If so, maybe a DFU restore is needed.
If so, maybe a DFU restore is needed.
Took a day, but all's well now.
Glad it helped.
No: There’s no opportunity to use FileVault recovery keys when you’re doing a DFU on a T2 Mac. If you have to DFU, your data is lost.
(edited to clarify per reply)
It’s not failure, it’s secure by design to prevent attackers/governments from stealing your files without consent.
Under DFU brick and reset circumstances, the private key is gone, because otherwise an attacker could just upload a hacked firmware via DFU and access all your files.
I assume the installer uses a different process that performs a DFU upgrade-in-place that safely manages the handoff using signed code and such, but that’s not the process we get as a last restore described above.
If you don’t have off-device backups, you’re accepting the risk of losing all your data at any time due to any number of possible failures (software and hardware). Not much use getting upset about this specific case.
I wouldn't be surprised if Apple ships Configurator iOS someday, but today is not that day.
Still sucks, just a bit less. not really different than an iPhone, except that you can rebuild those on Windows (for now).
The checkra1n team recently showed that all Macs with a T2 chip are vulnerable to checkm8 exploit used to jailbreak iPhones, and this could persist for a while due to the T2 chip staying on between application processor reboots.
This allows override of mic disconnect (except on the newest models which switched to hardware disconnect), Secure Boot/Firmware Password, and allows you to bypass Apple's signing of Intel ME firmware, TB3 firmware, and CPU microcode. Whether or not there is still Intel signing after that is unknown, but there are already some sort of issues with the host key being leaked on that. The one useful feature I can think of is allowing SSD replacement (you still have to find a way to resolder ofc) and Touch Bar customization.
I think the most likely attack vector for this is an evil maid style attack where corrupted T2 firmware is loaded that rewrites the contents of the SSD while macOS is running to launch further exploit code on that platform.
The one thing not to worry about is if you have FileVault turned on with a password, that still can't be cracked because your password is not stored anywhere on the device. But the BitLocker-style automatic encryption with no password that just locks the SSD to that specific T2 chip isn't useful anymore.