Earlier quoted context omitted.
You can turn it on or off, but if you want to do anything on your own you have to turn it off as your can't sign anything. If they were really giving you what you say they should make signing your own apps as easy as turning it on/off.
This can't be stressed enough. Freedom (indeed "ownership") means that I should be able to run any app I want on my device without having to create an account with Apple. It would be great if I could have both freedom and security, but Apple has decided that is not an option. I have to choose one or the other. I choose freedom.
Secure Boot in the Era of the T2
61–70 of 97 posts
Re: Secure Boot in the Era of the T2
#62Earlier quoted context omitted.
> It used to be the case, and still widely accepted for a lot of other products, that physical ownership actually meant something beyond just being a consumer. It still does. The only thing is we've distinguished physical ownership and mere physical possession. It is a feature that if I leave my personal laptop at my desk at work while using the bathroom, my IT department can't rootkit it. It is an improvement to my…
Even if you turn secure boot off you cannot grant for love or any amount of money permission for software of your choosing to access the built in storage which is pretty much required for normal people to be able to run software of their choosing on the machine. Few people will buy equivalent external ssd storage for 300-500 and carry it around with them to have access to a second OS. There is absolutely no reason to…
Re: Secure Boot in the Era of the T2
#63Earlier quoted context omitted.
> And, the typical scenario will be a user who leaves it disabled, making both macOS and Linux and possibly Windows (if also installed) more vulnerable to bootkit attacks. No way. The typical user will leave it enabled because they will only use macOS.
Bootcamp will also install Microsoft's root for UEFI so that Windows 10 can run fully secure.
Re: Secure Boot in the Era of the T2
#64Earlier quoted context omitted.
You can turn it on or off, but if you want to do anything on your own you have to turn it off as your can't sign anything. If they were really giving you what you say they should make signing your own apps as easy as turning it on/off.
This can't be stressed enough. Freedom (indeed "ownership") means that I should be able to run any app I want on my device without having to create an account with Apple. It would be great if I could have both freedom and security, but Apple has decided that is not an option. I have to choose one or the other. I choose freedom.
This is a step forward for most users and not a step backwards for any users. Sure, it would be better to let you enroll your own keys. But as it is you have more options than you have previously, and you as device owner are the only person who can decide between those options - attackers have no more options than they had previously.
Go, buy a Mac, choose freedom, you can do that.
Re: Secure Boot in the Era of the T2
#65Earlier quoted context omitted.
> It used to be the case, and still widely accepted for a lot of other products, that physical ownership actually meant something beyond just being a consumer. It still does. The only thing is we've distinguished physical ownership and mere physical possession. It is a feature that if I leave my personal laptop at my desk at work while using the bathroom, my IT department can't rootkit it. It is an improvement to my…
Even if you turn secure boot off you cannot grant for love or any amount of money permission for software of your choosing to access the built in storage which is pretty much required for normal people to be able to run software of their choosing on the machine. Few people will buy equivalent external ssd storage for 300-500 and carry it around with them to have access to a second OS. There is absolutely no reason to…
Given that Windows works, it's hard to believe that any issues accessing internal storage are a result of permissions. It just sounds like nobody's implemented Linux support for the hardware. Why don't you?
If you're not able to either spend time writing a driver or hiring someone to do so, you have no meaningful ability to exercise your software freedom. You might be lucky if someone else implements support; you might not. But that's always been true.
Re: Secure Boot in the Era of the T2
#66Earlier quoted context omitted.
Even if you turn secure boot off you cannot grant for love or any amount of money permission for software of your choosing to access the built in storage which is pretty much required for normal people to be able to run software of their choosing on the machine. Few people will buy equivalent external ssd storage for 300-500 and carry it around with them to have access to a second OS. There is absolutely no reason to…
What software of your choice have you attempted to use, where did it fail, and what's the stack trace? Given that Windows works, it's hard to believe that any issues accessing internal storage are a result of permissions. It just sounds like nobody's implemented Linux support for the hardware. Why don't you? If you're not able to either spend time writing a driver or hiring someone to do so, you have no meaningful ab…
So no, stop it with all this "Linux works if you just disable Secure Boot" nonsense. It doesn't. You can run Linux from a USB key, sure, but it can't access the internal NVMe SSD!
Re: Secure Boot in the Era of the T2
#67Earlier quoted context omitted.
Even if you turn secure boot off you cannot grant for love or any amount of money permission for software of your choosing to access the built in storage which is pretty much required for normal people to be able to run software of their choosing on the machine. Few people will buy equivalent external ssd storage for 300-500 and carry it around with them to have access to a second OS. There is absolutely no reason to…
Huh? You can absolutely grant software of your choosing permission to access the built in storage. How else does Windows or Linux on Mac work?
Re: Secure Boot in the Era of the T2
#68Earlier quoted context omitted.
which is great for data privacy. ...and absolutely horrible for freedom. It used to be the case, and still widely accepted for a lot of other products, that physical ownership actually meant something beyond just being a consumer. Now companies are turning the security against users, lest they also be attackers. From the point of view of the DRM-advocating media corporations, the user is an attacker. Locking down the…
> It used to be the case, and still widely accepted for a lot of other products, that physical ownership actually meant something beyond just being a consumer. It still does. The only thing is we've distinguished physical ownership and mere physical possession. It is a feature that if I leave my personal laptop at my desk at work while using the bathroom, my IT department can't rootkit it. It is an improvement to my…
This is exactly why _you_ must be in control of what software can boot and not Apple or some other company. It's not exactly freedom if you must disable the secure boot feature to run your own software, it's a work-around.
If Apple really cared about freedom they would provide you with your own _unique_ key to sign your own software, so you can ensure that your system actually runs _your_ software.
Re: Secure Boot in the Era of the T2
#69> We believe the T2 platform is a leap forward in platform security in the Apple ecosystem, and it begins to bring exciting security properties like Secure Boot capabilities to the mass market. So the vast PC-market with UEFI secure boot which predates this by 6 year was somehow not the “mass market”, but the relatively tiny MacBook market is? With factual errors like this present already in the introduction, it’s ha…
You are missing the bigger picture in your attempt to immediately discard the original articles premise because you feel like it comes off as fanboy-fluff. No other device on the market currently provides a secondary processor that runs full validation of the UEFI firmware before allowing the processor to start booting. It's not just secure boot, which has been around for a while, it's everything around it. On almost…
HP laptops have a secondary processor (SureStart) for firmware integrity, http://h10032.www1.hp.com/ctg/Manual/c05163901
Re: Secure Boot in the Era of the T2
#70Earlier quoted context omitted.
Huh? You can absolutely grant software of your choosing permission to access the built in storage. How else does Windows or Linux on Mac work?
I believe they are referring to the fact that linux (and non boot camp windows) cannot access the SSD on T2 equiped macbooks. People seem to disagree if it's the T2 itself or just a driver issue with apples proprietary controller.