Earlier quoted context omitted.
That's a very disingenuous assessment of the situation at hand. Epic knowingly violated their developer agreement. There was no retaliation. There was the consequences that were written into the developer agreement that Epic agreed to.
> Epic knowingly violated their developer agreement. There was no retaliation I think you don't understand how this works. The agreement itself is the subject of the lawsuit and thus MUST be violated in order to show harm. Epic did it on purpose in order to sue Apple and whether you agree with that or not, it is the only mechanism the law allows to make the agreement itself the subject of the suit. And Epic does have…
Apple’s T2 security chip jailbreak
301–310 of 393 posts
Re: Apple’s T2 security chip jailbreak
#302Earlier quoted context omitted.
> I rely on Mac and FileVault for professional use ... then phase out your use, because proprietary systems will always get cracked given enough time.
Good point, let’s switch to unbreakable open source systems based on OpenSSL instead. This kind of advocacy is not only unhelpful but actually counterproductive
Re: Apple’s T2 security chip jailbreak
#303I'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to cra…
Apple did actually screw the pooch on this one. Typically, it's criminally illegal to circumvent DRM in the US (and 99% of the rest of the world). However, there are also certain exemptions that have been granted, within the US only (other countries are not so lucky). The right to repair is one such exemption[1]. If Apple had separated security from first-party repair enforcement, then anyone found even attempting to…
It absolutely is not. It is completely unenforceable, especially in the case of criminal circumvention, and serves no realistic or practical purpose. Anyone who commits said "crime" in any meaningfully damaging sense and is caught will already be committing the actual crime of infringement, and so tacking circumvention on is largely pointless. It only serves to deter legitimate public research.
Also, the T2 isn't in any way classifiable as "technological measures used to prevent unauthorized access to copyrighted works". This law is meant to apply to copyright-protection DRM and has nothing to do with software security measures designed to prevent unauthorized access to computer systems. Circumventing the protection of those measures is only legal to do on systems on which you are authorized to do so, and is otherwise illegal under separate law.
Re: Apple’s T2 security chip jailbreak
#304Earlier quoted context omitted.
Risk what though? They have changed the keyboard now.
They’ve changed the keyboard three times over 4 years , iirc; I am somewhat skeptical that they really know how to get it right given the constraints of their current design.
Re: Apple’s T2 security chip jailbreak
#305Earlier quoted context omitted.
Good point, let’s switch to unbreakable open source systems based on OpenSSL instead. This kind of advocacy is not only unhelpful but actually counterproductive
Software encryption is very often much easier to rotate than integrated solutions. When all the TPM chips were broken, Windows stopped using them for BitLocker, but didn't reencrypt any of the affected disks. They're just as vulnerable as they were.
Re: Apple’s T2 security chip jailbreak
#306Earlier quoted context omitted.
Incredible work. > It's a pretty peppy chip, at times coming close to my 8th gen i7...yikes. Have you got any benchmarks? It is passively cooled right? I am really surprised to hear a ~2016 arm64 CPU can can beat a 2019 Intel i7 in even synthetic benchmarks.
Some synthetic benchmarks are so simple that they almost reduce to a measure of CPU clock speed and instruction parallelism. Find a benchmark that uses a unique instruction combination on one CPU and it will heavily disadvantage the other CPU. Add a real world workload to the mix with heavy memory access and mixed compute workloads and the chips will diverge significantly in performance. I work with some cross-platfo…
Re: Apple’s T2 security chip jailbreak
#307Earlier quoted context omitted.
Fair enough, but the problem is mainly when you are in a third world country and parts are very difficult to get, and where Mac stores are non-existent.
People in third world countries buy Macbooks - really? A decent macbook is several times above an average monthly income in a first-world country already...
Re: Apple’s T2 security chip jailbreak
#308Earlier quoted context omitted.
I never understood this sentiment, if people choose to pay their way into a walled garden, why should they still care about hardware ownership/repairabilty, etc.?
I'm a happy iPhone, iPad and Mac user but have also jailbroken some of my old iPhones before so they could be used by family in China. In the arguments about opening up the iPhone and forcing Apple to allow third party app stores and allow side loading I'm on Apple's side. I think Apple should decide what products they design, how they design them and what features they should have. If I like the feature set, I'll bu…
Apple of course has an internal version of iOS that lets you do this.
Re: Apple’s T2 security chip jailbreak
#309Earlier quoted context omitted.
They are well aware of the issue and have been for some time. There’s not all that much they can do to fix this, although they have certainly tried.
> There’s not all that much they can do to fix this, although they have certainly tried. Forgive my ignorance, why is there not much they can do and what have they tried?
Re: Apple’s T2 security chip jailbreak
#310Earlier quoted context omitted.
Can you describe a scenario where Touch ID is safe against evil maid attacks (say, a chip is installed allowing anyone to transmit a certain signal that spoofs Touch ID) while also allowing unrestricted modifications by someone with physical possession of the device (as this T2 rooting post celebrates)? Right now, that security is provided by Apple crypto-locking the Touch ID sensor to the T2 chip so that it cannot b…
Allow the users to install their own keys. Changing keys invalidates all encrypted/secured data. Which means you have to export the data if you do hardware changes and reimport it after supplying your own. Once you have your own keys installed you could sign additional hardware with them. If apple is a viable root of trust then you yourself should be too. There's nothing magical that only apple can do.
How would this benefit third-party repair shops, though?