Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

251–260 of 393 posts

Re: Apple’s T2 security chip jailbreak

#251
post #86
post #61

Earlier quoted context omitted.

Sorry, but the only rational consumer response to a device that actively works against you is not to purchase it, not hack it. Once millions of people pay to be imprisoned on their own devices, the long game is lost no matter how good the hackers are, the firm has the upper hand and the resources to prevail in the long run. And I am perfectly happy to assert this as a political preference, and vote in office people t…

> Sorry, but the only rational consumer response to a device that actively works against you is not to purchase it, not hack it. "Actively works against you" is your reading. I very much appreciate what the T2 does, and hope the next update will be even more difficult to hack (aside from its other functionality).

then perhaps you would be better suited on a forum focused on your interests... I'm thinking "Apple Shill News" instead.

Re: Apple’s T2 security chip jailbreak

#252
post #43

Earlier quoted context omitted.

The T2 was more or less a stopgap solution between their current Intel-based offerings and the AppleSilicon devices in regards to their security aspirations. My understanding is that there will be no T3, as evidenced in the DTK, which makes a lot of sense considering how identical these chips will be to their mobile counterparts.

I'm a user on a 2019 16-inch MBP (MacBookPro16,1) who hopes to move to Linux as my base OS on this hardware full-time over the next 12 months. ( https://github.com/Dunedan/mbp-2016-linux ) This is because I honestly cannot find a laptop with the combination of 64+ GB RAM, a non-NDIVIA GPU (edit: to clarify, this is because of NVIDIA's notoriously bad compatibility with Linux), and other premium hardware aspects like…

I'm stuck with a 15" 2018 macbook pro running macOS because of T2. I feel your pain.

Re: Apple’s T2 security chip jailbreak

#253
post #197

Earlier quoted context omitted.

Where and how do you see the T2 chip being the mechanism that Apple stops reselling of hardware? Yes it could be used that way. But they have never even indicated that they've been thinking of using the secure enclave for that purpose.

It's not an intentional anti-resale feature, but it does make repair a lot harder, because it locks (or at least, can lock) specific hardware components to the motherboard. This means if something on the laptop breaks, you can't repair it without the T2 chip knowing about it and potentially refusing to work. Apple has at least told their authorized repair partners that failing to register the repair with Apple may br…

Data recovery - in an era where you have to go out of your way to keep your data out of the cloud, backups are easier than ever and can be done wirelessly - this is going to be your major objection?

Please. As for matching parts to the motherboard, they have a point when it comes to I/O devices. It’s probably way more cloak and dagger than most people will ever have to worry about but it’s not unheard of. Again, if you don’t want to think about such things and want a device that trades ease of repair for improved base security why isn’t that something that shouldn’t be a choice?

I’m generally pretty pro right to repair, but as with anything there are pro’s and con’s to all choices and I’m not fond of several of the right to repair arguments for government regulation being made. Apple is far from the only maker of computers out there. It is the only maker of macOS, but that still doesn’t justify people trying to dictate their business model - especially when many aspects of their business models are major reasons why I prefer their platforms.

Re: Apple’s T2 security chip jailbreak

#254
post #250

Earlier quoted context omitted.

Because a hardware vendor telling you what you can and can't do with the stuff you own is immoral.

Then don’t buy it? It’s not like Apple is the only vendor. Kind of hard to have diversity/options if everyone keeps insisting all vendors do everything the same way.

I can buy what I want and also do what I want to what I purcwhased.

Re: Apple’s T2 security chip jailbreak

#255
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

Incredible work. > It's a pretty peppy chip, at times coming close to my 8th gen i7...yikes. Have you got any benchmarks? It is passively cooled right? I am really surprised to hear a ~2016 arm64 CPU can can beat a 2019 Intel i7 in even synthetic benchmarks.

Mostly synthetics and some program compilation (configure+make) tests. Yes, it is passively cooled. To clarify, it does not match the host Intel CPU (i7-8750H @ 2.2GHz) but in some synthetics, i.e. Coremark, the T2 does come close. I would attribute the i7's lackluster performance mainly to thermal throttling issues.

Re: Apple’s T2 security chip jailbreak

#256

Earlier quoted context omitted.

> Filevault and by extension Touch ID are more or less crippled Sorry, what does this sentence mean? That someone with physical access to my machine can now unencrypt my FileVault encrypted hard drive?

Some one from Apple, I'm sure you read this. Please answer this ASAP. I rely on mac and FileValute for professional use at work. Need to know the state of this exploit.

>FileVault for professional use

Probably not the best choice :) you never want to use proprietary software if security is a concern

Re: Apple’s T2 security chip jailbreak

#257
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

[deleted]

Re: Apple’s T2 security chip jailbreak

#258

Earlier quoted context omitted.

Fair enough, but the problem is mainly when you are in a third world country and parts are very difficult to get, and where Mac stores are non-existent.

People in third world countries buy Macbooks - really? A decent macbook is several times above an average monthly income in a first-world country already...

OFC we do, that's just plain xenophobic. I'm a Colombian software developer and my company has given me Macbook Pro.

Re: Apple’s T2 security chip jailbreak

#259

I'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to cra…

Apple did actually screw the pooch on this one. Typically, it's criminally illegal to circumvent DRM in the US (and 99% of the rest of the world). However, there are also certain exemptions that have been granted, within the US only (other countries are not so lucky). The right to repair is one such exemption[1]. If Apple had separated security from first-party repair enforcement, then anyone found even attempting to…

The US is effectively the only place in the world where circumventing DRM is actually illegal and prosecute-able, every other country has various exemptions and bypasses that remove its teeth. Here in Canada for example, you can happily argue "I was doing it to learn how it worked" and fall under the education exemption, unless you're stripping DRM and actively selling the content or something similar.

You should have a skim through https://en.wikipedia.org/wiki/Digital_rights_management#Laws

Re: Apple’s T2 security chip jailbreak

#260
post #52

Earlier quoted context omitted.

De-capping would probably be much harder than rooting T2.

And both would be much harder than just holding a gun to someone's head until they give up their password.

But only one of those could potentially be stealthy enough so that target would not notice anything.
Post reply on HN