Apple’s T2 security chip jailbreak
reportcybercrime.com
reportcybercrime.com
The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on.
Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3].
Some key takeaways from the T2 being jailbroken:
- Custom Bootloaders (OpenCore, Coreboot, etc) are now possible as the T2 validates/sends the UEFI payload to PCH using a bridgeOS binary called MacEFIUtil, which can trivially have its signature checks patched.
- Filevault and by extension Touch ID are more or less crippled, especially in light of the recent SEP exploits. Amusingly, Apple uses a hardcoded "passcode", analogous to an iDevice's unlock pin in plain text within the UEFI firmware.
- Support for In-System Debugging of the PCH/Intel processor over USB. This works in a similar fashion to those Bonobo cable used for debugging iDevices [4]. We are working on building an accessory that you can purchase and plug into your Mac with a USB male endpoint exposing Intel's DCI debugging protocol.
- Lightweight AppleSilicon Tinkering environment. With SSH support from macOS on device, and the T2's modest specs, its a nice sandbox for messing with arm64 stuff. It's a pretty peppy chip, at times coming close to my 8th gen i7...yikes.
1. https://www.theiphonewiki.com/wiki/T8012_checkm8
2. https://twitter.com/qwertyoruiopz/status/1237904335184564224
3. https://twitter.com/su_rickmark/status/1286886010681462784
Do you have any thoughts about what Apple's switch to own-brand ARM chips in laptops and desktops will mean for T2/T3/etc?
This is because I honestly cannot find a laptop with the combination of 64+ GB RAM, a non-NDIVIA GPU (edit: to clarify, this is because of NVIDIA's notoriously bad compatibility with Linux), and other premium hardware aspects like its market-leading trackpad at this time - and I doubt that will change anytime soon.
I live with the debilitating T2 kernel panic hardware bug every week. There's also a very bad graphics bug that I and many others are facing. (Not sure if that one can be avoided by simply using Linux.)
I just want to do away with this T2 chip, and whatever it does to get in the way of an otherwise great Intel-based computing experience. The CPU can handle all my encryption just fine...
Thank you to your team for what you're doing. I assume Apple will constantly patch T2 jailbreaks with future macOS system updates (as that's how firmware is updated), and play a long-term cat and mouse game.
Only 14”, and perhaps less performant, but here is this one: https://puri.sm/products/librem-14/.
You can also buy any newer Thinkpad (my recommendation). They are also available with AMD CPUs.
It's pretty easy to buy Linux laptops these days.
It's only MBP NVIDIA GPU in Linux (older model) that I have extensive experience on so far, and it's been terrible with nouveau.
I'd rather just have/use Intel GPU over them as well, I am not a laptop gamer to need anything NVIDIA offers in exchange for the pain in maintenance using out of tree modules to me.
Depending on which distro you use NVIDIA grapics can be quite painless. Using Pop!_OS, I just had to download the correct iso from their downloads page.
I believe most other distros have NVIDIA's drivers in their non FL/OSS repos as well.
Optimus graphics will even work with the most current drivers.
I can switch to built in Intel video for better battery but it requires a reboot. I see this as a stopgap. My home machine has an amd video.
I only need the NVIDIA graphics every so often on my laptop though, so it's fine for me.
On desktop I've had no issues.
In my experience they're largely OK. There are some rough edges - you'll struggle to get Steam and CUDA working at the same time, for example - but no showstopping problems.
I certainly don't have a debilitating kernel panic every week :)
All this is on top of the fact that they still don't support Wayland and you have to reboot to switch between the igpu and the nvidia gpu.
Last time I looked, it was perfectly possible to install them directly, without support by the distro. Yes, it's more work.
> Nvidia gpus require proprietary drivers
There's an open source driver, nouveau, but of course it's behind the newest hardware.
Yes, you can install them and they will break with every single update and you need to re-install them. And you will encounter bugs that no-one has any idea why they are there and no-one will help you with.
>There's an open source driver, nouveau, but of course it's behind the newest hardware.
It's not just behind, it's actively sabotaged by nvidia by locking basic hardware functions behind closed firmware that it encrypted.
Yes but to GP’s stated requirements, the trackpad feels like trying to push a marble around in peanut butter.
One of these years we'll get a comparable AMD laptop. Fingers crossed.
[0] https://www.lenovo.com/us/en/laptops/thinkpad/thinkpad-t-ser...
Sorry, what does this sentence mean? That someone with physical access to my machine can now unencrypt my FileVault encrypted hard drive?
... then phase out your use, because proprietary systems will always get cracked given enough time.
This kind of advocacy is not only unhelpful but actually counterproductive
Probably not the best choice :) you never want to use proprietary software if security is a concern
LUKS and GEIL are full-disk encryption systems, and if you need FDE, you must use them under ZFS, not ZFS native encryption.
