Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

221–230 of 393 posts

Re: Apple’s T2 security chip jailbreak

#221

Earlier quoted context omitted.

I hope you have reported the issue to Apple so they can fix it ASAP ?

They are well aware of the issue and have been for some time. There’s not all that much they can do to fix this, although they have certainly tried.

> There’s not all that much they can do to fix this, although they have certainly tried.

Forgive my ignorance, why is there not much they can do and what have they tried?

Re: Apple’s T2 security chip jailbreak

#222

Earlier quoted context omitted.

I'm a user on a 2019 16-inch MBP (MacBookPro16,1) who hopes to move to Linux as my base OS on this hardware full-time over the next 12 months. ( https://github.com/Dunedan/mbp-2016-linux ) This is because I honestly cannot find a laptop with the combination of 64+ GB RAM, a non-NDIVIA GPU (edit: to clarify, this is because of NVIDIA's notoriously bad compatibility with Linux), and other premium hardware aspects like…

Why without an Nvidia GPU? Just go with an XPS 15 or 17 and embrace Nvidia on Linux. I have three developers running Linux on HP zBooks with Nvidia GPUs without any hassle. You can also buy any newer Thinkpad (my recommendation). They are also available with AMD CPUs. It's pretty easy to buy Linux laptops these days.

It's pretty easy to buy Linux laptops these days.

Yes but to GP’s stated requirements, the trackpad feels like trying to push a marble around in peanut butter.

Re: Apple’s T2 security chip jailbreak

#223

Earlier quoted context omitted.

I will anecdotally disagree. Depending on which distro you use NVIDIA grapics can be quite painless. Using Pop!_OS, I just had to download the correct iso from their downloads page. I believe most other distros have NVIDIA's drivers in their non FL/OSS repos as well. Optimus graphics will even work with the most current drivers.

I’m using Pop!Os (preinstalled) with a sys76 laptop. Works great (can even game) battery life is terrible (though it looks fantastic and can drive a 32 inch high dpi external) I can switch to built in Intel video for better battery but it requires a reboot. I see this as a stopgap. My home machine has an amd video.

It's definitely sub-optimal needing to reboot.

I only need the NVIDIA graphics every so often on my laptop though, so it's fine for me.

On desktop I've had no issues.

Re: Apple’s T2 security chip jailbreak

#224
post #135

Earlier quoted context omitted.

I never understood this sentiment, if people choose to pay their way into a walled garden, why should they still care about hardware ownership/repairabilty, etc.?

It's a trade-off. I buy MBPs for the great form-factor and OS, not for the walled-garden shenanigans. If those shenanigans can be somewhat reduced, the trade-off balance looks better.

I don't mean to me facetious, but I am genuinely curious: why should you get to have it your way? You are attempting to buy a product they do not sell.

Re: Apple’s T2 security chip jailbreak

#225

Earlier quoted context omitted.

They are well aware of the issue and have been for some time. There’s not all that much they can do to fix this, although they have certainly tried.

> There’s not all that much they can do to fix this, although they have certainly tried. Forgive my ignorance, why is there not much they can do and what have they tried?

My understanding is that because this is a hardware-based issue, there’s no way to release a software patch to fix it.

Re: Apple’s T2 security chip jailbreak

#226
post #80

Earlier quoted context omitted.

> The biggest competitor for new MacBooks are old MacBooks. Maybe true 5-10 years ago, but not true now.

Replying from my 7 year old Macbook Air. This might be the last Apple product I'm buying.

Replying from my 6 year old Macbook pro, I would definitely consider buying a new one (space on my 256 GB SSD is getting tight, and it seems a bit of a waste to just upgrade that), but I am hesitant about the newer models.

Re: Apple’s T2 security chip jailbreak

#227
post #130

Earlier quoted context omitted.

You have to get rid of the packaging, and dump all the manuals etc or otherwise you might get a date with customs to explains why you have 10 unopened MBP's in your backpack and you get a nice import fee + VAT or you can leave them at the customs office. Also, you get about 10% tax added when buy.

Last time I did this, when the officials saw the number of laptops in my carryon they sent me over to the diplomat line for faster processing.

LOL, what happened then?

Re: Apple’s T2 security chip jailbreak

#228
post #197

Earlier quoted context omitted.

Mac hardware traditionally holds resale value. The T2 chip threatens to turn that hardware into a brick once resold. So beyond that jailbreaking ultimately makes the user's data more secure once Apple repairs and releases a fix (likely only going forward with new hardware) the jailbreak will cure the problem with aftermarket bricks for hardware with this T2 chip.

Where and how do you see the T2 chip being the mechanism that Apple stops reselling of hardware? Yes it could be used that way. But they have never even indicated that they've been thinking of using the secure enclave for that purpose.

They also indicated they'd never ever use Mac's notarization requirement to block legitimate software.

Then they got in a legal fracas with Epic and immediately retaliated against Epic by banning all their software from all Apple hardware!

Apple has shown they are very eager to use their position of power to strong-arm the competition, and these kinds of chips only add to their power.

Re: Apple’s T2 security chip jailbreak

#229
post #135

Earlier quoted context omitted.

It's a trade-off. I buy MBPs for the great form-factor and OS, not for the walled-garden shenanigans. If those shenanigans can be somewhat reduced, the trade-off balance looks better.

I don't mean to me facetious, but I am genuinely curious: why should you get to have it your way? You are attempting to buy a product they do not sell.

Because a hardware vendor telling you what you can and can't do with the stuff you own is immoral.

Re: Apple’s T2 security chip jailbreak

#230
post #188

Earlier quoted context omitted.

They aren’t, they’ve removed much of the Intel software that is usually included with UEFI except what is required for DRMed video. If the T2 is compromised, they say that one could compromise UEFI on the device permanently as well. https://support.apple.com/guide/security/uefi-firmware-overv...

...this is starting to feel like a major screwup on Apple’s part, is there a reason to think otherwise?

Yes, although now the Mac is as secure as any PC with UEFI Secure Boot (and no Intel ME), which isn’t necessarily the end of the world if you have a long firmware password (which protects the Recovery Mode secure boot utility) and login password (which protects FileVault). If you’re in a position where you could be compromised by a state actor or a hacker group (that can find a public flaw in Secure Boot that isn’t just turning it off), perhaps throw away your Mac, but everyone else should still be “okay”.

Part of me wonders if there could be a way to permanently disable DFU mode (preferably outside of epoxy in the upper left USB-C port). That would prevent someone from jailbreaking the T2, albeit you would no longer be able to replace the SSD or Touch ID sensor (not that you’d want to anyway if you were at risk).

Post reply on HN