For the whole of Mac OS X until Mojave, the system booted from its firmware into a single boot volume, containing a fairly traditional mixture of system and user files. As with most boot volumes, this made it difficult to protect system files that shouldn’t change between macOS updates, and to detect whether changes have occurred in them, whether by corruption or maliciously. Apple introduced System Integrity Protection (SIP) in 2015 (El Capitan) to try to address the first of those, but it has limited effectiveness and can’t detect changes at all.

When designing the architecture to be used in Apple silicon Macs, Apple decided that they should have a secure boot process, in which each stage hands over to code that has already been verified as intact and correct. This chain of verification starts in the Boot ROM, which verifies the next stage, the Low-Level Bootloader (LLB), before loading it, and that then proceeds to iBoot, which has the task of verifying the System.

For the smaller chunks of code and data that compose each part of the boot process before the kernel, it’s efficient to compute a hash of its code and compare that against what it should be, but that isn’t a good approach to verifying the 9 GB or so required for the system itself. To handle that, Apple chose to build a tree of hashes instead. Out at its leaves are individual files in the system, each hashed in a group to provide a set of intermediate hashes. Those in turn are hashed in groups, until at the top of the tree is a master hash of the hashes below it. That master hash is known as the seal, and is hashed again to produce a key for the whole system, its signature.

Read more at eclecticlight.co

Leave a Reply

Discover more from

Subscribe now to keep reading and get access to the full archive.

Continue reading