GELI ;)
ZFS native encryption on Root is ~IS full disk encryption minus the boot-loader, i would say that's "full" interesting data encryption.
As long as the incentives of the developer of the security scheme and the end-user are aligned (so no backdoors), I would trust a widespread, proprietary solution which appears to stand up to significant attacks (the solution being widespread means there are lots of efforts underway to crack it) more than an open-source implementation that nobody uses.
Counting published vulnerabilities in open source systems vs closed source systems says nothing about the relative true ratio of vulnerabilities.
Does it? In order to claim that, one would have to have some idea of (a) the ratio of disclosed vulnerabilities to true vulnerabilities discovered in both open source, accessible code vs closed source, hardware locked code, and (b) the relative ratios of disclosed vulnerabilities.
Do you have any idea what either ratio might be? 1:1? 4:1? 1:4? 100:1?
I'm not GP and I'm not arguing for either side, just pointing i tout.
If you read the thread, note that I’m not taking a side other than finding it absurd to claim that all open source products are inherently better than all proprietary products with no analysis or data.
Open source full disk encryption can be password cracked without limitations just like a hacked T2 chip. A sleeping open source full disk encryption machine can be accessed with enough skill to pull things out of frozen ram, etc.
If you use a strong password to encrypt your drive you should still be safe, unless Apple did something really stupid. The password is used as a one-way hash to generate the key.
However if you can login with Touch ID and they find a way to use known SE exploits, it's compromised. Your fingerprint isn't a secret that gets hashed – instead it's verified by the SE which also holds the secret key for the drive.
> It's a pretty peppy chip, at times coming close to my 8th gen i7...yikes.
Have you got any benchmarks? It is passively cooled right? I am really surprised to hear a ~2016 arm64 CPU can can beat a 2019 Intel i7 in even synthetic benchmarks.
Add a real world workload to the mix with heavy memory access and mixed compute workloads and the chips will diverge significantly in performance.
I work with some cross-platform code that has to run on mobile devices and desktop platforms. The advances Apple has made in low power performance are incredible, but the idea that their iPhone chips are as fast as desktop computers is still far from the truth unless you’re measuring specific, heavily optimized workloads.
I’m still excited to see what Apple can do with a full desktop level power budget though.
https://cpu.userbenchmark.com/Compare/Intel-Core-i7-8700-vs-...
Kind of hard to have diversity/options if everyone keeps insisting all vendors do everything the same way.
The downvote button on Hacker News doesn't work like a dislike button by the way
Customers have a legal right to do basically anything they want with something that they own.
Benign neglect (not creating limitations) is not the same as active interference (actively preventing) and Apple is much more on the side of active interference. They could simply do nothing (which is cheaper). They choose not to, at which point we get to question their motives.
In the end your question reduces to "why do you want anything at all that someone doesn't already make?" and that doesn't make alot of sense given that new products come out on the market all the time.
I don't like the walled garden but i still brought a iPhone because iPhones get updates for really long time(3 years minimum). Iphone SE(1st gen) released in 2016 got the iOS14 update.
Yes it could be used that way. But they have never even indicated that they've been thinking of using the secure enclave for that purpose.
The T2 also has a particularly wonky approach to disk encryption. It uses a key management approach where neither you nor Apple control the actual key material. This means that a dead T2 takes your data with it and there is no recovery. In pre-T2 MacBooks, Apple had a lifeboat connector which could be used for data recovery from the soldered-on SSD. They got rid of this with the T2, because there's no point - only that specific T2 in that specific motherboard is ever able to decrypt the data.
Please. As for matching parts to the motherboard, they have a point when it comes to I/O devices. It’s probably way more cloak and dagger than most people will ever have to worry about but it’s not unheard of. Again, if you don’t want to think about such things and want a device that trades ease of repair for improved base security why isn’t that something that shouldn’t be a choice?
I’m generally pretty pro right to repair, but as with anything there are pro’s and con’s to all choices and I’m not fond of several of the right to repair arguments for government regulation being made. Apple is far from the only maker of computers out there. It is the only maker of macOS, but that still doesn’t justify people trying to dictate their business model - especially when many aspects of their business models are major reasons why I prefer their platforms.
Until then, clouds operate on a best-effort basis, some of which rely on hacks or break common use-cases (I can't put a Git repo in iCloud for example, and it doesn't perform well with lots of small files, and accessing the iCloud folder from the terminal apparently has problems). Why is iCloud still not a supported target for Time Machine, Apple's official backup solution for macOS?
