Crouching T2, Hidden Danger
ironpeak.be
ironpeak.be
- Requires physical device access.
- Cannot decrypt FileVault without you entering decryption key post-exploitation.
- Cannot access secrets in the Secure Enclave.
This isn't great, but it's not really a huge security issue? The main attack vector here is stolen Macs being re-sold as they can be "un-bricked".
I know part of the point of the T2 is to make physical access less interesting an attack vector, but it's typically doing so after a machine has been stolen. This makes it more attractive to do without stealing, but that's an attack style that is only really done by state level threats, and one that was still possible anyway, because hardware access is essentially game-over anyway at that point.
I feel like this is over-blown? Am I missing something? Is there another attack vector here that's worse for "regular users"?
For what it's worth, we're talking about mostly personal laptops, tablets, and smartphones here - not corporate servers. I wouldn't be so quick to dismiss the "physical access" requirement, although that does at least make it difficult for attackers to exploit the vulnerability at a large scale.
With the former, the device is already stolen. The only difference here is that the thief can re-sell it. That's not a huge win for the user who it was stolen from.
With the latter, you need ongoing physical access in order to install and maintain a presence on the device. That's a sophisticated attack, but sophisticated attackers already have ways of doing this.
I don’t think that’s 100% true. Yes, you need persistent hardware to re-root the T2 on every reboot. But what about a one and done T2 attack - a drive by keylogger installer? Get credentials and then mount a more traditional attack to install APT/RAT.
Also from my reading of that, the T2 chip doesn't reboot with the laptop -- it stays powered on at all times after it first starts up. If that's really the case, a reboot won't do much except kill non-persistent things that are running on macOS itself.
So, a) a T2 hack persists until such reinstall and b) you don’t need a persistent beachhead if you’ve taken the hill and maintain persistence there. This exploit opens the door to that, and you can install keyboard intercepts via the new System Extensions Interface. Did it yesterday myself via an update to Karibiner. Notarization can be disabled by interrupting the network pathway and you can definitely disable SIP after you capture the password. In essence, T2 is the lynchpin that prevents the defeat of other aspects of macOS security.
> This makes it more attractive to do without stealing, but that's an attack style that is only really done by state level threats, and one that was still possible anyway, because hardware access is essentially game-over anyway at that point.
My thought was that the T2 chip is responsible for rate-limiting access to the Secure Enclave. Specifically, for rate-limiting attempts to derive a key from as user-supplied password and the secret in the Secure Enclave.
This allows for weaker passwords to be used, because brute-forcing requires the secure-enclave in the loop, and access to that enclave is rate-limited. Drop that rate-limiting, and the brute-force attack becomes a lot more viable.
As far as I know, this was at stake when the FBI wanted apple's help a while ago to decrypt an Iphone. However, I have no idea whether this is the same scheme used for MacOS devices. Nor do I know whether the T2 chip is actually responsible for rate-limiting.
a) An unattended laptop can be compromised in under five mins, all without any obvious indications. There are also loaner situations, at schools etc. where machines are shared.
b) no specialized hardware is necessary, so it's really cheap to execute.
c) this is probably the worst part - power cycling the laptop does not reset the T2 ("The T2 chip is fully booted and stays on, even if your Mac device is shutdown.") - so there's no practical way to ensure that your machine is not compromised after a brief interlude. For extra fun, if it turns out the attack can be executed by a malicious wall port, then things start to get really interesting.
They could also install a hardware keylogger, so a non-exploitable T2 doesn't really help here in the general case. We just have to hope that the TSA aren't at the level of your average state actor.
1). send it to apple(or respective company) and if they don't respond after followups, put it on internet 2) put it on internet so it gains popularity and makes the aforesaid companies do something!
in some cases like these (those require physical access) this is fine, but what if someone uncovers a potential remote hack for every android or apple phone out there! which option would be ethical?
https://www.bugcrowd.com/resource/what-is-responsible-disclo...
As for security for "other users" - users with high security requirements can be targeted, even with a locked system.
As an example - if someone messes with my laptop while I'm away, TPM will fail and Windows will demand I re-enter my bitlocker key upon start. If you can suppress that - that's a big issue.
They don't care enough to be inconvenienced for it, but they do care when their identity is stolen, when they are blackmailed with photos, etc.
This is what's good about the T2, it secures those sorts of things for regular users in a very convenient way. This vulnerability does not appear to really change that for regular users (although it likely does for orgs with high security requirements, i.e. those considering an APT part of their threat model).
Even without this, many people could be owned just by installing a key logger on their external keyboard which would likely be easier to access and hack than the T2/ laptop.
