The fact that Apple uses this chip to, among other things, block "unauthorized repair" (can't change a freaking SSD in 2020, really), makes me very happy that people are finding ways to break this chip to make repairs more accessible. On the other hand, this could have serious implications on the iOS security model for example. And I'm pretty sure someone is gonna run Doom on the touchbar in some months.
For me it was conscious choice: Security ≫ Repairability. I don't mind getting a new MacBook, but I do mind if it gets compromised. This way I know it would be a screen replacement at best.
Apple’s T2 security chip jailbreak
371–380 of 393 posts
Re: Apple’s T2 security chip jailbreak
#372Earlier quoted context omitted.
That's a very disingenuous assessment of the situation at hand. Epic knowingly violated their developer agreement. There was no retaliation. There was the consequences that were written into the developer agreement that Epic agreed to.
Apple revoked the developer accounts that Epic uses, so Epic could no longer notarize their (unrelated, MacOS desktop) software. No matter what you think about the lawsuit, you have to admit that Apple used their position of power to strong-arm the competition, and went against their promises to end-users regarding notarization.
Re: Apple’s T2 security chip jailbreak
#373Earlier quoted context omitted.
luks or zfs.
I want not note, that ZFS is not full disk encryption. ZFS native encryption was designed to allow secure backups via "zfs send | zfs receive" mechanism, so it encrypt only data blocks, and not metadata. LUKS and GEIL are full-disk encryption systems, and if you need FDE, you must use them under ZFS, not ZFS native encryption.
GELI ;)
ZFS native encryption on Root is ~IS full disk encryption minus the boot-loader, i would say that's "full" interesting data encryption.
Re: Apple’s T2 security chip jailbreak
#374Earlier quoted context omitted.
>Planned obsolescence just means artificially shortening the upgrade cycle. No, it doesn't not. Planned obsolescence, just the like the actual words in the term are defined, means planning for the fact that technology and the components it's made from has a finite lifespan and that, at some point, users of that technology will have to upgrade. You're inferring that companies are intentionally sabotaging their product…
> https://en.wikipedia.org/wiki/Planned_obsolescence >In economics and industrial design, planned obsolescence (also called built-in obsolescence or premature obsolescence) is a policy of planning or designing a product with an artificially limited useful life, so that it becomes obsolete (i.e., unfashionable, or no longer functional) after a certain period of time.[1] The rationale behind this strategy is to generat…
The T2 is a security chip. It ensures the integrity of the system. If that integrity is compromised, the chip shouldn't allow third parties to replace components unless those components can be replaced and the integrity restored. You're acting like the T2 was added just to make repairs harder instead of to make the device more secure which, by design, makes repairs more difficult.
It's the same reason that car manufacturers don't let repair shops generate new key fobs unless they're registered with the manufacturer.
Re: Apple’s T2 security chip jailbreak
#375Earlier quoted context omitted.
Nvidia gpus require proprietary drivers that are only provided for specific distros and are only supported for a small amount of time. And if you find any bug well tough luck, nobody can help you. For a work setup that you rely on someone else in the company for support they might be fine but I wouldn't recommend them for a personal setup. All this is on top of the fact that they still don't support Wayland and you h…
> that are only provided for specific distros Last time I looked, it was perfectly possible to install them directly, without support by the distro. Yes, it's more work. > Nvidia gpus require proprietary drivers There's an open source driver, nouveau, but of course it's behind the newest hardware.
Yes, you can install them and they will break with every single update and you need to re-install them. And you will encounter bugs that no-one has any idea why they are there and no-one will help you with.
>There's an open source driver, nouveau, but of course it's behind the newest hardware.
It's not just behind, it's actively sabotaged by nvidia by locking basic hardware functions behind closed firmware that it encrypted.
Re: Apple’s T2 security chip jailbreak
#376Earlier quoted context omitted.
macOS will deprecate older Macs 6-7 years after their release. You can use older Macs as Linux machines, with one of the BSDs, or with Windows. The T2 chip can prevent people from putting their OS of choice on their hardware once Apple deprecates support for their machine.
There is no evidence that is going to be the case. I can still use bootcamp on legacy machines, I don’t see that changing with the T2.
Re: Apple’s T2 security chip jailbreak
#377Earlier quoted context omitted.
> https://en.wikipedia.org/wiki/Planned_obsolescence >In economics and industrial design, planned obsolescence (also called built-in obsolescence or premature obsolescence) is a policy of planning or designing a product with an artificially limited useful life, so that it becomes obsolete (i.e., unfashionable, or no longer functional) after a certain period of time.[1] The rationale behind this strategy is to generat…
I know what the definition is. Your second statement doesn't support your first one. Apple provides hardware and software support for their devices at a far greater level and duration than nearly every other hardware manufacturer. They're not artificially limiting the lifetime of their products, they're ending support for devices that, in most cases, literally can't support new features that they're adding. The T2 is…
Sure it's a security chip but why is it they didn't make it so the owner can do a one-way unlock (like Android's bootloader unlock) so people can fix their own Macs?
Because preventing repairs is one of the desirable side effect of this design.
Re: Apple’s T2 security chip jailbreak
#378Earlier quoted context omitted.
No, not "idiot user". No one is imprisoned. In the same way that people choose to be part of organizations and groups with rules and limits to what can be done, people choose to use devices that are slightly limited in exchange for reliability and security. I don't want Apple waste time and resources to need to support the people that call the call center to ask for this supposed code and most people using their devi…
No, it wouldn't, see the terminal unlock code for contract phones discussed below. If your opinion is that the free market is all correcting and magical and that laws and regulations should never intervene in private consumer choices, I have a failed state I can introduce you to, not to mention a salmonela infested burrito.
You call it a prison. I call it a fortress.
Re: Apple’s T2 security chip jailbreak
#379Earlier quoted context omitted.
I know what the definition is. Your second statement doesn't support your first one. Apple provides hardware and software support for their devices at a far greater level and duration than nearly every other hardware manufacturer. They're not artificially limiting the lifetime of their products, they're ending support for devices that, in most cases, literally can't support new features that they're adding. The T2 is…
Side effects. That's exactly why they do it. Sure it's a security chip but why is it they didn't make it so the owner can do a one-way unlock (like Android's bootloader unlock) so people can fix their own Macs? Because preventing repairs is one of the desirable side effect of this design.
Apple has no need to prevent people from repairing their devices. They lose money on most repairs they do. What they're concerned about is their brand. If someone gets their device repaired at a shitty shop that isn't Apple certified and uses parts that aren't real Apple parts (like every screen repair kiosk in your local mall), people don't see future screen issues as issues with that repair or screen. They see a problem with an iPhone. That's what the desirable side-effect is. Apple doesn't want to prevent repairs, they want to prevent shitty repairs and security breaches.
Re: Apple’s T2 security chip jailbreak
#380Earlier quoted context omitted.
True, but to be fair, the same mechanism also blocks thieves from using and/or selling stolen Macs.
> True, but to be fair, the same mechanism also blocks thieves from using and/or selling stolen Macs. That would be a fair excuse if the mechanism was under the control of the machine's rightful owner.
Subverting these mechanisms provides a way to prevent the system from making this assertion.
Likewise, the alleged "anti-repair" mechanism for TouchID sensors and TouchBar relate directly to protecting the system's ability to distinguish between the "rightful owner" and a thief.
"Do what I want with the machine I own" is functionally indistinguishable from "increase the resale value of the machine I stole".