Furthermore, most people do not make this calculation in their head of "Okay, anything I put behind the T2 is Apple's property now so I'd better have unencrypted backups". They just buy the computer that works and says that it keeps thieves and snoops out of their data. Everything we're talking about with backups comes as a post-purchase surprise, usually AFTER the data is already lost.
This is referencing the Touch Bar repair which means that the user has encrypted their drive with Touch ID. The only reason any repair would be harder is because the Touch ID sensor is paired to the secure enclave. The same goes for the SSD. Without the key, as you stated, you shouldn't be able to access the data so I don't see how that's any different than "having a data recovery mechanism". A data recovery mechanism shouldn't exist if you don't have the proper keys.
Then they got in a legal fracas with Epic and immediately retaliated against Epic by banning all their software from all Apple hardware!
Apple has shown they are very eager to use their position of power to strong-arm the competition, and these kinds of chips only add to their power.
I think you don't understand how this works. The agreement itself is the subject of the lawsuit and thus MUST be violated in order to show harm. Epic did it on purpose in order to sue Apple and whether you agree with that or not, it is the only mechanism the law allows to make the agreement itself the subject of the suit. And Epic does have a right to sue Apple for whatever reason they choose.
Not to the consumer.
Apple promised to the users (not Epic) they would only use notarization to block harmful software. Epic's software is not harmful to the user, and the lawsuit didn't change anything about that.
The T2 chip can prevent people from putting their OS of choice on their hardware once Apple deprecates support for their machine.
This is substantially inaccurate. Current versions of macOS run on nearly all Apple systems from 2012 (8 years old), with the exception of some 2012 Mac Pros. The limiting factor in most cases is GPUs -- macOS 10.14 and later require some GPU capabilities which weren't reliably available in 2012.
Catalina, released in October 2019, dropped support for MacBooks released before 2015, MacBook Air models from before mid-2012, MacBook Pro models from before mid-2012, Mac Minis from before late 2012, and Mac Pros from before late 2013[1]. Do the math and that is 5 to 7 years between initial release of the hardware and deprecation by macOS.
[1] https://www.macworld.co.uk/feature/mac-software/what-version...
Those machines were all sold in 2011 or earlier. Saying "before 2015" is misleading, because the MacBook name was used during two disjoint periods to refer to two completely different machines.
Between 2006 and mid-2011, the MacBook brand name was used for a line of low-cost Core 2 laptops, most of which had plastic cases. (Some sales to schools continued through 2012.) These are the laptops which were not supported by macOS 10.14 and later.
Between mid-2011 and 2015, there were no computers sold under the MacBook brand. Apple only sold laptops under the MacBook Air and MacBook Pro brands during this period.
In 2015, Apple reused the MacBook brand name for a line of 12" ultraportable laptops. These are supported under current releases of macOS.
No, models release before 2015 were deprecated. Same thing with the models of other lines that only had 7 years before being deprecated by macOS.
In the arguments about opening up the iPhone and forcing Apple to allow third party app stores and allow side loading I'm on Apple's side. I think Apple should decide what products they design, how they design them and what features they should have. If I like the feature set, I'll buy the. I do not think it's reasonable for other people to dictate to Apple what code they should write and how it should work, health and safety or deceptive marketing aside. The ability to side load apps would be a software feature that needs to be designed, coded, QA tested, secured etc. Who gets to make all those decisions? I don't think it makes sense to force Apple into doing these things if it doesn't want to do them. You don't like the inability to side load? Buy another phone.
On the other hand once I own a device, it's mine. If I have the ability to jailbreak it, or hack it, or do whatever to it that's my business, not Apple's.
Apple of course has an internal version of iOS that lets you do this.
My money is on the second option but AFAIK there's no study like this.
Forgive my ignorance, why is there not much they can do and what have they tried?
This is interesting; does this mean Apple isn't enabling Intel Boot Guard, relying only on the checks enforced by MacEFIUtil?
Fantastic work, by the way.
https://support.apple.com/guide/security/uefi-firmware-overv...
Part of me wonders if there could be a way to permanently disable DFU mode (preferably outside of epoxy in the upper left USB-C port). That would prevent someone from jailbreaking the T2, albeit you would no longer be able to replace the SSD or Touch ID sensor (not that you’d want to anyway if you were at risk).
Granted, owners of the affected hardware might not like it, but this sheds light on issues that are actually present in the hardware. Who's to say that "law authority" or some criminal organization didn't do any work on this without intention to publish their results?
If people have sensitive data and were counting the T2 chip to keep it secure, now they know there are limitations to this security model. They can now weigh the pros and cons and, if applicable, set up an alternative that will be more secure. This could also push Apple to provide better security in upcoming products.
Everything he exposes will be fixed and improved. If anything he's helping make Apple devices more secure.
