Unfixable flaw in Apple's T2 security chip

konfab

Honorary Master
Joined
Jun 23, 2008
Messages
36,198
This is a good thing for Apple users. It will mean their iToys will be much cheaper to repair.
 

Johnatan56

Honorary Master
Joined
Aug 23, 2013
Messages
30,961
This is a good thing for Apple users. It will mean their iToys will be much cheaper to repair.
Additionally, the jailbreak is automatically ended if the user reboots the T2 chip – although it is worth noting that this doesn’t automatically happen whenever you reboot your Mac.
Thirdly, the malicious party can’t get instant access to already-encrypted data. Instead, hackers would need to install keyloggers or other malware that accesses new data.
Not really.
 

konfab

Honorary Master
Joined
Jun 23, 2008
Messages
36,198
Not really.

Not from what I have read here:
Custom Bootloaders (OpenCore, Coreboot, etc) are now possible as the T2 validates/sends the UEFI payload to PCH using a bridgeOS binary called MacEFIUtil, which can trivially have its signature checks patched.

- Filevault and by extension Touch ID are more or less crippled, especially in light of the recent SEP exploits. Amusingly, Apple uses a hardcoded "passcode", analogous to an iDevice's unlock pin in plain text within the UEFI firmware.

- Support for In-System Debugging of the PCH/Intel processor over USB. This works in a similar fashion to those Bonobo cable used for debugging iDevices [4]. We are working on building an accessory that you can purchase and plug into your Mac with a USB male endpoint exposing Intel's DCI debugging protocol.

- Lightweight AppleSilicon Tinkering environment. With SSH support from macOS on device, and the T2's modest specs, its a nice sandbox for messing with arm64 stuff. It's a pretty peppy chip, at times coming close to my 8th gen i7...yikes.
https://news.ycombinator.com/item?id=24636166
 

Rocket-Boy

Honorary Master
Joined
Jul 31, 2007
Messages
10,199
Where the big problem comes with this exploit is lost and stolen devices.
Normally they are fairly solid in terms of not being usable but this will change that for sure.
 

konfab

Honorary Master
Joined
Jun 23, 2008
Messages
36,198
Apple and cheaper in the same sentence does not work.
It works when Apple ceases to be part of the transaction.

Currently, Apple pretty much locks all hardware to unique signatures. Which means that chip A will only with a specified instance of chip B. This is a problem when chip B breaks.
 

CPTBoy

Expert Member
Joined
Dec 1, 2011
Messages
1,207
This is great for allowing for example Linux to be installed on T2 enabled Macs.
 

neoprema

Honorary Master
Joined
Jan 12, 2016
Messages
10,898
All the Apple haters rushing out to defend their inferior products :ROFL:
 
Top