Live data from Hacker News

Secure Boot in the Era of the T2

duo.com

61–70 of 97 posts

Re: Secure Boot in the Era of the T2

#61
post #39

Earlier quoted context omitted.

You can turn it on or off, but if you want to do anything on your own you have to turn it off as your can't sign anything. If they were really giving you what you say they should make signing your own apps as easy as turning it on/off.

This can't be stressed enough. Freedom (indeed "ownership") means that I should be able to run any app I want on my device without having to create an account with Apple. It would be great if I could have both freedom and security, but Apple has decided that is not an option. I have to choose one or the other. I choose freedom.

You disable Gatekeeper and thus run run any app without having an account with Apple.

Re: Secure Boot in the Era of the T2

#62
post #31

Earlier quoted context omitted.

> It used to be the case, and still widely accepted for a lot of other products, that physical ownership actually meant something beyond just being a consumer. It still does. The only thing is we've distinguished physical ownership and mere physical possession. It is a feature that if I leave my personal laptop at my desk at work while using the bathroom, my IT department can't rootkit it. It is an improvement to my…

Even if you turn secure boot off you cannot grant for love or any amount of money permission for software of your choosing to access the built in storage which is pretty much required for normal people to be able to run software of their choosing on the machine. Few people will buy equivalent external ssd storage for 300-500 and carry it around with them to have access to a second OS. There is absolutely no reason to…

Huh? You can absolutely grant software of your choosing permission to access the built in storage. How else does Windows or Linux on Mac work?

Re: Secure Boot in the Era of the T2

#63

Earlier quoted context omitted.

> And, the typical scenario will be a user who leaves it disabled, making both macOS and Linux and possibly Windows (if also installed) more vulnerable to bootkit attacks. No way. The typical user will leave it enabled because they will only use macOS.

Bootcamp will also install Microsoft's root for UEFI so that Windows 10 can run fully secure.

So Apple will let you run macOS or Windows, but not Linux or anything else. Wow. This is the exact scenario the secure boot opponents several years ago were trying to stop.

Re: Secure Boot in the Era of the T2

#64
post #39

Earlier quoted context omitted.

You can turn it on or off, but if you want to do anything on your own you have to turn it off as your can't sign anything. If they were really giving you what you say they should make signing your own apps as easy as turning it on/off.

This can't be stressed enough. Freedom (indeed "ownership") means that I should be able to run any app I want on my device without having to create an account with Apple. It would be great if I could have both freedom and security, but Apple has decided that is not an option. I have to choose one or the other. I choose freedom.

That's literally what I said. There's a checkbox for you to choose freedom inside System Preferences. You, as a device owner, can check that box. Someone with temporary access to your computer cannot.

This is a step forward for most users and not a step backwards for any users. Sure, it would be better to let you enroll your own keys. But as it is you have more options than you have previously, and you as device owner are the only person who can decide between those options - attackers have no more options than they had previously.

Go, buy a Mac, choose freedom, you can do that.

Re: Secure Boot in the Era of the T2

#65
post #31

Earlier quoted context omitted.

> It used to be the case, and still widely accepted for a lot of other products, that physical ownership actually meant something beyond just being a consumer. It still does. The only thing is we've distinguished physical ownership and mere physical possession. It is a feature that if I leave my personal laptop at my desk at work while using the bathroom, my IT department can't rootkit it. It is an improvement to my…

Even if you turn secure boot off you cannot grant for love or any amount of money permission for software of your choosing to access the built in storage which is pretty much required for normal people to be able to run software of their choosing on the machine. Few people will buy equivalent external ssd storage for 300-500 and carry it around with them to have access to a second OS. There is absolutely no reason to…

What software of your choice have you attempted to use, where did it fail, and what's the stack trace?

Given that Windows works, it's hard to believe that any issues accessing internal storage are a result of permissions. It just sounds like nobody's implemented Linux support for the hardware. Why don't you?

If you're not able to either spend time writing a driver or hiring someone to do so, you have no meaningful ability to exercise your software freedom. You might be lucky if someone else implements support; you might not. But that's always been true.

Re: Secure Boot in the Era of the T2

#66
post #65

Earlier quoted context omitted.

