In addition, Apple has a mechanism they use to only allow recent versions of their software to be installed on devices, by requiring a "phone home" process when you install it. This requirement can be disabled *after* you have a working install.
-
Show this thread
-
This makes sense; what Apple is doing is giving us advanced users a way to opt out of all of this, while making sure regular users cannot be compromised. The opt outs are stored on the SSD. So if you wipe your disk, Apple will treat your Mac like a secured device again.
1 reply 15 retweets 49 likesShow this thread -
One neat thing though, is that in fact these security settings are *per OS install*. This means that it should be entirely possible to dual-boot a *fully secure macOS* and Linux. That means you should be able to run iOS apps in macOS (which is disallowed without security).
4 replies 9 retweets 56 likesShow this thread -
This is like having an Android that can dual-boot the stock OS without OEM unlock and passing all SafetyNet checks, and also whatever custom OS you want without Gapps and anything else. Which is really cool.
1 reply 2 retweets 41 likesShow this thread -
So the takeaway here is: Apple have built a very clever secureboot process previously unseen in any kind of desktop computer. They make us go through hoops to boot Linux, but those hoops are there to protect normal users.
1 reply 39 retweets 156 likesShow this thread -
Once your Mac is set up with an OS install with permissive security, there is no phoning home or anything like that; that is just for from-scratch setups or if you need to reinstall.
1 reply 1 retweet 30 likesShow this thread -
It is up to us (i.e. Asahi Linux) to provide recovery mechanisms that allow you to fix a broken Linux install without having to depend on additional Apple software or do a full machine restore (and we will, don't worry).
1 reply 1 retweet 34 likesShow this thread -
In other words: Apple Silicon is like a Google Pixel device, but better. You need the factory OS to get to the "enable OEM unlock" toggle, and after that you're good. As long as you only mess with the installed OS (system/data partitions), you can do whatever you want.
1 reply 7 retweets 49 likesShow this thread -
On Android there is a signed, verified boot chain, up until the OS kernel where unlocking is possible - exactly the same as on Apple Silicon. Apple Silicon allows multiple installed OSes, and that boundary is slightly before the OS kernel (includes OS loader and some firmware).
1 reply 3 retweets 28 likesShow this thread -
If you truly wipe all storage on Android, you hard-brick the device (unless you can find private vendor tools to restore from a blank slate, if possible at all). On Apple Silicon you can always fix it with a documented process - but it does involve phoning home to Apple.
2 replies 5 retweets 32 likesShow this thread
Apple Silicon Macs do have a separate NOR flash for core system firmware and manufacturing settings (think: serial numbers, certificates, calibration data, etc) - if you wipe *that* then you have to send the thing off to Apple to fix it. But there is no reason for us to touch NOR
-
-
I think that about sums things up for what to expect when setting up a Mac to run Asahi Linux. The actual process is all going to be automated in a `curl | sh` style thing in macOS or Recovery Mode, so regular users won't have to care much about the details either.
2 replies 1 retweet 69 likesShow this thread -
Hector Martin Retweeted Xeno Kovah
By the way, we have to thank
@XenoKovah,@NikolajSchlej, and everyone else involved for designing this process and making this entire thing possible.https://twitter.com/XenoKovah/status/1339914714055368704 …Hector Martin added,
Xeno Kovah @XenoKovahI purposely designed a mechanism so that M1 Macs would retain the capability to boot completely arbitrary code instead of XNU if users wanted. But you have to 1) reboot to recoveryOS with a physical power button press and 2) put in your SEP-backed credentials. https://twitter.com/NikolajSchlej/status/1339789591096614918 …Show this thread1 reply 5 retweets 70 likesShow this thread
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.