Apple's T2 Will Block Linux from Booting
phoronix.com
phoronix.com
I'm glad that Apple still has the "fine, but it's your funeral" option that lets users do what they want. Secure by default, open if you want/need it.
Apple chose to exclude that certificate.
Apple seems very aggressive about blocking 3rd party code from running on their hardware.
I think the goal of the T2 is to block Hackintosh and also to block hardware upgrades.
At some point Apple is going to lock this down. They have a history of doing so and giving them the benefit of the doubt is probably a bad call.
Although there's no way for us to really know, I don't really think that's their priority. Sounds more like a side-effect. Consumers capable of assembling, installing and updating a Hackintosh are probably less than 0.1% of the entire Apple user-base. They are peanuts, from a merely commercial point of view.
They also don't really need to prevent hardware upgrades with an enforcing chip. They are already preventing hardware upgrades by releasing hardware that physically cannot be upgraded. Just think about their laptops released in the last 5 years, with RAM blocks and SSDs soldered to the motherboard...
Apple lays out pretty well what the T2 chip does in their documentation.