Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

211–220 of 393 posts

Re: Apple’s T2 security chip jailbreak

#211

Great day to be Apple I guess. I imagine there’s no better incentive to get people to move en masse to your new architecture than an exploit for your old architecture that completely and irreparably breaks its security model showing up weeks before it’s released.

I don’t think this is the type of thing that affects broad consumer decision making on product replacement.

Maybe a slight impact if it was the only story in the news right now and the cable networks ran it regularly? Still a stretch.

Re: Apple’s T2 security chip jailbreak

#212
post #188

Earlier quoted context omitted.

>Custom bootloaders are now possible This is interesting; does this mean Apple isn't enabling Intel Boot Guard, relying only on the checks enforced by MacEFIUtil? Fantastic work, by the way.

They aren’t, they’ve removed much of the Intel software that is usually included with UEFI except what is required for DRMed video. If the T2 is compromised, they say that one could compromise UEFI on the device permanently as well. https://support.apple.com/guide/security/uefi-firmware-overv...

...this is starting to feel like a major screwup on Apple’s part, is there a reason to think otherwise?

Re: Apple’s T2 security chip jailbreak

#213
post #204

Earlier quoted context omitted.

You're right, I forgot to divide the 13 and 14 salary. Even with those included, I'm at 2750 NET per month(49K/year before taxes), which is still below the 3000+ average claimed above and devs tend to be above average paid(usually). Or everyone else makes 3000+ and I'm underpaid, who knows. :D Sucks that people in this country don't usually discuss salaries because reasons.

you are right, just redid the calculation and i am at 33k post-tax too. i guess i had the family bonus still active when i did it last time. nobody discussed salaries in germany/UK either though. wasn't just a problem in vienna for me ;) how are the salaries in vienna these days for software devs?

No idea since I don't live in Vienna but afaik worse than in German/Swiss tech hubs but at a lower CoL.

Whether the overall salary/CoL ratio is a better deal for you here than in the other hubs really depends on how good your salary is and how much you'll spend.

Re: Apple’s T2 security chip jailbreak

#214
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

>Hi guys, I am part of the team working on all things T2.

So there is a team working on this? What is the incentive model? Are you paid to do this work? What is the revenue model?

I woke up today learning my MacBook Pro is now substantially less secure but why? So I can run games on the touch bar? So I can use the T2 as a raspberry pi?

Re: Apple’s T2 security chip jailbreak

#215
post #197

Earlier quoted context omitted.

Mac hardware traditionally holds resale value. The T2 chip threatens to turn that hardware into a brick once resold. So beyond that jailbreaking ultimately makes the user's data more secure once Apple repairs and releases a fix (likely only going forward with new hardware) the jailbreak will cure the problem with aftermarket bricks for hardware with this T2 chip.

Where and how do you see the T2 chip being the mechanism that Apple stops reselling of hardware? Yes it could be used that way. But they have never even indicated that they've been thinking of using the secure enclave for that purpose.

It's not an intentional anti-resale feature, but it does make repair a lot harder, because it locks (or at least, can lock) specific hardware components to the motherboard. This means if something on the laptop breaks, you can't repair it without the T2 chip knowing about it and potentially refusing to work. Apple has at least told their authorized repair partners that failing to register the repair with Apple may brick the device should Apple choose to further lock down unauthorized repairs in future firmware updates.

The T2 also has a particularly wonky approach to disk encryption. It uses a key management approach where neither you nor Apple control the actual key material. This means that a dead T2 takes your data with it and there is no recovery. In pre-T2 MacBooks, Apple had a lifeboat connector which could be used for data recovery from the soldered-on SSD. They got rid of this with the T2, because there's no point - only that specific T2 in that specific motherboard is ever able to decrypt the data.

Re: Apple’s T2 security chip jailbreak

#216
post #175

I'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to cra…

As an Apple customer I'm 100% happy with public developments like this. I really believe Apple tries to take hardware security seriously and an exploit it the open like this is surely to be addressed in the next generation of devices. Apple consumer devices have been shown to resist state-level actor threats in the past and even if current devices won't be 100% resistant forever I trust Apple to be a couple of steps…

How did you get the information that apple devices resist state-level actor threats?

Repeatedly state actors have broken into iphones and icloud accounts, and apple laptops are frequently the first devices to fall in the Pwn2Own contests.

Re: Apple’s T2 security chip jailbreak

#217
post #48

Earlier quoted context omitted.

> The goal was to aim for perfection, a machine that is so reliable it wouldn't need to repair in the first place. You will have to excuse me, but that is a load of bullcrap. Let's take the case that irritates me the most: The SSD. By definition of the technology that is NAND storage, an SSD will be able to operate "within norm" and without bit errors for so long. Rewrite for long enough and you'll see your data wavi…

Who is Linus Sebastian, why should I care about him, and why I should consider his case typical?

That Linus is a YouTube star who reviews computer stuff. I like to think he got popular because his name is Linus and people mistook him for Torvalds or he came up in searches. I've seen a couple of his videos and he talks to the camera in a manner reminiscent of a young kids show host. I half expected him to start reciting the basic colors to me during a video about doing direct GPU passthrough on multiple VMs. Tone aside, and I know I'm not his core audience, it was a good presentation.

Re: Apple’s T2 security chip jailbreak

#218

Earlier quoted context omitted.

You guys are fighting the good fight for everything that owning hardware and being a user used to mean. Thank you.

I never understood this sentiment, if people choose to pay their way into a walled garden, why should they still care about hardware ownership/repairabilty, etc.?

We don't live in a world with a robust operating system market where people can pick and choose the perfect option for them. You have three choices and they are each going to be a mixed bad of good and bad features for almost everyone.

Re: Apple’s T2 security chip jailbreak

#219
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

Why do you believe it's moral for you to do work which is making people's data less secure, helping law authority crack iPhones, etc?

Law enforcement has been going apeshit about legally forcing Apple to build in hardware backdoors to their products. If this jailbreak didn't exist, they'd be putting a gun to Apple's head and demanding decryption tools for all iPhones.

Furthermore, the entire point of a jailbreak is to regain root access to your own device - Apple provides no way for a user to do so, which I find at least somewhat irksome. The way it currently stands, all iOS devices ship with Apple having total control over the device, and a jailbreak lets you claw back control by force if you so choose.

Re: Apple’s T2 security chip jailbreak

#220
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

>Hi guys, I am part of the team working on all things T2. So there is a team working on this? What is the incentive model? Are you paid to do this work? What is the revenue model? I woke up today learning my MacBook Pro is now substantially less secure but why? So I can run games on the touch bar? So I can use the T2 as a raspberry pi?

Your MacBook Pro didn't now become less secure. It always was. We should be thankful to these people for making the vulnerability clear to us.
Post reply on HN