Live data from Hacker News

Apple Silicon Macs can't boot from external drive if internal drive failed

bombich.com

361–370 of 422 posts

Re: Apple Silicon Macs can't boot from external drive if internal drive failed

#361

General grumpiness about this particular design decision aside, it appears that since the T2 Macs, the main SSD was being used to store core system firmware. On T2 I think it's BridgeOS that sends the EFI image to the Intel side to boot it, and it does the firmware verification and loading. This setup has a benefit; namely, it is now impossible to brick the system with a bad BIOS/EFI flash, and you'll never need to u…

>since whatever failure damaged the SSD is statistically likely to compromise the reliability of the rest of the board. Any failure is grounds for "rework" of the board on a hardware level if necessary,up to and including repair/replacement of the onboard flash, and not just a simple workaround in my opinion.

This is entirely unfounded. Storage units are expendable, but the rest of the system lasts a lot longer.

Re: Apple Silicon Macs can't boot from external drive if internal drive failed

#362

Earlier quoted context omitted.

> Well, that's kind of the point. Being able to yoink the SSD from the original machine, plug it into another compatible one, and decrypt the contents with your password, is not a vulnerability, it's a feature.

I think that’s a joke? I mean, why even encrypt it in that case? It’s not like the drive is a web service that will detect and block your password attempts…

No it's not a joke. If the password is sufficiently complex, it can't be brute forced in a reasonable amount of time. But it's still a way for you to get your data back having only the SSD on which it is stored.

Or, well, fine, let there be an active element. But let me export the master key then. It's my device, I have root access to it, I should be allowed to do that. And, yes, do still put the SSD into a slot.

> I mean, why even encrypt it in that case?

Yeah because your time machine backup drive that's encrypted with "just" a password (you did encrypt it, right?) is somehow more secure than an internal SSD encrypted in the same exact way.

Re: Apple Silicon Macs can't boot from external drive if internal drive failed

#363
post #338
post #330

Earlier quoted context omitted.

I think that getting people to understand that regular backup are necessary when physical things, that exist around water, other humans, and electricity, are involved, is an impossible task that usually ends in tears. If you don't back up your data outside of a single entity, you will lose that data eventually. iCloud is the obvious choice for critical data, within the Apple ecosystem. Outside of one of the cloud ser…

this is like telling someone that if they lose their keys, or if a light bulb inside their house goes bad, they will lose their house and all their possessions, and then say 'you should insure everything you own'. Its a ridiculous decision by Apple made purely for profit

I'm sorry, but storage devices have a failure rate of exactly 100%. They always have, and always will. Sometimes spontaneously, sometimes slowly. This has never had anything to do with Apple.

The correct approach to data integrity is backups, not trying to scrape bits from something that smoke has escaped from.

If your data is on a single device, you will eventually lose that data. Some people haven't experienced it yet, but it's a known truth that whole industries have processes around.

Re: Apple Silicon Macs can't boot from external drive if internal drive failed

#364

Earlier quoted context omitted.

I'm using a MacBook Air 2015 and it's basically still a fast, perfectly usable machine. Quad core i7, 8GB RAM, SSD. However, I wish I could replace the battery, I wish the SSD was more easily upgradeable, and it would be nice to double the RAM.

Not to be overly pedantic, but Apple didn't release any quad-core MacBook Airs in 2015.(see https://support.apple.com/kb/sp714?locale=en_US ) Intel didn't even have quad-core ULV CPUs available until late 2017-2018. I only comment because the jump between dual & quad core is a pretty big one, as is the presumed jump to newer chips with 6, 8, and 16 core processors in modern machines. Dual core has remained surprising…

You're right this is a dual core, with two way hyperthreading, so 4 logical cores.

Re: Apple Silicon Macs can't boot from external drive if internal drive failed

#365

Earlier quoted context omitted.

>whatever failure damaged the SSD is statistically likely to compromise the reliability of the rest of the board Sorry, but how? That's just reads like BS. SSDs have limited lifespans due to the limited write cycles of the NAND chips. So no, what damages NAND does not damage the rest of the board. The more you write and swap to flash, the faster it wears out, taking your Macbook down with it when it dies. Granted, I…

In practice, exhausting NAND write endurance is usually not what causes SSDs to fail in the field. It is especially unlikely to be the underlying cause of unexpected and seemingly premature catastrophic SSD failure. Also, it is not possible for an SSD to decrease your usable storage space over time. That would break any partition table format or filesystem that expects an ordinary block device. It also wouldn't win y…

> Though keep in mind that "failure" here is defined as "only able to retain data for one year" for consumer SSDs

So the M1 Mac lasts a year before the owner has to shell for an apple authorised repair to replace the disk ? Me thinks that may not be the story for apple or dell

What am I missing

Re: Apple Silicon Macs can't boot from external drive if internal drive failed

#366

Earlier quoted context omitted.

