Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

41–50 of 393 posts

Re: Apple’s T2 security chip jailbreak

#42
post #32

The fact that Apple uses this chip to, among other things, block "unauthorized repair" (can't change a freaking SSD in 2020, really), makes me very happy that people are finding ways to break this chip to make repairs more accessible. On the other hand, this could have serious implications on the iOS security model for example. And I'm pretty sure someone is gonna run Doom on the touchbar in some months.

>The fact that Apple uses this chip to, among other things, block "unauthorized repair" I actually dont mind they block unauthorised repair, at least I believe in the Steve Jobs's Apple era he wanted the best customer experience. And they want the Data of what is failing in their Mac where their Genius Bar gain first hand experience and knowledge which leads to feedback to the Design team. ( They dont publicly announ…

> The goal was to aim for perfection, a machine that is so reliable it wouldn't need to repair in the first place.

You will have to excuse me, but that is a load of bullcrap.

Let's take the case that irritates me the most: The SSD.

By definition of the technology that is NAND storage, an SSD will be able to operate "within norm" and without bit errors for so long. Rewrite for long enough and you'll see your data waving you good-bye.

As for your other claims about recording errors and whatnot, you can EASILY achieve those (matter of fact it's already implemented in UEFI by some manufacturers), and NOT disallow people from repairing their computer.

Sure the lifespan of an SSD is ideally 5/7 years. But that is a death sentence, not a search for perfection.

Also, what happens if Apple simply refuses to fix your computer, or supply your with parts ! And yes this has happened rather publicly (Linus Sebastian's Mac Pro)

So again, apologies for the language but that is a load of bullcrap

Re: Apple’s T2 security chip jailbreak

#43
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

Thank you for your work! Do you have any thoughts about what Apple's switch to own-brand ARM chips in laptops and desktops will mean for T2/T3/etc?

The T2 was more or less a stopgap solution between their current Intel-based offerings and the AppleSilicon devices in regards to their security aspirations. My understanding is that there will be no T3, as evidenced in the DTK, which makes a lot of sense considering how identical these chips will be to their mobile counterparts.

Re: Apple’s T2 security chip jailbreak

#44
post #17

Earlier quoted context omitted.

The things stored in the enclave are encrypted with a key derived from, among other things, your device password so no jailbreak is going to provide access to them. It would be a big deal if one could, say, run 'offline' dictionary attacks against secure enclave content.

Same password results in a different hash if you run it again.

that's literally opposite to how hashing works

Re: Apple’s T2 security chip jailbreak

#45

Earlier quoted context omitted.

People in third world countries buy Macbooks - really? A decent macbook is several times above an average monthly income in a first-world country already...

I'd guess many in third-world countries buy second-hand Macbooks, as they have a reputation (at least in the past) for lasting a long time? And are there any first-world countries (except maybe the US^^) where a 13" Macbook is several times the average net monthly income? In Germany, for instance, the monthly average net wage (MANW) is €2500, while the price of a 13" Macbook starts at €1300. Italy: MANW is €1700, Spa…

You mixed that reputation up with Lenovo thinkpads. Apple keyboards break down after several years with the touchpad and butterfly keyboard disasters are even unusable afresh. You cannot replace anything, and are way overpriced.

Thinkpads on the other hand are like Toyota's

Re: Apple’s T2 security chip jailbreak

#47

Earlier quoted context omitted.

Fair enough, but the problem is mainly when you are in a third world country and parts are very difficult to get, and where Mac stores are non-existent.

People in third world countries buy Macbooks - really? A decent macbook is several times above an average monthly income in a first-world country already...

It can be a business investment. I sometimes send work to third-world countries via Fiverr, and these people definitely have decent hardware. They buy and write off their machines like any other business in the world.

Re: Apple’s T2 security chip jailbreak

#48
post #32

Earlier quoted context omitted.

>The fact that Apple uses this chip to, among other things, block "unauthorized repair" I actually dont mind they block unauthorised repair, at least I believe in the Steve Jobs's Apple era he wanted the best customer experience. And they want the Data of what is failing in their Mac where their Genius Bar gain first hand experience and knowledge which leads to feedback to the Design team. ( They dont publicly announ…

> The goal was to aim for perfection, a machine that is so reliable it wouldn't need to repair in the first place. You will have to excuse me, but that is a load of bullcrap. Let's take the case that irritates me the most: The SSD. By definition of the technology that is NAND storage, an SSD will be able to operate "within norm" and without bit errors for so long. Rewrite for long enough and you'll see your data wavi…

Who is Linus Sebastian, why should I care about him, and why I should consider his case typical?

Re: Apple’s T2 security chip jailbreak

#49
post #17

Earlier quoted context omitted.

The things stored in the enclave are encrypted with a key derived from, among other things, your device password so no jailbreak is going to provide access to them. It would be a big deal if one could, say, run 'offline' dictionary attacks against secure enclave content.

> run 'offline' dictionary attacks against secure enclave content. Isn't the T2 chip the only reason they can't do that:: because it sets a minimum time-limit and cooldown period on attempts to authenticate using the device passcode? So presumably rooting T2 and removing the artificial time limits and/or extracting KDF data would mean game-over because brute-forcing `[0-9]{4,8}`, with even the most expensive hash fun…

The Secure Enclave is just a part of the T2 chip. My understanding is that this is similar to if you jailbreak your iOS device, you won't get any special access to the Secure Enclave.

And as I understand it, it's also the Secure Enclave that enforces the attempt limits.

Re: Apple’s T2 security chip jailbreak

#50
post #35

Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootl…

> Filevault and by extension Touch ID are more or less crippled

Sorry, what does this sentence mean? That someone with physical access to my machine can now unencrypt my FileVault encrypted hard drive?

Post reply on HN