Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

331–340 of 393 posts

Re: Apple’s T2 security chip jailbreak

#331
post #8

I wonder if this has security implications. The T2 houses the "secure enclave" and that's where your private keys, certificates and passwords are stored.

I still don't understand why nobody seems to be able to answer the question that everybody would want to know the answer to, which is:

Is it possible to get at the encrypted user data of a locked MacBook or not?

*

Yes or no, please...

Re: Apple’s T2 security chip jailbreak

#332

Earlier quoted context omitted.

>keep working fine for most people for close to a decade or so doesn't mesh with - >you're not supposed to be running a 10 year old laptop or 2-3 versions old OS Planned obsolescence just means artificially shortening the upgrade cycle. That's it. And Apple has been doing this in the Mac world through different methods.

>Planned obsolescence just means artificially shortening the upgrade cycle. No, it doesn't not. Planned obsolescence, just the like the actual words in the term are defined, means planning for the fact that technology and the components it's made from has a finite lifespan and that, at some point, users of that technology will have to upgrade. You're inferring that companies are intentionally sabotaging their product…

>https://en.wikipedia.org/wiki/Planned_obsolescence

>In economics and industrial design, planned obsolescence (also called built-in obsolescence or premature obsolescence) is a policy of planning or designing a product with an artificially limited useful life, so that it becomes obsolete (i.e., unfashionable, or no longer functional) after a certain period of time.[1] The rationale behind this strategy is to generate long-term sales volume by reducing the time between repeat purchases (referred to as "shortening the replacement cycle").[2] It is the deliberate shortening of a lifespan of a product to force consumers to purchase replacements.[3]

Apple does this with their hardware by limiting the software support period and economical hardware repair. Having something like the T2 ensures that third parties are not able to extend the life of their systems in a reasonable manner.

Re: Apple’s T2 security chip jailbreak

#333

Earlier quoted context omitted.

What has changed in the last 5 years? MacOS users have no legitimate alternative if they want to keep their desktop on macOS. If you want a macOS system legally, there's two options, either buy a new Mac, or an old one.

The competition has just done a lot of catching up in the last few years. Hardware: Other vendors have trackpads with multi-touch (which for me was one of the most amazing things about the first Macbook I ever owned), super high-res screens, and other such features these days. The form factors are thin and stylish as well (there are other aluminum unibody laptops these days). Software: MacOS has gotten worse, Linux d…

We're not on the same page. My point being that the macOS users that Apple are targeting with this policy has the choice between a new Mac and an used one.

That's where they make their money. People that just want good specs at cheap prices are not their target market.

Re: Apple’s T2 security chip jailbreak

#335
post #325

Earlier quoted context omitted.

Ah, the ole "idiot user" rhetoric, imprisoned for their own sake. Say I call the Apple support center, ask for the code, and they warn me in no uncertain terms that I'm voiding my warranty and would not be eligibile for continued support. How can this prevent any mentally sane person from trusting Apple made the correct decisions and not root their device?

No, not "idiot user". No one is imprisoned. In the same way that people choose to be part of organizations and groups with rules and limits to what can be done, people choose to use devices that are slightly limited in exchange for reliability and security. I don't want Apple waste time and resources to need to support the people that call the call center to ask for this supposed code and most people using their devi…

No, it wouldn't, see the terminal unlock code for contract phones discussed below. If your opinion is that the free market is all correcting and magical and that laws and regulations should never intervene in private consumer choices, I have a failed state I can introduce you to, not to mention a salmonela infested burrito.

Re: Apple’s T2 security chip jailbreak

#336
post #135

Earlier quoted context omitted.

It's a trade-off. I buy MBPs for the great form-factor and OS, not for the walled-garden shenanigans. If those shenanigans can be somewhat reduced, the trade-off balance looks better.

I don't mean to me facetious, but I am genuinely curious: why should you get to have it your way? You are attempting to buy a product they do not sell.

After you buy your hardware it's yours to do with as you will. If these hacks result in the ability to load whatever you like on the T2 and intel proper then why not? Hackers like to hack. A lot of programmers are also hackers (in the traditional sense, not the negative sentiments that the press gives it)

Re: Apple’s T2 security chip jailbreak

#337

Earlier quoted context omitted.

I never understood this sentiment, if people choose to pay their way into a walled garden, why should they still care about hardware ownership/repairabilty, etc.?

"if people choose to pay their way into a walled garden, why should they still care about hardware ownership/repairabilty, etc.?" I don't like the walled garden but i still brought a iPhone because iPhones get updates for really long time(3 years minimum). Iphone SE(1st gen) released in 2016 got the iOS14 update.

I'm in the same boat as well :) . I keep a mac laptop for work/consulting stuff and otherwise have a linux box and several rpi's for my linux hacking hobbies :)

Re: Apple’s T2 security chip jailbreak

#338
post #16

Earlier quoted context omitted.

That's running purely in usermode, and nothing was broken in this demonstration, the touch bar is being used "as intended"

Exactly. This would "in theory" allow Doom to be running outside of the "prescribed parameters".

can we run text mode doom over ssh mayhaps?

Re: Apple’s T2 security chip jailbreak

#339

The fact that Apple uses this chip to, among other things, block "unauthorized repair" (can't change a freaking SSD in 2020, really), makes me very happy that people are finding ways to break this chip to make repairs more accessible. On the other hand, this could have serious implications on the iOS security model for example. And I'm pretty sure someone is gonna run Doom on the touchbar in some months.

True, but to be fair, the same mechanism also blocks thieves from using and/or selling stolen Macs.

That just means apple should have done a better job securing the chip. All of these management chips have a bad history of security look up HP and Dell BMC chips as well

Re: Apple’s T2 security chip jailbreak

#340

I'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to cra…

I think it's always best for these things to come out if there's a flaw. You can bet if these guys found it that China, the US government, and 11 eyes by extension all knew about it before that. It's best to know the truth, that the security is broken, rather than crossing your fingers and hoping the security works.
Post reply on HN