Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

281–290 of 393 posts

Re: Apple’s T2 security chip jailbreak

#281
post #250

Earlier quoted context omitted.

Then don’t buy it? It’s not like Apple is the only vendor. Kind of hard to have diversity/options if everyone keeps insisting all vendors do everything the same way.

I can buy what I want and also do what I want to what I purcwhased.

People can use their mouths to say at least the fact of flaws the product and services you purchased which acts as an advice to not purchase them

The downvote button on Hacker News doesn't work like a dislike button by the way

Re: Apple’s T2 security chip jailbreak

#282
post #242

Earlier quoted context omitted.

You don't care that you can't change out the SSD, but you will care when you take your dead laptop to the Genius Bar and they tell you it's going to be cheaper to buy a new one and that your data is already gone.

I don’t see how this changes the calculus. Presumably the parent knew this when they bought the laptop. People buy cars that are stupidly expensive to repair all the time. Just because the cost of ownership of a Honda Civic is lower than a Mercedes doesn’t mean everyone’s gonna go with the Honda. If it works like iOS and just flashes a warning then I don’t see the issue. The self-check thing is invaluable when buying…

I could be wrong, but most mac users excluding developers don't know anything when they bought the laptop.

> that your data is already gone.

By the way, the parent comment was talking about this

Re: Apple’s T2 security chip jailbreak

#283
post #145

Earlier quoted context omitted.

In the "carrier era" you could still buy unlocked phones directly from the manufacturer. Your analogy doesn't hold. The truth is that there is a threshold, a level of user complaints that turns a legitimate practice into an anti-competitive one. People disagree on where this threshold lies - is it at 0, is it at 1000, is it at millions? Until recently, most of Apple's shenanigans have kept the complaints under thresh…

That wasn’t the case for CDMA phones in the US (and back then not every manufacturer made models for multiple bands). There was no SIM card to swap in. If you could buy unlocked phones from the manufacturer without the carrier subsidy, what was anti-competitive about it? That’s an interesting metric for anti-competitive practice. Isn’t a large number of user complaints basically the core mechanism that drives market…

A manufacturer had to have a relationship with carriers to move enough product to make its prices affordable even off-carrier. Manufacturers who couldn’t sell through carriers were effectively made uncompetitive by the carrier cartel, that also resulted in a number of other restrictions (how one can pay for stuff etc). In this sense, as I wrote elsewhere, Apple strong-arming ATT was a big step forward; but it also took legislation on this side of the pond to force carriers to play nice with unlockings, there was no chance the market would self-correct.

Which takes me to the second point: the market alone often does not self-correct. This is why we have antitrust laws and authorities to enforce them. People lack the education to be able to reason about “voting with their wallet” in an effective way; and even when they do, they often don’t have the resources to follow through. This is why contract bundles are so popular, despite the fact that they make handset more expensive overall: people can’t do math, and when they do they still often lack the cash reserves to buy a handset in one go rather than paying small instalments for a long time. If a market fails, it’s legitimate for the law to step in; and one indication of failure is the level of discontent from consumers.

Re: Apple’s T2 security chip jailbreak

#284
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

>Hi guys, I am part of the team working on all things T2. So there is a team working on this? What is the incentive model? Are you paid to do this work? What is the revenue model? I woke up today learning my MacBook Pro is now substantially less secure but why? So I can run games on the touch bar? So I can use the T2 as a raspberry pi?

There is a team taking advantage (jailbreaking on iOS) of the security flaw in all A-series chips up to A11 in the hardware-level bootloader. The T2 in your 2018 or newer Mac is a variant of the A10.

The bootROM flaw allows for an exploit that can only be executed with physical access, another Mac and DFU mode. It's not persistent.

The main use of this exploit was to install unsigned code on iOS devices (jailbreaking.) The team is doing it for free, however many contributors take advantage of Apple's bug bounty program for income, therefore making newer devices more secure.

Re: Apple’s T2 security chip jailbreak

#285

Earlier quoted context omitted.

It's not an intentional anti-resale feature, but it does make repair a lot harder, because it locks (or at least, can lock) specific hardware components to the motherboard. This means if something on the laptop breaks, you can't repair it without the T2 chip knowing about it and potentially refusing to work. Apple has at least told their authorized repair partners that failing to register the repair with Apple may br…

But isn't the repair being harder a net-benefit for the consumer? It's not like the repair is arbitrarily harder. It's harder because the repairs in question deal with the TouchID sensor and the SSD, like you said. I wouldn't want someone being able to access my data just by replacing a component on the computer that then bypassed all the security systems present on the computer. It's the same situation as when repla…

"You should have had a backup" is not an acceptable excuse for not having a data recovery mechanism. Furthermore, full disk encryption is not bypassable in the way you suggest. Your login password is (supposed to be) the key material for the encryption, which is stored off-device, preferably in your head. In other disk encryption systems that are not locked to a particular encryption chip, if you take the disk out of the machine and plug it into another machine, it won't be readable unless you have that password.

Furthermore, most people do not make this calculation in their head of "Okay, anything I put behind the T2 is Apple's property now so I'd better have unencrypted backups". They just buy the computer that works and says that it keeps thieves and snoops out of their data. Everything we're talking about with backups comes as a post-purchase surprise, usually AFTER the data is already lost.

Re: Apple’s T2 security chip jailbreak

#286
post #135

Earlier quoted context omitted.

It's a trade-off. I buy MBPs for the great form-factor and OS, not for the walled-garden shenanigans. If those shenanigans can be somewhat reduced, the trade-off balance looks better.

I don't mean to me facetious, but I am genuinely curious: why should you get to have it your way? You are attempting to buy a product they do not sell.

Why would I not? Why should I accept everything companies do without ever complaining? Am I not allowed to tell the fishmonger that his fish doesn’t look that fresh to me? In the same way, I’m free to tell Apple their fish would taste better with some adjustments.

Re: Apple’s T2 security chip jailbreak

#288

Earlier quoted context omitted.

Isn't a password always required to decrypt on a cold boot?

Yes, but that doesn't help you if someone steals your MacBook when it's asleep.

Someone would have to DFU your laptop before hand and jailbreak the chip, since booting into DFU requires shutting the system down.

Re: Apple’s T2 security chip jailbreak

#289

Earlier quoted context omitted.

Last time I did this, when the officials saw the number of laptops in my carryon they sent me over to the diplomat line for faster processing.

That's funny, when I flew in LA from Bali, I got stuffed in a room for four hours because I had a rock in my suitcase.

Returning from Singapore I was asked if I had any "rare feathers"... I said no but was still taken aside and searched.

Re: Apple’s T2 security chip jailbreak

#290
post #197

Earlier quoted context omitted.

Where and how do you see the T2 chip being the mechanism that Apple stops reselling of hardware? Yes it could be used that way. But they have never even indicated that they've been thinking of using the secure enclave for that purpose.

macOS will deprecate older Macs 6-7 years after their release. You can use older Macs as Linux machines, with one of the BSDs, or with Windows. The T2 chip can prevent people from putting their OS of choice on their hardware once Apple deprecates support for their machine.

> macOS will deprecate older Macs 6-7 years after their release.

This is substantially inaccurate. Current versions of macOS run on nearly all Apple systems from 2012 (8 years old), with the exception of some 2012 Mac Pros. The limiting factor in most cases is GPUs -- macOS 10.14 and later require some GPU capabilities which weren't reliably available in 2012.

Post reply on HN