Earlier quoted context omitted.
AFAIK, it's not just about the security of your data (you don't need a T2 chip to encrypt data), but also about discouraging theft of the hardware itself. In light of that, how do you allow for components to be swapped out wholesale without breaking the security model? Isn't the entire point that you can't just steal a Macbook, swap out the SSD, and now you have a functioning (stolen) laptop?
Trying to prevent theft that way is a fundamentally flawed approach. It's in the end all about controlling the phone you brought to prevent you from using it in any way they don't like or using it longer then they like (by repairing it). Theft will happen anyway. You can even sell permanently-locked/bricked devices to people which doesn't look to closely at the sellers description. Sure you will need to sell them for…
Apple’s T2 security chip jailbreak
191–200 of 393 posts
Re: Apple’s T2 security chip jailbreak
#192Earlier quoted context omitted.
You guys are fighting the good fight for everything that owning hardware and being a user used to mean. Thank you.
I never understood this sentiment, if people choose to pay their way into a walled garden, why should they still care about hardware ownership/repairabilty, etc.?
Re: Apple’s T2 security chip jailbreak
#193I imagine there’s no better incentive to get people to move en masse to your new architecture than an exploit for your old architecture that completely and irreparably breaks its security model showing up weeks before it’s released.
Re: Apple’s T2 security chip jailbreak
#194Earlier quoted context omitted.
The T2 was more or less a stopgap solution between their current Intel-based offerings and the AppleSilicon devices in regards to their security aspirations. My understanding is that there will be no T3, as evidenced in the DTK, which makes a lot of sense considering how identical these chips will be to their mobile counterparts.
I'm a user on a 2019 16-inch MBP (MacBookPro16,1) who hopes to move to Linux as my base OS on this hardware full-time over the next 12 months. ( https://github.com/Dunedan/mbp-2016-linux ) This is because I honestly cannot find a laptop with the combination of 64+ GB RAM, a non-NDIVIA GPU (edit: to clarify, this is because of NVIDIA's notoriously bad compatibility with Linux), and other premium hardware aspects like…
One of these years we'll get a comparable AMD laptop. Fingers crossed.
[0] https://www.lenovo.com/us/en/laptops/thinkpad/thinkpad-t-ser...
Re: Apple’s T2 security chip jailbreak
#195The fact that Apple uses this chip to, among other things, block "unauthorized repair" (can't change a freaking SSD in 2020, really), makes me very happy that people are finding ways to break this chip to make repairs more accessible. On the other hand, this could have serious implications on the iOS security model for example. And I'm pretty sure someone is gonna run Doom on the touchbar in some months.
Re: Apple’s T2 security chip jailbreak
#196Earlier quoted context omitted.
I will anecdotally agree; I've been a Linux laptop user for... well, 2 decades maybe? and explicitly choose Dell Mobile Precision and/or IBM/Lenovo T-series laptops with ATI/AMD, dealing with NVIDIA graphics is just a pain in the ass once we passed the GeForce era (ish). I'd rather just have/use Intel GPU over them as well, I am not a laptop gamer to need anything NVIDIA offers in exchange for the pain in maintenance…
I will anecdotally disagree. Depending on which distro you use NVIDIA grapics can be quite painless. Using Pop!_OS, I just had to download the correct iso from their downloads page. I believe most other distros have NVIDIA's drivers in their non FL/OSS repos as well. Optimus graphics will even work with the most current drivers.
Re: Apple’s T2 security chip jailbreak
#197Earlier quoted context omitted.
I never understood this sentiment, if people choose to pay their way into a walled garden, why should they still care about hardware ownership/repairabilty, etc.?
Mac hardware traditionally holds resale value. The T2 chip threatens to turn that hardware into a brick once resold. So beyond that jailbreaking ultimately makes the user's data more secure once Apple repairs and releases a fix (likely only going forward with new hardware) the jailbreak will cure the problem with aftermarket bricks for hardware with this T2 chip.
Yes it could be used that way. But they have never even indicated that they've been thinking of using the secure enclave for that purpose.
Re: Apple’s T2 security chip jailbreak
#198Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…
> Filevault and by extension Touch ID are more or less crippled Sorry, what does this sentence mean? That someone with physical access to my machine can now unencrypt my FileVault encrypted hard drive?
If you use a strong password to encrypt your drive you should still be safe, unless Apple did something really stupid. The password is used as a one-way hash to generate the key.
However if you can login with Touch ID and they find a way to use known SE exploits, it's compromised. Your fingerprint isn't a secret that gets hashed – instead it's verified by the SE which also holds the secret key for the drive.
Re: Apple’s T2 security chip jailbreak
#199Earlier quoted context omitted.
I will anecdotally agree; I've been a Linux laptop user for... well, 2 decades maybe? and explicitly choose Dell Mobile Precision and/or IBM/Lenovo T-series laptops with ATI/AMD, dealing with NVIDIA graphics is just a pain in the ass once we passed the GeForce era (ish). I'd rather just have/use Intel GPU over them as well, I am not a laptop gamer to need anything NVIDIA offers in exchange for the pain in maintenance…
I will anecdotally disagree. Depending on which distro you use NVIDIA grapics can be quite painless. Using Pop!_OS, I just had to download the correct iso from their downloads page. I believe most other distros have NVIDIA's drivers in their non FL/OSS repos as well. Optimus graphics will even work with the most current drivers.
Re: Apple’s T2 security chip jailbreak
#200I'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to cra…
Perhaps this unsurprising, nearly predestined exploit can convince people that they should not completely rely on biometrics for security.