Jump to content
170 posts in this topic

Recommended Posts

9 minutes ago, deeveedee said:

 

I'll answer your question with another question.  Let's say we were to take an informal poll in this forum, where we ask each person with evidence of a security vulnerability to raise their hand.  If no one raises their hand, are we safe?

I would say, for sure, no. But as I said just before, mine was just a question, with no hidden agenda. That's it. So, if your answer to my question is "no", that's ok. I will not pose any doubt on that.

BTW - I believe that Open Core and CLOVER are safe. It is only OCLP that I have a problem with for the following reasons:

  1. OCLP breaks the macOS seal. With the broken seal, macOS loses much of its ability to protect from other threats that are not OCLP
  2. OCLP injects 3rd-party, uncertified software into the network layer. Without attestation to chain of custody and without a FIPS-certified lab test, allowing this on your Mac is insane
  3. OCLP must partially disable SIP (the way SIP is partially disabled, I'm not especially concerned about this, but the combination of the broken seal and injected 3rd-party software with SIP expands the threat/attack surface)

 

12 minutes ago, acquarius13 said:

I would say, for sure, no. But as I said just before, mine was just a question, with no hidden agenda. That's it. So, if your answer to my question is "no", that's ok. I will not pose any doubt on that.

 

I have formulated an attack scenario that I would use to hack an OCLP-patched Mac.  It is a multi-step process that I will not share.

Edited by deeveedee
  • Like 2
  • Thanks 1

Thanks, @eSaF. I am not bashing OCLP and I wouldn't bash for the sake of bashing.  The OCLP Devs have done a great job of creating software that is available to and usable by the masses who have Intel Macs.  Almost all of them will install OCLP without any knowledge of what is being discussed in this forum.

  • Like 1

All - you may not have appreciated my methods, but my intent with all my "hype" was to prompt a conversation with an OCLP Dev.  I was able to speak with a Dev and I rather enjoyed the conversation.  See here.

 

EDIT: As you see in MacRumors, OCLP Devs have some serious fans who won't spare any expense (or barb, attack or ridicule) to defend the OCLP Devs.

 

Now if you'll excuse me, I'm going to get back to writing that novel I mentioned.  I think it's going to be a best seller.

Edited by deeveedee
  • Like 2
2 hours ago, deeveedee said:

BTW - I believe that Open Core and CLOVER are safe. It is only OCLP that I have a problem with for the following reasons:

  1. OCLP breaks the macOS seal. With the broken seal, macOS loses much of its ability to protect from other threats that are not OCLP
  2. OCLP injects 3rd-party, uncertified software into the network layer. Without attestation to chain of custody and without a FIPS-certified lab test, allowing this on your Mac is insane
  3. OCLP must partially disable SIP (the way SIP is partially disabled, I'm not especially concerned about this, but the combination of the broken seal and injected 3rd-party software with SIP expands the threat/attack surface)

 

Nothing against getting hacked, but the inconvenience is just too much. If an update comes to ventura, you just click on install and come back 30 minutes later. But here, you need 5 restarts to just be able to click the "update' button. Shame, I wanted those moving wallpapers so much.

2 hours ago, Nightf4ll said:

Shame, I wanted those moving wallpapers so much.

 

I don't get it... what is so special with the moving wallpapers? Is it some kind of innovation that I can't appreciate like the rest of the users ? No major changes since BigSur and now we are excited for stuff like "wallpapers, new emojis, different scheme colors, etc." Apparently I am getting old. Other than that system works just fine.

Edited by CloverLeaf
  • Haha 1
10 hours ago, Nightf4ll said:

does -amfipassbeta imply I need the amfipass kext? How come there is a kext now? Doesn-t the -amfi=0x80 work anymore?

 

Read the last section titled AMFI and AMFIPass.kext.

https://www.insanelymac.com/forum/topic/357571-guide-how-to-install-macos-14-sonoma-on-z390-aorus-elite-motherboard-using-opencore/#comment-2811916

 

  • Like 1
7 hours ago, deeveedee said:

 

I hadn't considered that the entire team would be paid and bought by the nation-state.  I like it - I'll change the plot.

 

For those wondering why I've gone off on this crazy tangent, it occurred to me how utterly insane I was for allowing uncertified, 3rd-party software to require that SIP be partially disabled, allow it to root my hack (breaking the macOS "seal"), allow it to install uncertified software at the network layer (for Wi-Fi) and then to trust my hack for anything that requires data privacy, data integrity and protected digital identity.

 

I am typing this on my HackMini8,1 that does not require OCLP.  I will be removing OCLP from my Dell laptop and reverting to High Sierra on that laptop.  I already changed all passwords associated with websites that I visited while using my OCLP-patched Dell laptop.

