Hacker News new | ask | show | jobs
by morpheuskafka 2279 days ago
You had better not trust the T2 chip, because it is vulnerable to the checkm8 exploit and the checkra1n folks have already demonstrated total compromise. The encryption functionality isn't affected if you have FileVault on, because your password is not stored anywhere on the device, but everything else, from basic SMC functions like mic/cam/fans/touchbar to secure boot to verifying the microcode and ME firmware before loading are totally useless now.

AFAIK, the T2 is always powered on even when the main CPU is off, so this could have ultra-long-term persistence.

1 comments

Reference?