completely insecure if you are not the only one with the key
How Secure Boot Works on M1 Series Macs
21–30 of 117 posts
Re: How Secure Boot Works on M1 Series Macs
#22Earlier quoted context omitted.
Show me where Apple says they protect against attackers who already have your passcode.
That's not what I was talking about... secure boot and locked boot loaders are "protected" with keys held by manufacturers...
You wrote:
> completely insecure if you are not the only one with the key
What key is shared between you and the manufacturer here? There's signing keys and there's passcodes, which ones are you "not the only one with"?
Re: How Secure Boot Works on M1 Series Macs
#23completely insecure if you are not the only one with the key
And they've shown that to be not unreasonable at least when it comes something like root private keys. Fact is they've been operating for a long time now and like the rest of the big players that hasn't been a leak issue. It's not that big a deal for a big player to physically secure such things to a high enough degree that it's unlikely to be a limiting factor. Dedicated rooms, full offline, hardware backed Shamir's secret sharing for m-of-n key signing ritual requirements etc etc.
Re: How Secure Boot Works on M1 Series Macs
#24completely insecure if you are not the only one with the key
Re: How Secure Boot Works on M1 Series Macs
#25completely insecure if you are not the only one with the key
The private key held by Apple and used to sign code from Apple? Yes, this is how modern crypto works. Some useful background reading: https://www.schneier.com/books/applied-cryptography/ .
It doesn't matter how secure communication between Apple and Apple device because even if it's perfect the owner is not secured from the Apple itself and those who Apple would love to communicate with. For instance oppressive governments. (here the result of such communication: blocked app that oppresive government didn't like https://apps.apple.com/us/app/%D0%BD%D0%B0%D0%B2%D0%B0%D0%BB...)
Re: How Secure Boot Works on M1 Series Macs
#26completely insecure if you are not the only one with the key
For the record, I'm in favor of legal mandate that hardware owners have the buy-time option to enable adding their own keys to any root trust stores on their devices. However, that'd be in addition to Apple's keys and wouldn't be about the security of Apple's keys, because Apple is part of the fundamental trust foundation if you buy a Mac or iDevice. Period. The devices are massively vertically integrated, right down…
It is not about trusting Apple or any other company for that matter. It is about tendency and attempt to make it a norm/legalize to sell personal computers without respecting right of the owner to have a full control over their own computer. If owner cannot fully control own computer this computer cannot be called 'personal' anymore.
This practice needs a push back as it completely unacceptable. It should be made illegal to sell such devices if that is not already the case because you can be left without working computer just because link to the company isn't available for some reason.
Company goes away and you are left without a working computer. Internet isn't available and you have brick instead of your computer. This is crazy and even more crazy that there are bunch of people brainwashed enough to the level that they do not even perceive it as a problem. Probably because they can't think 3 steps forward.
Re: How Secure Boot Works on M1 Series Macs
#27completely insecure if you are not the only one with the key
For the record, I'm in favor of legal mandate that hardware owners have the buy-time option to enable adding their own keys to any root trust stores on their devices. However, that'd be in addition to Apple's keys and wouldn't be about the security of Apple's keys, because Apple is part of the fundamental trust foundation if you buy a Mac or iDevice. Period. The devices are massively vertically integrated, right down…
take a look at the "Why not Apple devices?" section
Re: How Secure Boot Works on M1 Series Macs
#28completely insecure if you are not the only one with the key
It really depends on the threat you are planing against. If for some reason I'm target of US government - I'm screwed anyway. If my concern is trusting the laptop after I left it in train station and got it back from some random dude - it's good enough.
Re: How Secure Boot Works on M1 Series Macs
#29completely insecure if you are not the only one with the key
It really depends on the threat you are planing against. If for some reason I'm target of US government - I'm screwed anyway. If my concern is trusting the laptop after I left it in train station and got it back from some random dude - it's good enough.
It really doesn't depend on the threat at all. It's about the model of the society you wish to have and what values you promote.
It's about who you wish to be responsible : the 'big company' caring about your safety and taking your freedom on the way or you caring yourself about own safety and preserving freedom on the way. I do not really think there is a choice here because the first option will always be abused at some point.
Freedom does matter and it comes with responsibility. THIS is the main issue here. THIS is what separates society with responsible citizens from the society with 'irresponsible people' who wish to trade their freedom for 'safety' resulting in loosing both (and democracy itself after some time).