Showing security problems is the opposite of making Technology less secure. Maybe ask Apple why they think it's a good idea to have closed source special chip at all.
Furthermore, the entire point of a jailbreak is to regain root access to your own device - Apple provides no way for a user to do so, which I find at least somewhat irksome. The way it currently stands, all iOS devices ship with Apple having total control over the device, and a jailbreak lets you claw back control by force if you so choose.
So there is a team working on this? What is the incentive model? Are you paid to do this work? What is the revenue model?
I woke up today learning my MacBook Pro is now substantially less secure but why? So I can run games on the touch bar? So I can use the T2 as a raspberry pi?
The bootROM flaw allows for an exploit that can only be executed with physical access, another Mac and DFU mode. It's not persistent.
The main use of this exploit was to install unsigned code on iOS devices (jailbreaking.) The team is doing it for free, however many contributors take advantage of Apple's bug bounty program for income, therefore making newer devices more secure.
On the other hand, this could have serious implications on the iOS security model for example.
And I'm pretty sure someone is gonna run Doom on the touchbar in some months.
It's not scalable, but works pretty good when a group of friends purchases them.
Cost of MBP in the US: $2,799 (€2,390)
Cost of MBP in NL: €3,199 ($3,746)
Cost of plane ticket from NL to US: (pre-covid) ~€600
Good thing Apple laptops don't come with manuals. There isn't much much more than a couple stickers and a microfiber cloth in the box.
And are there any first-world countries (except maybe the US^^) where a 13" Macbook is several times the average net monthly income? In Germany, for instance, the monthly average net wage (MANW) is €2500, while the price of a 13" Macbook starts at €1300. Italy: MANW is €1700, Spain: €1800, France: €2400, UK: €2200. Go to the Nordic countries, Switzerland, Ireland, Austria etc. and we're talking MANW of €3000+. Canada has MANW of around US$3400.
^^ If the US is the only first-world country matching your statement, one could argue this is further evidence that the US is no longer a first-world country.
Thinkpads on the other hand are like Toyota's
I don't mind though; I'm actually happy when it happens because I get a new battery and top case for free.
https://hackaday.com/2018/03/12/new-guts-make-old-thinkpads-...
I have 10 and 15 year old iBooks and MacBooks and MacBook Pros with intact keyboards...
You mixed the issue with the butterfly BS keyboards in the past 2-3 years with the old Apple keyboards (which didn't just "break down"). The resale value of old Mac laptops I think speaks for itself related to that.
That said, Thinkpads are indeed built like Toyotas and have easy replacements.
Sadly 4 years now, they started in 2016. It's the main issue blocking me from buying another MBP - this keyboard broke when it was already out of warranty, I really don't want to risk it again.
Does not happen with proper keyboards. Esp. thinkpads.
Why Apple had to mess with that perfect formula, I will never understand. I blame Ive.
Since you could have derived this data from the same source as all the other numbers in your post, I'm not sure what the point of your little dig was.
Maybe in Switzerland , but in Austria the MANW is definitely not 3000+ Euros a month. As a developer I don't earn nowhere near close that NET every month and salaries here are lower overall than in Germany.
3k/month NET here means almost 70K/year pre-tax for a single person with no children.
Or everyone else makes 3000+ and I'm underpaid, who knows. :D Sucks that people in this country don't usually discuss salaries because reasons.
nobody discussed salaries in germany/UK either though. wasn't just a problem in vienna for me ;)
how are the salaries in vienna these days for software devs?
Whether the overall salary/CoL ratio is a better deal for you here than in the other hubs really depends on how good your salary is and how much you'll spend.
That would be a fair excuse if the mechanism was under the control of the machine's rightful owner.
But they can’t.
Because it’s not about giving you control, but about controlling you.
I'll be interested in trusted hardware when I see an implementation that actually puts the device owner into the privileged position, rather than reserving it for the device manufacturer.
Subverting these mechanisms provides a way to prevent the system from making this assertion.
Likewise, the alleged "anti-repair" mechanism for TouchID sensors and TouchBar relate directly to protecting the system's ability to distinguish between the "rightful owner" and a thief.
"Do what I want with the machine I own" is functionally indistinguishable from "increase the resale value of the machine I stole".
I actually dont mind they block unauthorised repair, at least I believe in the Steve Jobs's Apple era he wanted the best customer experience. And they want the Data of what is failing in their Mac where their Genius Bar gain first hand experience and knowledge which leads to feedback to the Design team. ( They dont publicly announce or admit it, but the database has those problem listed. )
The goal was to aim for perfection, a machine that is so reliable it wouldn't need to repair in the first place. And if and when they fail, Genius Bar is there to help. You used to get some nice gesture from Apple Retail. Now they are simply trying gouge customers into buying a new MacBook, hopefully with AppleCare+, or replacement for the logic board. Every single problem they will just quote you to replace the logic board price. Not only are they expensive, the actual work or replacement isn't even up to Apple's standard.
