4 ms·
Pre-T2 macs had eficheck to verify the EFI's integrity, but with the T2 being so secure, it's not necessary anymore: https://openradar.appspot.com/radar?id=5020
by zydeco 6y ago
Pre-T2 macs had eficheck to verify the EFI's integrity, but with the T2 being so secure, it's not necessary anymore: https://openradar.appspot.com/radar?id=5020911870672896 https://openradar.appspot.com/radar?id=5020911870672896
- MuffinFlavored 6y agoHow are these hackers modifying the EFI section without any kind of digital signature? It's really wide open for writing on all new Macs?
- zydeco 6y agoThe EFI firmware is validated by the T2, which then passes it on to the x86 CPU. I assume this modification would not persist after the T2 reboots.
- aunali1 6y agoUnfortunately, this is not the complete picture. The T2 simply programs the embedded flash within the PCH over an eSPI interface. Meaning, a successful reprogram from the T2 WILL persist until the following occurs: - A T2 Restore - A macOS System Update
- penwellr 6y agorickmark here: Sorry no, that's inaccurate. The T2 provides MacEFI.im4 to the Intel processor by emulating a flash controller over eSPI. So by modifying this file, and removing signature checks you can run any payload you like (see the EFI replacement video)
- MuffinFlavored 6y agoSo there is some kind of signature defeat involved, correct?
- h0m3us3r 6y agoYes, sigchecks had to be patched out of the kernel. And yes, it does not persist T2 reboot, but T2 only reboots if you hold power button for 5 sec. MacOS "reboot" does _not_ reboot T2.
- deleted 6y ago[deleted]