The T2 firmware needs to be restored after modifying the SSD amount.
This upgrade is typically reserved for an Apple Authorized Service Provider, but sure, if you have another Mac, you can do it all alone yourself.
The T2 firmware needs to be restored after modifying the SSD amount.
This upgrade is typically reserved for an Apple Authorized Service Provider, but sure, if you have another Mac, you can do it all alone yourself.
https://www.pandasecurity.com/en/mediacenter/mobile-security...
Every approach has pro's and con's. Overall not a huge fan of secure enclave type solutions but I do think their benefits still outweigh the hassles.
Security/Convenience - always a tug of war.
Which is absent if you are replacing it.
So when you put new primary storage in the machine, a new firmware that is cryptographically signed with the hardware keys that are unique to the T2 in each computer are used.
If they didn't use Apple Configurator running on a second Mac for this they would have to put all of that functionality in firmware on the machine somewhere. Driving up cost and complexity for an obscure task on a low volume machine in the first place. Yes, sounds like a valid use of engineering resources to overcome the "hardship" of having access to a second Mac for the 10 minutes (or less) the swap requires.
What is it with HN recently and all this childish Apple bashing ? If I want Apple bashing, I'll head on over to The Register where its a well known fact they hold a long-term grudge against Apple because of some decade's old fight they picked with Apple's PR department.
Back to the case in point, this HN post is disgustingly misleading.
What the Apple support article is actually saying is that if you have : (1) A spare mac with Apple Configurator 2 installed (2) A USB-C/USB-C cable or USB-C/USB-A cable
Then you can do the repair yourself.
This is not exactly a significant obstacle !
(1) Apple Configurator is a FREE download from the App Store (2) You can run Apple Configurator on any Apple machine, you DO NOT NEED another Mac Pro! (3) Any self-respecting tech will already have USB cables by the dozen
Yes, you need "another mac", but let's face it, if you use a Mac Pro at work or at home, then you most likely have "another mac" of some description around the place. And if you don't, you probably have one or more friends who have one !
That strikes me as rather emotive phrasing for an discussion about SSD upgrades.
Anyway - surely the point is that something that used to be simple (upgrading storage in a personal computer) now has a potentially large hurdle in it's way.
Does finding that to be a step backwards make one an anti-Apply fanboy?
You can always plug in a second SSD via a PCIe slot too.
Only emotive in the context of people using HN for clickbaity Apple bashing that is unsubstantiated by actual facts.
If you could be bothered to actually read the Apple Support document, you would see the reason access to Apple Configurator is required is because the SSD is tied to the T2 security chip. So you are not "just swapping out an SSD", there is a security element too. Frankly I think that is a good thing that changing hard drives is linked to the security chip.
Again - please take the temperature down a notch. I'm significantly less invested in this topic than you seem to be.
And to respond to your specific point - I'm not clear on how a new blank drive would be a security concern. There might be a technical reason why it has to be this way - or it could just be poor design. At this stage I'm curious to know the thinking behind this.
> Frankly I think that is a good thing that changing hard drives is linked to the security chip.
I'm trying to think of an attack where "needing a second computer" is a major hurdle once you've got physical access.
The Apple security guide spells it out but I can hopefully summarize: the firmware for the T2 is stored on the the SSD, and it gets signed with hardware keys present in the T2 itself so the system can know if it's code is intact or has been modified.
If you remove the existing SSD and install a new one, there is no longer any T2 firmware present. Without it, the T2 can't start and since the T2 is the starting point for the entire boot process - well, hopefully it's obvious as to why this is an issue.
Why not embed the firmware on the motherboard? Well, being able to update it is a nice thing. Not having to worry about running out of storage in firmware memory embedded on a motherboard years before is also a good thing too; especially when the trade off is a pretty darn minor hassle - IF you ever upgrade your drive (which the vast majority of people never do).
If you think this is outrageous, then you must be pretty ignorant of more than a few really gross problems with Intel's TPM (analog to Apple's T2) - many of which can't be fixed without new hardware. At least with this approach issues can be addressed and aren't burned into silicon. Intel could have made parts of their firmware updatable but they punted since it's pretty hard to maintain a secure chain; especially if you are relying just on resources in the computer you are also mucking around with at a pretty low level to update pretty sensitive things.
I'd much rather be able to keep my machine secure even if it requires occasional simultaneous access to a 2nd Mac vs. being stuck forevermore with issues in hardware. And even if you use Linux, those TPM bits are still exposed :p
Ultimately, claiming access to a second Mac for a Mac Pro (!) owner is any kind of hardship is utterly ridiculous. Every single Mac Pro owner I know (and I have and still use a cheesegrater Mac Pro) also has a Mac laptop since, you know, Mac Pro's are far from portable. And even if I didn't, as a Mac user I have many Mac friends I could bum a laptop off of for the 10 minutes it would take to swap an SSD and install.
I must live in a bubble. I don't experience the emotion of disgust. I don't know people who experience the emotion of disgust. I'm honestly not sure how one defines the word, and I get the impression that many people who use the word don't really understand it either.
On the other hand there may be some "in the womb" biological tendency toward caution, aversion to change, that correlates with Republican affiliation. Experiencing disgust may just be one of those things, like how some people taste bitter as intolerable.
I'd describe the feeling I get when seeing my cat puke out a meal, followed by her starting to eat that slimy bloody pudding again, as disgust. Just to name an example. Have you really never experienced that? Lucky you I'd say :)
Apart from that, i.e. the very literal sense ('dis' is like a negative, 'gust' is taste), disgust also gets used in the sense of morally disliking something profoundly. Again not that uncommon.
But I get your point: these days it seems to get used often when it is not very close to the actual meaning. And as such gets hollowed out a bit.
And yet, you went ahead to perfectly describe (in all but the explicit term), how you are effectively disgusted by the supporters of the previous US President, the people who use the word disgust, and Republicans in general - and in a completely unrelated thread to boot.
One could very well ascribe this to virtue signalling and projection.
I'd say implying that having access to a second Mac for 10 minutes to bless a drive in a $6,000+ computer as a "hardship" is not just emotive but bombastic.
Hell it wasn't too long ago that some computers required other computers in order to boot. Yes, I'm being a bit cheeky but we are talking about a procedure affecting a fraction of an already small pool of users - Mac Pro owners.
This is an overblown and sensationalized "story" purely because Apple is involved.