Even if you turn secure boot off you cannot grant for love or any amount of money permission for software of your choosing to access the built in storage which is pretty much required for normal people to be able to run software of their choosing on the machine. Few people will buy equivalent external ssd storage for 300-500 and carry it around with them to have access to a second OS. There is absolutely no reason to…

What software of your choice have you attempted to use, where did it fail, and what's the stack trace? Given that Windows works, it's hard to believe that any issues accessing internal storage are a result of permissions. It just sounds like nobody's implemented Linux support for the hardware. Why don't you? If you're not able to either spend time writing a driver or hiring someone to do so, you have no meaningful ab…

Windows works on the new MacBook not because it has special drivers for NVMe-via-T2 but because Apple trusts Microsoft's EFI key.

So no, stop it with all this "Linux works if you just disable Secure Boot" nonsense. It doesn't. You can run Linux from a USB key, sure, but it can't access the internal NVMe SSD!

Re: Secure Boot in the Era of the T2

#67

Earlier quoted context omitted.

Even if you turn secure boot off you cannot grant for love or any amount of money permission for software of your choosing to access the built in storage which is pretty much required for normal people to be able to run software of their choosing on the machine. Few people will buy equivalent external ssd storage for 300-500 and carry it around with them to have access to a second OS. There is absolutely no reason to…

Huh? You can absolutely grant software of your choosing permission to access the built in storage. How else does Windows or Linux on Mac work?

I believe they are referring to the fact that linux (and non boot camp windows) cannot access the SSD on T2 equiped macbooks. People seem to disagree if it's the T2 itself or just a driver issue with apples proprietary controller.

Re: Secure Boot in the Era of the T2

#68
post #31

Earlier quoted context omitted.

which is great for data privacy. ...and absolutely horrible for freedom. It used to be the case, and still widely accepted for a lot of other products, that physical ownership actually meant something beyond just being a consumer. Now companies are turning the security against users, lest they also be attackers. From the point of view of the DRM-advocating media corporations, the user is an attacker. Locking down the…

> It used to be the case, and still widely accepted for a lot of other products, that physical ownership actually meant something beyond just being a consumer. It still does. The only thing is we've distinguished physical ownership and mere physical possession. It is a feature that if I leave my personal laptop at my desk at work while using the bathroom, my IT department can't rootkit it. It is an improvement to my…

> I can't make sure my computer is running the code I want it to if everyone else can make my computer run the code they want it to

This is exactly why _you_ must be in control of what software can boot and not Apple or some other company. It's not exactly freedom if you must disable the secure boot feature to run your own software, it's a work-around.

If Apple really cared about freedom they would provide you with your own _unique_ key to sign your own software, so you can ensure that your system actually runs _your_ software.

Re: Secure Boot in the Era of the T2

#69

> We believe the T2 platform is a leap forward in platform security in the Apple ecosystem, and it begins to bring exciting security properties like Secure Boot capabilities to the mass market. So the vast PC-market with UEFI secure boot which predates this by 6 year was somehow not the “mass market”, but the relatively tiny MacBook market is? With factual errors like this present already in the introduction, it’s ha…

You are missing the bigger picture in your attempt to immediately discard the original articles premise because you feel like it comes off as fanboy-fluff. No other device on the market currently provides a secondary processor that runs full validation of the UEFI firmware before allowing the processor to start booting. It's not just secure boot, which has been around for a while, it's everything around it. On almost…

> No other device on the market currently provides a secondary processor that runs full validation of the UEFI firmware before allowing the processor to start booting.

HP laptops have a secondary processor (SureStart) for firmware integrity, http://h10032.www1.hp.com/ctg/Manual/c05163901

Re: Secure Boot in the Era of the T2

#70
post #67

Earlier quoted context omitted.

Huh? You can absolutely grant software of your choosing permission to access the built in storage. How else does Windows or Linux on Mac work?

I believe they are referring to the fact that linux (and non boot camp windows) cannot access the SSD on T2 equiped macbooks. People seem to disagree if it's the T2 itself or just a driver issue with apples proprietary controller.

According to https://www.omgubuntu.co.uk/2018/11/apple-t2-chip-cant-boot-... you just have to turn off the extra security.
Post reply on HN