4 ms·
> you need ongoing physical access in order to install and maintain a presence on the device I don’t think that’s 100% true. Yes, you need persistent hardware
by CodeWriter23 6y ago
> you need ongoing physical access in order to install and maintain a presence on the device
I don’t think that’s 100% true. Yes, you need persistent hardware to re-root the T2 on every reboot. But what about a one and done T2 attack - a drive by keylogger installer? Get credentials and then mount a more traditional attack to install APT/RAT.
- danpalmer 6y agoYeah so the user should reboot if they believe someone has tampered with the device, such as after a TSA check.
- kelnos 6y agoWill that help for all cases, though? Wouldn't this allow someone to install a persistent keylogger that would survive reboots? Also from my reading of that, the T2 chip doesn't reboot with the laptop -- it stays powered on at all times after it first starts up. If that's really the case, a reboot won't do much except kill non-persistent things that are running on macOS itself.
- CodeWriter23 6y agoThe article says you need a hardware device to maintain persistence and also recommends using Apple Configurator to “ reinstall bridgeOS on your T2 chip“. So, a) a T2 hack persists until such reinstall and b) you don’t need a persistent beachhead if you’ve taken the hill and maintain persistence there. This exploit opens the door to that, and you can install keyboard intercepts via the new System Extensions Interface. Did it yesterday myself via an update to Karibiner. Notarization can be disabled by interrupting the network pathway and you can definitely disable SIP after you capture the password. In essence, T2 is the lynchpin that prevents the defeat of other aspects of macOS security.