Page 1 of 1

Unpatchable security flaw found in all Apple Silicon CPUs

Posted: Fri Mar 22, 2024 8:14 pm
by OpenXTalkPaul
Academic researchers discovered the vulnerability, first reported by Ars Technica, which allows hackers to gain access to secret encryption keys on Apple computers with Apple's new Silicon M-Series chipset. This includes the M1, M2, and M3 Apple MacBook and Mac computer models.  
Glad that I never did spend the money on an Apple Silicon Mac.
https://mashable.com/article/apple-sili ... ption-keys

Re: Unpatchable security flaw found in all Apple Silicon CPUs

Posted: Fri Mar 22, 2024 8:19 pm
by tperry2x
Oh dear. Very difficult to rectify that indeed. That's the kind of thing that makes certain folks at my workplace 'sit up and take notice', and by that I mean likely create a mandatory policy that nobody is to use a Mac based on Apple silicon, and probably ban that across the entire trust of schools (19 and counting).

Re: Unpatchable security flaw found in all Apple Silicon CPUs

Posted: Sat Mar 23, 2024 7:08 am
by richmond62
So no great urgency about working out how to build Mac Silicon standalones witH OXT. 8-)

Re: Unpatchable security flaw found in all Apple Silicon CPUs

Posted: Sat Mar 23, 2024 7:37 am
by tperry2x
Haha, I suppose that's one way of looking at it.

I don't see Apple reverting to intel again though. They very rarely U-turn, even in the face of incontrovertible evidence of a bad idea (the charging cable port underneath a magic-mouse for example).

They could maybe disable the affected part via a firmware update (again unlikely). This will likely be some kind of firmware bolt-on security patch, between the prefetch and the hardware, involving additional obfuscation and encryption.

It will greatly lesson the speed gains seem in the m-series chips, and also affect their efficiency - therefore impacting battery life too in laptops I'd imagine. (Two main reasons why anyone would want to switch to apple silicon in the first place).

Will have to see how it pans out. That's not to say that Microsoft or Linux don't have security concerns too.

But largely MS and Linux aren't advertising their systems as 'unhackable'. Apple have always framed the device lock-in and closed ecosystem as to why the Mac is secure, but things like the vulnerability above make all those security gestures a bit null and void.

Re: Unpatchable security flaw found in all Apple Silicon CPUs

Posted: Sat Mar 23, 2024 8:05 am
by richmond62
We all know something I learnt in America in 1993: Apple built a system-cum-machine so, like an automatic car, you did not have to concentrate on certain things as much as one with a manual gear box. While Windows was there you run on any IBM compatible any company could cobble together.

And, in 1993 comparing the Apple GUI (Mac OS 7) with the Microsoft one (Windows 3.1); there was no contest: all double declutching with Windows 3.1.

Now, 30+ years later things are not the same, but Apple still pumps out the same propaganda.

And, as Apple has a virtual monopoly in the Paris Hilton glitz department, it can get away with its expensive thing that looks more and more like a plastic bath toy. Microsoft (who have their own faults) at least experience some threat from Linux.

And this fiasco proves that Apple have become complacent owing to a lack of competition in their niche.