The thing is, can't you just stick a keylogger onto the machine at this point and get an equivalent compromise? I log you login and then use that to authenticate?
Its probably a good idea to get a new Arm Mac as your next Macbook Pro because the T2 chip doesn't even need to be there anymore.
It’s not there as a ‘bridge’ - plenty of macs without T2 processors run macOS 11 and Siri with full feature parity, and neither of those things relies on the T2.
(This is why you can’t install OSes other than macOS on these devices. It’s not because of DRM or anything—though that’s an aspect of it. Rather, it’s because the T2 is in control of boot, and no other OS has had a second-stage bootloader written for it that will load onto the T2 chip to do hardware bringup from that side.)
Maybe “bridge” is the wrong word here—though I can see the meaning. A precise term, I think, would be “polyfill.” The T2 is the place where Apple is putting 1. its IP-core customizations that it can’t just plop into the Intel CPU, because it doesn’t control the Intel CPU; and 2. its top-level “BIOS-alike”, allowing them to bring up the hardware in a way they control, rather than having to convince the Intel CPU to do it in a way it understands.
The T2 and the Intel CPU acting together, roughly simulates an architecture akin to that of an ARM Mac (as with any other polyfill, where the old runtime and the polyfill acting together roughly simulate the capabilities of the new runtime.)
The interesting thing about this, is that it’s likely that because the polyfill roughly simulates the environment of an ARM mac (where these IP cores are accessible directly through the CPU, and where hardware bringup is always done in Apple’s preferred fashion without having to trick the Intel CPU into it), the drivers written for Intel-plus-T2 macOS, are also likely able to be run with only small changes, directly on ARM macOS.
That’s why the GP is calling the T2 a “bridge”: it’s a half-step across the chasm between the archtectures; an intermediate architectural target that allows some but not all of the work of developing ARM macOS to be done before any Apple Silicon ARM platforms like the A14Z were actually available to be developed on.
That’s not true. The camera use indicator light is hardwired into the camera circuitry and turns on when the sensor is powered up. There is no “software” involved in turning on the camera use indicator light.
https://arstechnica.com/information-technology/2019/09/devel...
How difficult would it be to steal someone's phone, but illegal stuff on it, and call the police? Could you figure it out for 10k USD?
I can think of so many more much more significant security issue, from remote root access to windows machines, potentially intentionally flawed VPN security, TPM on intel machines that are remotely exploitable and provide persistent access to machine and the list goes on and on.
There is something about Apple that makes folks blow up. Perhaps it's just they are one of the few with a bit of a reasonable reputation here.
Steal someone's phone? You realize iphones since Xs forward are using A12+ chips, they don't even have the intel / T2 combo being talked about as far as I know. And then to get access you need to install a keylogger PHYSCIALLY into the macbook. All this is "possible", but you can probably do a keylogger without breaking T2 and get equivalent access at the end of the day.
The overseas android market is a wasteland security side - no one even pretends, they don't even keep the phones updated.
Which exists on likely 99% of people's setups, Mac, Windows, whatever. Keyloggers on external keyboards, keyboard hacks, bios hacks...
> Stolen phones, people incarcerated
This hack doesn't unencrypted the drive, so this hack won't help if you just steal someone's laptop. You have to get physical access, hack the T2, then get it back into their hands so they can put their password in to decrypt the drive.
> How difficult would it be to steal someone's phone, but illegal stuff on it...
This hack affects MacBooks & Macs with the T2 security chip installed, not about phones.
Yeah, Twitter is terrible.
Sigh
>> This could be used to e.g. circumvent activation lock, allowing stolen iPhones or macOS devices to be reset and sold on the black market.
Is making me very sad. As someone who had things stolen in the past, thieves are the scum of the earth - I was hoping that the implementation of lock on apple devices would be a major roadblock to theft.
There's also times when accidental IMEI's are added to the list - or duplicate IMEI's are issued for the same device (common with cheap phones), I can't imagine going through the unblocking process internationally.
During initial setup the iPhone checks in with Apple (presumably providing its serial number, etc) and gets some client certificates back for things like iMessage, push notifications, etc.
So even if you circumvent activation lock client-side and get to the phone's home screen, you shouldn't be able to really use it for much (beyond a simple phone and web browser).
Didn't this become false advertising?
I don't think this counts as false advertising. "False advertising" is the colloquial phrase but the actual law uses terms like "misleading" or "deceptive":
> The FTC Act prohibits unfair or deceptive advertising in any medium. That is, advertising must tell the truth and not mislead consumers. A claim can be misleading if relevant information is left out or if the claim implies something that's not true[1].
