Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

231–240 of 393 posts

Re: Apple’s T2 security chip jailbreak

#231

Earlier quoted context omitted.

> Filevault and by extension Touch ID are more or less crippled Sorry, what does this sentence mean? That someone with physical access to my machine can now unencrypt my FileVault encrypted hard drive?

Some one from Apple, I'm sure you read this. Please answer this ASAP. I rely on mac and FileValute for professional use at work. Need to know the state of this exploit.

> I rely on Mac and FileVault for professional use

... then phase out your use, because proprietary systems will always get cracked given enough time.

Re: Apple’s T2 security chip jailbreak

#232
post #81

Earlier quoted context omitted.

One could say that you're mixing Thinkpads from IBM era, where they were really well made (my first A21m holds a special place in my heat till this day), Thinkpads from Lenovo that are plastic piece of garbage and MacBooks from Apple post keyboard change, that was indeed faulty, but it isn't anymore. There you go, I've fixed it for ya ;)

That’s going back a very long time. Early Lenovo ThinkPads like the X60 were also excellent.

If you haven't come across it, [HOPE]'s work getting modern internals in X60s is pretty cool. Not sure where the project is at now, I think at some point they were orderable.

https://hackaday.com/2018/03/12/new-guts-make-old-thinkpads-...

Re: Apple’s T2 security chip jailbreak

#233
post #175

Earlier quoted context omitted.

As an Apple customer I'm 100% happy with public developments like this. I really believe Apple tries to take hardware security seriously and an exploit it the open like this is surely to be addressed in the next generation of devices. Apple consumer devices have been shown to resist state-level actor threats in the past and even if current devices won't be 100% resistant forever I trust Apple to be a couple of steps…

How did you get the information that apple devices resist state-level actor threats? Repeatedly state actors have broken into iphones and icloud accounts, and apple laptops are frequently the first devices to fall in the Pwn2Own contests.

Don't know why you were downvoted, it's common knowledge that state actors can break Apple's encryption. Apple makes a huge show of refusing to break their own encryption but with a subpoena they legally have to provide the encrypted data and then state actors just go elsewhere for cracking.

Re: Apple’s T2 security chip jailbreak

#234
post #228
post #197

Earlier quoted context omitted.

Where and how do you see the T2 chip being the mechanism that Apple stops reselling of hardware? Yes it could be used that way. But they have never even indicated that they've been thinking of using the secure enclave for that purpose.

They also indicated they'd never ever use Mac's notarization requirement to block legitimate software. Then they got in a legal fracas with Epic and immediately retaliated against Epic by banning all their software from all Apple hardware! Apple has shown they are very eager to use their position of power to strong-arm the competition, and these kinds of chips only add to their power.

No they did not do that at all.

Re: Apple’s T2 security chip jailbreak

#235
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

Incredible work. > It's a pretty peppy chip, at times coming close to my 8th gen i7...yikes. Have you got any benchmarks? It is passively cooled right? I am really surprised to hear a ~2016 arm64 CPU can can beat a 2019 Intel i7 in even synthetic benchmarks.

Some synthetic benchmarks are so simple that they almost reduce to a measure of CPU clock speed and instruction parallelism. Find a benchmark that uses a unique instruction combination on one CPU and it will heavily disadvantage the other CPU.

Add a real world workload to the mix with heavy memory access and mixed compute workloads and the chips will diverge significantly in performance.

I work with some cross-platform code that has to run on mobile devices and desktop platforms. The advances Apple has made in low power performance are incredible, but the idea that their iPhone chips are as fast as desktop computers is still far from the truth unless you’re measuring specific, heavily optimized workloads.

I’m still excited to see what Apple can do with a full desktop level power budget though.

Re: Apple’s T2 security chip jailbreak

#236
post #228
post #197

Earlier quoted context omitted.

Where and how do you see the T2 chip being the mechanism that Apple stops reselling of hardware? Yes it could be used that way. But they have never even indicated that they've been thinking of using the secure enclave for that purpose.

They also indicated they'd never ever use Mac's notarization requirement to block legitimate software. Then they got in a legal fracas with Epic and immediately retaliated against Epic by banning all their software from all Apple hardware! Apple has shown they are very eager to use their position of power to strong-arm the competition, and these kinds of chips only add to their power.