 

In order for OCLP to be trustworthy for me, it would need one of the following:

  1. The ability to patch graphics and Wi-Fi without breaking the MacOS "seal" (and thus without rooting my hack) and the ability to perform the patches without requiring SIP to be partially or fully disabled - OR -
  2. A certified attestation of the chain of custody of the OCLP software (all of it - the python and the post-install patches) and a certification from a FIPS-certified lab that OCLP and the post-install patches are safe and secure.  This certified chain of custody and lab test would need to accompany each new OCLP version.

Just my personal opinion, but if you are using OCLP, which requires you to partially disable SIP, allow OCLP to break the macOS "seal" and allow OCLP to inject uncertified 3rd-party software into your rooted-Mac or rooted-hack and you continue to do your online banking with your Mac, make stock trades with your Mac, login to your e-mail with your Mac or even something seemingly harmless like login to your FaceBook page, you are placing yourself in grave danger.

Clever thing to do. I, myself dont use OCLP for obvius reasons you already mentioned. But on the other hand, everyone of us has some patched third party app "for educative purposes", and we have no insight what clever guy who patched it made, maybe something by the side for his benefit of any kind.

 

1. Chris1111 did that for Kepler cards, it was mainly ok but we live in time when SIP must be somehow disabled.

 

2. Same stands for me, but this community dont exists on that pro level. I always think that briliant guys who made OCLP, want to trade with Apple not on poor economic level, but on big one. When Apple calculate what serious busines damage they have done with OCLP on approx. two figure percentage sold new or refurbished Macs, they contact them and make them an offer they cant refuse. I am shure of that. Many briliant guys take offer from Apple and live happily ever after.

 

Your opinion is hope for everyone of us. We are all on some level somehow paranoic for our private data goin' in the hands of criminals, but all OCLP associates  who have solid past with software engineering, in my humble opinion is not that kind of people. 

Edited by notobo
  • Like 1
6 hours ago, deeveedee said:

 

I have formulated an attack scenario that I would use to hack an OCLP-patched Mac.  It is a multi-step process that I will not share.

I meet a guy who can hack almost anything, on any level. That made me not scared, but put me on the ground with some safety sw in which people beleive that they are good protection. As I said, when you are on net, you are totaly and absolutely nude to that very small percentage of hackers. 

 

Constantinople wasn't conquered from entrance through the main gate, but from small forbidden door called Kerka Porta. 😀

 

History is everywhere around us. Sory for off thinking. I am film editor and screenwriter, and @deeveedee blow my mind with possible scenario that we are all doomed from the Mykola and friends. 😅

Edited by notobo
  • Like 3
10 minutes ago, notobo said:

History is everywhere around us. Sory for off thinking. I am film editor and screenwriter, and @deeveedee blow my mind with possible scenario that we are all doomed from the Mykola and friends. 😅

 

I will sell you the movie rights to my novel.  I may be convinced to write a sequel for you, too.

  • Haha 2
27 minutes ago, deeveedee said:

 

I will sell you the movie rights to my novel.  I may be convinced to write a sequel for you, too.

🙃 

 

As a comunity m8 you'll lend me, not sell me :lol:

 

I am Mac fanatic for almost 30+ years my friend. Had everything from SE to Mac Pros. First iPhone  was tested in local magazine because I was kind to borrowed them. But this Hackintoshing I call it hobby and  especially this Insanelymac comunity, made me feel alive like the first time I turn on famous Unix machine with Apple logo.

  • Like 1
3 hours ago, eng_redaesm said:

could explaiin please how is your  Rx580 is metal3 supported 

mine ! showing metal2

 

Also @eSaF and @deeveedee

I suspect that, if the iGPU is metal 3 capable but the RX580 is only metal 2, this info about graphics says metal 3 although dGPU is not.

 

If @eSaF runs the attached swift file

/Users/yo > swift /Users/yo/Desktop/main.swift
All credits go to ricoc90
AMD Radeon RX 6600 supports Metal3 
Intel(R) UHD Graphics 630 supports Metal3 

What is the output? Are both GPUs metal 3?

 

main.swift

Edited by miliuco
  • Like 3
23 hours ago, Nightf4ll said:

 

does -amfipassbeta imply I need the amfipass kext? How come there is a kext now? Doesn-t the -amfi=0x80 work anymore?

 

Yes, you need AMFIPass.kext and try both boot-args. One of them args will work, i have 99% sure that your hardware will need -amfipassbeta

Edited by Max.1974
  • Like 1
Guest
This topic is now closed to further replies.
×
×
  • Create New...