I will need time to dig up some data. But MacBook Pro 2016+'s resale price has dropped quite significantly compared to MBP 2015 in the same age. And MBP 2015 second hand market is actually going strong.
You will have to excuse me, but that is a load of bullcrap.
Let's take the case that irritates me the most: The SSD.
By definition of the technology that is NAND storage, an SSD will be able to operate "within norm" and without bit errors for so long. Rewrite for long enough and you'll see your data waving you good-bye.
As for your other claims about recording errors and whatnot, you can EASILY achieve those (matter of fact it's already implemented in UEFI by some manufacturers), and NOT disallow people from repairing their computer.
Sure the lifespan of an SSD is ideally 5/7 years. But that is a death sentence, not a search for perfection.
Also, what happens if Apple simply refuses to fix your computer, or supply your with parts ! And yes this has happened rather publicly (Linus Sebastian's Mac Pro)
So again, apologies for the language but that is a load of bullcrap
You see, I dont disagree. Apple was striving for an ideal that is not achievable. What they are aiming, trying and actually doing are three different thing.
They are aiming for planned obsolescence. The biggest competitor for new MacBooks are old MacBooks.
Maybe true 5-10 years ago, but not true now.
Hardware: Other vendors have trackpads with multi-touch (which for me was one of the most amazing things about the first Macbook I ever owned), super high-res screens, and other such features these days. The form factors are thin and stylish as well (there are other aluminum unibody laptops these days).
Software: MacOS has gotten worse, Linux distros have continued to catch up, both in the look and behavior of the OS itself but also in terms of the app ecosystem, esp with companies like Valve spending the big bucks to get lots of games running well on Linux. Speaking of games, MacOS continues to suck when it comes to gaming anyway – so for example I do a bit of gaming on my new MBP 16" and the mild chore of dual-booting continues to irk me. I also splashed out for the 8GB GPU upgrade and performance is still not great. Not quite enough for me to make the switch but I'm not a very hardcore gamer. I know people that need a workhorse a bit more than I do (professional video editors and such) who have recently (last 5 years) made the switch from macbooks to things like razers because they want to be able to really push through serious workloads on the go.
That's where they make their money. People that just want good specs at cheap prices are not their target market.
No, by "old Macbooks" I mean "including current and last year models". Not that only past macbooks had large resale value...
>Planned obsolescence is needed to ensure that people upgrade.
In the Apple world, upgrading is part of the idea and appeal -- you're not supposed to be running a 10 year old laptop or 2-3 versions old OS. The OS is not about backwards compatibility, it's about moving forward faster...
That's part of the appeal of the thing, and part of the reason for the extra control.
I don't want legacy 10/20 year old apps and frameworks to be supported, I don't want apps that don't take advantage of the latest frameworks, hardware and OS features, and so on...
If "compatible with 30 year old programs" is a desirable feature, there's always Windows.
doesn't mesh with -
>you're not supposed to be running a 10 year old laptop or 2-3 versions old OS
Planned obsolescence just means artificially shortening the upgrade cycle. That's it. And Apple has been doing this in the Mac world through different methods.
No, it doesn't not. Planned obsolescence, just the like the actual words in the term are defined, means planning for the fact that technology and the components it's made from has a finite lifespan and that, at some point, users of that technology will have to upgrade. You're inferring that companies are intentionally sabotaging their products to compel and force people to upgrade and that might be the stupidest take I've ever heard.
>In economics and industrial design, planned obsolescence (also called built-in obsolescence or premature obsolescence) is a policy of planning or designing a product with an artificially limited useful life, so that it becomes obsolete (i.e., unfashionable, or no longer functional) after a certain period of time.[1] The rationale behind this strategy is to generate long-term sales volume by reducing the time between repeat purchases (referred to as "shortening the replacement cycle").[2] It is the deliberate shortening of a lifespan of a product to force consumers to purchase replacements.[3]
Apple does this with their hardware by limiting the software support period and economical hardware repair. Having something like the T2 ensures that third parties are not able to extend the life of their systems in a reasonable manner.
The T2 is a security chip. It ensures the integrity of the system. If that integrity is compromised, the chip shouldn't allow third parties to replace components unless those components can be replaced and the integrity restored. You're acting like the T2 was added just to make repairs harder instead of to make the device more secure which, by design, makes repairs more difficult.
It's the same reason that car manufacturers don't let repair shops generate new key fobs unless they're registered with the manufacturer.
Sure it's a security chip but why is it they didn't make it so the owner can do a one-way unlock (like Android's bootloader unlock) so people can fix their own Macs?
