Earlier quoted context omitted.
> run 'offline' dictionary attacks against secure enclave content. Isn't the T2 chip the only reason they can't do that:: because it sets a minimum time-limit and cooldown period on attempts to authenticate using the device passcode? So presumably rooting T2 and removing the artificial time limits and/or extracting KDF data would mean game-over because brute-forcing `[0-9]{4,8}`, with even the most expensive hash fun…
De-capping would probably be much harder than rooting T2.
Apple’s T2 security chip jailbreak
241–250 of 393 posts
Re: Apple’s T2 security chip jailbreak
#242Earlier quoted context omitted.
Some of the people here can’t understand that some people have different opinions. I don’t care that I can’t easily change the SSD. If that were important to me, I would buy a different laptop. I don’t consider my MacBook Pro to be working against me, at all.
You don't care that you can't change out the SSD, but you will care when you take your dead laptop to the Genius Bar and they tell you it's going to be cheaper to buy a new one and that your data is already gone.
If it works like iOS and just flashes a warning then I don’t see the issue. The self-check thing is invaluable when buying used devices.
Re: Apple’s T2 security chip jailbreak
#243Earlier quoted context omitted.
You guys are fighting the good fight for everything that owning hardware and being a user used to mean. Thank you.
I never understood this sentiment, if people choose to pay their way into a walled garden, why should they still care about hardware ownership/repairabilty, etc.?
In the arguments about opening up the iPhone and forcing Apple to allow third party app stores and allow side loading I'm on Apple's side. I think Apple should decide what products they design, how they design them and what features they should have. If I like the feature set, I'll buy the. I do not think it's reasonable for other people to dictate to Apple what code they should write and how it should work, health and safety or deceptive marketing aside. The ability to side load apps would be a software feature that needs to be designed, coded, QA tested, secured etc. Who gets to make all those decisions? I don't think it makes sense to force Apple into doing these things if it doesn't want to do them. You don't like the inability to side load? Buy another phone.
On the other hand once I own a device, it's mine. If I have the ability to jailbreak it, or hack it, or do whatever to it that's my business, not Apple's.
Re: Apple’s T2 security chip jailbreak
#244Earlier quoted context omitted.
As an Apple customer I'm 100% happy with public developments like this. I really believe Apple tries to take hardware security seriously and an exploit it the open like this is surely to be addressed in the next generation of devices. Apple consumer devices have been shown to resist state-level actor threats in the past and even if current devices won't be 100% resistant forever I trust Apple to be a couple of steps…
How did you get the information that apple devices resist state-level actor threats? Repeatedly state actors have broken into iphones and icloud accounts, and apple laptops are frequently the first devices to fall in the Pwn2Own contests.
Re: Apple’s T2 security chip jailbreak
#245[+] Yes, I realize that this also applies to stolen laptops, but this is an actual pain point with running fleets of Macs, from what I've heard.
Re: Apple’s T2 security chip jailbreak
#246Earlier quoted context omitted.
...this is starting to feel like a major screwup on Apple’s part, is there a reason to think otherwise?
Yes, although now the Mac is as secure as any PC with UEFI Secure Boot (and no Intel ME), which isn’t necessarily the end of the world if you have a long firmware password (which protects the Recovery Mode secure boot utility) and login password (which protects FileVault). If you’re in a position where you could be compromised by a state actor or a hacker group (that can find a public flaw in Secure Boot that isn’t j…
Re: Apple’s T2 security chip jailbreak
#247Interesting. Does this mean that companies can now use this to unlock corp laptops that ex-employees have iCloud/activation-locked to their personal accounts without Apple's help? [+] [+] Yes, I realize that this also applies to stolen laptops, but this is an actual pain point with running fleets of Macs, from what I've heard.
Re: Apple’s T2 security chip jailbreak
#248Earlier quoted context omitted.
I'm a user on a 2019 16-inch MBP (MacBookPro16,1) who hopes to move to Linux as my base OS on this hardware full-time over the next 12 months. ( https://github.com/Dunedan/mbp-2016-linux ) This is because I honestly cannot find a laptop with the combination of 64+ GB RAM, a non-NDIVIA GPU (edit: to clarify, this is because of NVIDIA's notoriously bad compatibility with Linux), and other premium hardware aspects like…
While it doesn't entirely meet your specs you can get a T495 with 32GB of RAM [0] and Vega graphics. We're getting close, I am holding on to my T470 as a daily driver and it's one of the best laptops I've owned (I'm forced to use a 16" MBP for work as well - and I still prefer the T470). One of these years we'll get a comparable AMD laptop. Fingers crossed. [0] https://www.lenovo.com/us/en/laptops/thinkpad/thinkpad-t…
Re: Apple’s T2 security chip jailbreak
#249Interesting. Does this mean that companies can now use this to unlock corp laptops that ex-employees have iCloud/activation-locked to their personal accounts without Apple's help? [+] [+] Yes, I realize that this also applies to stolen laptops, but this is an actual pain point with running fleets of Macs, from what I've heard.
Re: Apple’s T2 security chip jailbreak
#250Earlier quoted context omitted.
I don't mean to me facetious, but I am genuinely curious: why should you get to have it your way? You are attempting to buy a product they do not sell.
Because a hardware vendor telling you what you can and can't do with the stuff you own is immoral.
Kind of hard to have diversity/options if everyone keeps insisting all vendors do everything the same way.