That's a very disingenuous assessment of the situation at hand. Epic knowingly violated their developer agreement. There was no retaliation. There was the consequences that were written into the developer agreement that Epic agreed to.

Re: Apple’s T2 security chip jailbreak

#237
post #142
post #61

Earlier quoted context omitted.

Sorry, but the only rational consumer response to a device that actively works against you is not to purchase it, not hack it. Once millions of people pay to be imprisoned on their own devices, the long game is lost no matter how good the hackers are, the firm has the upper hand and the resources to prevail in the long run. And I am perfectly happy to assert this as a political preference, and vote in office people t…

Some of the people here can’t understand that some people have different opinions. I don’t care that I can’t easily change the SSD. If that were important to me, I would buy a different laptop. I don’t consider my MacBook Pro to be working against me, at all.

You don't care that you can't change out the SSD, but you will care when you take your dead laptop to the Genius Bar and they tell you it's going to be cheaper to buy a new one and that your data is already gone.

Re: Apple’s T2 security chip jailbreak

#238
post #144

Earlier quoted context omitted.

This might be a confusion started from the answer of "amelius", the logic of which I don't fully support. I believe consumer freedom is hampered first and foremost by monopolies (or, in the mobile OS case, oligopolies) and my political choice is to maximize market forces and restrict anti-competitive behavior. This is the grounds on which I oppose Apple practices, not some idea that if people buy Apple products it so…

Again, where is the monopoly that forces you to buy devices with a T2 chip (or something) analogous? That’s simply not the world we live in, and it doesn’t seem to me like we’re moving toward it. And if your political choice is to maximize market forces, why are you trying to fight the market forces that result in there being a large market for Apple’s devices and a small (but extant and healthy) market for the devic…

Monopoly power is not a market force, it's an abuse of the market to the detriment of the consumers. If "the market forces that result in there being a large market for Apple’s devices" is Apple using its platform to, say, restrict competition and maximize app revenue, thus having more money to invest in their platform, thus forcing competitors to apply the same dubious tactics or fail, then this is not a pro-consumer model because it leads to an oligopoly at best or impenetrable monopoly at worst.

The consumers can buy any system with any chip they want. If it is employed by Apple to enhance security that's great, for example the Mac. If it's used to lockdown the device so that no competing software can be run, a la iPhone, for them to maintain the stranglehold on the app market, then I am against it on political grounds and my position is not falsifiable.

You are inworking an oligopoly situation and accuse me of wanting to turn it into a monopoly, but I want the exact opposite: all existing platforms to still exist, and additionally, all those prevented by anti-competitive behavior, which by my non-falsifiable definition includes any lockdown on the hardware that is sold in the marketplace, that can only be, and is only used to limit the options of the owner.

It is not like Apple devices would cease to be produced or be confiscated if we pass laws mandating software freedom on purchased hardware, from iPhones to tractors.

Re: Apple’s T2 security chip jailbreak

#239

Earlier quoted context omitted.

Why without an Nvidia GPU? Just go with an XPS 15 or 17 and embrace Nvidia on Linux. I have three developers running Linux on HP zBooks with Nvidia GPUs without any hassle. You can also buy any newer Thinkpad (my recommendation). They are also available with AMD CPUs. It's pretty easy to buy Linux laptops these days.

Everyone in the Linux space, from what I regularly read and hear, says that NVIDIA GPUs are notorious and a bad idea for using Linux. They're saying go with AMD. (As well as Ryzen instead of Intel for CPUs, where possible.) The only open-source nouveau drivers are absolutely terrible, I can attest to that fact myself. There's several benefits to not relying on NVIDIA's proprietary and non-in-built drivers for a decen…

I'm in the Linux space. My GTX 1060 works just fine.

Re: Apple’s T2 security chip jailbreak

#240
post #142

Earlier quoted context omitted.

Some of the people here can’t understand that some people have different opinions. I don’t care that I can’t easily change the SSD. If that were important to me, I would buy a different laptop. I don’t consider my MacBook Pro to be working against me, at all.

You don't care that you can't change out the SSD, but you will care when you take your dead laptop to the Genius Bar and they tell you it's going to be cheaper to buy a new one and that your data is already gone.

One reason Apple laptops are popular is that people, on average, like both the laptops and the service they get from Apple.
Post reply on HN