Because preventing repairs is one of the desirable side effect of this design.
Apple has no need to prevent people from repairing their devices. They lose money on most repairs they do. What they're concerned about is their brand. If someone gets their device repaired at a shitty shop that isn't Apple certified and uses parts that aren't real Apple parts (like every screen repair kiosk in your local mall), people don't see future screen issues as issues with that repair or screen. They see a problem with an iPhone. That's what the desirable side-effect is. Apple doesn't want to prevent repairs, they want to prevent shitty repairs and security breaches.
Evidence doesn't support this at all. When was the last root exploit due to an bootloader unlock?
Towing the Apple line gets you nowhere. There is overwhelming support for companies to allow for a right of repair. Most people don't have any issues with security advances, but they do have a problem with companies using this as an excuse to further lock-in to devices that are fully paid for by consumers.
The guarantee of a popular modern 1Tb NVME SSD is you'll at least be able to write 600Tb. I don't know your usage pattern, but those are a lot of write actions.
Remember every component in any electronic device has a finite age: the fan cooling the cpu, keyboards have max. presses, hinges wear out, sockets have a maximum amount of plug/unplug actions.
There's an advantage to soldering on memory, SSD etc: no chance of a bad connector causing problems. The entire class of problems fixed by 'reseating your DIMMS' is gone.
And I am perfectly happy to assert this as a political preference, and vote in office people that vow to protect consumers from this kind of racketeering. I understand this might not be your cup of tea, and that some people prefer unfettered capitalism, its your political right. However I fell that allowing this in our society limits my freedom and choices, because the things you buy affect me too.
This pretty much kills the whole "intended" security line, the intent is user control.
But on the surface it does seem like that could work.
Only if the "20 character secret code" had the same security characteristics, which it doesn't.
The "none of the users want it" is circular reasoning. If unlock was possible on a mass scale, developers would build for the unfettered iDevices and a market would emerge separate from the one Apple controls. Then users would want it, since it provides value for them - cheaper apps, legal apps that are banned in the Store etc. Of course Apple will fight to the death to prevent such a thing.
There is less money overall put into these products, and correspondingly less software, but that’s not because of anti-competitive practices. It’s because the reality is less people care about this stuff. I don’t think “people are obligated to put effort into the products I want” is a particularly noble political position, since you seem to be insistent on framing it that way. The position you’re talking about in the carrier case is different, it’s “people are obligated not to conspire together to do things that none of their users want and give them no options to vote with their feet”.
The truth is that there is a threshold, a level of user complaints that turns a legitimate practice into an anti-competitive one. People disagree on where this threshold lies - is it at 0, is it at 1000, is it at millions? Until recently, most of Apple's shenanigans have kept the complaints under thresholds small enough to be socially acceptable, that's all. If more people complain, that threshold could be reached.
That’s an interesting metric for anti-competitive practice. Isn’t a large number of user complaints basically the core mechanism that drives market competition? Once you have enough users complaining about an aspect of a product (or otherwise being underserved), why would they not go to a competitor if one is allowed to exist (as they are in this situation)?
Which takes me to the second point: the market alone often does not self-correct. This is why we have antitrust laws and authorities to enforce them. People lack the education to be able to reason about “voting with their wallet” in an effective way; and even when they do, they often don’t have the resources to follow through. This is why contract bundles are so popular, despite the fact that they make handset more expensive overall: people can’t do math, and when they do they still often lack the cash reserves to buy a handset in one go rather than paying small instalments for a long time. If a market fails, it’s legitimate for the law to step in; and one indication of failure is the level of discontent from consumers.
How can this prevent any mentally sane person from trusting Apple made the correct decisions and not root their device?
You call it a prison. I call it a fortress.
"Actively works against you" is your reading. I very much appreciate what the T2 does, and hope the next update will be even more difficult to hack (aside from its other functionality).
I think you’re going to have to try harder to convince anyone that this situation is analogous to second hand smoke. You probably want to come up with better arguments for your “political” movement.
The metric you use of avoiding "restricting freedom" is a strongly ideological stance in itself and is not a natural goal political systems strive for. You might value some flavors of individual autonomy and imply they have an universal vocation by calling them "freedom". I might favor other sets, such as the restriction of corporate power and consumer empowerment, and call those, in turn "freedom", see for example the GPL ethos. Both sets of political views are legitimate and can be pursued in a democracy.
I’m not trying to judge your statements by my goalposts as you seem to be implying, I’m trying to understand the internal logic of what you’ve been saying which AFAICT isn’t lining up.
