3 ms·
You don't need a chip for this. And to their credit Librem laptops have offered such a hardware switch for a while now (perhaps since they began selling laptops
by Digital-Citizen 8y ago
You don't need a chip for this. And to their credit Librem laptops have offered such a hardware switch for a while now (perhaps since they began selling laptops) with (as I understand it) no chipset involved.
Putting this functionality into a computer chip is ridiculous and unnecessary partially because there's no clear way for ordinary non-technical users to control that, and partially because this suggests that software (as I presume the software on this new chip will be alterable by Apple) can still affect whether the mic is hot. The headline "Apple's T2 chip will prevent hackers from eavesdropping on your microphone" should probably be interpreted to mean that Apple won't be prevented from listening in.
Camera access and wireless network access should also be physically disconnectable via a simple user-controlled piece of hardware which electrically disconnecting the on-board webcam and wireless network device from the rest of the system -- a slider or rocker switch. This too is something I understand Librem laptops offer but is uncommon elsewhere.
- xvector 8y agoIf your threat model includes "I don't trust Apple", then all discussion is moot. You could provide all the hardware killswitches you want. Apple could still design a way around them to get your data while the laptop is active. Now, if you trust Apple, the T2 chip is perfectly secure for this use case. Apple claims this serves as a hardware disconnect baked into the silicon, in which case it is no different from a mechanical switch. Finally, the whole argument about user control over various security features is interesting. I will say that Apple has, better than any other manufacturer, struck almost perfectly the balance between security and usability. Apple's software/hardware security does its job, does it well, and gets out of your way. Including 20 different hardware switches and 150 different security settings that mean nothing to the average user would not be in their design language. It's all about your threat model. Perhaps yours is a bit too severe to use traditional consumer devices.
- Digital-Citizen 8y agoYou're missing the point (as are the moderators, apparently): trust is a factor only when it comes to proprietary software. If you have to "trust Apple" to deal with Apple software, then you've lost any reason to trust them as they've already shown that they ought not be trusted -- both in principle (by distributing proprietary software) and in specific examples as per https://www.gnu.org/proprietary/malware-apple.html https://www.gnu.org/proprietary/malware-apple.html (only some of which aren't Apple's fault but merely run on Apple-made OSes, and some of which include bad business practices by Apple). Buying into claims ought not be needed and isn't needed except for proprietary software where such trust is apparently often misplaced. You can't tell if "the T2 chip is perfectly secure for this use case" because you don't know what runs on it. Apple claims a lot of things and one had good reason to believe Apple wouldn't, for instance, leave a remotely-exploitable vulnerability in iTunes unfixed for years after being notified about that vulnerability while governments exploited that vulnerability. But according to http://www.telegraph.co.uk/technology/apple/8912714/Apple-iTunes-flaw-allowed-government-spying-for-3-years.html http://www.telegraph.co.uk/technology/apple/8912714/Apple-iT... that's what Apple did. If Apple distributed free software trusting Apple wouldn't enter into the discussion. We could inspect what Apple distributed, we'd be allowed to change what we don't like about the software Apple distributed to us, and we could distribute improved versions of that software to help others. No need to buy into uninspectable code we're not allowed to change or distribute further. And the answer to the question you didn't answer which the original poster asked -- do you need a chip to do this task -- remains "no". Purism's hardware is proof by existence. With Purism's hardware switch there's no software involved to accomplish this feature and they (as far as I know) distribute a free software distro called "PureOS" (a GNU/Linux system) which also happens to have earned an FSF-approved distro entry.