It would be a big deal if one could, say, run 'offline' dictionary attacks against secure enclave content.
Isn't the T2 chip the only reason they can't do that:: because it sets a minimum time-limit and cooldown period on attempts to authenticate using the device passcode?
So presumably rooting T2 and removing the artificial time limits and/or extracting KDF data would mean game-over because brute-forcing `[0-9]{4,8}`, with even the most expensive hash function - and with a salted hash - can probably be done on a desktop within a day.
...but why can't we do that today by de-capping the T2 chip and looking at its flash storage with an electron-microscope?
And as I understand it, it's also the Secure Enclave that enforces the attempt limits.
Is it possible to get at the encrypted user data of a locked MacBook or not?
*
Yes or no, please...