That being said, I actually think this is a reasonable way to do secure boot. The default OS the device ships with can be validated, but there's still a proper owner override so you can boot into Linux or whatever. They even use the SEP to validate that the owner override has been tripped by the owner. The first user account you make gets handed a key generated by the SEP that can be used to sign kernels, so only that account can actually use the owner override. This is a good way to stop evil-maid attacks in their tracks while still not locking the user out of their property.
My only real complaint is that Apple's gone to great lengths to ensure the iOS side of their business is completely unaffected by owner overrides:
- If you boot into an owner-signed OS volume, macOS disables it's iOS support
- iPad-fused M1s won't generate or respect owner keys
This is silly. If individual iOS applications are sensitive to owner overrides, then they already have devicecheck APIs to get a cryptographic attestation that they haven't been tampered with. The SEP could flag those attestations as coming from an owner-signed kernel and picky banking apps[0] could check for that.
[0] And Pokemon GO, because it's easier to blacklist jailbroken users than to enforce a rate limit on GPS jumps
And they've shown that to be not unreasonable at least when it comes something like root private keys. Fact is they've been operating for a long time now and like the rest of the big players that hasn't been a leak issue. It's not that big a deal for a big player to physically secure such things to a high enough degree that it's unlikely to be a limiting factor. Dedicated rooms, full offline, hardware backed Shamir's secret sharing for m-of-n key signing ritual requirements etc etc.
It is not about trusting Apple or any other company for that matter. It is about tendency and attempt to make it a norm/legalize to sell personal computers without respecting right of the owner to have a full control over their own computer. If owner cannot fully control own computer this computer cannot be called 'personal' anymore.
This practice needs a push back as it completely unacceptable. It should be made illegal to sell such devices if that is not already the case because you can be left without working computer just because link to the company isn't available for some reason.
Company goes away and you are left without a working computer. Internet isn't available and you have brick instead of your computer. This is crazy and even more crazy that there are bunch of people brainwashed enough to the level that they do not even perceive it as a problem. Probably because they can't think 3 steps forward.
I have bad news about Intel CPUs.
>[Intel] processors are running a closed-source variation of the open-source MINIX 3. We don't know exactly what version or how it's been modified since we don't have the source code. We do know that with it there Neither Linux nor any other operating system have final control of the x86 platform.
https://www.zdnet.com/article/minix-intels-hidden-in-chip-op...
The full control of devices you own is absolutely essential. It requires a complete transparency of basic components like cpu micro-code, firmware and hardware otherwise it can and will be abused.[0]
.. unless everything is absolutely transparent including microcode and hardware it is not acceptable as freedom respecting solution.[1]
then I've got unexpected opposition from the one who is making linux for M1 ( marcan_42). If even him fail to understand the consequences of accepting such hostage situation with Apple devices and claim "Freedom isn't the answer." [2]. If even he is ready to downgrade discussion to the personal disrespect toward people like me [3] who merely trying to point out the the danger of the hostage situation while go 'easy' on Apple and ready to justify all of their current mistakes then we have a serious problem. I do not wish to use the term "doomed" but probably we observe limited ability of highly technical minds to resist to the primitive brainwashing and manipulation the big companies provide by presenting it as a norm to trade 'freedom' for the 'safety' . Some people can't even think a few steps forward and understand that by helping companies to promote such agenda we'll end up with loosing both 'safety' and 'freedom'.
[0] https://news.ycombinator.com/item?id=29658817
[1] https://news.ycombinator.com/item?id=29675597
Unfortunately, that's going to constitute a lot of the people you encounter these days. Half-measures are better than no-measures, but I really do miss the days of vigilant software development instead of cleaning up Apple's scraps.
The "look beyond freedom" quote probably should also be looked at with the context that he's talking about the FSF, which has an odd habit of being extremely absolutist in ways that actually hurt the user. Like, they'll point out that Wi-Fi cards with proprietary firmware are bad, but then endorse very similar hardware where the firmware blob is in ROM or some features are lasered off just to conform to the "proprietary ROMs don't count" rule. Marcan is arguing for creating a gradual sliding scale of "proprietary, user-hostile, and/or insecure" to "Free, user-respecting, and/or secure" and then looking at the trade-offs between them, rather than just creating a really high bar based on what made sense in the late 1980s and sticking to it forever.
