Live data from Hacker News

Apple Exclaves

randomaugustine.medium.com

191–200 of 233 posts

Re: Apple Exclaves

#191
post #69

Earlier quoted context omitted.

That seems very unlikely since nothing of that sort was ever attempted by Jobs on their desktops.

I'm not sure it's so much about extracting value exactly but Jobs long believed in making sealed appliances that people couldn't and wouldn't have to tinker with as opposed to more easily modify able computers sold by competitors https://folklore.org/Diagnostic_Port.html > Expandability, or the lack thereof, was far and away the most controversial aspect of the original Macintosh hardware design. Apple co-founder Ste…

> Jobs long believed in making sealed appliances that people couldn't and wouldn't have to tinker with as opposed to more easily modify able computers sold by competitors

But at the same time he was also very proud of the PowerMac G3/G4 case which could be opened at any time (even when it was on) with the side being hinged with a prominent, friendly finger loop.

Re: Apple Exclaves

#192

Earlier quoted context omitted.

As someone who builds industrial/scientific machines, the consumer oriented devices that Apple makes are completely unusable for me. Locking down completely capable computing devices seems like such a waste. I'm also not a fan of how Apple controls devices and the market of software after the device has changed owner. I'm staying the hell away from this ecosystem. Not sure why many so-called "hackers" are so enthusia…

What's excessively locked down on MacBooks? There are some security features that (for good reason) get in the way of e.g. dtrace, but I'm not aware of any of those that you can't turn off. > I'm also not a fan of how Apple controls devices and the market of software after the device has changed owner. What's this about?

One thing in particular that bugs me about Macbooks is the fail-deadly hardware security. Disk encryption is good, yes - I use LUKS myself - but it tends to backfire on regular consumers if done poorly. I've had to tell far too many people that their data is perma-gone from a fried Macbook motherboard. (And no, "they should have used Time Machine" is not a valid excuse for such poor design.)

Such scenarios are trivially recoverable on better-designed machines with removable storage and consumer-friendly software FDE. BitLocker does this reasonably well - yes, there are privacy concerns w.r.t. key backups, but one must strike a balance between convenience and security.

ETA: To be clear, this setup would be entirely tolerable to me, but I (and everyone else in here) is hardly an average consumer when it comes to technology.

Re: Apple Exclaves

#193
post #187

I see exclaves as a significant but intermediate step. Apple is making XNU less of a liability, but they're still playing defense instead of fully embracing a microkernel architecture. If I had to bet, exclaves will be a bridge to something bigger, either a more modular OS (like Fuchsia) or a CHERI-inspired security model where memory safety is enforced at the hardware level. Apple is leading the pack in consumer OS…

[deleted]

Re: Apple Exclaves

#194
post #130

I'm quite surprised that they use a secure exclave to control the physical camera LED - this is absolutely massive overengineering to do something very simple. A tiny bit of hardwired dedicated logic integrated into the camera module would be more than adequate to do this - just gating of either the digital I/O or the power to the camera, and a pulse-stretcher so the LED goes on for at least a few seconds each time t…

What if they want to add Face ID to the Mac but have the camera light not illuminate for that internal function, since that can also be developed securely so that nothing in user space can access the camera during that query.

FaceID doesn’t use the standard visual camera.

It’s (for example) similar to the Kinect. It projects a pattern of structured light in IR then looks at that with an IR camera to be able to determine depth.

Re: Apple Exclaves

#195

Earlier quoted context omitted.

If it’s all in software but the kernel has lower privileges, I’m curious how they’ll be able to update it? And if there is an API to update via the kernel, what’s stopping a push via a malicious source pretending to be Apple?

Less than entirely confident stab (someone please correct if I get this wrong): - Exclave exposes a small set of functions that kernel may call for sensitive operations - One of those is “update exclave”. The input to this is a blob signed with Apple’s private key. - Exclave verifies signature, so a compromised kernel and push a malicious update How the exclave gets Apple’s public key is a little opaque to me. One wa…

I would think the Secure Enclave would handle such things.

That said I’m not sure what you or GP mean by “update exclave”. It’s just part of the kernel binary loaded up at system start. Wouldn’t it be updated the same way the rest of the kernel is, probably requiring a restart?

Re: Apple Exclaves

#196
post #195

Earlier quoted context omitted.

