Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

271–280 of 393 posts

Re: Apple’s T2 security chip jailbreak

#271
post #197

Earlier quoted context omitted.

Mac hardware traditionally holds resale value. The T2 chip threatens to turn that hardware into a brick once resold. So beyond that jailbreaking ultimately makes the user's data more secure once Apple repairs and releases a fix (likely only going forward with new hardware) the jailbreak will cure the problem with aftermarket bricks for hardware with this T2 chip.

Where and how do you see the T2 chip being the mechanism that Apple stops reselling of hardware? Yes it could be used that way. But they have never even indicated that they've been thinking of using the secure enclave for that purpose.

macOS will deprecate older Macs 6-7 years after their release. You can use older Macs as Linux machines, with one of the BSDs, or with Windows.

The T2 chip can prevent people from putting their OS of choice on their hardware once Apple deprecates support for their machine.

Re: Apple’s T2 security chip jailbreak

#272
post #142

Earlier quoted context omitted.

Some of the people here can’t understand that some people have different opinions. I don’t care that I can’t easily change the SSD. If that were important to me, I would buy a different laptop. I don’t consider my MacBook Pro to be working against me, at all.

You don't care that you can't change out the SSD, but you will care when you take your dead laptop to the Genius Bar and they tell you it's going to be cheaper to buy a new one and that your data is already gone.

All I care about is having a high-quality *nix machine. Right now, a MacBook Pro with macOS fits that bill well: the calculus may very well change, on both the hardware and OS side, when x86 is replaced with ARM64, though.

Re: Apple’s T2 security chip jailbreak

#273
post #233

Earlier quoted context omitted.

How did you get the information that apple devices resist state-level actor threats? Repeatedly state actors have broken into iphones and icloud accounts, and apple laptops are frequently the first devices to fall in the Pwn2Own contests.

Don't know why you were downvoted, it's common knowledge that state actors can break Apple's encryption. Apple makes a huge show of refusing to break their own encryption but with a subpoena they legally have to provide the encrypted data and then state actors just go elsewhere for cracking.

citation needed

Re: Apple’s T2 security chip jailbreak

#274
post #130

Earlier quoted context omitted.

You have to get rid of the packaging, and dump all the manuals etc or otherwise you might get a date with customs to explains why you have 10 unopened MBP's in your backpack and you get a nice import fee + VAT or you can leave them at the customs office. Also, you get about 10% tax added when buy.

Last time I did this, when the officials saw the number of laptops in my carryon they sent me over to the diplomat line for faster processing.

That's funny, when I flew in LA from Bali, I got stuffed in a room for four hours because I had a rock in my suitcase.

Re: Apple’s T2 security chip jailbreak

#275
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

Why do you believe it's moral for you to do work which is making people's data less secure, helping law authority crack iPhones, etc?

I'm glad they released their jailbreak, because otherwise, those exploits would be sold and traded on the black market or collected and used by malicious groups, and we would be none the wiser. We'd walk around believing our machines are secure, and act like it, while that clearly isn't the truth.

Re: Apple’s T2 security chip jailbreak

#276
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

Incredible work. > It's a pretty peppy chip, at times coming close to my 8th gen i7...yikes. Have you got any benchmarks? It is passively cooled right? I am really surprised to hear a ~2016 arm64 CPU can can beat a 2019 Intel i7 in even synthetic benchmarks.

A ~2017 i7 is only 4% slower than a ~2019 i7:

https://cpu.userbenchmark.com/Compare/Intel-Core-i7-8700-vs-...

Re: Apple’s T2 security chip jailbreak

#277

Earlier quoted context omitted.

Just imagine opening your laptop without turning it on, and using it to unlock your front door without getting up, or turning off/on the TV, or the temperature of the house.

What holds you back from using a smartphone?

Nothing. But I don't know about you, but I'm more likely to have a laptop nearby than my phone. Especially if the kiddo is playing his dragon game on it.

Re: Apple’s T2 security chip jailbreak

#278
post #139

Earlier quoted context omitted.

> with the butterfly BS keyboards in the past 2-3 years Sadly 4 years now, they started in 2016. It's the main issue blocking me from buying another MBP - this keyboard broke when it was already out of warranty, I really don't want to risk it again.

Risk what though? They have changed the keyboard now.

They’ve changed the keyboard three times over 4 years, iirc; I am somewhat skeptical that they really know how to get it right given the constraints of their current design.

Re: Apple’s T2 security chip jailbreak

#279

Interesting. Does this mean that companies can now use this to unlock corp laptops that ex-employees have iCloud/activation-locked to their personal accounts without Apple's help? [+] [+] Yes, I realize that this also applies to stolen laptops, but this is an actual pain point with running fleets of Macs, from what I've heard.

Is this a pain point when you’re using Deployment Programs, or what’s now called School Manager or Business Manager?

DEP allows you to clear Activation Lock with your MDM: https://support.apple.com/en-us/HT202804

Re: Apple’s T2 security chip jailbreak

#280
post #262

Earlier quoted context omitted.

>FileVault for professional use Probably not the best choice :) you never want to use proprietary software if security is a concern

What is a non-proprietary solution for full-disk encryption?

luks or zfs.
Post reply on HN