If you're talking about building a sustainable community so the end product is polished and upstreamed and ready for end users, I'd say we have that with the M1. Things are already getting upstreamed and there is more than enough momentum. This wasn't the case with PS4, which was just me and a few other fail0verflow folks putting together a proof of concept. It helps when you don't have to spend cycles finding exploits and can focus on delivering a working OS :)
I mean, to be honest, someone only knowing “whys” alone is kind of disappointing — especially combined with the often seen narcissism of developers and you get someone who does not understand the problem domain spewing bullshit about it with confidence. We can see plenty of examples to that under any firefox, wayland or systemd threads.
I'm happy to debate the pros and cons to different security approaches, and I want every prospective buyer of these machines to be informed about the decisions and trade-offs that went into their deaign, and what to expect. I'm not interested in debating someone who immediately dismisses all technical discussion and just invokes references to authoritarianism, brings up boiling frogs with no evidence, immediately dismisses my arguments as wrong and assumes they need correction, and ends with ad hominem attacks.
As I said, go buy a Pinebook and please leave the rest of us alone. We're trying to give the users of these machines choice. You're trying to take away our choice to use them through moral arguments.
We’re talking about Apple, one of the most valuable companies in the world, sat on over $100bn in cash just “going away”, in what, the lifetime of a laptop? For me that’s 3-5 years, for others maybe 10. That’s an absurd premise. The probability of that is so close to zero it doesn’t bear consideration.
The point is, if I want to buy a personal computer and stuff it in the closet for 50 years to use later, that's between me and the creator. Not Tim Cook.
It's one of the reasons I'm not using Apple products anymore.
take a look at the "Why not Apple devices?" section
Would you really be more comfortable knowing that your hardware vendor had the capability to produce machines with a low-level, unremoveable backdoor? I'm not sure I would. A feature like that can be used against users more easily than it can be used by those users.
What? They do. Apple absolutely has the capability to build any or all machines with low-level unremoveable backdoors, like, in the freaking processor if they wanted. I'm not clear on what your issue is here. The current state of affairs is that for devices like the iPhone, the manufacturer can setup a secure software tree where the root of trust contains only their keys. And for many (if not most) of their customers that's a good thing, because in their threat model running their own arbitrary code is of lower utility and much higher risk then getting social engineered into bypassing key protections or the like. There is important power in grouping together buying decisions in an unbypassable way, it's why the likes of Facebook for example cannot insist on bypassing iOS privacy protections. They can't pick people off, because people literally do not have the choice. Facebook must deal with Apple for the ~97% (or whatever it is who don't/can't jailbreak) majority of users.
However there are real issues with that too for a sizable number of owners. So all I want is that there be an option at purchase time which allows owners to load their own root keys. The whole chain of trust infrastructure is still there, but technical users or those with specific needs can then run their own (and still be better off). Making it buy-time means that users who want to ensure they cannot be compelled later can still do that too. Nobody loses.
A feature like that can be used against users more easily than it can be used by those users.
How? Most people will stick with defaults, and I'd be ok with Apple or whomever qualifying an open device with reduced software support or some small charge for example too. And once it's been sold, it's the same as currently. I think that's a reasonable tradeoff.
> How? Most people will stick with defaults
By having an attacker deliver a system to a user with a custom root of trust -- which could mean anything from a state-sponsored attacker to an abusive partner.
It doesn't matter how secure communication between Apple and Apple device because even if it's perfect the owner is not secured from the Apple itself and those who Apple would love to communicate with. For instance oppressive governments. (here the result of such communication: blocked app that oppresive government didn't like https://apps.apple.com/us/app/%D0%BD%D0%B0%D0%B2%D0%B0%D0%BB...)
It really doesn't depend on the threat at all. It's about the model of the society you wish to have and what values you promote.
It's about who you wish to be responsible : the 'big company' caring about your safety and taking your freedom on the way or you caring yourself about own safety and preserving freedom on the way. I do not really think there is a choice here because the first option will always be abused at some point.
Freedom does matter and it comes with responsibility. THIS is the main issue here. THIS is what separates society with responsible citizens from the society with 'irresponsible people' who wish to trade their freedom for 'safety' resulting in loosing both (and democracy itself after some time).
If you don’t like their model, choose someone else. Why should average users who would otherwise be served perfectly well by Apple’s solution be required to be “responsible” for some subset of personal security you think denotes a “responsible” citizen from an “irresponsible” one?
