Secure Boot in the Era of the T2
1–10 of 97 posts
Re: Secure Boot in the Era of the T2
#2Re: Secure Boot in the Era of the T2
#3I think this can't be stated enough. The fact of the matter is that pre T2, evil maid attacks were ridiculously easy. Now they're at least as secure as iOS -- which also means that shared vulnerabilities can be patched and detected. By no means is it perfect security, but it's a heck of a lot better than "stick boot disk in and gain keys to the kingdom."
For so long we've gone by the mantra that physical access means you have root. Now we're a step ahead of that -- which is great for data privacy.
Re: Secure Boot in the Era of the T2
#4Does this have any bearing on running linux on macbooks?
So it doesn't stop you in a way a game console might, but you lose some features of the hardware by doing so.
Re: Secure Boot in the Era of the T2
#5It doesn't seem like it's a gain in security. Instead of attacking the "main system", you can just attack the T2; it's similar in complexity, meaning it will have similar vulnerabilities.
Re: Secure Boot in the Era of the T2
#6> Apple should be lauded for trying to bring their laptop and desktop lines into the same defensive posture as their mobile offerings. I think this can't be stated enough. The fact of the matter is that pre T2, evil maid attacks were ridiculously easy. Now they're at least as secure as iOS -- which also means that shared vulnerabilities can be patched and detected. By no means is it perfect security, but it's a heck…
...and absolutely horrible for freedom. It used to be the case, and still widely accepted for a lot of other products, that physical ownership actually meant something beyond just being a consumer. Now companies are turning the security against users, lest they also be attackers. From the point of view of the DRM-advocating media corporations, the user is an attacker. Locking down the platform to allow only "trusted" (not by you, but by them!) code only benefits when their goals align with yours; you may agree with them on not wanting things like ransomware, but not on things like them not allowing you to share a file between two apps or even run code you wrote yourself.
It's scarier than any security attack to see what used to be an open and free platform turned into a walled garden of corporate control and obedience.
(Insert famous Benjamin Franklin quote.)
Re: Secure Boot in the Era of the T2
#7> Apple should be lauded for trying to bring their laptop and desktop lines into the same defensive posture as their mobile offerings. I think this can't be stated enough. The fact of the matter is that pre T2, evil maid attacks were ridiculously easy. Now they're at least as secure as iOS -- which also means that shared vulnerabilities can be patched and detected. By no means is it perfect security, but it's a heck…
This hasn't been the case for a long time. Chromebooks shipped with "verified boot" since the first consumer hardware in 2011. Windows machines have been shipping with UEFI secure boot, which Apple uses the T2 chip to implement, for the past 6 years.
Re: Secure Boot in the Era of the T2
#8Does this have any bearing on running linux on macbooks?
AFAIK, there's no way to inject new keys, so you have a exclusive choice between running Linux and having secure boot enabled. So it doesn't stop you in a way a game console might, but you lose some features of the hardware by doing so.
https://unix.stackexchange.com/questions/463422/how-can-you-...
Re: Secure Boot in the Era of the T2
#9The T2 does so much, essentially running an OS comparable to iOS. The author even suggests it might allow apps. It doesn't seem like it's a gain in security. Instead of attacking the "main system", you can just attack the T2; it's similar in complexity, meaning it will have similar vulnerabilities.
Re: Secure Boot in the Era of the T2
#10> Apple should be lauded for trying to bring their laptop and desktop lines into the same defensive posture as their mobile offerings. I think this can't be stated enough. The fact of the matter is that pre T2, evil maid attacks were ridiculously easy. Now they're at least as secure as iOS -- which also means that shared vulnerabilities can be patched and detected. By no means is it perfect security, but it's a heck…
which is great for data privacy. ...and absolutely horrible for freedom. It used to be the case, and still widely accepted for a lot of other products, that physical ownership actually meant something beyond just being a consumer. Now companies are turning the security against users, lest they also be attackers. From the point of view of the DRM-advocating media corporations, the user is an attacker. Locking down the…