Right now, as a consumer (which, like you, is my only realistic lever on this situation), I’m pretty happy that I own some Apple devices and some very not-Apple devices. I’d be pretty pissed if I was forced to choose only one of these (in either direction). I think you’d find the same reaction if you became president of the world and threw everyone’s Apple devices in the trash and handed them a Librem 5 or something similar. Do you contest that this would be their reaction? If so, what is your definition of market forces and anti-competitive behavior?
The consumers can buy any system with any chip they want. If it is employed by Apple to enhance security that's great, for example the Mac. If it's used to lockdown the device so that no competing software can be run, a la iPhone, for them to maintain the stranglehold on the app market, then I am against it on political grounds and my position is not falsifiable.
You are inworking an oligopoly situation and accuse me of wanting to turn it into a monopoly, but I want the exact opposite: all existing platforms to still exist, and additionally, all those prevented by anti-competitive behavior, which by my non-falsifiable definition includes any lockdown on the hardware that is sold in the marketplace, that can only be, and is only used to limit the options of the owner.
It is not like Apple devices would cease to be produced or be confiscated if we pass laws mandating software freedom on purchased hardware, from iPhones to tractors.
- on the one hand (I believe) developers would prefer owning more open devices (like Librem/Purism, Pine64 etc.)
- on the other hand they want to develop for the masses, which means they will need access to Apple hardware.
I don’t care that I can’t easily change the SSD. If that were important to me, I would buy a different laptop.
I don’t consider my MacBook Pro to be working against me, at all.
If it works like iOS and just flashes a warning then I don’t see the issue. The self-check thing is invaluable when buying used devices.
> that your data is already gone.
By the way, the parent comment was talking about this
I don't mind getting a new MacBook, but I do mind if it gets compromised. This way I know it would be a screen replacement at best.
But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to crack. That's a shame, because it's a very neat and cohesive security platform that gets out of one's way and works really well even for highly non-technical people. Their security stance is one of the things that keep me in Apple's ecosystem and I know a number of people and companies who feel alike. So, coming from that point of view, I do hope they fix this in time for their first round of ARM Macs.
Right now, that security is provided by Apple crypto-locking the Touch ID sensor to the T2 chip so that it cannot be modified to allow unauthorized access without being disabled altogether.
With the ability to bypass the restrictions of the T2 OS, that protection is stripped away, and replaced by .. nothing, as far as I can determine.
This is akin to removing your car’s electronic anti-theft system because it requires OEM keys. Sure, you can do so, but your car is a lot easier to steal, too. Only it’s not your car here, it’s your computer and all personal data on it, and all SSH keys you use to access remote servers, too.
I’m all for repairability but it’s worrying that the tech community is so invested in removing a padlock that offends them that they set aside security and risk issues in favor of rooting without addressing it at all. If this complete lack of interest in device security is the best we can do, we don’t deserve repairability, and we don’t deserve root.
If apple is a viable root of trust then you yourself should be too. There's nothing magical that only apple can do.
How would this benefit third-party repair shops, though?
In light of that, how do you allow for components to be swapped out wholesale without breaking the security model?
Isn't the entire point that you can't just steal a Macbook, swap out the SSD, and now you have a functioning (stolen) laptop?
Seems like a great idea!
And I think that's actually incredibly underappreciated feature, most people are both bad at memorizing long, complex passwords/passphrases and not all that motivated since the threat is quite abstract. I've had a hard time convincing some people to have any sort of password at all on their laptop (that they travel with, work in all sorts of places and are overall pretty careless with), as it carries the risk of forgetting the password and it's cumbersome and inconvenient compared to being able to simply open the computer to a logged-in desktop.
Making security less of a hassle really does help with adoption. Having a short, relatively weak, but not trivial password is way way better than having none at all, and realistically that's all most people are ever going to have, so making those passwords hold up better is a really smart move that instantly ups the security of lots and lots of people out there.
But that's not something I believe you could do without a scheme like tieing the encrypted data to a complex secret inside a specific T2 that is uncracked, otherwise you could simply put the SSD in another computer and brute-force it there.
Theft will happen anyway. You can even sell permanently-locked/bricked devices to people which doesn't look to closely at the sellers description. Sure you will need to sell them for cheap, but that's all.
That idea is like saying all cars must be always tracked, always link up with the drivers phone and be remote-controllable by there manufacturer to prevent theft.
Sure it would prevent theft, maybe, until people find ways to brake it. But it's still totally unreasonable with a lot of hidden cost to it.
E.g. in case of apple laptops the cost is losing a lot of small independent companies as well as any way to properly repair an Apple laptop. (Apple doe NOT provide proper repairs they at best replace whole components often the whole main board because it's one component when many damages tend to be similar because people use their devices similar and often are reasonable fixable with a bit of not-easy-but-not-very-hard-either soldering).
