4 ms·
It is indeed a failed design. What you describe is how FV2 in Apple devices work. You have a native always-on DEK (Data Encryption Key) in the SEP (Secure Encla
by oneplane 2y ago
It is indeed a failed design. What you describe is how FV2 in Apple devices work. You have a native always-on DEK (Data Encryption Key) in the SEP (Secure Enclave Processor) that itself is encrypted with a KEK (Key Encryption Key) which in turn can have multiple encrypted versions for different end-users, which each has their password to decrypt the KEK, or better, authenticate to the SEP and it will decrypt the KEK. This is not exactly how it works, but a simplified story.
On top of that, there is indeed a small secure pre-boot stage where the user (any local user) logs in, which does both the OS login as well as the disk decryption (well, KEK decryption but that's a detail). It is of course also using a KDF so it's not just the end-user's password plainly applied to a cryptography function. This too is a simplified story (the pre-boot isn't actually a preboot, the OS is on a read-only signed volume since it's not secret/confidential, it's only important to prevent tampering).
This works, it works well, and has not had any real durable attacks that work against it so far.
- wat10000 2y agoYep. I’m a Mac user and the FDE is basically transparent. The only thing you notice in normal use is that you get a login prompt immediately when (re)booting, and the actual OS boot happens after that, as opposed to booting and then logging in.
- Cumpiler69 2y ago>It is indeed a failed design. What you describe is how FV2 in Apple devices work. You have a native always-on DEK (Data Encryption Key) in the SEP (Secure Enclave Processor) That's what TPM 2.0 is supposed to do on PC and why Microsoft is demanding it for Windows 11 yet people don't seem to see the need for it for some reason, then whine about the security implementation.
- whatevaa 2y agoCause literally millions of devices will end up in landfills. Not figuratevelly, literally.
- Cumpiler69 2y agoWhat happened to the MACs that had no secure enclave?
- brirec 2y agoThat’s whataboutism — Apple slowly has been precluding all of those from getting the latest updates officially (I think the iMac Pro is the last supported Mac without a T2 chip), and they’re ostensibly supposed to go into the landfill too, and that’s also bad!
- Cumpiler69 2y agoIt's not whataboutism, it was a very relevant question and possibly a precedent, no need to react aggressively. For one, you can't implement blanket security features on an OS unless all devices have TPM 2.0, so all users who want the better security will have to have TPM 2.0 devices. Those who don't can stay on current hardware and use it till it falls apart. Secondly, if Microsoft is bad for deprecating SW support for devices without HW security features why isn't the same uproar against Apple for doing the same?
- wat10000 2y agoI may not be hanging out in the right places, but the uproar seems to be about the same to me. I.e. for both of them, it’s a few angry comments online.