So maybe if Apple made some very strong statements to the tune of "This T2 chip will absolutely never ever be hacked, its impossible", that might be misleading. I suspect the Apple legal team is a little more clever than that, though.
General marketing fluff like "This car is good, you should buy this car" doesn't count as false advertising if your car breaks down. I think this falls into that category.
[1] https://www.ftc.gov/tips-advice/business-center/guidance/adv...
No-one (at least, no-one reputable) claims that anything is 100% secure. You'll only hear that a product feature makes it 'more secure'. And that's still (slightly) true, since you could reasonably argue:
1) Even with an exploit, hackers have to do some extra work to bypass the feature.
2) The product was more secure for a time, until the exploit was discovered.
No, it absolutely is not. It is a 100% genuine trade off, and you are being deceptive out of your own personal interests if you lie and claim it isn't. The ability to do anything necessarily means the ability to do bad things, and the more power is available the more work, knowledge, and metaknowledge is needed to both make full use of it and avoid pitfalls.
Software lockdowns prevent power users like the typical HNer from doing useful and valuable things. But they also help ensure that non-power users (who, remember, may anything from doctors to engineers to diplomats to farmers, brilliant experts in their own fields key to society just not in computers) cannot even be social engineered into getting themselves too deep in trouble. And this is obviously, objectively a real problem, and one frankly the tech community brought in part on ourselves with constant "the user is at fault, the user is stupid" stuff for decades. But why SHOULDN'T users just be able to go easily find anything they think looks interesting and give it a whirl, and have a reasonable expectation that it'll meet certain isolation/privacy/payment standards, and if not that it'll get automatically removed and the developer banned? And even for power users, lockdowns can help shift the power balance away from developers and pool user buying power through a point so that devs are forced to obey certain basic standards whether they like it or not.
Of course, software lockdowns also destroy valuable innovation, and they create a single point of pressure that is in turn prone to abuse or (likely worse in theory and more prevalent in practice) pressure from even more powerful entities. The likes of China, the EU, or if things go bad enough the US can force censorship onto a vast array of people and devices via iOS in a way that they can't with traditional systems.
On the hardware side, lockdowns make repair more difficult/centralized. But they also prevent hardware hacks, and have proven make theft vastly less economic.
IMO, I'd like to see a single point, buy-time option to opt for the ability for an owner to load their own root keys for software, hardware, both, or neither. Personally, I'd go for software and not hardware: the devices are very reliable, I'm not a hardware hacker myself and in my own model I'd prefer to run the risk of buying replacement kit rather then even think about hardware subversion. For my parents and grandparents I'd strongly push them to continue with "neither" which should be the default. I'm sure many on HN would like both. Maybe some (particularly in countries where official repairs are much harder) would even prefer to keep the software side of things locked down for malware but as a practical matter allow repairs.
But it's intensely frustrating to still see techies who apparently never dealt with family support or Help Desk or whatever in their lives blithely repeat 1990s/early-00s memes about PEBKAC/PICNIC/lusers etc. The BOFH was a ton of fun to read but it's realworld application has limits. I don't feel bad about not being skilled at small engine work, or pharmaceuticals or whatever.
IMO you're better off just using an encrypted filesystem and typing in a passphrase on boot than dealing with hardware this locked down.
So while the headline is strictly true based on the contents of the article, I would call it excessively alarmist, at best. This is not something that the average user ever needs to worry about.
Overall I’m pretty happy hear. A stolen laptop can’t steal my secrets either from the Secure Enclave or disk, and this exploits prevents us from amassing iBricks because the hardware can always be recovered.
1) DRM on these machines is dead (yay).
2) "Anti-theft" features, which are really there just as an excuse to put a dedicated DRM chip into your box, are dead.
3) Physical access to your machine by a sophisticated attacker is game over (unless your data is encrypted and at rest).
I hope #3 isn't news to you, despite having an Apple logo on your machine (or Phone).
Maybe today things seem fine, but with declining sales, desperate companies are likely to do whatever it takes to make money. Doing something Anti-consumer is not new to Apple's core philosophy.
With prism the NSA can reach directly into live servers of American companies and get into the content, not merely metadata of conversations.
https://www.google.co.in/amp/s/amp.theguardian.com/world/201...
I'm sure they do care a bit, but it conveniently differentiates them and locks their customers in.
Hence, regulation. Lay down the rules, let the free market fight to the bone over who does it best.
Seriously, if you're under the attention of "state actors" you need to worry about this. Otherwise, not so sure.
Also, it's still better than Android phones where last time I checked there was a software based method to unlock.
Looks to me like Apple are at least trying.