Many follow their example and without push back there will be no someone else because average users my not understand consequences unless they are educated by people who do understand them. Like with many other areas requiring certain level of expertise to understand consequences of certain desicions.
> we’ve tried relying on “user responsibility” before, >Why should average users who would otherwise be served perfectly well by Apple’s solution be required to be “responsible”
Do you believe in choice? If you do then average users should have a choice whether to rely on Apple or switch such functionality off. Without having such choice people become less and less responsible. You can say they choose by buying such machines but I do not think this could be qualified as a choice just like accepting EULA. It's not really a choice.
I think if Apple was to add a developer mode to the iPhone, 99% of people would actually shut up.
I just don't think that the counterargument is completely spurious. Craig Federighi taking the stand in court and saying that Mac security is at a place they "don’t find acceptable" doesn't exactly make me feel all warm and fuzzy about Apple's future plans. And so if someone says they don't want to buy an M1 Mac, even if it's open today, because they see the iPhone as indicative of the direction Apple is going, I think that's fair, even if I disagree about Apple's intentions.
By contrast, if Apple added a way to unlock the bootloader on iPhones tomorrow, this argument would immediately evaporate. :)
Apple could certainly choose to lock down future Mac iterations (though I don't think they will), but I think fears that they might retroactively lock down existing Macs are just unfounded and ignore the realities of the situation.
Of course people are free to buy or not buy machines for whatever reason; that's why I want everyone to be informed about the details. My beef is with those who disagree with this stance, and think people shouldn't buy these machines period because Apple is evil and those who buy their devices sheep, and anyone who thinks otherwise is mistaken, and there is no room for having different priorities when choosing hardware because Freedom™ is the only priority that matters. For whatever definition of Freedom™ they feel like using that day.
> I think the irony would be less dramatic if the free software wasn't running on hardware constructed with slave labor.
Why do you feel the need to direct criticism of Apple's business practices at me? I do not work for Apple.
> but people's worries about the conflict of interests here is fully justified.
Then don't buy the machines and move on with your life?
> Apple and open source are not friends
Neither are they enemies. The world isn't binary. I do not exclude from my life everything that is related to everyone who isn't explicitly my friend, do you?
> their ultimate goal is to stomp you out and expand control
Ah yes, stomp us out by... building machines we can use to run our own OS? They could've just not done that and we wouldn't exist.
> just don't be surprised when your blood, sweat and tears ultimately end up being used to grease the gears of their production line.
So which is, are they going to stomp us out or are they going to embrace the extra business we bring? You can't have it both ways, you know.
> We're talking about a trillion-dollar company that doesn't release their own device drivers or schematics; it's ridiculous that we even need to finish the job for them in the first place.
I find it fun finishing the job for them. This is exactly the kind of project I enjoy doing. If you don't, then choose a different free software to contribute to.
> It's hard to see this work as "noble" in the same way other free software projects are, at least to me.
So our project is inherently morally inferior to others because you simultaneously think Apple should've done the work for us and Apple are our enemies. ????????
Seriously, this makes no sense. You know Linux itself started out as a hobby OS with no corporate backing and tons of other drivers are reverse engineered, right? Do you also think Nouveau isn't noble? What about LineageOS? What about XBMC/Kodi when it started? Freedreno, Panfrost, and friends? All of those projects are or were about bringing free software to devices designed and manufactured by giant corporations without any support.
Heck, I got sued by a multinational for bringing Linux back to the PS3, and I still don't regret it. That work got upstreamed, by the way.
That's a really good point I hadn't thought of!
"When Apple's servers go down you lose the ability to do low-level recovery on these machines anyway, since DFU flashing requires phoning home to get a ticket for your machine as well as low-level configuration data"
Yes, if you don't have internet access you have a problem, but I'm personally happy enough with the benefits of this security model that I'm willing to accept the tradeoff.
For now ... Thank you for the link but may I suggest you to think about the future and where it leads.
So iPhone is closed for 15 years already and thus "the future is doom and gloom" is happening for 15 years already. The more important question is what will be next.
>You really need to find an argument other than an unqualified "the future is doom and gloom" when after all this time that future hasn't come and the platform remains open.
Argument can be qualified or unqualified depending on the topic. It is unclear which topic assumed here.
