Earlier quoted context omitted.
Second hand devices they may, although I'm not sure how many people are shipping Apple products out of the Country given the large scam risk.
Oh, prepare to be mind-blown. Let me tell you how it works. Someone goes to the US (such as a direct flight to NY or ATL), they hop off the plane, load a backpack full of laptops, then fly back and resell them without paying import taxes or VAT. It works even better if the person flying is flying for work and someone else buys the ticket. It's not scalable, but works pretty good when a group of friends purchases them…
Apple’s T2 security chip jailbreak
161–170 of 393 posts
Re: Apple’s T2 security chip jailbreak
#162Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…
> Filevault and by extension Touch ID are more or less crippled Sorry, what does this sentence mean? That someone with physical access to my machine can now unencrypt my FileVault encrypted hard drive?
Re: Apple’s T2 security chip jailbreak
#163Earlier quoted context omitted.
>The fact that Apple uses this chip to, among other things, block "unauthorized repair" I actually dont mind they block unauthorised repair, at least I believe in the Steve Jobs's Apple era he wanted the best customer experience. And they want the Data of what is failing in their Mac where their Genius Bar gain first hand experience and knowledge which leads to feedback to the Design team. ( They dont publicly announ…
> The goal was to aim for perfection, a machine that is so reliable it wouldn't need to repair in the first place. You will have to excuse me, but that is a load of bullcrap. Let's take the case that irritates me the most: The SSD. By definition of the technology that is NAND storage, an SSD will be able to operate "within norm" and without bit errors for so long. Rewrite for long enough and you'll see your data wavi…
The guarantee of a popular modern 1Tb NVME SSD is you'll at least be able to write 600Tb. I don't know your usage pattern, but those are a lot of write actions.
Remember every component in any electronic device has a finite age: the fan cooling the cpu, keyboards have max. presses, hinges wear out, sockets have a maximum amount of plug/unplug actions.
There's an advantage to soldering on memory, SSD etc: no chance of a bad connector causing problems. The entire class of problems fixed by 'reseating your DIMMS' is gone.
Re: Apple’s T2 security chip jailbreak
#164Earlier quoted context omitted.
> I honestly cannot find a laptop with the combination of 64 GB RAM, a non-NDIVIA GPU, and other premium hardware like its market-leading trackpad at this time Only 14”, and perhaps less performant, but here is this one: https://puri.sm/products/librem-14/ .
Yes, I'm after 15"+ too.
Re: Apple’s T2 security chip jailbreak
#165Earlier quoted context omitted.
I'm a user on a 2019 16-inch MBP (MacBookPro16,1) who hopes to move to Linux as my base OS on this hardware full-time over the next 12 months. ( https://github.com/Dunedan/mbp-2016-linux ) This is because I honestly cannot find a laptop with the combination of 64+ GB RAM, a non-NDIVIA GPU (edit: to clarify, this is because of NVIDIA's notoriously bad compatibility with Linux), and other premium hardware aspects like…
Why without an Nvidia GPU? Just go with an XPS 15 or 17 and embrace Nvidia on Linux. I have three developers running Linux on HP zBooks with Nvidia GPUs without any hassle. You can also buy any newer Thinkpad (my recommendation). They are also available with AMD CPUs. It's pretty easy to buy Linux laptops these days.
All this is on top of the fact that they still don't support Wayland and you have to reboot to switch between the igpu and the nvidia gpu.
Re: Apple’s T2 security chip jailbreak
#166Earlier quoted context omitted.
eh, my 2013 rMBP is kicking a long pretty well. Kinda sluggish but no issues with the keyboard. It's been dropped a few times too and the screen cable disconnected at some point from a fall but was an easy fix.
2012-2015 rMBPs are the best laptops ever produced, imho. My 2012 rMBP has been passed down to my brother, with a new ssd, and still rocks. Why Apple had to mess with that perfect formula, I will never understand. I blame Ive.
Re: Apple’s T2 security chip jailbreak
#167Earlier quoted context omitted.
So, if only Apple didn't tie the ability to repair and extend the device you purchased from them to the security of your own data, you would be able to feel a more consistent emotion with regards to interest in a fix; that seems all on Apple being a bit evil :/.
AFAIK, it's not just about the security of your data (you don't need a T2 chip to encrypt data), but also about discouraging theft of the hardware itself. In light of that, how do you allow for components to be swapped out wholesale without breaking the security model? Isn't the entire point that you can't just steal a Macbook, swap out the SSD, and now you have a functioning (stolen) laptop?
Theft will happen anyway. You can even sell permanently-locked/bricked devices to people which doesn't look to closely at the sellers description. Sure you will need to sell them for cheap, but that's all.
That idea is like saying all cars must be always tracked, always link up with the drivers phone and be remote-controllable by there manufacturer to prevent theft.
Sure it would prevent theft, maybe, until people find ways to brake it. But it's still totally unreasonable with a lot of hidden cost to it.
E.g. in case of apple laptops the cost is losing a lot of small independent companies as well as any way to properly repair an Apple laptop. (Apple doe NOT provide proper repairs they at best replace whole components often the whole main board because it's one component when many damages tend to be similar because people use their devices similar and often are reasonable fixable with a bit of not-easy-but-not-very-hard-either soldering).
EDIT: And most important! The theft constraint can be archived to a reasonable degree WITHOUT locking out third party repair. A example (through not applicable to mac in this case) is how I setup my laptop with a custom EFI platform key/certificate and a BIOS password so to reuse it after theft people have to replace the BIOS chip soldered onto the motherboard (it has no publicly known master key or reset pin). Apple can archive similar things so that theft is more costy but third party repairs are still mostly unconstrained.
Re: Apple’s T2 security chip jailbreak
#168Earlier quoted context omitted.
You could explain this a bit more? Not really understanding how this would be useful.
Just imagine opening your laptop without turning it on, and using it to unlock your front door without getting up, or turning off/on the TV, or the temperature of the house.
Re: Apple’s T2 security chip jailbreak
#169Re: Apple’s T2 security chip jailbreak
#170Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…
Why do you believe it's moral for you to do work which is making people's data less secure, helping law authority crack iPhones, etc?
Granted, owners of the affected hardware might not like it, but this sheds light on issues that are actually present in the hardware. Who's to say that "law authority" or some criminal organization didn't do any work on this without intention to publish their results?
If people have sensitive data and were counting the T2 chip to keep it secure, now they know there are limitations to this security model. They can now weigh the pros and cons and, if applicable, set up an alternative that will be more secure. This could also push Apple to provide better security in upcoming products.