T2 chip is user-hostile. Hardcoded, non-overwritable trusted public keys are user-hostile. Simple stuff, really.
That is, so far nobody has leveraged this to hack FileVault or SecureEnclave passwords generally, and until then, this is still marginally more secure than no T2 at all.
Once the above is no longer true, then a MacBook with T2 will be... exactly as secure as a machine with no T2 at all, right?
I guess I'm not seeing how this makes a MacBook less secure than alternatives. What am I missing?
But then again, I don't quite understand what problem is T2 solving that isn't solved by simply encrypting the file system with FileVault.
Because I believe the latter is true, not the former, but I believe nearly every manufacturer of complicated electronics has put things into their products that I personally cannot explicitly access, so it doesn't bother me as much as it might bother you.
If I'm a lawyer, CEO, or a human rights journalist (or just anyone) who professionally needs a reasonably secure device as the normal expectation, how can it be reasonable to be required to have your laptop with you at all times in order to maintain its security?
Is there precedent in consumer law that if security integrity of hardware is a normal feature of that product category and a computer model is fundamentally unfixable in this aspect, then you have the right to demand a refund or a replacement with a model not containing the same defect? (I know that this depends on your country. My country has strong consumer law.)
It's interesting to think about where the line is there. If someone really wants to compromise your device, then they could open it up and plant a bug anyway. But this feels over the line and grounds for being a manufacturer hardware fault, because attacking it would not require to physically modify the device but to merely use the device in the manner that it already came from the manufacturer.
Your filevault password has not been compromised by any T2 issue.
The secure enclave is rate limited.
If you are such a valuable target, then the key logger needed to get your credentials can be installed T2 or without T2 issues. Once "they" have that they can decrypt your drive.
The number of folks who are targeted at this level with physical direct access is relatively small. Even for state actors, REMOTE compromise is MUCH more appealing.
It's apple that does something exotic, breaking industry standards, and then calls what should be standard by some new name for marketing reasons. Same with how lots of people think a "retina" display is some wonderful apple invention and not just a standard samsung panel.
No, really, does anyone actually enjoy using cheap laptops? The only use case I think they would excel at is as a thin client for VMWare/Cisco virtualization solutions, or as a barebones terminal for Linux distros (at which point anything with a keyboard works for you).
Anyways, if laptops do security the same way laptops do touchpads, I would not be excited to depend on that. At all.
It would be completely irresponsible not to physically secure your hardware if you were in a position of trust.
You can "restore" "reasonable" security to your Mac even in the almost unthinkable light of a possible actually available exploit, that can be reasonably be expected to affect you personally, by using a strong filevault password. Maybe you want to add a tripwire (file integrity) check at boot time, or a manual check when you mount any drive.
No, the precedent you ask for does not exist. In fact, the opposite is true.
This is probably partially why I'm getting downvoted. Cultural differences. Americans are not aware of what's possible when things are actually fair for the consumer. They're used to 'tough luck' culture.
Upon further reading, I'm concluding this might not be a massive problem with other precautions in place, but the valid discussion point still remains. If a manufacturer designs a product which turns out to have a problem caused to the consumer which breaches reasonable expectations of its usability, and either needs repairing / recalling / replacing / refunding, many countries offer resource to the consumer. Under this principle, I wonder about unpatchable hardware security defects which cause a major problem...it needs to be explored more.
From their ad copy -
"Every MacBook Pro is equipped with the Apple T2 Security Chip — our second‑generation custom Mac silicon designed to make everything you do even more secure. It includes a Secure Enclave coprocessor that powers Touch ID and provides the foundation for secure boot and encrypted storage capabilities. It also consolidates many discrete controllers, including the system management controller, audio controller, and SSD controller, into one."
Under many jurisdictions' consumer laws, advertised features or promises by the manufacturer are not everything that they are legally held to. There is also statutory warranty, and other parts of consumer law, which can include rules on basic expectations of how that category of consumer item is expected to perform (I'm not talking CPU speeds, but major issues like a keyboard fundamentally not working at a reasonable success rate), how long it's reasonably expected to work without failing (for that category of item), and so on.
Very broad principles, but with some clear examples provided by consumer bodies to consumers, and it's reviewed on a case by case basis. You can bring it to the proverbial small claims court (or consumer complaint body), and they can review the claim.
I suppose I just won't bring up this matter to HN before. It's too alien to the US consumer situation and mustn't apply to most readers here.
Any decent smartcard has physical security no worse than T2, but it will probably cost 100 times less, and it will at least allow you to chose a long enough password instead of 4 digit pin.
IANAL. You are.