6 ms·
Why not just do the usual dd if=/dev/zero of=<disk> bs=1M count=1024 instead of using those weird proprietary tools?
by devit 6y ago
Why not just do the usual dd if=/dev/zero of=<disk> bs=1M count=1024 instead of using those weird proprietary tools?
- sillysaurusx 6y agoYou'd likely brick your mac if you don't do it the anointed way.
- my123 6y agoAs long as you don't shoot yourself in the foot by touching other NVMe namespaces (and even that should be recoverable) and the SPI flash onboard, things can be restorable through DFU.
- wtallis 6y agoWhile it would make a lot of sense for Apple to use NVMe namespaces in this manner, it appears from information posted elsewhere in this thread by marcan_42 that Apple is not doing so, and is just using regular GPT partitions within a single NVMe namespace to store the stuff that isn't on the motherboard's NOR flash.
- my123 6y agoI can tell you that devices with Apple CPUs _do_ have multiple NVMe namespaces. The recovery OS and 1TR are not data needed to be saved permanently (as in serial number and such, without which you cannot restore the device), you can recover them through DFU. Data critical for being able to restore is in the SPI flash. (and it's assumed that some of it might be in other NVMe namespaces too)
- jabberwcky 6y agoThis option is horrendously inefficient on most modern drives. For many SSDs, issuing a secure erase request is an almost instantaneous process as it only requires the drive to generate a replacement encryption key, and need not even entail bulk writing or erasing physical flash pages
- wtallis 6y agoWriting 1 GB of zeros is also almost instantaneous. Even though it's overkill, writing 1 GB is hardly worth worrying about. Though I'd recommend also wiping the backup GPT at the end of the drive.
- jabberwcky 6y agoIt is still bad advice, zero filling an SSD is not nearly the same as erasing it due to the presence of large (up to 10% or more of the drive) overprovisioning areas present in all devices, ignoring the permanent wear zero-filling the drive also causes, and the fact the controller believes real data remains stored, placing restrictions on its ability to perform internal maintenance
- wtallis 6y agoIt's fine advice. The wear of writing 1GB of zeros can and should be ignored. It's insignificant. And the drive's spare area is only relevant if you're trying to thoroughly wipe sensitive information from a device before disposing of it. But right now we're just trying to make a device appear functionally empty so that we can re-install an OS without remnants of any previous installation getting in the way. This does not require the (sometimes dubious) security assurances of a secure erase command.
- jabberwcky 6y ago> But right now we're just trying to make a device appear functionally empty so that we can re-install an OS without remnants of any previous installation getting in the way The only portable, reliable, robust way to accomplish this is wiping the drive. If the original author had issued a secure erase, they would not have encountered any subsequent difficulties, all of which were due to partially erasing the device.
- wtallis 6y ago> The only portable, reliable, robust way to accomplish this That's setting the bar too high. If we're comfortable with solutions that will work on all mainstream PC platforms including Macs, then it is sufficient to overwrite partition tables with zeros. I have never heard of an OS installer that scans for deleted partitions, and worrying about the possibility of such a thing causing problems is unreasonable.
- giuliomagnifico 6y agoNo. Don’t ever try dd. I suspect it will brick the Mac.
- rvz 6y agoYou do realise if you get this wrong, you can't simply 'replace' the SSD on an Apple Silicon based Mac? You'll likely brick the device if the recovery partition is also wiped in the process. It's back to the Apple Store for you.
- wtallis 6y agoFor years, Intel Macs have been able to net boot to install the OS onto an empty drive. Did Apple ditch that functionality or move it from the firmware to a recovery partition with the M1 Macs?
- m1mac 6y agoFrom what I can tell, Internet Recovery (which downloaded a recovery OS) is gone and replaced by 1TR which is stored on a hidden flash partition. 1TR is capable of downloading the OS and installing it, so in a way it can be considered the replacement for Internet Recovery. While architecturally simpler (and probably more secure by allowing the network stack to be removed from the low-level boot infrastructure?), the disadvantage is that you can mess up the 1TR partition. If you do, the only way to recover the machine is to do a DFU restore from another Mac via Apple Configurator. That's not terribly convenient if you don't have another Mac around. (An Apple Store can DFU restore for you, but last I checked Apple Stores are appointment-only due to COVID and it's almost impossible to get an appointment there these days.)
- tannhaeuser 6y ago> probably more secure by allowing the network stack to be removed from the low-level boot infrastructure That's up for debate due to certificate expiration issues, isn't it?
- marcan_42 6y agoThat "bricks" your Mac, and you have to do a DFU restore with Apple Configurator 2 to recover from it. The SSD on these Macs contains system firmware, including the boot picker and recovery mode. Do not wipe the entire top-level block device. They cannot boot from external media, by design. M1 Macs are not PCs, and you shouldn't blindly apply whatever you think you know from the PC world. Their low-level design is much closer to an embedded device like a Raspberry Pi, minus the SD card slot. https://github.com/AsahiLinux/docs/wiki/M1-vs.-PC-Boot https://github.com/AsahiLinux/docs/wiki/M1-vs.-PC-Boot It's hard to truly brick these things (you need to wipe NOR flash for that, and even then Apple can fix it without taking them apart, but you can't, because if you wipe NOR flash calibration data is gone and it has to go back through part of the manufacturing test process), but wiping the entire SSD isn't going to help you. If you start messing at that level, you'd better be prepared with another Mac and Apple Configurator 2 to get a proper clean start.
- tannhaeuser 6y agoThat's scary. Back on my old PowerBook, I saw it as an advantage that OpenFirmware could boot from external devices in the most straightforward way, and could act in target disk mode, and so did Apple. Hearing of all these troubles, I'm genuinely concerned with using MacOS today because of these unknown unknowns. What's the threat that this Apple bossing is supposed to shield against that couldn't be achieved by mere disk encryption?
- sneak 6y agoAdvanced desktop malware, for one. Theft of devices, for another.
- userbinator 6y agoTheir low-level design is much closer to an embedded device like a Raspberry Pi, minus the SD card slot. ...or like a iPhone. From that article you linked: Some PC motherboards implement a similar feature as part of a separate chip, which can flash the UEFI firmware from a USB stick without actually turning on the motherboard normally, but this is only common in higher-end stand alone motherboards. That might be referring to boot-block recovery, and I haven't seen any with a "separate chip" besides the dual-BIOS type; it's in the same flash (just a normally write-protected part) as the rest of the BIOS. The older ones will look for a flashable ROM image on the first floppy drive, but I'm not surprised if the newer ones will do it with USB instead.