Earlier quoted context omitted.
> Filevault and by extension Touch ID are more or less crippled Sorry, what does this sentence mean? That someone with physical access to my machine can now unencrypt my FileVault encrypted hard drive?
The Secure Enclave on the T2 chip was used to store secrets that were supposed to stay inaccessible, even to someone with physical access. If you use a strong password to encrypt your drive you should still be safe, unless Apple did something really stupid. The password is used as a one-way hash to generate the key. However if you can login with Touch ID and they find a way to use known SE exploits, it's compromised.…
Apple’s T2 security chip jailbreak
261–270 of 393 posts
Re: Apple’s T2 security chip jailbreak
#262Earlier quoted context omitted.
Some one from Apple, I'm sure you read this. Please answer this ASAP. I rely on mac and FileValute for professional use at work. Need to know the state of this exploit.
>FileVault for professional use Probably not the best choice :) you never want to use proprietary software if security is a concern
Re: Apple’s T2 security chip jailbreak
#263Earlier quoted context omitted.
Where and how do you see the T2 chip being the mechanism that Apple stops reselling of hardware? Yes it could be used that way. But they have never even indicated that they've been thinking of using the secure enclave for that purpose.
It's not an intentional anti-resale feature, but it does make repair a lot harder, because it locks (or at least, can lock) specific hardware components to the motherboard. This means if something on the laptop breaks, you can't repair it without the T2 chip knowing about it and potentially refusing to work. Apple has at least told their authorized repair partners that failing to register the repair with Apple may br…
Re: Apple’s T2 security chip jailbreak
#264Earlier quoted context omitted.
You guys are fighting the good fight for everything that owning hardware and being a user used to mean. Thank you.
I never understood this sentiment, if people choose to pay their way into a walled garden, why should they still care about hardware ownership/repairabilty, etc.?
Re: Apple’s T2 security chip jailbreak
#265Re: Apple’s T2 security chip jailbreak
#266Earlier quoted context omitted.
The Secure Enclave on the T2 chip was used to store secrets that were supposed to stay inaccessible, even to someone with physical access. If you use a strong password to encrypt your drive you should still be safe, unless Apple did something really stupid. The password is used as a one-way hash to generate the key. However if you can login with Touch ID and they find a way to use known SE exploits, it's compromised.…
Isn't a password always required to decrypt on a cold boot?
Re: Apple’s T2 security chip jailbreak
#267Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…
Why do you believe it's moral for you to do work which is making people's data less secure, helping law authority crack iPhones, etc?
Re: Apple’s T2 security chip jailbreak
#268Earlier quoted context omitted.
Some one from Apple, I'm sure you read this. Please answer this ASAP. I rely on mac and FileValute for professional use at work. Need to know the state of this exploit.
>FileVault for professional use Probably not the best choice :) you never want to use proprietary software if security is a concern
As long as the incentives of the developer of the security scheme and the end-user are aligned (so no backdoors), I would trust a widespread, proprietary solution which appears to stand up to significant attacks (the solution being widespread means there are lots of efforts underway to crack it) more than an open-source implementation that nobody uses.
Re: Apple’s T2 security chip jailbreak
#269Re: Apple’s T2 security chip jailbreak
#270Earlier quoted context omitted.
Exactly. This would "in theory" allow Doom to be running outside of the "prescribed parameters".
So the monsters would actually leave the touchbar. This sounds really risky, folks