24 ms·
Apple’s T2 security chip jailbreak
- neximo64 6y agoThere are so many ads on this site
- loxs 6y agoI didn't see any (uBlock origin + NoScript)
- accountLost 6y agoAny reason you don't use an ad blocker ? I see no ad with Firefox + uBlock Origin.
- bayindirh 6y agoJust use the reader mode? Firefox's one clears the article pretty neatly.
- fit2rule 6y agoAnd so the futility of captured computing continues. I would love to write software for the Touch Bar that runs when I shut the MacBook down .. it'd be quite useful for some things, I imagine - such as using it for a remote control for other equipment I own.
- fastball 6y agoYou could explain this a bit more? Not really understanding how this would be useful.
- withinboredom 6y agoJust imagine opening your laptop without turning it on, and using it to unlock your front door without getting up, or turning off/on the TV, or the temperature of the house.
- bluefirex 6y agoWhat holds you back from using a smartphone?
- withinboredom 6y agoNothing. But I don't know about you, but I'm more likely to have a laptop nearby than my phone. Especially if the kiddo is playing his dragon game on it.
- bilegeek 6y agoGiven that T2 is basically and ARM processor + other stuff, I wonder if it's possible to have a separate dump kernel, like OpenVMS. Some watchdog that runs on the chip, and either gracefully shuts down or handles a kernel crash.
- californical 6y agoThis is huge! Does anyone know if Apple is able to ship updated software to patch this? I thought the T2 was fairly isolated from the rest of the system. If it’s not easy to fix OTA, this will be really painful for security. Excited to see what sorts of things people build from this though! Would be cool to run a mini OS on the touch bar when the rest of the system is powered off.
- my123 6y agoThey cannot. Both the AP and the SEP ROMs are hacked on the T2.
- javajosh 6y agoIf you follow the links you'll find https://checkra.in/ https://checkra.in/ which gives you a dmg download - however the release notes don't mention anything about a T2 jailbreak. I would treat this with skepticism.
- austhrow743 6y agoThe tweet is legit though https://twitter.com/jamiebishop123/status/1308355178307948545 https://twitter.com/jamiebishop123/status/130835517830794854... and jamiebishop123 is in checkra1n's "made by" list.
- californical 6y agoIt does claim “partial bridgeOS support” which is the OS that runs on the T2. So maybe not as crazy. Good call though, it’s good to be aware of that sort of thing
- bartvk 6y agoI wonder if this has security implications. The T2 houses the "secure enclave" and that's where your private keys, certificates and passwords are stored.
- harrygeez 6y agoof course. Previously your keys are stored securely in a vault in a security facility but now the doors to the security facility is blown wide open. They still need to figure out the Secure Enclave though, which is no easy feat
- deleted 6y ago[deleted]
- saagarjha 6y agoIt’s been largely figured out already. The actual work is going into A11’s enclave at the moment.
- pvg 6y agoThe things stored in the enclave are encrypted with a key derived from, among other things, your device password so no jailbreak is going to provide access to them. It would be a big deal if one could, say, run 'offline' dictionary attacks against secure enclave content.
- systemvoltage 6y agoSame password results in a different hash if you run it again.
- aneutron 6y agoThe fact that Apple uses this chip to, among other things, block "unauthorized repair" (can't change a freaking SSD in 2020, really), makes me very happy that people are finding ways to break this chip to make repairs more accessible. On the other hand, this could have serious implications on the iOS security model for example. And I'm pretty sure someone is gonna run Doom on the touchbar in some months.
- draugadrotten 6y agoDoom on touchbar (2016) https://www.theverge.com/circuitbreaker/2016/11/21/13697058/macbook-touchbar-doom-hack-sure-why-not https://www.theverge.com/circuitbreaker/2016/11/21/13697058/... https://twitter.com/b3ll/status/800472338496036864?s=20 https://twitter.com/b3ll/status/800472338496036864?s=20
- quenix 6y agoThat's running purely in usermode, and nothing was broken in this demonstration, the touch bar is being used "as intended"
- aneutron 6y agoExactly. This would "in theory" allow Doom to be running outside of the "prescribed parameters".
- sgt 6y agoSo the monsters would actually leave the touchbar. This sounds really risky, folks
- GekkePrutser 6y agoOnly if you feed them after midnight!
- DaiPlusPlus 6y ago
- lxgr 6y agoDoes the T2 have any secure storage like the A12 and newer, or are all boot ROM exploits essentially unpatchable? And do we know if this specific exploit is a boot ROM exploit?
- saagarjha 6y agoIt’s the checkra1n BootROM exploit, yes. T2 does have a SEP processor like every modern iPhone but that’s been recently cracked too (interestingly enough because Apple tried to run some trickery to “patch the unpatchable” using it).
- gigatexal 6y agohow quickly will they patch this now is my question
- aunali1 6y agoHi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on. Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3]. Some key takeaways from the T2 being jailbroken: - Custom Bootloaders (OpenCore, Coreboot, etc) are now possible as the T2 validates/sends the UEFI payload to PCH using a bridgeOS binary called MacEFIUtil, which can trivially have its signature checks patched. - Filevault and by extension Touch ID are more or less crippled, especially in light of the recent SEP exploits. Amusingly, Apple uses a hardcoded "passcode", analogous to an iDevice's unlock pin in plain text within the UEFI firmware. - Support for In-System Debugging of the PCH/Intel processor over USB. This works in a similar fashion to those Bonobo cable used for debugging iDevices [4]. We are working on building an accessory that you can purchase and plug into your Mac with a USB male endpoint exposing Intel's DCI debugging protocol. - Lightweight AppleSilicon Tinkering environment. With SSH support from macOS on device, and the T2's modest specs, its a nice sandbox for messing with arm64 stuff. It's a pretty peppy chip, at times coming close to my 8th gen i7...yikes. 1. https://www.theiphonewiki.com/wiki/T8012_checkm8 https://www.theiphonewiki.com/wiki/T8012_checkm8 2. https://twitter.com/qwertyoruiopz/status/1237904335184564224 https://twitter.com/qwertyoruiopz/status/1237904335184564224 3. https://twitter.com/su_rickmark/status/1286886010681462784 https://twitter.com/su_rickmark/status/1286886010681462784 4. http://bonoboswd.com/ http://bonoboswd.com/
- DaiPlusPlus 6y agoThank you for your work! Do you have any thoughts about what Apple's switch to own-brand ARM chips in laptops and desktops will mean for T2/T3/etc?
- aunali1 6y agoThe T2 was more or less a stopgap solution between their current Intel-based offerings and the AppleSilicon devices in regards to their security aspirations. My understanding is that there will be no T3, as evidenced in the DTK, which makes a lot of sense considering how identical these chips will be to their mobile counterparts.
- person_of_color 6y agoIts clear that bootROM is not the way forward.
- saagarjha 6y agoThere’s no alternative; something needs to bring up the chip when it comes out of reset.
- person_of_color 6y agoits called storage
- saagarjha 6y agoHow you know know how to read storage? Something needs to load drivers and such, does it not?
- poslix97 6y agoBottom line, can you use this exploit to read the user data on a recent (2019+) iPhone or MacBook if you have possession of the device and it's locked? Yes or no?
- dividedbyzero 6y agoI'm torn on this; on the one hand, the prospect of being able to circumvent things like unauthorized repair prevention down the line is neat, and who knows what people may be able to tease out of this (apparently quite powerful chip). So that's neat. But it also breaks Apple's security platform in a big way, since this should make Apple's biometry scheme in their Macbooks much weaker and FileVault a lot easier to crack. That's a shame, because it's a very neat and cohesive security platform that gets out of one's way and works really well even for highly non-technical people. Their security stance is one of the things that keep me in Apple's ecosystem and I know a number of people and companies who feel alike. So, coming from that point of view, I do hope they fix this in time for their first round of ARM Macs.
- saurik 6y agoSo, if only Apple didn't tie the ability to repair and extend the device you purchased from them to the security of your own data, you would be able to feel a more consistent emotion with regards to interest in a fix; that seems all on Apple being a bit evil :/.
- floatingatoll 6y agoCan you describe a scenario where Touch ID is safe against evil maid attacks (say, a chip is installed allowing anyone to transmit a certain signal that spoofs Touch ID) while also allowing unrestricted modifications by someone with physical possession of the device (as this T2 rooting post celebrates)? Right now, that security is provided by Apple crypto-locking the Touch ID sensor to the T2 chip so that it cannot be modified to allow unauthorized access without being disabled altogether. With the ability to bypass the restrictions of the T2 OS, that protection is stripped away, and replaced by .. nothing, as far as I can determine. This is akin to removing your car’s electronic anti-theft system because it requires OEM keys. Sure, you can do so, but your car is a lot easier to steal, too. Only it’s not your car here, it’s your computer and all personal data on it, and all SSH keys you use to access remote servers, too. I’m all for repairability but it’s worrying that the tech community is so invested in removing a padlock that offends them that they set aside security and risk issues in favor of rooting without addressing it at all. If this complete lack of interest in device security is the best we can do, we don’t deserve repairability, and we don’t deserve root.
- xxxxxann 6y agoHi guys Watch the video where I masturbate in front of the webcam after a simple registration http://chatie.club/xxx http://chatie.club/xxx Nickname anna1 ️
- headmelted 6y agoGreat day to be Apple I guess. I imagine there’s no better incentive to get people to move en masse to your new architecture than an exploit for your old architecture that completely and irreparably breaks its security model showing up weeks before it’s released.
- bredren 6y agoI don’t think this is the type of thing that affects broad consumer decision making on product replacement. Maybe a slight impact if it was the only story in the news right now and the cable networks ran it regularly? Still a stretch.
- mmastrac 6y agoInteresting. Does this mean that companies can now use this to unlock corp laptops that ex-employees have iCloud/activation-locked to their personal accounts without Apple's help? [+] [+] Yes, I realize that this also applies to stolen laptops, but this is an actual pain point with running fleets of Macs, from what I've heard.
- nixgeek 6y agoIs this a pain point when you’re using Deployment Programs, or what’s now called School Manager or Business Manager?
- snazz 6y agoDEP allows you to clear Activation Lock with your MDM: https://support.apple.com/en-us/HT202804 https://support.apple.com/en-us/HT202804
- aunali1 6y agoYep, it involves the same techniques used for iDevices but with less steps. I won't go into details here for obvious reasons.
- Nextgrid 6y agoAre you saying that there is a long-term way to bypass Activation Lock? My understanding was that even if you bypass it locally (through jailbreak), you will not be able to use any of Apple's online services (iMessage, App Store, push notifications, etc) because Apple will not let this device register (and get the necessary client certificates) unless the original account's credentials are provided first, and this is enforced server-side and thus immune to local exploits.
- neycoda 6y agoThe only way to truly secure something is to make it inaccessible. You can't pick the lock of a door if it's a wall, you know.
- iamcaps 6y agoSo as I recently got a Mac from a guy and he don’t remember the password and I’m stuck on activation lock should I keep it or should I sell it or throw it ! Thanks a lot