Less than entirely confident stab (someone please correct if I get this wrong): - Exclave exposes a small set of functions that kernel may call for sensitive operations - One of those is “update exclave”. The input to this is a blob signed with Apple’s private key. - Exclave verifies signature, so a compromised kernel and push a malicious update How the exclave gets Apple’s public key is a little opaque to me. One wa…

I would think the Secure Enclave would handle such things. That said I’m not sure what you or GP mean by “update exclave”. It’s just part of the kernel binary loaded up at system start. Wouldn’t it be updated the same way the rest of the kernel is, probably requiring a restart?

No, because that way a rogue kernel could overwrite the exclave itself and the next reboot would be insecure. You can’t trust a low-trust environment to update a high-trust environment.

Re: Apple Exclaves

#197

Earlier quoted context omitted.

The better analogy might be, "when the morality police call the restaurant, they divulge which table you sit at every day during lunch". And it's also not clear that it would be noticed: national security letters, gag orders, parallel construction, etc. It's just another principal-agent problem, and I agree that a fully self-sovereign life, with no dependence on trust or agents, is an unrealizable ideal; and, that a…

> a fully self-sovereign life, with no dependence on trust or agents, is an unrealizable ideal I agree with this part, but relying Apple is quite far from self-sovereignty compared to many other practical alternatives: not relying on external clouds, GrapheneOS, Linux. By relying on Apple, you not only pay a tax to essentially bribe them to not attack you (perhaps a viable strategy, not too different from taxes to go…

I’m kind of with you, but tell me.. who “deserves” trust?

Re: Apple Exclaves

#198
post #72

Earlier quoted context omitted.

He didn’t jump the line, he just got in multiple lines.

Sure. On the one hand, everything adhered to the letter of the law. On the other, he used his money to get served before other people in an otherwise similar position would have been able to do. I personally view that as more of a failing in the system itself (why are there multiple lines to begin with when organ transport is a solved problem?), but it's not unreasonable to look at somebody exploiting that broken sys…

There are multiple lines because when an organ comes up, it can only last so long, so a person needs to be able to get to the hospital without a certain period of time. Usually this means driving distance. When you have a private plane, the distance expands. The organ still goes to the most sick person in line, not the one with the most money.

I was at a talk with Martine Rothblatt several years back, who created a startup for 3D printed organs. They ended up also building electric helicopters to transport those organs, because the transportation bottleneck was a huge issue.

I try not to judges peoples character when they’re looking death in the face. No one really knows what they’ll do in that scenario. Most people who can save their own life will. This was the premise of the movie SAW… how far are you willing to go to save your own life? How strong is your survival instinct? Most people are never tested, and it’s easy to sit back and judge, but would you just sit back and die? How do we even know there was someone else in line behind Jobs? It could be that he got an organ that would have otherwise been wasted.

Re: Apple Exclaves

#199

Earlier quoted context omitted.

As someone who builds industrial/scientific machines, the consumer oriented devices that Apple makes are completely unusable for me. Locking down completely capable computing devices seems like such a waste. I'm also not a fan of how Apple controls devices and the market of software after the device has changed owner. I'm staying the hell away from this ecosystem. Not sure why many so-called "hackers" are so enthusia…

I'm one of the most technically-inclined people I know in my personal social circle (not true in my professional circle.) I'd even probably go so far as to label myself a "hacker". But I do care about UX (which Apple nails). I do care about convenience (which Apple nails.) And I do care about privacy (which, and I know I'll get flak for this, Apple _also nails_ when compared to any other device on the market that isn…

There are processes on macOS you can’t signal without disabling SIP.

Re: Apple Exclaves

#200

Earlier quoted context omitted.

An exclave isn’t hardware, it’s an isolated piece of software that deals with a certain sensitive operation that you don’t want the kernel to have access to. So if you exploit it, then yes you have access to something that the kernel doesn’t–but that’s the point, because the goal is if you exploit the kernel you shouldn’t get access to that.

I'm a little confused reading the article on how exclaves are related to the Mach kernel. Is there a second, parallel seL4 kernel running on the same chip? If so, how do two kernels execute at the same time? > To allow for execution of exclave Services while isolated from XNU, Apple has introduced a new kernel called the Secure Kernel (SK). Or do exclaves run on a separate chip, like Secure Enclaves-with-a-N do? (The…

They run on the AP
Post reply on HN