Skip to content

Comment on Apple T2 Security Chip: Security Overview [pdf]parent

Comments

Why you need security chip to ensure that?

So no malware can be installed to override a software based interlock. No malware can alter the contents of the T2 chip so code there cannot be changed, altered or mitigated.

The T2 chip is just an ARM CPU running a customized version of watchOS. So in theory malware could take over control of the T2 chip.

I also wonder what implications on features like the mentioned microphone disconnect that'd have. My guess is that the T2 chip which also acts as audio controller, simply doesn't forward audio signals received from the microphone to macOS if the lid is closed.

Edit: Never mind. After reading further it becomes clear that it's really disconnected in hardware:

This disconnect is implemented in hardware alone, and therefore > prevents any software, even with root or kernel privileges in macOS, and even > the software on the T2 chip, from engaging the microphone when the lid is > closed.

To prevent nefarious software from listening in unknown to you.

Why it needs to go trough security chip?

Laptop closed -> microphone cut off does not need complex logic. It's just simple switch.

Hardware switches are more expensive and less durable.

the NSA/CIA/3LA can't backdoor a physical switch

Why not?

Do you have schematics of your laptop?

I don't think you do, it's just an additional security feature that they put in the T2 PDF for some reason.

If the trigger is mechanical it's ok, but if the trigger is electrical (and handled by some hardware) then the chip is useful.

So Bloomberg has something for a slow news day.

Because if you don't mention that you've got a hardware switch covering the mic someone will ask you why your security chip has this glaringly obvious hole in it.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.