Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

141–150 of 393 posts

Re: Apple’s T2 security chip jailbreak

#141
post #133

Earlier quoted context omitted.

That’s a bizarre analogy to me, and you’re implying a symmetry to the situation that doesn’t exist. I want to be able to buy a product that has the properties that I want, and I want you to be able to buy a product with properties that you want (in part because I also want and own products with the properties you want). You want the only option to be products made with the properties you want, so that other businesse…

The condescendence is really unwarranted, it is a simple idea that purchasing options are affected by political choices of others. To give a symmetrical example, you are not allowed to purchase completely safe recreational drugs, because of the opinions the majority holds on their use. The metric you use of avoiding "restricting freedom" is a strongly ideological stance in itself and is not a natural goal political s…

Okay, but again, if your metric is consumer empowerment, how does you dictating the properties of products consumers can buy based on your personal preferences result in more consumer empowerment? Can most consumers take their System76 laptop, and then set it up so it has the properties of a laptop with something like the T2 chip if they so desire? Any more than you can reasonably be expected to delid the T2 chip in a MacBook to get it to do what you want?

I’m not trying to judge your statements by my goalposts as you seem to be implying, I’m trying to understand the internal logic of what you’ve been saying which AFAICT isn’t lining up.

Re: Apple’s T2 security chip jailbreak

#142
post #61

The fact that Apple uses this chip to, among other things, block "unauthorized repair" (can't change a freaking SSD in 2020, really), makes me very happy that people are finding ways to break this chip to make repairs more accessible. On the other hand, this could have serious implications on the iOS security model for example. And I'm pretty sure someone is gonna run Doom on the touchbar in some months.

Sorry, but the only rational consumer response to a device that actively works against you is not to purchase it, not hack it. Once millions of people pay to be imprisoned on their own devices, the long game is lost no matter how good the hackers are, the firm has the upper hand and the resources to prevail in the long run. And I am perfectly happy to assert this as a political preference, and vote in office people t…

Some of the people here can’t understand that some people have different opinions.

I don’t care that I can’t easily change the SSD. If that were important to me, I would buy a different laptop.

I don’t consider my MacBook Pro to be working against me, at all.

Re: Apple’s T2 security chip jailbreak

#143

Earlier quoted context omitted.

People in third world countries buy Macbooks - really? A decent macbook is several times above an average monthly income in a first-world country already...

I'd guess many in third-world countries buy second-hand Macbooks, as they have a reputation (at least in the past) for lasting a long time? And are there any first-world countries (except maybe the US^^) where a 13" Macbook is several times the average net monthly income? In Germany, for instance, the monthly average net wage (MANW) is €2500, while the price of a 13" Macbook starts at €1300. Italy: MANW is €1700, Spa…

Can you please provide a source from where you got your numbers as I have a feeling some are quite wrong.

Maybe in Switzerland , but in Austria the MANW is definitely not 3000+ Euros a month. As a developer I don't earn nowhere near close that NET every month and salaries here are lower overall than in Germany.

Re: Apple’s T2 security chip jailbreak

#144
post #133

Earlier quoted context omitted.

The condescendence is really unwarranted, it is a simple idea that purchasing options are affected by political choices of others. To give a symmetrical example, you are not allowed to purchase completely safe recreational drugs, because of the opinions the majority holds on their use. The metric you use of avoiding "restricting freedom" is a strongly ideological stance in itself and is not a natural goal political s…

Okay, but again, if your metric is consumer empowerment, how does you dictating the properties of products consumers can buy based on your personal preferences result in more consumer empowerment? Can most consumers take their System76 laptop, and then set it up so it has the properties of a laptop with something like the T2 chip if they so desire? Any more than you can reasonably be expected to delid the T2 chip in…

This might be a confusion started from the answer of "amelius", the logic of which I don't fully support. I believe consumer freedom is hampered first and foremost by monopolies (or, in the mobile OS case, oligopolies) and my political choice is to maximize market forces and restrict anti-competitive behavior. This is the grounds on which I oppose Apple practices, not some idea that if people buy Apple products it somehow prevents development for other platforms.

Re: Apple’s T2 security chip jailbreak

#145
post #110

Earlier quoted context omitted.

Oh come on. It is a similar issue with network locked terminals - networks fought tooth and nail to keep the unlock codes away from the people who finished their contracts. In the end, it costs them nothing to provide the codes, but real money to lose customers. The "none of the users want it" is circular reasoning. If unlock was possible on a mass scale, developers would build for the unfettered iDevices and a marke…

The difference was when that was common, virtually all the carriers in certain countries did it because as you said it netted them more money and for a while they mostly refused the compete on it. There are plenty of competitors selling rootable phones and laptops, there’s even ones completely without stuff like Intel’s Management Engine. These are more niche, because the desire for them is more niche, but they’re by…

In the "carrier era" you could still buy unlocked phones directly from the manufacturer. Your analogy doesn't hold.

The truth is that there is a threshold, a level of user complaints that turns a legitimate practice into an anti-competitive one. People disagree on where this threshold lies - is it at 0, is it at 1000, is it at millions? Until recently, most of Apple's shenanigans have kept the complaints under thresholds small enough to be socially acceptable, that's all. If more people complain, that threshold could be reached.

Re: Apple’s T2 security chip jailbreak

#146

Earlier quoted context omitted.

Everyone in the Linux space, from what I regularly read and hear, says that NVIDIA GPUs are notorious and a bad idea for using Linux. They're saying go with AMD. (As well as Ryzen instead of Intel for CPUs, where possible.) The only open-source nouveau drivers are absolutely terrible, I can attest to that fact myself. There's several benefits to not relying on NVIDIA's proprietary and non-in-built drivers for a decen…

What's your experience been with amdgpu?

