Live data from Hacker News

Apple’s T2 security chip jailbreak

reportcybercrime.com

71–80 of 393 posts

Re: Apple’s T2 security chip jailbreak

#72
post #4

And so the futility of captured computing continues. I would love to write software for the Touch Bar that runs when I shut the MacBook down .. it'd be quite useful for some things, I imagine - such as using it for a remote control for other equipment I own.

You could explain this a bit more? Not really understanding how this would be useful.

Re: Apple’s T2 security chip jailbreak

#73
post #43

Earlier quoted context omitted.

Thank you for your work! Do you have any thoughts about what Apple's switch to own-brand ARM chips in laptops and desktops will mean for T2/T3/etc?

The T2 was more or less a stopgap solution between their current Intel-based offerings and the AppleSilicon devices in regards to their security aspirations. My understanding is that there will be no T3, as evidenced in the DTK, which makes a lot of sense considering how identical these chips will be to their mobile counterparts.

I'm a user on a 2019 16-inch MBP (MacBookPro16,1) who hopes to move to Linux as my base OS on this hardware full-time over the next 12 months. (https://github.com/Dunedan/mbp-2016-linux)

This is because I honestly cannot find a laptop with the combination of 64+ GB RAM, a non-NDIVIA GPU (edit: to clarify, this is because of NVIDIA's notoriously bad compatibility with Linux), and other premium hardware aspects like its market-leading trackpad at this time - and I doubt that will change anytime soon.

I live with the debilitating T2 kernel panic hardware bug every week. There's also a very bad graphics bug that I and many others are facing. (Not sure if that one can be avoided by simply using Linux.)

I just want to do away with this T2 chip, and whatever it does to get in the way of an otherwise great Intel-based computing experience. The CPU can handle all my encryption just fine...

Thank you to your team for what you're doing. I assume Apple will constantly patch T2 jailbreaks with future macOS system updates (as that's how firmware is updated), and play a long-term cat and mouse game.

Re: Apple’s T2 security chip jailbreak

#74

I'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to cra…

If it really matters, Apple can bring an update that blocks these attacks. If the system depends on security through obscurity, sorry, that never lasts.

Re: Apple’s T2 security chip jailbreak

#76
post #69

Earlier quoted context omitted.

AFAIK, it's not just about the security of your data (you don't need a T2 chip to encrypt data), but also about discouraging theft of the hardware itself. In light of that, how do you allow for components to be swapped out wholesale without breaking the security model? Isn't the entire point that you can't just steal a Macbook, swap out the SSD, and now you have a functioning (stolen) laptop?

The initial transition from the apple root of trust to your own root (which you would then use to install new hardware) could require being authenticated, this way a thief couldn't do it while the legitimate owner could.

That's a route I hadn't thought of.

Seems like a great idea!

Re: Apple’s T2 security chip jailbreak

#77
post #61

Earlier quoted context omitted.

Sorry, but the only rational consumer response to a device that actively works against you is not to purchase it, not hack it. Once millions of people pay to be imprisoned on their own devices, the long game is lost no matter how good the hackers are, the firm has the upper hand and the resources to prevail in the long run. And I am perfectly happy to assert this as a political preference, and vote in office people t…

Many people buy iPhones / Macs because of the (intended) security provided by things like the T2 chip.

Such people would have no issue if they were to be provided with a 20 character secret code that allows rooting and fine grained security control. They would simply not enter it and rely on Apple's decisions for them.

This pretty much kills the whole "intended" security line, the intent is user control.

Re: Apple’s T2 security chip jailbreak

#78
post #45

Earlier quoted context omitted.

You mixed that reputation up with Lenovo thinkpads. Apple keyboards break down after several years with the touchpad and butterfly keyboard disasters are even unusable afresh. You cannot replace anything, and are way overpriced. Thinkpads on the other hand are like Toyota's

My 2016 MBPr was of the first gen with all these changes and it's doing fine as I type this message.

My 2017 MBPr isn't quite the same -- I've had the keyboard changed 3 times so far due to the double key tap issue.

I don't mind though; I'm actually happy when it happens because I get a new battery and top case for free.

Re: Apple’s T2 security chip jailbreak

#79

I'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to cra…

Apple did actually screw the pooch on this one.

Typically, it's criminally illegal to circumvent DRM in the US (and 99% of the rest of the world). However, there are also certain exemptions that have been granted, within the US only (other countries are not so lucky). The right to repair is one such exemption[1].

If Apple had separated security from first-party repair enforcement, then anyone found even attempting to break the T2 chip might have been up for jail time. However, the right to repair is a valid defense.

Of course, making circumvention criminally illegal doesn't make the chip itself any more technically secure; say against criminals. It is a pretty solid deterrent though.

[1] https://www.copyright.gov/1201/2018/

Re: Apple’s T2 security chip jailbreak

#80

Earlier quoted context omitted.

> Apple was striving for an ideal that is not achievable They are aiming for planned obsolescence. The biggest competitor for new MacBooks are old MacBooks.

> The biggest competitor for new MacBooks are old MacBooks. Maybe true 5-10 years ago, but not true now.

Replying from my 7 year old Macbook Air. This might be the last Apple product I'm buying.
Post reply on HN