this post was submitted on 21 Jul 2023
932 points (100.0% liked)
Technology
37739 readers
730 users here now
A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.
Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.
Subcommunities on Beehaw:
This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
I see.
I was going on the fact that the T2 has a "No Security" option for its Secure Boot config, while according to Apple Support the Apple Silicon ones (I don't have one) only offer "Full" or "Reduced" security, which would still require signing: Change security settings on the startup disk of a Mac with Apple silicon
Dunno how the Asahi folks are planning on doing it, but they do indeed say there is no bootlock 🤔
Update: according to the Asahi docs, I seem to understand that Apple Silicon devices allow creating some sort of "OS containers" that can be chosen to boot from separately from the Mac OS one, and in such a custom container the security can be set to "permissive" limited to that container: https://github.com/AsahiLinux/docs/wiki/Open-OS-Ecosystem-on-Apple-Silicon-Macs Interesting.
Yep, that’s a fitting term. You definitely still have to rely on macOS (and keep a copy of it around, e.g. for firmware upgrades, which of course basically only come bundled with macOS versions), but other than that, you can do more or less what you want to – as long as you’re outside of it.
I quite like this idea though if I’m being honest, normie users get all the hardened security from the regular boot chain without experiencing basically any difference/downsides, while hardware enthusiasts and (Linux) tinkerers still have options open (well, options that you can get if you have a new chip on a rarer architecture with previously no third party OS).