Author Topic: Additional info on external booting  (Read 626 times)

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
Additional info on external booting
« on: November 10, 2018, 10:58:33 AM »
If you have a new Mac, one that includes the T2 chip, you will have a default setting that may prevent you from booting from an external drive. I think that chip is in the new Mac mini, and MacBook Pro. There will be others as the new models are released. The purpose of the T2 chip is to lock down you Mac even more from malware and hardware hacks.

Many have complained that they cannot boot into Linux on their new Macs. While reading the discussion at TidBITS, I came across info of the Startup Security Utility. There is a section on that window that shows a setting that is normally set that may be causing problems when trying to boot from an external drive.

So far, the only way I have found to access this utility is through a Recovery restart. There, you will find the "Utilities" menu and under that will be the "Startup Security Utilities" item.

If you don't have the T2 chip, all you will probably see is an option to set a hardware password which you will see before the normal log in screen. That is usually off by default.

If you do have the T2 chip, you will see a much different Startup Security Utilities window. That is where you will find the settings shown in the attached image. The settings shown in that image will have the "External Boot" set to "Disallow..." by default! That is fine, except you may not have been aware of that.

In my humble opinion, the language says that you can not boot from an external drive no matter what OS might be on it. While it does not explicitly say that, that's the way I interpret it, but I've only been speaking English for ~74 years. I hav ben rong beefour, houevr!

All I am saying is that we may have to start asking if a questioner has a T2 machine or if they are unable to boot from an external drive that they think they should be able to. Just another detail that can cause inconveniences when trouble-shooting problems...
« Last Edit: November 10, 2018, 11:06:57 AM by Xairbusdriver »
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes:

Offline jchuzi

  • TS Addict
  • *****
  • Posts: 3094
    • View Profile
Re: Additional info on external booting
« Reply #1 on: November 10, 2018, 03:14:10 PM »
This doesn't seem very secure to me. A knowledgeable rogue would probably be aware of this trick, boot into Recovery, and then do whatever he/she wants. Unless, of course, you have set a firmware password.
Jon

macOS 11.7.10, iMac Retina 5K 27-inch, late 2014, 3.5 GHz Intel Core i5, 1 TB fusion drive, 16 GB RAM, Epson SureColor P700, Photoshop CC, Lightroom CC, MS Office 365

Offline Xairbusdriver

  • Administrator
  • TS Addict
  • *****
  • Posts: 26388
  • 27" iMac (mid-17), Big Sur, Mac mini, Catalina
    • View Profile
    • Mid-South Weather
Re: Additional info on external booting
« Reply #2 on: November 10, 2018, 04:32:38 PM »
Correct, but since booting into Recovery doesn't require a password, all bets are off if/when you lose possession of the Mac for any longer period of time. My only concern is when we might be dealing with someone asking for help, we recommend booting from a clone and that fails; did it fail because 1. the external drive or clone is bad or 2. the default settings are blocking any external booting? :wallbash: Not a problem right now, most machines with this hardware are probably less than a few months old! ;) By the time they need an external boot, I will have forgot about this setting! :rolleyes:
THERE ARE TWO TYPES OF COUNTRIES
Those that use metric = #1 Measurement system
And the United States = The Banana system
CAUTION! Childhood vaccinations cause adults! :yes: