16 ms·
Hi guys, I am part of the team working on all things T2. [1] The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The pa
by aunali1 6y ago
Hi guys, I am part of the team working on all things T2. [1]
The checkra1n support is just in a PoC state, it will successfully exploit and boot the T2. The payload support is partially broken, but being worked on.
Additionally, we have SSH working over usbmuxd from a tethered device [2] and SSH working from macOS on device, with an SDK in the works [3].
Some key takeaways from the T2 being jailbroken:
- Custom Bootloaders (OpenCore, Coreboot, etc) are now possible as the T2 validates/sends the UEFI payload to PCH using a bridgeOS binary called MacEFIUtil, which can trivially have its signature checks patched.
- Filevault and by extension Touch ID are more or less crippled, especially in light of the recent SEP exploits. Amusingly, Apple uses a hardcoded "passcode", analogous to an iDevice's unlock pin in plain text within the UEFI firmware.
- Support for In-System Debugging of the PCH/Intel processor over USB. This works in a similar fashion to those Bonobo cable used for debugging iDevices [4]. We are working on building an accessory that you can purchase and plug into your Mac with a USB male endpoint exposing Intel's DCI debugging protocol.
- Lightweight AppleSilicon Tinkering environment. With SSH support from macOS on device, and the T2's modest specs, its a nice sandbox for messing with arm64 stuff. It's a pretty peppy chip, at times coming close to my 8th gen i7...yikes.
1. https://www.theiphonewiki.com/wiki/T8012_checkm8 https://www.theiphonewiki.com/wiki/T8012_checkm8
2. https://twitter.com/qwertyoruiopz/status/1237904335184564224 https://twitter.com/qwertyoruiopz/status/1237904335184564224
3. https://twitter.com/su_rickmark/status/1286886010681462784 https://twitter.com/su_rickmark/status/1286886010681462784
4. http://bonoboswd.com/ http://bonoboswd.com/
- DaiPlusPlus 6y agoThank you for your work! Do you have any thoughts about what Apple's switch to own-brand ARM chips in laptops and desktops will mean for T2/T3/etc?
- aunali1 6y agoThe T2 was more or less a stopgap solution between their current Intel-based offerings and the AppleSilicon devices in regards to their security aspirations. My understanding is that there will be no T3, as evidenced in the DTK, which makes a lot of sense considering how identical these chips will be to their mobile counterparts.
- mindfulhack 6y agoI'm a user on a 2019 16-inch MBP (MacBookPro16,1) who hopes to move to Linux as my base OS on this hardware full-time over the next 12 months. (https://github.com/Dunedan/mbp-2016-linux https://github.com/Dunedan/mbp-2016-linux) This is because I honestly cannot find a laptop with the combination of 64+ GB RAM, a non-NDIVIA GPU (edit: to clarify, this is because of NVIDIA's notoriously bad compatibility with Linux), and other premium hardware aspects like its market-leading trackpad at this time - and I doubt that will change anytime soon. I live with the debilitating T2 kernel panic hardware bug every week. There's also a very bad graphics bug that I and many others are facing. (Not sure if that one can be avoided by simply using Linux.) I just want to do away with this T2 chip, and whatever it does to get in the way of an otherwise great Intel-based computing experience. The CPU can handle all my encryption just fine... Thank you to your team for what you're doing. I assume Apple will constantly patch T2 jailbreaks with future macOS system updates (as that's how firmware is updated), and play a long-term cat and mouse game.
- fsflover 6y ago> I honestly cannot find a laptop with the combination of 64 GB RAM, a non-NDIVIA GPU, and other premium hardware like its market-leading trackpad at this time Only 14”, and perhaps less performant, but here is this one: https://puri.sm/products/librem-14/ https://puri.sm/products/librem-14/.
- mindfulhack 6y agoYes, I'm after 15"+ too.
- fsflover 6y agoThey also have a 15” version, but it’s much less performant. They will probably present a new model soon with the same specs like the one above.
- 6y ago
- peteretep 6y ago> Filevault and by extension Touch ID are more or less crippled Sorry, what does this sentence mean? That someone with physical access to my machine can now unencrypt my FileVault encrypted hard drive?
- deepstack 6y agoSome one from Apple, I'm sure you read this. Please answer this ASAP. I rely on mac and FileValute for professional use at work. Need to know the state of this exploit.
- m1gu3l 6y agolol good luck and god bless with all that.
- pstadler 6y agoBow for the chosen one!
- devenblake 6y ago> I rely on Mac and FileVault for professional use ... then phase out your use, because proprietary systems will always get cracked given enough time.
- acdha 6y agoGood point, let’s switch to unbreakable open source systems based on OpenSSL instead. This kind of advocacy is not only unhelpful but actually counterproductive
- tedunangst 6y agoSoftware encryption is very often much easier to rotate than integrated solutions. When all the TPM chips were broken, Windows stopped using them for BitLocker, but didn't reencrypt any of the affected disks. They're just as vulnerable as they were.
- teruakohatu 6y agoIncredible work. > It's a pretty peppy chip, at times coming close to my 8th gen i7...yikes. Have you got any benchmarks? It is passively cooled right? I am really surprised to hear a ~2016 arm64 CPU can can beat a 2019 Intel i7 in even synthetic benchmarks.
- Grazester 6y agoNot to be stickler but he said come close, not beat. Not that it's any less impressive.
- PragmaticPulp 6y agoSome synthetic benchmarks are so simple that they almost reduce to a measure of CPU clock speed and instruction parallelism. Find a benchmark that uses a unique instruction combination on one CPU and it will heavily disadvantage the other CPU. Add a real world workload to the mix with heavy memory access and mixed compute workloads and the chips will diverge significantly in performance. I work with some cross-platform code that has to run on mobile devices and desktop platforms. The advances Apple has made in low power performance are incredible, but the idea that their iPhone chips are as fast as desktop computers is still far from the truth unless you’re measuring specific, heavily optimized workloads. I’m still excited to see what Apple can do with a full desktop level power budget though.
- saagarjha 6y agoI suspect the "benchmarks are stupid" comments will die down the moment people start running desktop software on these chips, because it will cease to be a convenient excuse. While benchmarks may occasionally be slightly misleading, they are usually a good indicator of performance if done well–and if you've ever actually run desktop-class software on one of these chips you'll see that the divergence is just not there.
- aunali1 6y agoMostly synthetics and some program compilation (configure+make) tests. Yes, it is passively cooled. To clarify, it does not match the host Intel CPU (i7-8750H @ 2.2GHz) but in some synthetics, i.e. Coremark, the T2 does come close. I would attribute the i7's lackluster performance mainly to thermal throttling issues.
- PostThisTooFast 6y agoCan we make the embarrassing emoji bar useful now? Like turning it into a giant Delete key (since Apple idiotically omits a real Delete key from its keyboards).
- Causality1 6y agoYou guys are fighting the good fight for everything that owning hardware and being a user used to mean. Thank you.
- deleted 6y ago[deleted]
- curiousgal 6y agoI never understood this sentiment, if people choose to pay their way into a walled garden, why should they still care about hardware ownership/repairabilty, etc.?
- CraigJPerry 6y agoProbably comes down to definition of choice. Up thread someone else is describing how a particular macbook is the only hardware meeting their criteria but the OS is hobbling them.
- toyg 6y agoIt's a trade-off. I buy MBPs for the great form-factor and OS, not for the walled-garden shenanigans. If those shenanigans can be somewhat reduced, the trade-off balance looks better.
- Ductapemaster 6y agoI don't mean to me facetious, but I am genuinely curious: why should you get to have it your way? You are attempting to buy a product they do not sell.
- Karunamon 6y agoBecause a hardware vendor telling you what you can and can't do with the stuff you own is immoral.
- 6y ago
- Aaargh20318 6y agoI hope you have reported the issue to Apple so they can fix it ASAP ?
- saagarjha 6y agoThey are well aware of the issue and have been for some time. There’s not all that much they can do to fix this, although they have certainly tried.
- btreecat 6y ago> There’s not all that much they can do to fix this, although they have certainly tried. Forgive my ignorance, why is there not much they can do and what have they tried?
- hoytschermerhrn 6y agoMy understanding is that because this is a hardware-based issue, there’s no way to release a software patch to fix it.
- saagarjha 6y agoApple tried to use a side channel in their security coprocessor to detect if the device had booted out of DFU (which is part of how the exploit worked). This didn't work because people found a vulnerability in that processor itself.
- 56khole 6y agoFirstly, thanks so much for your hard work. All I want is to run Arch on an MBP 15,1. I've given your repos on Github a try--do you have a functioning bootloader config? T2 just freezes GRUB for me no matter what I try. Thanks again
- hlandau 6y ago>Custom bootloaders are now possible This is interesting; does this mean Apple isn't enabling Intel Boot Guard, relying only on the checks enforced by MacEFIUtil? Fantastic work, by the way.
