Live data from Hacker News

Secure Boot in the Era of the T2

duo.com

81–90 of 97 posts

Re: Secure Boot in the Era of the T2

#81

Earlier quoted context omitted.

They even go beyond the assumption of sniffing passwords from users head on the iPhone. Thanks to the face/fingerprint reader, most people are incapable of divulging their pin/password to someone claiming to be the county password inspector. While in an absolute/legal sense it’s less secure, for day to day use by most people it’s more secure as there is no password for someone to watch you enter, or socialy compel yo…

Don't know about face id, but with finger ID you certainly need to know the pin number for all the cases that finger ID doesn't work. More than that, it's easier for a security guard to point the phone at your face / push your thumb on the sensor than get you to reveal a passcode

> Don't know about face id, but with finger ID you certainly need to know the pin number for all the cases that finger ID doesn't work.

This is the case with Face ID as well. I use my PIN more with Face ID than I did with Touch ID.

> More than that, it's easier for a security guard to point the phone at your face / push your thumb on the sensor than get you to reveal a passcode

It's fairly easy to discreetly disable, FWIW. Just "squeeze" your phone for two seconds (i.e. press the power button and either volume button) to disable Face ID. It also won't work if you're looking away or have your eyes closed.

Re: Secure Boot in the Era of the T2

#82
post #3

> Apple should be lauded for trying to bring their laptop and desktop lines into the same defensive posture as their mobile offerings. I think this can't be stated enough. The fact of the matter is that pre T2, evil maid attacks were ridiculously easy. Now they're at least as secure as iOS -- which also means that shared vulnerabilities can be patched and detected. By no means is it perfect security, but it's a heck…

are my back ups encrypted? I can physically get those too.

That's up to you. The details depend on what you're using to do backups.

Re: Secure Boot in the Era of the T2

#83
post #3

> Apple should be lauded for trying to bring their laptop and desktop lines into the same defensive posture as their mobile offerings. I think this can't be stated enough. The fact of the matter is that pre T2, evil maid attacks were ridiculously easy. Now they're at least as secure as iOS -- which also means that shared vulnerabilities can be patched and detected. By no means is it perfect security, but it's a heck…

How is it different from UEFI secure boot which was on PC for years?

Re: Secure Boot in the Era of the T2

#84
post #64

Earlier quoted context omitted.

That's literally what I said. There's a checkbox for you to choose freedom inside System Preferences. You, as a device owner, can check that box. Someone with temporary access to your computer cannot. This is a step forward for most users and not a step backwards for any users . Sure, it would be better to let you enroll your own keys. But as it is you have more options than you have previously, and you as device own…

I can't argue with the notion that this adds an option for users, and increases the security of users who choose to use the functionality. I can't help but think that you're suffering from some kind of IT Stockholm Syndrome, however. Characterizing a secure boot option that only allows MacOS to be booted securely, (with no option to enroll your own keys) as "freedom" sounds to me like characterizing the 2002 Iraqi pr…

I'm not characterizing the presence of the switch as freedom - I'm characterizing the existence of the choice "Do things the old way" as containing as much freedom as you previously had, and pointing out that a) such a choice exists b) the ability to make the choice is in the hands of the owner only.

You can't meaningfully characterize the 2002 Iraqi election as a loss of freedom. You can characterize it as a farce, sure. You can call it evidence that you had no freedom all along. (And if people want to say that the lack of user-enrolled secure boot has been a freedom problem with personal computers since forever, I will certainly agree with them.) But you can't meaningfully say, "We had more freedom before this election, and I want to go back to how things were." So arguments about giving up essential liberty and temporary safety just don't technically make sense. If you don't have essential liberty now, you certainly didn't have it before.

I also think that there will be some users who will choose freely to use macOS because they genuinely believe that's better for their computing freedom, and they're not manifestly wrong in reaching that conclusion (whereas I would be much more skeptical of someone saying "I voted for Saddam because I think he's going to do good things for the country"). As I mentioned there is no competent free software implementation of an OS secure against evil maid attacks, with secure boot and TPM-locked full disk encryption. You can, in theory, fiddle with tpm-tools and cryptsetup and shim (or coreboot?) and build something of your own; I've never seen anyone do it, and I've certainly not seen a distro that provides a one-click option in the installer to do it. macOS on a system with a T2 chip provides this out of the box. Windows with BitLocker does. Chrome OS does. (I suppose Chromium OS does, but doing binary builds of that seems at least as tricky as getting cryptsetup and tpm-tools working.) A user who decides to use a proprietary platform as a tradeoff for knowing that their machine is only running software they've chosen (even though their choices are limited) is not obviously making a mistake.

(I will admit that I have a Chromebook for secure stuff and a normal Debian stable laptop for everyday stuff, and I am considering the purchase of a Mac with a T2 chip, for roughly these reasons. I've wanted to figure out TrouSerS / tpm-tools for years but at this point it's clear I won't get around to it.)

