessary to benefit from that exception or limitation and where that beneficiary has legal access to the protected work or subject-matter concerned.

There are certain exceptions, in articles 1, 2, 3 and 4, which can be read at https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL.... So there's not a blanket right to circumvent DRM; and nothing is spelt out that clearly.

Additionally, not a lawyer or in Government, however, in my lay-mans reading of this directive, I'm seeing a lot of usages of the word "may". I'm (possibly incorrectly) interpreting this as meaning a Member State can introduce these copyright exceptions, not that it's mandated as the FSFE article states.

Re: Apple’s T2 security chip jailbreak

#126
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

I hope you have reported the issue to Apple so they can fix it ASAP ?

Re: Apple’s T2 security chip jailbreak

#127
post #85

Earlier quoted context omitted.

> True, but to be fair, the same mechanism also blocks thieves from using and/or selling stolen Macs. That would be a fair excuse if the mechanism was under the control of the machine's rightful owner.

What do you mean? As fas as preventing a thief from using a stolen Mac, it is under the owner's control.

He mean the owner can disable it to repair his machine, and not forced on him.

Re: Apple’s T2 security chip jailbreak

#128
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

Firstly, thanks so much for your hard work. All I want is to run Arch on an MBP 15,1. I've given your repos on Github a try--do you have a functioning bootloader config? T2 just freezes GRUB for me no matter what I try. Thanks again

Re: Apple’s T2 security chip jailbreak

#129
post #110

Earlier quoted context omitted.

Or perhaps Apple doesn’t want to have to build and support a complicated alternate signing mechanism that virtually none of their users want? I don’t see how a company should have an obligation to offer you exactly the product you want, particularly when there are tons of viable alternatives (which I’m guessing you’re using right now to type these messages).

Oh come on. It is a similar issue with network locked terminals - networks fought tooth and nail to keep the unlock codes away from the people who finished their contracts. In the end, it costs them nothing to provide the codes, but real money to lose customers. The "none of the users want it" is circular reasoning. If unlock was possible on a mass scale, developers would build for the unfettered iDevices and a marke…

The difference was when that was common, virtually all the carriers in certain countries did it because as you said it netted them more money and for a while they mostly refused the compete on it. There are plenty of competitors selling rootable phones and laptops, there’s even ones completely without stuff like Intel’s Management Engine. These are more niche, because the desire for them is more niche, but they’re by no means extinct or on the way out. The users have the option to opt for different products with the properties you want.

There is less money overall put into these products, and correspondingly less software, but that’s not because of anti-competitive practices. It’s because the reality is less people care about this stuff. I don’t think “people are obligated to put effort into the products I want” is a particularly noble political position, since you seem to be insistent on framing it that way. The position you’re talking about in the carrier case is different, it’s “people are obligated not to conspire together to do things that none of their users want and give them no options to vote with their feet”.

Re: Apple’s T2 security chip jailbreak

#130
post #28

Earlier quoted context omitted.

Second hand devices they may, although I'm not sure how many people are shipping Apple products out of the Country given the large scam risk.

Oh, prepare to be mind-blown. Let me tell you how it works. Someone goes to the US (such as a direct flight to NY or ATL), they hop off the plane, load a backpack full of laptops, then fly back and resell them without paying import taxes or VAT. It works even better if the person flying is flying for work and someone else buys the ticket. It's not scalable, but works pretty good when a group of friends purchases them…

You have to get rid of the packaging, and dump all the manuals etc or otherwise you might get a date with customs to explains why you have 10 unopened MBP's in your backpack and you get a nice import fee + VAT or you can leave them at the customs office. Also, you get about 10% tax added when buy.
Post reply on HN