https://news.ycombinator.com/item?id=30738720
https://news.ycombinator.com/item?id=30738679
Extracting the relevant bits and cleaning them up:
Macs/iOS devices and PCs—through the Secure Enclave and TPM/Secure Boot/Bitlocker, respectively—offer really good protection against physical access attacks. They verify the integrity of boot components and are only able to decrypt the system volume if they detect an untampered boot chain. Further, they can lock down direct memory access to protect powered-on systems from bypasses to user authentication. This is why nowadays, if a thief steals your laptop and you had the hard drive encryption with hardware security features on (on Windows, if you set up with a Microsoft Account, this is enabled without any further action by the user), you can feel fairly secure that even a technically savvy thief cannot access your data.
And:
This tweet is wrong when it claims that Secure Boot does not protect against physical presence attacks. This misunderstands the point of Secure Boot. Secure Boot can indeed be disabled, but that will change the TPM PCR values, so assuming a standard BitLocker configuration, the TPM will fail to unlock the BitLocker key. So if you try to disable Secure Boot on such a machine, you will be unable to boot or otherwise access that volume (even with another machine) unless you have the BitLocker recovery key.
What if the user is sane?
I assume you mean by not using a Microsoft Account to sign in to the machine. In that case, you literally just right click on the OS drive and click Turn On Bitlocker. It asks you where to save a recovery key and then you’re good to go.
Microsoft has, I think rightly, calculated that the risk of losing access their data is worse for most users than the risk that the government gets a warrant for their recovery key.
And if you want to protect against the government, then it’s really easy to set up Bitlocker to not backup to MS. You can change the key with one or two commands, or with a GUI, even if you use a Microsoft account to sign in.
In any case, I’m not saying the Bitlocker design is perfect. There are good arguments to be made in favor of the iOS or Mac models (which are slightly different, even to each other). Microsoft also has the unenviable problem of dealing with shitty OEMs with buggy firmwares that change the PCR values unexpectedly, locking users out of their data and requiring a recovery key.
But your original claim—that physical attack protection is novel to ARM-based Apple devices—is just completely wrong.
But yes, the more typical scenario envisioned when developing these systems is laptop theft, unattended office PCs (e.g. theft or snooping by contractors), etc.
That’s what you said and it’s completely and unequivocally false. No caveats.
Yet for some reason I'm hesitant to reduce the security of my main personal machine, even if that 'reduction' results in a consistent level of security with my old 2015 x64 MacBook. The reality is that I probably need to go and determine if there are a greater volume of more prevalent kernel level exploits to figure out what the factor of risk really is - it may be that these features are exploited more regularly and to greater effect than they were in 2015.
Are you sure? There are several userspace APIs to do this so a kext would be very concerning and, quite frankly, inappropriate for this usecase.
> [...] does not work on macOS for audio capture due to a fundamental limitation whereby apps that want to access the system's audio require a signed kernel extension. Chromium, and by extension Electron, does not provide this.
https://www.electronjs.org/docs/latest/api/desktop-capturer#...
And, at any rate, the kext they want you to install is the same one Rogue Amoeba uses for their well known and widely used app, Audio Hijack. Discord licenses it from them; they mention it in the dialogue that prompts you to install it.
It's not like you allow any kernel extension to run, do you? You still have to approve each of them manually.
Atm I have two usb-serial adapters with different chipsets hanging off the x86 mac mini plus an Arduino that comes with its own usb serial. Is that possible on arm macs?
Apple still sells models with Intel CPUs. People who buy them presumably don't want their existing workflow to break, and are willing to buy an old generation of CPU to get that.