Live data from Hacker News

Secure Boot in the Era of the T2

duo.com

71–80 of 97 posts

Re: Secure Boot in the Era of the T2

#71
post #64
post #39

Earlier quoted context omitted.

This can't be stressed enough. Freedom (indeed "ownership") means that I should be able to run any app I want on my device without having to create an account with Apple. It would be great if I could have both freedom and security, but Apple has decided that is not an option. I have to choose one or the other. I choose freedom.

That's literally what I said. There's a checkbox for you to choose freedom inside System Preferences. You, as a device owner, can check that box. Someone with temporary access to your computer cannot. This is a step forward for most users and not a step backwards for any users . Sure, it would be better to let you enroll your own keys. But as it is you have more options than you have previously, and you as device own…

With UEFI Secure Boot, you can enroll your own "Machine Owner Key" and use the private part for signing, thus having both, freedom and to a certain degree security (the hardware has firmware, that with high degree of probability won't be signed by your key, so you will have to keep someone else key enrolled too; so it is not perfect either).

Platforms like T2, which allow only on/off, but not key enrollments, are a step back.

Re: Secure Boot in the Era of the T2

#72
post #66
post #65

Earlier quoted context omitted.

What software of your choice have you attempted to use, where did it fail, and what's the stack trace? Given that Windows works, it's hard to believe that any issues accessing internal storage are a result of permissions. It just sounds like nobody's implemented Linux support for the hardware. Why don't you? If you're not able to either spend time writing a driver or hiring someone to do so, you have no meaningful ab…

Windows works on the new MacBook not because it has special drivers for NVMe-via-T2 but because Apple trusts Microsoft's EFI key. So no, stop it with all this "Linux works if you just disable Secure Boot" nonsense. It doesn't. You can run Linux from a USB key, sure, but it can't access the internal NVMe SSD!

Judging by this post:

https://unix.stackexchange.com/a/479544

It looks like some kind of driver issue, not an intentional lockout.

To corroborate this, while I don’t have personal experience running Linux on T2 devices, I do know it’s possible to build xnu from source and boot the resulting unsigned kernel (in “No Security” mode) without the disk disappearing.

Re: Secure Boot in the Era of the T2

#73
post #3

> Apple should be lauded for trying to bring their laptop and desktop lines into the same defensive posture as their mobile offerings. I think this can't be stated enough. The fact of the matter is that pre T2, evil maid attacks were ridiculously easy. Now they're at least as secure as iOS -- which also means that shared vulnerabilities can be patched and detected. By no means is it perfect security, but it's a heck…

are my back ups encrypted? I can physically get those too.

Re: Secure Boot in the Era of the T2

#74
post #3

> Apple should be lauded for trying to bring their laptop and desktop lines into the same defensive posture as their mobile offerings. I think this can't be stated enough. The fact of the matter is that pre T2, evil maid attacks were ridiculously easy. Now they're at least as secure as iOS -- which also means that shared vulnerabilities can be patched and detected. By no means is it perfect security, but it's a heck…

I'm also super excited that the entertainment industry has caught up as well. Before it was ridiculously easy to inject ads and objectionable content into my video streams but thanks to HDCP I never have to worry about that again. It's so much more secure!

Re: Secure Boot in the Era of the T2

#75
post #65

Earlier quoted context omitted.

Even if you turn secure boot off you cannot grant for love or any amount of money permission for software of your choosing to access the built in storage which is pretty much required for normal people to be able to run software of their choosing on the machine. Few people will buy equivalent external ssd storage for 300-500 and carry it around with them to have access to a second OS. There is absolutely no reason to…

What software of your choice have you attempted to use, where did it fail, and what's the stack trace? Given that Windows works, it's hard to believe that any issues accessing internal storage are a result of permissions. It just sounds like nobody's implemented Linux support for the hardware. Why don't you? If you're not able to either spend time writing a driver or hiring someone to do so, you have no meaningful ab…

No matter now much time you spend writing your driver, until your kernel has the "correct" signature, it was wasted effort.

So unless you point out a method, how to factor the right key, all your suggestions are a waste of resources that lead nowhere.

