8 ms·
This just sound like the Intel Management Engine story waiting to happen again. A controller that handles camera, networking and is the "root of trust"? No than
by zapt02 9y ago
This just sound like the Intel Management Engine story waiting to happen again. A controller that handles camera, networking and is the "root of trust"? No thank you.
- dkonofalski 9y agoIn what way is this similar to the IME story? Apple's history with the Secure Enclave on iOS devices leads me to believe that this will be much more secure and that a white paper will be forthcoming unlike Intel's complete opacity surrounding IME.
- zapt02 9y agoDo you truly believe Apples sophisticated security enclave with computer-like capabilities (and probably running a full OS) will have a manual and white-paper? This is the exact opposite of what Apple will do, they will lock it down and put it behind patents as they do best.
- gsteinb88 9y agohttps://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://images.apple.com/business/docs/FaceID_Security_Guide.pdf https://images.apple.com/business/docs/FaceID_Security_Guide... Seems pretty likely there will be a whitepaper and some conference talks about this as well.
- zapt02 9y agoYou're linking a minimal manual which is required for corporate deployment, hardly anything Apple is being forthcoming about. I'm pretty sure you and I have different definitions of acceptable disclosure - unless Apple makes the entire chip possible to audit, I don't consider it to be acceptable.
- dpkonofa 9y agoA completely transparent audit like you're suggesting would compromise the majority of the security features of the enclave. The white paper gives enough about the mechanism to understand how it works without detailing specifics that would compromise the security of tech.
- dpkonofa 9y agoAre you joking? They already did release those things...
- innagadadavida 9y agoFYI when you patent something, it becomes public. Trade secrets keep it that way.
- willstrafach 9y ago1. You can opt to not utilize the security features offered. 2. This is not used for device management.
- kevin_thibedeau 9y agoIt is a SuperIO chip with on board co-processors that can inspect and modify data transferring to/from peripherals. It is most certainly used for management and capable of being compromised like the ME.
- willstrafach 9y agoYou have not refuted anything I said besides implying that I am wrong. Again: - You can turn off functionality if you do not want it. - There are no management or remote access capabilities. - The only way to compromise it would require compromising the main CPU anyway, and persistence would be a whole other (major) challenge.
- kevin_thibedeau 9y agoAh, so you're saying this chip is guaranteed to not have its own TCP/IP stack, no access to the NIC, and no latent zero-days that a remote attacker can exploit?
- willstrafach 9y agoThat is correct enough, but now sure what “it’s own” means. To be clear, this is not some mystery chip, it runs a derivative of iOS, and you can check out the firmware in /usr/standalone/firmware (You can even reverse engineer it if you have experience with ARM).
- r00fus 9y ago> This just sound like the Intel Management Engine story waiting to happen again Excuse me, implementation details matter. Outcomes matter. Apple has deployed 10x more devices with no known breach or defect.
- fjsolwmv 9y agoExcept for when they forgot to require a password for root access to her OS...
- nopreserveroot 9y agoAre you implying that Apple has deployed 10x more devices than Intel?
- toasterlovin 9y agoYeah, this is all technology from iOS devices.
- oblio 9y agoEven so, I somehow doubt that 15 years of iOS devices equals 30+ years of x86 devices.
- toasterlovin 9y ago
- acdha 9y agoDo you not use Chrome because IE6 was insecure? This attitude doesn't seem like it leads anywhere other than not using computers.
- manmal 9y agoI actually want Apple to control the network stack, because I trust them more than Intel, or the other chip vendors. If I understand it correctly, they can now stop the Intel ME from sending stuff out? That would be very reassuring. Apple has a very strong stance against selling my data, and others don’t.
- samcat116 9y agoI mean at the end of the day, something has to manage those devices.
- eridius 9y agoThe camera isn't a vector of attack, it's a thing to be attacked. The camera right now on desktop computers is wildly insecure, giving authority of it over to a secure enclave seems like a great way to finally start securing that path.
- gcr 9y agoOn the other hand, the ability to compromise the T2 chip would lend attackers the ability to use the camera outside of OS control and thus outside of user control. At least with OS updates, it's possible to patch potential security vulnerabilites. Of course it's much harder to patch silicon, as we're seeing now.
- willstrafach 9y agoYou misunderstand. It runs "bridgeOS" which can be updated with Apple-signed firmware updates, and most certainly will be for security updates.