EDIT: And most important! The theft constraint can be archived to a reasonable degree WITHOUT locking out third party repair. A example (through not applicable to mac in this case) is how I setup my laptop with a custom EFI platform key/certificate and a BIOS password so to reuse it after theft people have to replace the BIOS chip soldered onto the motherboard (it has no publicly known master key or reset pin). Apple can archive similar things so that theft is more costy but third party repairs are still mostly unconstrained.
Typically, it's criminally illegal to circumvent DRM in the US (and 99% of the rest of the world). However, there are also certain exemptions that have been granted, within the US only (other countries are not so lucky). The right to repair is one such exemption[1].
If Apple had separated security from first-party repair enforcement, then anyone found even attempting to break the T2 chip might have been up for jail time. However, the right to repair is a valid defense.
Of course, making circumvention criminally illegal doesn't make the chip itself any more technically secure; say against criminals. It is a pretty solid deterrent though.
That said, from the EU directive:
> Member States shall take appropriate measures to ensure that rightholders make available to the beneficiary of an exception or limitation provided for in national law in accordance with Article 5(2)(a), (2)(c), (2)(d), (2)(e), (3)(a), (3)(b) or (3)(e) the means of benefiting from that exception or limitation, to the extent necessary to benefit from that exception or limitation and where that beneficiary has legal access to the protected work or subject-matter concerned.
There are certain exceptions, in articles 1, 2, 3 and 4, which can be read at https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL.... So there's not a blanket right to circumvent DRM; and nothing is spelt out that clearly.
Additionally, not a lawyer or in Government, however, in my lay-mans reading of this directive, I'm seeing a lot of usages of the word "may". I'm (possibly incorrectly) interpreting this as meaning a Member State can introduce these copyright exceptions, not that it's mandated as the FSFE article states.
At least that is what I remember.
No, that is a pretty US specific mess up.
At least in the EU braking DRM for thinks like research purpose is fully legal as far as I know.
It's a bit more complicated if it's a but distributing tools which can brake DRM.
It's no as complicated if it's about publishing a (somewhat) scientific document explaining the general concept about how to brake it.
You should have a skim through https://en.wikipedia.org/wiki/Digital_rights_management#Laws
It absolutely is not. It is completely unenforceable, especially in the case of criminal circumvention, and serves no realistic or practical purpose. Anyone who commits said "crime" in any meaningfully damaging sense and is caught will already be committing the actual crime of infringement, and so tacking circumvention on is largely pointless. It only serves to deter legitimate public research.
Also, the T2 isn't in any way classifiable as "technological measures used to prevent unauthorized access to copyrighted works". This law is meant to apply to copyright-protection DRM and has nothing to do with software security measures designed to prevent unauthorized access to computer systems. Circumventing the protection of those measures is only legal to do on systems on which you are authorized to do so, and is otherwise illegal under separate law.
Apple consumer devices have been shown to resist state-level actor threats in the past and even if current devices won't be 100% resistant forever I trust Apple to be a couple of steps ahead every gen.
Of course, I'm jumping ship as soon as 100% open-source and verifiably secure HW+OS stack is available. But until then, it's Apple :P
Repeatedly state actors have broken into iphones and icloud accounts, and apple laptops are frequently the first devices to fall in the Pwn2Own contests.
Perhaps this unsurprising, nearly predestined exploit can convince people that they should not completely rely on biometrics for security.
It would be a big deal if one could, say, run 'offline' dictionary attacks against secure enclave content.
Isn't the T2 chip the only reason they can't do that:: because it sets a minimum time-limit and cooldown period on attempts to authenticate using the device passcode?
So presumably rooting T2 and removing the artificial time limits and/or extracting KDF data would mean game-over because brute-forcing `[0-9]{4,8}`, with even the most expensive hash function - and with a salted hash - can probably be done on a desktop within a day.
...but why can't we do that today by de-capping the T2 chip and looking at its flash storage with an electron-microscope?
And as I understand it, it's also the Secure Enclave that enforces the attempt limits.
Is it possible to get at the encrypted user data of a locked MacBook or not?
*
Yes or no, please...
https://twitter.com/jamiebishop123/status/130835517830794854...
and jamiebishop123 is in checkra1n's "made by" list.
Excited to see what sorts of things people build from this though! Would be cool to run a mini OS on the touch bar when the rest of the system is powered off.
[+] Yes, I realize that this also applies to stolen laptops, but this is an actual pain point with running fleets of Macs, from what I've heard.
I imagine there’s no better incentive to get people to move en masse to your new architecture than an exploit for your old architecture that completely and irreparably breaks its security model showing up weeks before it’s released.
Maybe a slight impact if it was the only story in the news right now and the cable networks ran it regularly? Still a stretch.