At my end, that's what I have to start testing on my 2019 MBP as I plan a transition to bare metal Linux fully on it, using the tools at https://github.com/Dunedan/mbp-2016-linux. (Will take several months.) I'll be sure to document it in that community and share tips when extensive testing is done.

It's only MBP NVIDIA GPU in Linux (older model) that I have extensive experience on so far, and it's been terrible with nouveau.

Re: Apple’s T2 security chip jailbreak

#147

Earlier quoted context omitted.

Why without an Nvidia GPU? Just go with an XPS 15 or 17 and embrace Nvidia on Linux. I have three developers running Linux on HP zBooks with Nvidia GPUs without any hassle. You can also buy any newer Thinkpad (my recommendation). They are also available with AMD CPUs. It's pretty easy to buy Linux laptops these days.

Everyone in the Linux space, from what I regularly read and hear, says that NVIDIA GPUs are notorious and a bad idea for using Linux. They're saying go with AMD. (As well as Ryzen instead of Intel for CPUs, where possible.) The only open-source nouveau drivers are absolutely terrible, I can attest to that fact myself. There's several benefits to not relying on NVIDIA's proprietary and non-in-built drivers for a decen…

I will anecdotally agree; I've been a Linux laptop user for... well, 2 decades maybe? and explicitly choose Dell Mobile Precision and/or IBM/Lenovo T-series laptops with ATI/AMD, dealing with NVIDIA graphics is just a pain in the ass once we passed the GeForce era (ish).

I'd rather just have/use Intel GPU over them as well, I am not a laptop gamer to need anything NVIDIA offers in exchange for the pain in maintenance using out of tree modules to me.

Re: Apple’s T2 security chip jailbreak

#148
post #144

Earlier quoted context omitted.

Okay, but again, if your metric is consumer empowerment, how does you dictating the properties of products consumers can buy based on your personal preferences result in more consumer empowerment? Can most consumers take their System76 laptop, and then set it up so it has the properties of a laptop with something like the T2 chip if they so desire? Any more than you can reasonably be expected to delid the T2 chip in…

This might be a confusion started from the answer of "amelius", the logic of which I don't fully support. I believe consumer freedom is hampered first and foremost by monopolies (or, in the mobile OS case, oligopolies) and my political choice is to maximize market forces and restrict anti-competitive behavior. This is the grounds on which I oppose Apple practices, not some idea that if people buy Apple products it so…

Again, where is the monopoly that forces you to buy devices with a T2 chip (or something) analogous? That’s simply not the world we live in, and it doesn’t seem to me like we’re moving toward it. And if your political choice is to maximize market forces, why are you trying to fight the market forces that result in there being a large market for Apple’s devices and a small (but extant and healthy) market for the devices you want? Do you think that most consumers “really want” the devices you want? If so, why do they choose not to buy them even though they are available?

Right now, as a consumer (which, like you, is my only realistic lever on this situation), I’m pretty happy that I own some Apple devices and some very not-Apple devices. I’d be pretty pissed if I was forced to choose only one of these (in either direction). I think you’d find the same reaction if you became president of the world and threw everyone’s Apple devices in the trash and handed them a Librem 5 or something similar. Do you contest that this would be their reaction? If so, what is your definition of market forces and anti-competitive behavior?

Re: Apple’s T2 security chip jailbreak

#149
post #58

Earlier quoted context omitted.

So, if only Apple didn't tie the ability to repair and extend the device you purchased from them to the security of your own data, you would be able to feel a more consistent emotion with regards to interest in a fix; that seems all on Apple being a bit evil :/.

AFAIK, it's not just about the security of your data (you don't need a T2 chip to encrypt data), but also about discouraging theft of the hardware itself. In light of that, how do you allow for components to be swapped out wholesale without breaking the security model? Isn't the entire point that you can't just steal a Macbook, swap out the SSD, and now you have a functioning (stolen) laptop?

You can also get away with a much weaker passphrase if you can somehow rate-limit brute force attacks. As I understand it that's one of the things the T2 does, you can't authenticate except through the T2, and the T2 will slow you down and lock you out after n tries.

And I think that's actually incredibly underappreciated feature, most people are both bad at memorizing long, complex passwords/passphrases and not all that motivated since the threat is quite abstract. I've had a hard time convincing some people to have any sort of password at all on their laptop (that they travel with, work in all sorts of places and are overall pretty careless with), as it carries the risk of forgetting the password and it's cumbersome and inconvenient compared to being able to simply open the computer to a logged-in desktop.

Making security less of a hassle really does help with adoption. Having a short, relatively weak, but not trivial password is way way better than having none at all, and realistically that's all most people are ever going to have, so making those passwords hold up better is a really smart move that instantly ups the security of lots and lots of people out there.

But that's not something I believe you could do without a scheme like tieing the encrypted data to a complex secret inside a specific T2 that is uncracked, otherwise you could simply put the SSD in another computer and brute-force it there.

Re: Apple’s T2 security chip jailbreak

#150

Earlier quoted context omitted.

If it really matters, Apple can bring an update that blocks these attacks. If the system depends on security through obscurity, sorry, that never lasts.

Apple cannot update this away; the vulnerability goes down to the very lowest levels of the software to the code burned into ROM.

They were able to update it away on the iPhone X. Checkrain doesn’t work on iOS 14 anymore.
Post reply on HN