Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

361–370 of 393 posts

Re: Apple’s T2 security chip jailbreak

#361
post #253

Earlier quoted context omitted.

It's not an intentional anti-resale feature, but it does make repair a lot harder, because it locks (or at least, can lock) specific hardware components to the motherboard. This means if something on the laptop breaks, you can't repair it without the T2 chip knowing about it and potentially refusing to work. Apple has at least told their authorized repair partners that failing to register the repair with Apple may br…

Data recovery - in an era where you have to go out of your way to keep your data out of the cloud, backups are easier than ever and can be done wirelessly - this is going to be your major objection? Please. As for matching parts to the motherboard, they have a point when it comes to I/O devices. It’s probably way more cloak and dagger than most people will ever have to worry about but it’s not unheard of. Again, if y…

The cloud is not going to replace local storage until low-latency, high-bandwidth internet connections become widespread and you can do iSCSI or similar with your cloud service. This is not going to happen anytime soon.

Until then, clouds operate on a best-effort basis, some of which rely on hacks or break common use-cases (I can't put a Git repo in iCloud for example, and it doesn't perform well with lots of small files, and accessing the iCloud folder from the terminal apparently has problems). Why is iCloud still not a supported target for Time Machine, Apple's official backup solution for macOS?

Re: Apple’s T2 security chip jailbreak

#362
post #68

Earlier quoted context omitted.

Allow the users to install their own keys. Changing keys invalidates all encrypted/secured data. Which means you have to export the data if you do hardware changes and reimport it after supplying your own. Once you have your own keys installed you could sign additional hardware with them. If apple is a viable root of trust then you yourself should be too. There's nothing magical that only apple can do.

I believe that Apple is burning their cryptographic key into readonly memory, so they would need to build out a readwrite pipeline and provide a secondary keystore option for "non-default" users that is writable by the hardware itself. That's a tall ask, but it's feasible, so we're good so far. The benefit to expert users with crypto competence is clear. How would this benefit third-party repair shops, though?

The point is that you'd backup the keys in advance (when you initially set up the machine) and when the machine dies and your T2 is fried the repair shop can just replace it with a new T2, load the backed-up keys into it and give you back your machine with the data intact.

Re: Apple’s T2 security chip jailbreak

#363

Interesting. Does this mean that companies can now use this to unlock corp laptops that ex-employees have iCloud/activation-locked to their personal accounts without Apple's help? [+] [+] Yes, I realize that this also applies to stolen laptops, but this is an actual pain point with running fleets of Macs, from what I've heard.

Yep, it involves the same techniques used for iDevices but with less steps. I won't go into details here for obvious reasons.

Are you saying that there is a long-term way to bypass Activation Lock? My understanding was that even if you bypass it locally (through jailbreak), you will not be able to use any of Apple's online services (iMessage, App Store, push notifications, etc) because Apple will not let this device register (and get the necessary client certificates) unless the original account's credentials are provided first, and this is enforced server-side and thus immune to local exploits.

Re: Apple’s T2 security chip jailbreak

#364
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

The T2 Mac startup chime is located in /System/Library/PrivateFrameworks/BridgeAccessibilitySupport.framework/AXEFIAudio_VoiceOver_Boot.aiff . I think it will only be months until someone manages to change the 'bong' sound into a custom startup chime. This will be very interesting...

Re: Apple’s T2 security chip jailbreak

#365
post #244

Earlier quoted context omitted.

On the flip side, the FBI had to (probably) decap chips to get into that one shooter’s iPhone, which is pretty good security IMO.

Did they actually get in to it?

It was an iPhone 5c, a pre secure-enclave iPhone so they were able to break in at the end. Apparently Cellebrite were the ones who cracked it.

Re: Apple’s T2 security chip jailbreak

#366
post #350
post #349

Earlier quoted context omitted.

Are you seriously claiming that anything short of omniscience is useless? In most fields people deal with incomplete data on a daily basis and this is no different. CVEs don’t tell you everything but they definitely give you more than zero, and more to the point, the many vulnerabilities in open source projects suggests that the very broad but completely unsupported claim I was responding to is based on ideology rath…

> the many vulnerabilities in open source projects suggests that the very broad but completely unsupported claim I was responding to is based on ideology rather than reasoned analysis Does it? In order to claim that, one would have to have some idea of (a) the ratio of disclosed vulnerabilities to true vulnerabilities discovered in both open source, accessible code vs closed source, hardware locked code, and (b) the…

Again, the comment I responded to made an absolute claim but, like you, had no supporting evidence. Unless one of you can produce some evidence it’s hard to support the belief that this is based on data.

If you read the thread, note that I’m not taking a side other than finding it absurd to claim that all open source products are inherently better than all proprietary products with no analysis or data.

Re: Apple’s T2 security chip jailbreak

#367
post #197

Earlier quoted context omitted.

Where and how do you see the T2 chip being the mechanism that Apple stops reselling of hardware? Yes it could be used that way. But they have never even indicated that they've been thinking of using the secure enclave for that purpose.

macOS will deprecate older Macs 6-7 years after their release. You can use older Macs as Linux machines, with one of the BSDs, or with Windows. The T2 chip can prevent people from putting their OS of choice on their hardware once Apple deprecates support for their machine.

There is no evidence that is going to be the case. I can still use bootcamp on legacy machines, I don’t see that changing with the T2.

Re: Apple’s T2 security chip jailbreak

#368

Earlier quoted context omitted.

I never understood this sentiment, if people choose to pay their way into a walled garden, why should they still care about hardware ownership/repairabilty, etc.?

I'd be interested in a real study that actually measured how often people are explicitly choosing the walled garden, and how often they're choosing something else that the walled garden "happens to come with". My money is on the second option but AFAIK there's no study like this.

My guess is most people have no idea what a walled garden is.

Re: Apple’s T2 security chip jailbreak

#369

Earlier quoted context omitted.

Why do you believe it's moral for you to do work which is making people's data less secure, helping law authority crack iPhones, etc?

Law enforcement has been going apeshit about legally forcing Apple to build in hardware backdoors to their products. If this jailbreak didn't exist, they'd be putting a gun to Apple's head and demanding decryption tools for all iPhones. Furthermore, the entire point of a jailbreak is to regain root access to your own device - Apple provides no way for a user to do so, which I find at least somewhat irksome. The way i…

The T2 isn’t used in the iPhone or iOS devices.

Re: Apple’s T2 security chip jailbreak

#370

Earlier quoted context omitted.

Some one from Apple, I'm sure you read this. Please answer this ASAP. I rely on mac and FileValute for professional use at work. Need to know the state of this exploit.

>FileVault for professional use Probably not the best choice :) you never want to use proprietary software if security is a concern

As it stands now, from my understanding, the failure case of the proprietary solution is the same level of security as the best case of the open source solution. So I don't see your point. Open source isn't any better.

Open source full disk encryption can be password cracked without limitations just like a hacked T2 chip. A sleeping open source full disk encryption machine can be accessed with enough skill to pull things out of frozen ram, etc.

Post reply on HN