Plug’nPwn – Connect to Jailbreak
blog.t8012.dev
blog.t8012.dev
We generally assume that an attacker with physical access is going to win, but there are limits on that - the usual assumption is that it's going to take some time, and potentially leave evidence that can be picked up with enough attention to detail (such as screws not being in precisely the same alignment). This attack violates all of that - there's no physical modification of the machine, and it takes under a minute. That's the difference between an attack where you know the machine has left your control for some time and an attack that can take place while you're momentarily distracted.
The lack of response to this from Apple is deeply disappointing. The attack isn't technically persistent - rebooting the T2 will clear it. But the T2 doesn't reboot when the host OS does, and Apple haven't published any guidance on how to guarantee that it has been (eg, does holding the power button down for long enough cut power to the T2? Does performing an SMC reset? Both seem to, but is that guaranteed to be the case if the T2 is running malicious code?). In addition, the Blackbird SEP exploit probably means that we have to assume that all secrets kept in the Secure Enclave can be stolen - but we don't have a full enumeration of what those typically are, or what the total security impact of this is as a result.
1) Apple will have a problem with this. They generally don’t care about small-scale things like hackintosh, but this is a bit different. Selling a device to automagically hack a key logger into a modern Mac goes over their ‘line in the sand’, I’d expect. Openly selling it is ... brave, IMHO.
2) I can see some further work on their part to beef up the security over usb-pd. Perhaps the first thing is, as the article suggests, to force external attention from the user (hold down both shift keys...) but ultimately I could see it going to challenge/response and sha256 keys or similar.
They have a real purpose as research tools...
A good friend of mine went head to head with the Dutch tax service. It was obvious from the start the tax service could never win. So he won...after about 5 years of legal proceedings and having to finance the whole thing up front before getting his money.
Remember you have to fight them in your spare time, for them it's just work time.
In Canada, for example: potential lawsuits must be signed off by a judge who believes the case has merit. This means that you cannot decide to bury someone in legal paperwork simply because you have the money to do so: you must also have a reasonable complaint.
Yes: I skipped over the fact that the US has arrangements with other countries and therefore there are other countries where you can still do this, but the US’s legal system makes it easy.
You can't normally run code on the T2 but I don't think that has much use outside of research. You can't run code on an SSD controller either.
Your point about SSD controllers is embarrassingly incorrect; there exist many hackers of SSD controllers, including OpenSSD [0], an entire open-source community of folks working on the problem.
Please stop apologizing for Apple's walled gardens. They intentionally limit access to hardware, even after it's legally sold and belongs to the new owner.
Edit: Downvoters, provide evidence or knock it off. Nobody's interested in Apple apologia this morning.
Yes, Apple limits access to program the t2.
Maybe we should stop paying a fashion company to sell us chips that we aren't allowed to touch.
They do, actually. Someone tried selling computers pre-configured with the correct hackintosh configs and Apple shut them down via a lawsuit[0]. They also got Wired to take down a video on 'how to hackintosh'[1], however the theme with these two events was that they occurred pre-2010. Given that a multitude of people have now created hackintosh tutorials, the only thing Apple would C&D now is someone doing what Psystar did and selling pre-configured machines.
0: https://en.wikipedia.org/wiki/Psystar_Corporation
1: https://www.zdnet.com/article/breaking-apple-suing-wired-for...
Maybe Wired is a sufficiently large distribution that the same thing applies, but if these guys had just released the details, I suspect Apple would just quietly patch stuff along the lines above. Selling it means they poked the bear. With a burning torch.
No, there is a clear distinction between what is being sold and what is being demonstrated. The latter requires additional hardware and software NOT provided with the advertised USB-PD probe being sold. Reading the end of the blog or even the product page immediately makes that distinction clear.
A thief who breaks into a car using one of those hook things for the window still needs to know what (s)he's doing. That doesn't mean you don't get a lot of police attention if you're wandering around a car-park with one of them...
The eye of Sauron will blink, swivel, and focus hard towards these guys, IMHO. Hope they have good^better lawyers.
Of course, a lawsuit may always be filed even if they have no belief they will win.
What basis would they have for that? Seems it falls squarely into the exceptions for any law that could conceivably form the basis for a complaint.
- A T2 Restore
- A macOS System Update
And, Apple's USB-C thunderbolt port... it's the T1000 of ports.
Persistent (and silent) hacks are kept out of the public’s eye because they get sold for six figures and higher. As soon as one of those becomes public, they are essentially worthless.
That's assuming they haven't just attached it to the port from the inside. Or, for that matter, replaced the entire logic board with their own, having used some less subtle attack against the original to extract and copy its secrets/data.
You can't really trust anything an attacker has had unsupervised physical access to.
It is impossible to untethered persist a modified version of MacEFI without another exploit on the T2 since it has to be signed by Apple and the signature is properly checked.
I mean, you can just ad-hoc sign?
A backdoor in there can wait for the user to type in their full disk encryption password, mount the disk, replace the kernel binary with a malicious version and then boot the system.
For good measure, repeat the above steps upon each system boot in case a system update or something overwrote the backdoored kernel.
---
This is actually similar to how Computrace/LoJack worked, except that one didn't defeat full disk encryption and would only place its payload onto unencrypted disks.
Once you own the T2 you can just disable secure boot and modify macOS anyway (like injecting EFI apps/drivers into the EFI System Partition).
Oh god please tell me this is a joke... what were they thinking? Seriously?!
Bad enough most Windows laptops run the keyboard through the EC, but at least nobody outside secret services attacks them and they are diverse, while everyone and their dog is picking at the T2 chip.
It's basically the southbridge controller for macs.
When do your fingers ever get on the bottom left corner of the screen, for example? That's classic Staingate and not an area you would touch the screen.
Also, sometimes the act of cleaning doesn't get off all the grime and pushes a residual layer around which you don't notice until sunlight or when snapping a pic.
Never had issues with the coating itself bubbling or coming off. Just saying, the laptop in the video looks potentially inside the realm of grime (where I live and hold scepter).
The bottom left corner of a monitor is the first place I touch it in order to adjust its position.
The critical difference is that a monitor doesn't have a computer body attached to it perpendicularly at the bottom. The ergonomics are completely different.
I just checked. Apparently all the time. Finger oil smears on my laptop screen are completely evenly distributed across the entire area. The screen in the video looks to me exactly like smeared oil and residue that was wiped only perfunctorily