Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…
> Filevault and by extension Touch ID are more or less crippled Sorry, what does this sentence mean? That someone with physical access to my machine can now unencrypt my FileVault encrypted hard drive?
Apple’s T2 security chip jailbreak
151–160 of 393 posts
Re: Apple’s T2 security chip jailbreak
#152Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…
Re: Apple’s T2 security chip jailbreak
#153I'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to cra…
Re: Apple’s T2 security chip jailbreak
#154Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…
Why do you believe it's moral for you to do work which is making people's data less secure, helping law authority crack iPhones, etc?
Re: Apple’s T2 security chip jailbreak
#155I'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to cra…
More and more after over 10 years working in tech I'm convinced that there is no digital system is a secure system. Hardware and Software.
Re: Apple’s T2 security chip jailbreak
#156Earlier quoted context omitted.
The difference was when that was common, virtually all the carriers in certain countries did it because as you said it netted them more money and for a while they mostly refused the compete on it. There are plenty of competitors selling rootable phones and laptops, there’s even ones completely without stuff like Intel’s Management Engine. These are more niche, because the desire for them is more niche, but they’re by…
In the "carrier era" you could still buy unlocked phones directly from the manufacturer. Your analogy doesn't hold. The truth is that there is a threshold, a level of user complaints that turns a legitimate practice into an anti-competitive one. People disagree on where this threshold lies - is it at 0, is it at 1000, is it at millions? Until recently, most of Apple's shenanigans have kept the complaints under thresh…
That’s an interesting metric for anti-competitive practice. Isn’t a large number of user complaints basically the core mechanism that drives market competition? Once you have enough users complaining about an aspect of a product (or otherwise being underserved), why would they not go to a competitor if one is allowed to exist (as they are in this situation)?
Re: Apple’s T2 security chip jailbreak
#157I'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to cra…
Apple did actually screw the pooch on this one. Typically, it's criminally illegal to circumvent DRM in the US (and 99% of the rest of the world). However, there are also certain exemptions that have been granted, within the US only (other countries are not so lucky). The right to repair is one such exemption[1]. If Apple had separated security from first-party repair enforcement, then anyone found even attempting to…
No, that is a pretty US specific mess up.
At least in the EU braking DRM for thinks like research purpose is fully legal as far as I know.
It's a bit more complicated if it's a but distributing tools which can brake DRM.
It's no as complicated if it's about publishing a (somewhat) scientific document explaining the general concept about how to brake it.
Re: Apple’s T2 security chip jailbreak
#158Earlier quoted context omitted.
I bet breaking DRM is legal in most parts of the world. Good luck to any company trying to sue an individual for breaking DRM. "Article 6.4 of the European Directive mandates Member States to ensure users can benefit from the copyright exceptions. This means that countries must have some kind of process in place to allow citizens to make copies of DRMed works." ( https://fsfe.org/news/2019/news-20191113-01.en.html )…
This is the first time I've heard about this, and quite interesting to me as Article 12 of WIPO Copyright Treaty specifically requires signatories make circumvention of DRM protection devices illegal. This would seemingly be in contradiction to that. However, seems as the US, who were the driving behind this treaty, also provide exceptions/exemptions, I can see how the EU were able to justify any such contradiction.…
At least that is what I remember.
Re: Apple’s T2 security chip jailbreak
#159Earlier quoted context omitted.
Can you describe a scenario where Touch ID is safe against evil maid attacks (say, a chip is installed allowing anyone to transmit a certain signal that spoofs Touch ID) while also allowing unrestricted modifications by someone with physical possession of the device (as this T2 rooting post celebrates)? Right now, that security is provided by Apple crypto-locking the Touch ID sensor to the T2 chip so that it cannot b…
I do not understand why you find it worrying that the tech community is invested in removing a restriction IN THE OPEN. If it can be removed for nefarious purposes, eventually, someone will do so and sell the exploit on the zero-day market (probably to a state actor). The existence of the vulnerability is just a fact, it is reality. Why do you feel safer not knowing about it? Whether you know about it or not the vuln…
Re: Apple’s T2 security chip jailbreak
#160Earlier quoted context omitted.
Apple cannot update this away; the vulnerability goes down to the very lowest levels of the software to the code burned into ROM.
They were able to update it away on the iPhone X. Checkrain doesn’t work on iOS 14 anymore.