- easton 6y agoThey aren’t, they’ve removed much of the Intel software that is usually included with UEFI except what is required for DRMed video. If the T2 is compromised, they say that one could compromise UEFI on the device permanently as well. https://support.apple.com/guide/security/uefi-firmware-overview-seced055bcf6/1/web/1 https://support.apple.com/guide/security/uefi-firmware-overv...
- Wowfunhappy 6y ago...this is starting to feel like a major screwup on Apple’s part, is there a reason to think otherwise?
- easton 6y agoYes, although now the Mac is as secure as any PC with UEFI Secure Boot (and no Intel ME), which isn’t necessarily the end of the world if you have a long firmware password (which protects the Recovery Mode secure boot utility) and login password (which protects FileVault). If you’re in a position where you could be compromised by a state actor or a hacker group (that can find a public flaw in Secure Boot that isn’t just turning it off), perhaps throw away your Mac, but everyone else should still be “okay”. Part of me wonders if there could be a way to permanently disable DFU mode (preferably outside of epoxy in the upper left USB-C port). That would prevent someone from jailbreaking the T2, albeit you would no longer be able to replace the SSD or Touch ID sensor (not that you’d want to anyway if you were at risk).
- aunali1 6y agoUnfortunately, physically obstructing the primary port would not completely prevent DFU from being accessed. With the aforementioned accessory device, the ACE Type-C controllers within Macs can automatically reroute the DFU, DCI, and PCH/T2 UARTs to any of the other ports, irrespective of the T2 and PCH. Apple uses this technique as part of their factory test harness.
- saberience 6y agoWhy do you believe it's moral for you to do work which is making people's data less secure, helping law authority crack iPhones, etc?
- saagarjha 6y agoThe same work allows users to have control over the hardware they own as well.
- vladvasiliu 6y agoIt could be argued that work like this actually helps make people's data more secure. Granted, owners of the affected hardware might not like it, but this sheds light on issues that are actually present in the hardware. Who's to say that "law authority" or some criminal organization didn't do any work on this without intention to publish their results? If people have sensitive data and were counting the T2 chip to keep it secure, now they know there are limitations to this security model. They can now weigh the pros and cons and, if applicable, set up an alternative that will be more secure. This could also push Apple to provide better security in upcoming products.
- netsharc 6y agoImagine if their "evil twins" working in the dark or for the NSA, KGB or Red Army, have cracked this but not tweeted about it. Now the Apple security is just as broken but you don't know about it. Is your data more or less secure?
- hu3 6y agoWhat makes you think state actors with inifinite budgets didn't do what this one guy is doing? Everything he exposes will be fixed and improved. If anything he's helping make Apple devices more secure.
- userbinator 6y agoIt's work which is enabling freedom, something that people are unfortunately giving up far too much of these days...
- dstroot 6y ago>Hi guys, I am part of the team working on all things T2. So there is a team working on this? What is the incentive model? Are you paid to do this work? What is the revenue model? I woke up today learning my MacBook Pro is now substantially less secure but why? So I can run games on the touch bar? So I can use the T2 as a raspberry pi?
- denis1 6y agoYour MacBook Pro didn't now become less secure. It always was. We should be thankful to these people for making the vulnerability clear to us.
- acolumb 6y agoThere is a team taking advantage (jailbreaking on iOS) of the security flaw in all A-series chips up to A11 in the hardware-level bootloader. The T2 in your 2018 or newer Mac is a variant of the A10. The bootROM flaw allows for an exploit that can only be executed with physical access, another Mac and DFU mode. It's not persistent. The main use of this exploit was to install unsigned code on iOS devices (jailbreaking.) The team is doing it for free, however many contributors take advantage of Apple's bug bounty program for income, therefore making newer devices more secure.
- aunali1 6y agoI would say it is persistent enough to be malicious. The T2 does not reboot, with the exception occuring during a DFU restore, extremely drained battery, or firmware update. With that in mind, a party intending harm would have more than enough time.
- deleted 6y ago[deleted]
- MartinNobel 6y agoThe T2 Mac startup chime is located in /System/Library/PrivateFrameworks/BridgeAccessibilitySupport.framework/AXEFIAudio_VoiceOver_Boot.aiff . I think it will only be months until someone manages to change the 'bong' sound into a custom startup chime. This will be very interesting...