{"id":83758,"date":"2020-10-07T16:50:01","date_gmt":"2020-10-07T13:50:01","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/vulnerability-found-in-apples-t2-security-chip\/"},"modified":"2020-10-07T16:50:01","modified_gmt":"2020-10-07T13:50:01","slug":"vulnerability-found-in-apples-t2-security-chip","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/vulnerability-found-in-apples-t2-security-chip\/","title":{"rendered":"#Vulnerability found in Apple&#8217;s T2 security chip"},"content":{"rendered":"<p>&#8220;<strong>#Vulnerability found in <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">App<\/a>le&#8217;s T2 security chip<\/strong>&#8221;<\/p>\n<div>\n<div class=\"article-gallery lightGallery\">\n<div data-thumb=\"https:\/\/scx1.b-cdn.net\/csz\/news\/tmb\/2020\/securitychip.jpg\" data-src=\"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2020\/securitychip.jpg\" data-sub-html=\"Credit: Pixabay\/CC0 Public Domain\">\n<figure class=\"article-img\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/scx1.b-cdn.net\/csz\/news\/800\/2020\/securitychip.jpg\" alt=\"security chip\" title=\"Credit: Pixabay\/CC0 Public Domain\" width=\"800\" height=\"480\"\/><figcaption class=\"text-darken text-low-up text-truncate-js text-truncate mt-3\">\n                Credit: Pixabay\/CC0 Public Domain<br \/>\n            <\/figcaption><\/figure>\n<\/div>\n<\/div>\n<p>Security firm IronPeak has found a vulnerability in Apple&#8217;s T2 security chip. They claim in a blog <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/ironpeak.be\/blog\/crouching-t2-hidden-danger\/\">post<\/a> that the vulnerability allows would-be hackers to gain root access to a wide variety of Apple computers.<\/p>\n<p>                                                                                Back in 2016, Apple introduced the T1 security chip. Its purpose was to serve as a secondary line of defense for Apple computers\u2014Apple referred to the chip as a gatekeeper for certain functions. Two years later, Apple introduced the T2 security chip\u2014it had more functionally and thus more features, which presumably made Apple computers even more secure. Unfortunately, it appears that the T2 security chip, at least according to IronPeak, has a very serious vulnerability of its own\u2014it allows an unauthorized user to gain root access, which gives virtually unlimited access to everything on the computer\u2014everything except user data. But it is also vulnerable to keylogger installation, which could capture the keystrokes of a legitimate user typing passwords, allowing access to user data and to applications such as banking and credit cards. Root access also allows for installing other software, such as programs that send captured data to hackers waiting for it online.<\/p>\n<p>Computers that have the vulnerability include most iMacs made in 2020, recent iMac Pros, Mac minis from 2018 on, Macbook Air computers made after 2018 and Macbook Pros made after 2018. Apple users who want to know if their computer has the vulnerability can check System Information to see if it lists the Apple T2 chip. Even worse for Mac owners, because the vulnerability is hardware-based, there is no patch coming to fix it. Users will likely have little recourse as it appears unlikely that Apple will redesign the T2 chip to work without the vulnerability anytime soon.<\/p>\n<p>There is one piece of good <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a>\u2014the vulnerability is physical, which means a hacker would require either direct access to the computer or indirect physical access, such as through a USB cable. This means that most Apple computer owners are at very low risk. The real risk lies with so-called state actors\u2014people using computers on behalf of government entities. If they are working with sensitive information, they could be at high risk.\n                                                                                                                        <\/p>\n<hr\/>\n<div class=\"article-main__explore my-4 d-print-none\">\n<p>                                            <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" class=\"text-medium text-info mt-2 d-inline-block\" href=\"https:\/\/phys.org\/news\/2014-02-apple-readies-mac-ios-flaw.html\">Apple readies security fix for Mac after iOS flaw<\/a>\n                                        <\/div>\n<hr class=\"mb-4\"\/>\n<div class=\"article-main__more p-4\">\n                                                                                                <strong>More information:<\/strong><br \/>\n                                                <a rel=\"nofollow noopener noreferrer\" target=\"_blank\" href=\"https:\/\/ironpeak.be\/blog\/crouching-t2-hidden-danger\/\">ironpeak.be\/blog\/crouching-t2-hidden-danger\/<\/a><\/p><\/div>\n<p class=\"article-main__note mt-4\">\n                                                \u00a9 2020 <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/sciencee\/\" data-internallinksmanager029f6b8e52c=\"5\" title=\"Science\" target=\"_blank\" rel=\"noopener\">Science<\/a> X Network<\/p>\n<p>                                        <!-- print only --><\/p>\n<div class=\"d-none d-print-block\">\n<p>                                                 <strong>Citation<\/strong>:<br \/>\n                                                 Vulnerability found in Apple&#8217;s T2 security chip (2020, October  7)<br \/>\n                                                 retrieved  7 October 2020<br \/>\n                                                 from https:\/\/techxplore.com\/news\/2020-10-vulnerability-apple-t2-chip.html<\/p>\n<p>                                            This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no<br \/>\n                                            part may be reproduced without the written permission. The content is provided for information purposes only.<\/p><\/div>\n<\/p><\/div>\n<p><script id=\"facebook-jssdk\" async=\"\" src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js\"><\/script><\/p>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more Like this articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/science\/\" target=\"_blank\" rel=\"noopener noreferrer\">Science category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/techxplore.com\/news\/2020-10-vulnerability-apple-t2-chip.html\" target=\"_blank\" rel=\"noopener noreferrer\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Vulnerability found in Apple&#8217;s T2 security chip&#8221; Credit: Pixabay\/CC0 Public Domain Security firm IronPeak has found a vulnerability in Apple&#8217;s T2 security chip. They claim in a blog post that the vulnerability allows would-be hackers to gain root access to a wide variety of Apple computers. Back in 2016, Apple introduced the T1 security chip&#8230;.<\/p>\n","protected":false},"author":1,"featured_media":83759,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2020\/securitychip.jpg","fifu_image_alt":"","footnotes":""},"categories":[16],"tags":[],"class_list":["post-83758","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sciencee"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/83758","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=83758"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/83758\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/83759"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=83758"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=83758"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=83758"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}