Re: Secure Boot in the Era of the T2

#85
post #80

Earlier quoted context omitted.

I can't argue with the notion that this adds an option for users, and increases the security of users who choose to use the functionality. I can't help but think that you're suffering from some kind of IT Stockholm Syndrome, however. Characterizing a secure boot option that only allows MacOS to be booted securely, (with no option to enroll your own keys) as "freedom" sounds to me like characterizing the 2002 Iraqi pr…

Without T2: You don't have the option of booting anything securely. With T2: You can boot macOS securely, but everything else is still insecure. If Apple had denied the option to disable secure boot, and didn't make any affordances to boot other OSes (albeit insecurely), we would indeed have lost freedom. The way they did it, we gained security within the macOS ecosystem without losing any freedom elsewhere.

Yes. Exactly. The T2 does nothing positive for software freedom.

Re: Secure Boot in the Era of the T2

#86
post #67

Earlier quoted context omitted.

I believe they are referring to the fact that linux (and non boot camp windows) cannot access the SSD on T2 equiped macbooks. People seem to disagree if it's the T2 itself or just a driver issue with apples proprietary controller.

According to https://www.omgubuntu.co.uk/2018/11/apple-t2-chip-cant-boot-... you just have to turn off the extra security.

Nobody ever said you can't disable secure boot and boot from an external drive. The point is that you can't access the expensive and essential internal storage where all your data lives. Here is an equivalent product a thunderbolt external nvme ssd 480GB for about $300.

https://www.amazon.com/Plugable-Thunderbolt-External-Compati...

If you don't mind spending hundreds of dollars, carrying around a second slightly awkward box wherein if you accidentally unplug it your computer crashes, and if you continue to use osx ferrying data between a and b periodically you too can run linux.

It would be utterly fantastic if people didn't keep responding to reports of the actual problem with articles like this which actually don't even touch on the item at hand.

Re: Secure Boot in the Era of the T2

#87
post #65

Earlier quoted context omitted.

Even if you turn secure boot off you cannot grant for love or any amount of money permission for software of your choosing to access the built in storage which is pretty much required for normal people to be able to run software of their choosing on the machine. Few people will buy equivalent external ssd storage for 300-500 and carry it around with them to have access to a second OS. There is absolutely no reason to…

What software of your choice have you attempted to use, where did it fail, and what's the stack trace? Given that Windows works, it's hard to believe that any issues accessing internal storage are a result of permissions. It just sounds like nobody's implemented Linux support for the hardware. Why don't you? If you're not able to either spend time writing a driver or hiring someone to do so, you have no meaningful ab…

Why don't I in my free time implement driver support for a machine I can't afford for a company with almost 300 billion in cash equivalents who has benefited massively from open source but wont even provide specification so that someone can do the free work for them effectively?

Why don't they send me a laptop along with the specs one of their engineers feels sufficient to implement support?

Re: Secure Boot in the Era of the T2

#88
post #80

Earlier quoted context omitted.

Without T2: You don't have the option of booting anything securely. With T2: You can boot macOS securely, but everything else is still insecure. If Apple had denied the option to disable secure boot, and didn't make any affordances to boot other OSes (albeit insecurely), we would indeed have lost freedom. The way they did it, we gained security within the macOS ecosystem without losing any freedom elsewhere.

Yes. Exactly. The T2 does nothing positive for software freedom.

Do you believe that nobody would ever freely choose to run macOS?

Re: Secure Boot in the Era of the T2

#89
post #78
post #64

Earlier quoted context omitted.

That's literally what I said. There's a checkbox for you to choose freedom inside System Preferences. You, as a device owner, can check that box. Someone with temporary access to your computer cannot. This is a step forward for most users and not a step backwards for any users . Sure, it would be better to let you enroll your own keys. But as it is you have more options than you have previously, and you as device own…

> This is a step forward for most users and not a step backwards for any users. Maybe. What happens when the check box goes away on a future version of MacOS? If my freedom depends entirely on an obscure checkbox rather than the ability to install my own keys, that seems like a thin reed to me.

Er, the option to install your own keys could go away too as easily, right?

Re: Secure Boot in the Era of the T2

#90
post #65

Earlier quoted context omitted.

What software of your choice have you attempted to use, where did it fail, and what's the stack trace? Given that Windows works, it's hard to believe that any issues accessing internal storage are a result of permissions. It just sounds like nobody's implemented Linux support for the hardware. Why don't you? If you're not able to either spend time writing a driver or hiring someone to do so, you have no meaningful ab…

Why don't I in my free time implement driver support for a machine I can't afford for a company with almost 300 billion in cash equivalents who has benefited massively from open source but wont even provide specification so that someone can do the free work for them effectively? Why don't they send me a laptop along with the specs one of their engineers feels sufficient to implement support?

"No one is going to give you the education you need to overthrow them." "The master's tools will never dismantle the master's house."

If you want freedom—real freedom—you'll have to work for it. You can't just wish for the powerful to let you borrow some of their freedom.

Post reply on HN