At some point, the CPU is almost irrelevant. A huge issue is software locked to a certain motherboard. And the fact that your Raspberry Pi isn’t going to be running x86 software flawlessly and doesn’t come with nearly the same peripherals as a typical laptop (without a lot more cost… but even then, a 1:1 replacement isn’t possible). The assumption that tech gets exponentially cheaper over time, ie Moore’s Law, only a…

The Pi is just an example, $250 Laptops today have performance that cost $700 a few years ago And the "extras" you mention also get cheaper due to economies of scale. 4k 30hz monitors used to run just under $1000. Now 4k 60hz monitors run just over $200. - At the end of the day you cannot compete with how much better we get at making things over time right now. Broken hardware is only a leading cause of replacing sma…

The cost for many of those parts and if they're glued will give you problems with reassembly.

Re: Apple Silicon Macs can't boot from external drive if internal drive failed

#367

Earlier quoted context omitted.

At that point I am sure it'll be much cheaper and faster to buy another laptop on sale instead of waiting for framework to make the motherboard with the CPU you want (if they do it at all), and pay extra for custom parts that only fit their latop, therefore locking you into their hardware ecosystem, no different from Apple except the parts are all generic x64 and you don't gain anything other than having in fit in th…

People get attached to their machines. It's like a car.

Haven't ever seen that myself ever, most people don't care, they just don't want to replace the machine if it still works if that counts, but nobody is using a classic all original parts device or seeks a classic HDD for their old computer. If you present them with a better one though, I bet most would be jumping for joy, but you have to make sure its "better" to them.

Re: Apple Silicon Macs can't boot from external drive if internal drive failed

#368

Earlier quoted context omitted.

> Well, that's kind of the point. Being able to yoink the SSD from the original machine, plug it into another compatible one, and decrypt the contents with your password, is not a vulnerability, it's a feature.

I think that’s a joke? I mean, why even encrypt it in that case? It’s not like the drive is a web service that will detect and block your password attempts…

If data is not encrypted with a piece of secret information (usually a password) with enough entropy to keep it secret in the face of offline attacks, then it is as good as not encrypted, period. The hope that your hardware design is sufficiently complex and non-repairable to prevent your attacker from disassembling it and performing such an attack is not a replacement for proper encryption.

And if it is encrypted with a secret with sufficient entropy, then making your hardware design non-repairable serves no reasonable purpose.

Re: Apple Silicon Macs can't boot from external drive if internal drive failed

#369

Earlier quoted context omitted.

> Well, that's kind of the point. Being able to yoink the SSD from the original machine, plug it into another compatible one, and decrypt the contents with your password, is not a vulnerability, it's a feature.

I think that’s a joke? I mean, why even encrypt it in that case? It’s not like the drive is a web service that will detect and block your password attempts…

You can easily limit password attempts by requiring a sufficiently difficult password hashing algorithm and then just use a secure passphrase. Nobody is breaking into my encrypted drives via a guessing attack (other attacks exist, but they ~all also exist on macs).

Re: Apple Silicon Macs can't boot from external drive if internal drive failed

#370

Earlier quoted context omitted.

I think that’s a joke? I mean, why even encrypt it in that case? It’s not like the drive is a web service that will detect and block your password attempts…

No it's not a joke. If the password is sufficiently complex, it can't be brute forced in a reasonable amount of time. But it's still a way for you to get your data back having only the SSD on which it is stored. Or, well, fine, let there be an active element. But let me export the master key then. It's my device, I have root access to it, I should be allowed to do that. And, yes, do still put the SSD into a slot. > I…

> But let me export the master key then.

You can do this encryption shindig with the ability to export by not using FileVault and using your own encryption software - Apple just doesn't allow this by default. In fact, why only store it on the computer? Rclone can upload and replicate an encrypted (via a long salt + password) copy of your data to dozens of cloud providers. Your encrypted data could be on 3 cloud providers in 10 physically separate locations on 30 different hard drives at once, possibly even in separate hemispheres. Or chuck it into S3 replication and be in all 81 availability zones if you so wish.

Post reply on HN