meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, October 7th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 7 October 2020

⏱️ 9 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Apple T2 Chip Vulnerability; NVIDIA; Cloudflare; Gavatar Privacy

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, October 7th, 2020 edition of the Sansonet Storm Center's

0:06.8

Stormcast. My name is Johannes Ulrich, and I'm recording from Jackstable, Florida.

0:13.6

I believe it was just yesterday that I talked about a UFI root kit that has been found in the wild well and today we do have a similar

0:25.4

story to start out with about sort of these embedded hardware slash firmware problems

0:33.0

this time affecting Apple's T2 security chip.

0:38.6

Now, first of all, what this T2 chip is trying to do is fundamentally difficult.

0:43.9

It's trying to protect a system from an attacker that has physical access to the system.

0:52.0

And of course, in the past, this has often failed, and apparently the T2 chip

0:57.0

doesn't get it quite right either. Now, this particular chip is not something that is sort of

1:04.7

standing on its own. It was developed just a security chip. It's actually based on Apple's A10 CPU that has been found in older iPhones.

1:16.8

And with that, well, we have a fully capable CPU. We also get pretty much a full operating system

1:23.7

called Bridge OS, which apparently is loosely based on watch OS.

1:30.3

So you have a CPU and you have a more or less fully functional operating system.

1:36.3

And essentially what this does is it carries over the security concept that was originally developed for the iPhone.

1:45.0

The iPhone in its 8-10 chip has a secure enclave processor that essentially stores things like

1:53.0

secrets.

1:54.0

And yes, this same SEP, the same secure enclave processor, also exists within the T2 chip.

2:02.5

And now it also has an operating system, but this operating system exists in ROM,

2:09.1

and that's a security feature in that it cannot physically be patched or updated.

2:16.0

But of course, by being based on the A10 processor and the SAP coming with that processor,

2:24.1

this T2 chip appears to be vulnerable to some of the same problems.

2:29.3

In particular, the checkmate exploit that of course has been taking advantage of now for a while to jail break iPhones.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.