Re: Secure Boot in the Era of the T2

#76
post #31

Earlier quoted context omitted.

which is great for data privacy. ...and absolutely horrible for freedom. It used to be the case, and still widely accepted for a lot of other products, that physical ownership actually meant something beyond just being a consumer. Now companies are turning the security against users, lest they also be attackers. From the point of view of the DRM-advocating media corporations, the user is an attacker. Locking down the…

> It used to be the case, and still widely accepted for a lot of other products, that physical ownership actually meant something beyond just being a consumer. It still does. The only thing is we've distinguished physical ownership and mere physical possession. It is a feature that if I leave my personal laptop at my desk at work while using the bathroom, my IT department can't rootkit it. It is an improvement to my…

>and it's weird that the usually pro-personal-liberty free software crowd hasn't decided that a free software implementation of the same thing is critically important.)

Purism did. But this requires hardware too which the free software people don't have access to.

Re: Secure Boot in the Era of the T2

#77

Earlier quoted context omitted.

Bootcamp will also install Microsoft's root for UEFI so that Windows 10 can run fully secure.

So Apple will let you run macOS or Windows, but not Linux or anything else. Wow. This is the exact scenario the secure boot opponents several years ago were trying to stop.

No, Apple will let you secure boot into macOS or Windows, and will allow you to disable secure boot so you can boot into Linux or anything else.

Re: Secure Boot in the Era of the T2

#78
post #64
post #39

Earlier quoted context omitted.

This can't be stressed enough. Freedom (indeed "ownership") means that I should be able to run any app I want on my device without having to create an account with Apple. It would be great if I could have both freedom and security, but Apple has decided that is not an option. I have to choose one or the other. I choose freedom.

That's literally what I said. There's a checkbox for you to choose freedom inside System Preferences. You, as a device owner, can check that box. Someone with temporary access to your computer cannot. This is a step forward for most users and not a step backwards for any users . Sure, it would be better to let you enroll your own keys. But as it is you have more options than you have previously, and you as device own…

> This is a step forward for most users and not a step backwards for any users.

Maybe. What happens when the check box goes away on a future version of MacOS? If my freedom depends entirely on an obscure checkbox rather than the ability to install my own keys, that seems like a thin reed to me.

Re: Secure Boot in the Era of the T2

#79
post #64
post #39

Earlier quoted context omitted.

This can't be stressed enough. Freedom (indeed "ownership") means that I should be able to run any app I want on my device without having to create an account with Apple. It would be great if I could have both freedom and security, but Apple has decided that is not an option. I have to choose one or the other. I choose freedom.

That's literally what I said. There's a checkbox for you to choose freedom inside System Preferences. You, as a device owner, can check that box. Someone with temporary access to your computer cannot. This is a step forward for most users and not a step backwards for any users . Sure, it would be better to let you enroll your own keys. But as it is you have more options than you have previously, and you as device own…

I can't argue with the notion that this adds an option for users, and increases the security of users who choose to use the functionality.

I can't help but think that you're suffering from some kind of IT Stockholm Syndrome, however. Characterizing a secure boot option that only allows MacOS to be booted securely, (with no option to enroll your own keys) as "freedom" sounds to me like characterizing the 2002 Iraqi presidential referendum as a "free election".

Apple's agenda isn't aligned with user freedom. There's no place for the word "freedom" in characterizing Apple. They arguably have a user security and privacy agenda, but they have no user freedom agenda.

Re: Secure Boot in the Era of the T2

#80
post #64

Earlier quoted context omitted.

That's literally what I said. There's a checkbox for you to choose freedom inside System Preferences. You, as a device owner, can check that box. Someone with temporary access to your computer cannot. This is a step forward for most users and not a step backwards for any users . Sure, it would be better to let you enroll your own keys. But as it is you have more options than you have previously, and you as device own…

I can't argue with the notion that this adds an option for users, and increases the security of users who choose to use the functionality. I can't help but think that you're suffering from some kind of IT Stockholm Syndrome, however. Characterizing a secure boot option that only allows MacOS to be booted securely, (with no option to enroll your own keys) as "freedom" sounds to me like characterizing the 2002 Iraqi pr…

Without T2: You don't have the option of booting anything securely.

With T2: You can boot macOS securely, but everything else is still insecure.

If Apple had denied the option to disable secure boot, and didn't make any affordances to boot other OSes (albeit insecurely), we would indeed have lost freedom. The way they did it, we gained security within the macOS ecosystem without losing any freedom elsewhere.

Post reply on HN