Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

341–350 of 393 posts

Re: Apple’s T2 security chip jailbreak

#341
post #244

Earlier quoted context omitted.

How did you get the information that apple devices resist state-level actor threats? Repeatedly state actors have broken into iphones and icloud accounts, and apple laptops are frequently the first devices to fall in the Pwn2Own contests.

On the flip side, the FBI had to (probably) decap chips to get into that one shooter’s iPhone, which is pretty good security IMO.

Did they actually get in to it?

Re: Apple’s T2 security chip jailbreak

#342
post #230

Earlier quoted context omitted.

Yes, although now the Mac is as secure as any PC with UEFI Secure Boot (and no Intel ME), which isn’t necessarily the end of the world if you have a long firmware password (which protects the Recovery Mode secure boot utility) and login password (which protects FileVault). If you’re in a position where you could be compromised by a state actor or a hacker group (that can find a public flaw in Secure Boot that isn’t j…

Unfortunately, physically obstructing the primary port would not completely prevent DFU from being accessed. With the aforementioned accessory device, the ACE Type-C controllers within Macs can automatically reroute the DFU, DCI, and PCH/T2 UARTs to any of the other ports, irrespective of the T2 and PCH. Apple uses this technique as part of their factory test harness.

Also the USB-C ports are not on the MLB, they are on I/O boards that can fairly easily be replaced …

Re: Apple’s T2 security chip jailbreak

#343

Earlier quoted context omitted.

> Epic knowingly violated their developer agreement. There was no retaliation I think you don't understand how this works. The agreement itself is the subject of the lawsuit and thus MUST be violated in order to show harm. Epic did it on purpose in order to sue Apple and whether you agree with that or not, it is the only mechanism the law allows to make the agreement itself the subject of the suit. And Epic does have…

This is quite incorrect. Epic can already demonstrate financial harm due to the 30% fee that Apple has been collecting. They did not also need to break the agreement in order to bring the lawsuit. The judge literally recommended they cure the breach and put Fortnite back on the App Store while the lawsuit was pending.

>Epic can already demonstrate financial harm due to the 30% fee that Apple has been collecting

Not to the consumer.

Re: Apple’s T2 security chip jailbreak

#344
post #243

Earlier quoted context omitted.

I'm a happy iPhone, iPad and Mac user but have also jailbroken some of my old iPhones before so they could be used by family in China. In the arguments about opening up the iPhone and forcing Apple to allow third party app stores and allow side loading I'm on Apple's side. I think Apple should decide what products they design, how they design them and what features they should have. If I like the feature set, I'll bu…

> The ability to side load apps would be a software feature that needs to be designed, coded, QA tested, secured etc. Apple of course has an internal version of iOS that lets you do this.

The public version lets you do this. Just a week at a time.

Re: Apple’s T2 security chip jailbreak

#345

Earlier quoted context omitted.

Last time I did this, when the officials saw the number of laptops in my carryon they sent me over to the diplomat line for faster processing.

LOL, what happened then?

There is only anticlimax :) The ‘executive’ screener was kindly about helping me sort them into a line of individual trays and then back into the luggage and didn’t show the slightest curiosity about any of it.

Re: Apple’s T2 security chip jailbreak

#346
post #298

Earlier quoted context omitted.

>FileVault for professional use Probably not the best choice :) you never want to use proprietary software if security is a concern

Go count how many CVEs have come out for OpenSSL, GNUTLS, LUKS, etc. and ask whether you’re offering helpful advice. Security is expensive and there are no silver bullets: at the end of the day you need a lot of skilled work and being open source doesn’t magically get that for free.

That's apples and oranges.

Counting published vulnerabilities in open source systems vs closed source systems says nothing about the relative true ratio of vulnerabilities.

Re: Apple’s T2 security chip jailbreak

#347
post #289

Earlier quoted context omitted.

That's funny, when I flew in LA from Bali, I got stuffed in a room for four hours because I had a rock in my suitcase.

Returning from Singapore I was asked if I had any "rare feathers"... I said no but was still taken aside and searched.

I like processing through Newark, New Jersey the best. They seem to have the least propensity for wasting your (their) time, or else a very good nose on who the actual problems are in the crowd and focusing their attention on them. [edit: and these use beagles to check luggage! How cute is that.]

Re: Apple’s T2 security chip jailbreak

#348

Earlier quoted context omitted.

While it doesn't entirely meet your specs you can get a T495 with 32GB of RAM [0] and Vega graphics. We're getting close, I am holding on to my T470 as a daily driver and it's one of the best laptops I've owned (I'm forced to use a 16" MBP for work as well - and I still prefer the T470). One of these years we'll get a comparable AMD laptop. Fingers crossed. [0] https://www.lenovo.com/us/en/laptops/thinkpad/thinkpad-t…

The T495 is my daily driver. I love this machine and I plan on using it for many years to come.

How can you all handle the low-resolution screen? I want one of those Lenovo laptops but with a higher resolution screen

Re: Apple’s T2 security chip jailbreak

#349
post #346
post #298

Earlier quoted context omitted.

Go count how many CVEs have come out for OpenSSL, GNUTLS, LUKS, etc. and ask whether you’re offering helpful advice. Security is expensive and there are no silver bullets: at the end of the day you need a lot of skilled work and being open source doesn’t magically get that for free.

That's apples and oranges. Counting published vulnerabilities in open source systems vs closed source systems says nothing about the relative true ratio of vulnerabilities.

Are you seriously claiming that anything short of omniscience is useless? In most fields people deal with incomplete data on a daily basis and this is no different. CVEs don’t tell you everything but they definitely give you more than zero, and more to the point, the many vulnerabilities in open source projects suggests that the very broad but completely unsupported claim I was responding to is based on ideology rather than reasoned analysis.

Re: Apple’s T2 security chip jailbreak

#350
post #349
post #346

Earlier quoted context omitted.

That's apples and oranges. Counting published vulnerabilities in open source systems vs closed source systems says nothing about the relative true ratio of vulnerabilities.

Are you seriously claiming that anything short of omniscience is useless? In most fields people deal with incomplete data on a daily basis and this is no different. CVEs don’t tell you everything but they definitely give you more than zero, and more to the point, the many vulnerabilities in open source projects suggests that the very broad but completely unsupported claim I was responding to is based on ideology rath…

> the many vulnerabilities in open source projects suggests that the very broad but completely unsupported claim I was responding to is based on ideology rather than reasoned analysis

Does it? In order to claim that, one would have to have some idea of (a) the ratio of disclosed vulnerabilities to true vulnerabilities discovered in both open source, accessible code vs closed source, hardware locked code, and (b) the relative ratios of disclosed vulnerabilities.

Do you have any idea what either ratio might be? 1:1? 4:1? 1:4? 100:1?

Post reply on HN