Live data from Hacker News

Apple T2 Security Chip: Security Overview [pdf]

apple.com

71–80 of 99 posts

Re: Apple T2 Security Chip: Security Overview [pdf]

#71
post #3

"All Mac portables with the Apple T2 Security Chip feature a hardware disconnect that ensures that the microphone is disabled whenever the lid is closed." It's interesting, I don't know if other brands do that?

I wonder what determines whether or not the lid is closed.

Re: Apple T2 Security Chip: Security Overview [pdf]

#72
post #46
post #41

Earlier quoted context omitted.

Why it needs to go trough security chip? Laptop closed -> microphone cut off does not need complex logic. It's just simple switch.

the NSA/CIA/3LA can't backdoor a physical switch

Why not?

Do you have schematics of your laptop?

Re: Apple T2 Security Chip: Security Overview [pdf]

#73

What happens if the T2 Chip fails? Is it possible to recover data on the disk? Or do we have to recover data from the last backup?

I'm just waiting for the Rossmann video when someone manages to spill some Coke on their T2 chip... Shit like this is why I will never buy another Apple product. With my encrypted drives I can pull them out, put them in another machine and decrypt them no issues.

Then they are not encrypted.

Re: Apple T2 Security Chip: Security Overview [pdf]

#74

What happens if the T2 Chip fails? Is it possible to recover data on the disk? Or do we have to recover data from the last backup?

I'm just waiting for the Rossmann video when someone manages to spill some Coke on their T2 chip... Shit like this is why I will never buy another Apple product. With my encrypted drives I can pull them out, put them in another machine and decrypt them no issues.

And the same goes for whoever steals/subpoenas your machine.

Shit like this is why I only buy Apple products.

The data I care about I have (encrypted) backups of. Not having backups and hoping that a specific hardware failure will not affect my ability to restore is equivalent to, well, just not having backups to begin with.

Re: Apple T2 Security Chip: Security Overview [pdf]

#75

Earlier quoted context omitted.

Last time this came around I believe it was shown that the process was similar to the one used in iOS.

With the very important difference that on the Mac, it can actually be turned off.

For now.

Re: Apple T2 Security Chip: Security Overview [pdf]

#76

Earlier quoted context omitted.

The mics are on the left hand side on that model. https://www.ifixit.com/Guide/MacBook+Pro+13-Inch+Retina+Disp...

…that's what I said?

Has this place become such a cesspit that you can't countenance the possibility I'm simply supporting your position and backing it up with evidence? Perhaps I should have added the word 'yes' as the first word.

And someone felt the need to down vote a reply simply containing evidence that proves a commenter correct? I despair sometimes.

Re: Apple T2 Security Chip: Security Overview [pdf]

#77
post #33

anyone who uses eGPUs (w/ Nvidia): whenever I setup my MBP shortly after buying (middle of this year), one of the steps required disabling Secure Boot and another security item via terminal. Is that still the case? Pretty sure my T2 chip is disabled due to this. Not a major loss if it must remain that way, but wasn't sure if it was just mitigating something that is no longer an issue.

It’s no longer required; High Sierra and Mojave both officially support eGPUs.

Re: Apple T2 Security Chip: Security Overview [pdf]

#78
post #29

Earlier quoted context omitted.

Why you need security chip to ensure that?

So no malware can be installed to override a software based interlock. No malware can alter the contents of the T2 chip so code there cannot be changed, altered or mitigated.

The T2 chip is just an ARM CPU running a customized version of watchOS. So in theory malware could take over control of the T2 chip.

I also wonder what implications on features like the mentioned microphone disconnect that'd have. My guess is that the T2 chip which also acts as audio controller, simply doesn't forward audio signals received from the microphone to macOS if the lid is closed.

Edit: Never mind. After reading further it becomes clear that it's really disconnected in hardware:

> This disconnect is implemented in hardware alone, and therefore > prevents any software, even with root or kernel privileges in macOS, and even > the software on the T2 chip, from engaging the microphone when the lid is > closed.

Re: Apple T2 Security Chip: Security Overview [pdf]

#79

What happens if the T2 Chip fails? Is it possible to recover data on the disk? Or do we have to recover data from the last backup?

As an example, the current gen Macbook Pro has an SSD that is soldered to the motherboard (so you obviously can't remove it and cable it up to USB via an adapter to extract data). Apple installed a port on the motherboard that their techs can use to recover data if the motherboard fails. But sure enough it didn't work with my 11 month old Macbook Pro. Moral of the story... even if Apple has a mechanism for hardware f…

The current generation of MacBook Pro doesn't have such a recovery port for the SSD anymore. The MacBook Pro 2016 and MacBook Pro 2017 had such a port, but the MacBook Pro 2018, which features the T2 chip, doesn't. As the encryption keys are located inside the T2 chip, if that chips breaks, all data on the SSD is lost.

Re: Apple T2 Security Chip: Security Overview [pdf]

#80
post #59

Earlier quoted context omitted.

They say that "The camera is not disconnected in hardware because its field of view is completely obstructed with the lid closed."

I wonder how long it will be until someone manages to figure out how to use image processing to read the noise seen by the camera sensor while the lid is closed and turn it into audio. Kind of like this: http://news.mit.edu/2014/algorithm-recovers-speech-from-vibr...

That's certainly an interesting thought, but do note (from the linked article):

In some of their experiments, the researchers used a high-speed camera that captured 2,000 to 6,000 frames per second..

I haven't checked, but I would be surprised if Apple uses cameras that are capable of that as normal user-facing webcams in their laptops ...

Recovering meaningful audio signal (which usually has lots of data above 1 kHz) from the <100 Hz sampling done by a camera seems difficult, Nyquist and all, right?

Post reply on HN