Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

181–190 of 393 posts

Re: Apple’s T2 security chip jailbreak

#181
post #177

Earlier quoted context omitted.

I am also interested in the numbers but you aren't earning anywhere near 3k net a month? thats roughly 56k pre-tax. doesn't sound too high to me?

Where did you get your 56K pre-tax? 3k/month NET here means almost 70K/year pre-tax for a single person with no children. Source: https://bruttonetto.arbeiterkammer.at/

same website :D 70k/year is 5k monthly which results in 44k post tax. thats 3700 a month post tax. only us austrians (and i think italians?) do this whole nonsense of 13/14/15/16th salary

Re: Apple’s T2 security chip jailbreak

#182

Earlier quoted context omitted.

You guys are fighting the good fight for everything that owning hardware and being a user used to mean. Thank you.

I never understood this sentiment, if people choose to pay their way into a walled garden, why should they still care about hardware ownership/repairabilty, etc.?

because they want a macbook, just disagree with apple on who should be able to fix it. the choice you mention doesn't exist, it's an illusion. you can't buy a macbook that apple allows you to fix yourself.

Re: Apple’s T2 security chip jailbreak

#183

The fact that Apple uses this chip to, among other things, block "unauthorized repair" (can't change a freaking SSD in 2020, really), makes me very happy that people are finding ways to break this chip to make repairs more accessible. On the other hand, this could have serious implications on the iOS security model for example. And I'm pretty sure someone is gonna run Doom on the touchbar in some months.

For me it was conscious choice: Security ≫ Repairability.

I don't mind getting a new MacBook, but I do mind if it gets compromised. This way I know it would be a screen replacement at best.

Re: Apple’s T2 security chip jailbreak

#184
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

Why do you believe it's moral for you to do work which is making people's data less secure, helping law authority crack iPhones, etc?

What makes you think state actors with inifinite budgets didn't do what this one guy is doing?

Everything he exposes will be fixed and improved. If anything he's helping make Apple devices more secure.

Re: Apple’s T2 security chip jailbreak

#185
post #92

Earlier quoted context omitted.

Consider that their machines maintain the biggest resale value in the PC market (pointing to less long-term issues) and keep working fine for most people for close to a decade or so (including demanding pros in video, music, and graphics), they're doing a bad job at it...

That more or less proves the point. There is very strong demand for old MacBooks because they last. Planned obsolescence is needed to ensure that people upgrade. That can be done multiple ways. This is just one of the approaches and will of course take time to settle in.

>There is very strong demand for old MacBooks because they last.

No, by "old Macbooks" I mean "including current and last year models". Not that only past macbooks had large resale value...

>Planned obsolescence is needed to ensure that people upgrade.

In the Apple world, upgrading is part of the idea and appeal -- you're not supposed to be running a 10 year old laptop or 2-3 versions old OS. The OS is not about backwards compatibility, it's about moving forward faster...

That's part of the appeal of the thing, and part of the reason for the extra control.

I don't want legacy 10/20 year old apps and frameworks to be supported, I don't want apps that don't take advantage of the latest frameworks, hardware and OS features, and so on...

If "compatible with 30 year old programs" is a desirable feature, there's always Windows.

Re: Apple’s T2 security chip jailbreak

#186
post #139
post #84

Earlier quoted context omitted.

> Apple keyboards break down after several years with the touchpad and butterfly keyboard disasters are even unusable afresh. You cannot replace anything, and are way overpriced. I have 10 and 15 year old iBooks and MacBooks and MacBook Pros with intact keyboards... You mixed the issue with the butterfly BS keyboards in the past 2-3 years with the old Apple keyboards (which didn't just "break down"). The resale value…

> with the butterfly BS keyboards in the past 2-3 years Sadly 4 years now, they started in 2016. It's the main issue blocking me from buying another MBP - this keyboard broke when it was already out of warranty, I really don't want to risk it again.

Risk what though? They have changed the keyboard now.

Re: Apple’s T2 security chip jailbreak

#187

Earlier quoted context omitted.

> Filevault and by extension Touch ID are more or less crippled Sorry, what does this sentence mean? That someone with physical access to my machine can now unencrypt my FileVault encrypted hard drive?

Some one from Apple, I'm sure you read this. Please answer this ASAP. I rely on mac and FileValute for professional use at work. Need to know the state of this exploit.

lol good luck and god bless with all that.

Re: Apple’s T2 security chip jailbreak

#188
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

>Custom bootloaders are now possible This is interesting; does this mean Apple isn't enabling Intel Boot Guard, relying only on the checks enforced by MacEFIUtil? Fantastic work, by the way.

They aren’t, they’ve removed much of the Intel software that is usually included with UEFI except what is required for DRMed video. If the T2 is compromised, they say that one could compromise UEFI on the device permanently as well.

https://support.apple.com/guide/security/uefi-firmware-overv...

Re: Apple’s T2 security chip jailbreak

#189

Earlier quoted context omitted.

Everyone in the Linux space, from what I regularly read and hear, says that NVIDIA GPUs are notorious and a bad idea for using Linux. They're saying go with AMD. (As well as Ryzen instead of Intel for CPUs, where possible.) The only open-source nouveau drivers are absolutely terrible, I can attest to that fact myself. There's several benefits to not relying on NVIDIA's proprietary and non-in-built drivers for a decen…

I will anecdotally agree; I've been a Linux laptop user for... well, 2 decades maybe? and explicitly choose Dell Mobile Precision and/or IBM/Lenovo T-series laptops with ATI/AMD, dealing with NVIDIA graphics is just a pain in the ass once we passed the GeForce era (ish). I'd rather just have/use Intel GPU over them as well, I am not a laptop gamer to need anything NVIDIA offers in exchange for the pain in maintenance…

I will anecdotally disagree.

Depending on which distro you use NVIDIA grapics can be quite painless. Using Pop!_OS, I just had to download the correct iso from their downloads page.

I believe most other distros have NVIDIA's drivers in their non FL/OSS repos as well.

Optimus graphics will even work with the most current drivers.

Re: Apple’s T2 security chip jailbreak

#190
post #181

Earlier quoted context omitted.

Where did you get your 56K pre-tax? 3k/month NET here means almost 70K/year pre-tax for a single person with no children. Source: https://bruttonetto.arbeiterkammer.at/

same website :D 70k/year is 5k monthly which results in 44k post tax. thats 3700 a month post tax. only us austrians (and i think italians?) do this whole nonsense of 13/14/15/16th salary

You're right, I forgot to divide the 13 and 14 salary. Even with those included, I'm at 2750 NET per month(49K/year before taxes), which is still below the 3000+ average claimed above and devs tend to be above average paid(usually).

Or everyone else makes 3000+ and I'm underpaid, who knows. :D Sucks that people in this country don't usually discuss salaries because reasons.

Post reply on HN