"I disagree with one product's direction, therefore all other products from the same company are doomed to that direction" is not a valid argument, especially not after 15 years of it not happening. Companies are capable of producing products targeting different markets and use cases.
"Domino's added a pizza I don't like to their menu, what will be next? Their entire line up will be a horrible inedible mess in a few years!"
See how stupid that sounds?
All you have to do is not buy an iPhone (like I didn't either) and stop spreading FUD about Macs.
>... not a valid argument, especially not after 15 years of it not happening.
It's not about trusting or not particular company. The idea is to protect and insist on certain level of respect toward owners of the computers that no company would dare/able to diminish without consequnces.
>"Domino's added a pizza I don't like to their menu, what will be next? Their entire line up will be a horrible inedible mess in a few years!"
>See how stupid that sounds?
"what will be next" question was addressing the issue of trusting to any company and about level of dependency from any company for any owner of any computer. The context of the question was not about trusting particular company. When the context is switched then anything may appear "stupid" but then it is interpretation to blame not the question.
>All you have to do is not buy an iPhone (like I didn't either) and stop spreading FUD about Macs.
The issue I am discussing can not be resolved by marked and buying preferences and therefore 'just buy something else' would not work and cannot help.
Like I said above, it's not about trusting Macs or company. It's about pushing back against the tendency to make personal computers more dependent and less personal.
It's about respecting independence for the owner not about security, not about trust to a particular company. It's about making trust to the company irrelevant enough. It's about preserving level of respect to the owner which reduces dependency and importance of the trust to a particular company.
I already explained to you how you have to trust the company if you're using their silicon. There is no way around that for modern devices. You're trying to fight a fight against the laws of physics.
Again, if you need absolute trust, then I suggest you order a Precursor, and then you'll have to be content doing all your computing on a 100MHz CPU.
> The idea is to protect and insist on certain level of respect toward owners of the computers that no company would dare/able to diminish without consequnces.
So you're saying companies shouldn't be allowed to have secure systems that benefit the average user; they should all be forced to do what you say is "respect" users, which means requiring that they develop their own secure boot infrastructure, in your world, since that's the only way they can be in control (or just give up security altogether).
Do you realize how hypocritical it is for someone advocating for freedom to try to take away everyone's freedom of choice by making it illegal or immoral to trade off your own personal vision of freedom for something they might care more about? Seriously, you brought up authoritarian governments, but you're the one using their propaganda tactics here. You're not just saying users should be able to buy devices they control; you're saying they shouldn't have the choice but to be in "control", even if it hurts them in other ways. The Way of the Freedom Party is the One True Way.
Have you considered that maybe, just maybe, there are actual practical consumer-protecting arguments to be made here without resorting to ridiculous extremist positions? Here's one: companies should be required to allow users to run their own software on devices that have reached end of support and are no longer receiving security updates. See? That is the kind of useful policy position that'll get people interested and might even have a chance at becoming law. Not "iPhones are evil and should be illegal".
If your fundamental firmware-stuff is screwed up on any platform, you are going to have a bad time. Being able to plug into an off-the-shelf machine and fix it, or to plug into another PC running special software, is much better than I'm accustomed to.
Sure I just have an impression after some googling that this DFU happens much more frequently then one would expect. Certainly I didn't expect it to happen in the first day after purchase but it did. So perhaps this pleasing 'much better' ability to fix it by just connecting it with another device that you probably do not possess(in my case) comes with another pleasure of having to do it more frequently. If that is the case then I really prefer the state to which you are accustomed to.
We have 3 Apple Silicon based Macs in the house, and there's 4-5 others that I support. So far 0 incidents in about 3 device years. I don't think it's tremendously common like you imply.
In the same time period, I built two Ryzen machines, and had to swap in older processors to run BIOS updates on each, and the laptops in my wife's classroom all decided to take themselves out of service for an hour one day to do BIOS updates that were delivered by Windows update and then only triggered on the second reboot after update when we all thought we were safe.
In this case, since others already know it, signing something is sufficient.
You wrote:
> completely insecure if you are not the only one with the key
What key is shared between you and the manufacturer here? There's signing keys and there's passcodes, which ones are you "not the only one with"?
because you don't even have the key? not sure where passcodes came from
> completely insecure if you are not the only one with the key
This implies you are referring to a key that the user has.
What key does the user have?
A passcode? Password?