T2 chip: (from Apple site)
“Introducing the Apple T2 chip, our second-generation custom Mac silicon. By
redesigning and integrating several controllers found in other Mac systems — like the system management controller, image signal processor, audio controller, and SSD controller — T2 delivers new capabilities to the Mac. For instance, the T2 image signal processor works with the FaceTime HD camera to enable enhanced tone mapping, improved exposure control, and face detection–based auto exposure and auto white balance. T2 also makes iMac Pro even more secure, thanks to a Secure Enclave coprocessor that provides the foundation for new encrypted storage and secure boot capabilities. The data on your SSD is encrypted using dedicated AES hardware with no effect on the SSD’s performance, while keeping the Intel Xeon processor free for your compute tasks. And secure boot ensures that the lowest levels of software aren’t tampered with and that only operating system software trusted by Apple loads at startup.”
More info:
https://www.macworld.com/article/32...e-imac-pro-the-start-of-a-mac-revolution.html
https://9to5mac.com/2018/01/04/t2-chip-imac-pro/
https://appleinsider.com/articles/1...me-camera-functions-previously-managed-by-cpu
“The T2 encrypts "every bit" of data sent to the flash storage array in the iMac Pro, and is responsible for decrypting it for the user. As a result, should the flash array be pulled from the iMac Pro, the data is irretrievable outside of the unit.
Another feature of the T2 is the boot process. Again on the fly, the T2 validates the boot process from start to finish, including verification of a legitimate and properly cryptographically signed bootloader, before the rest of the process is handed off to the rest of the iMac Pro's hardware for completion.”
https://www.portableone.com/Tech-Ne...y-the-first-of-its-kind-thanks-to-its-T2-chip
“The T2 runs all the subsystems of the iMac Pro, including the cooling system, audio, system management, disk drives, internal microphones, and the FaceTime camera, among other things, all by itself.
Another nice thing about the T2, is that as it handles the hard drives, it automatically encrypts every piece of data that comes in, which would make it impossible for anyone to read the data off the solid-state NAND chips, without authorization from the owner of the iMac. All of this happens also at full speed, which is approximately 3GB per second.
Over the past few years, attempt at infecting Apple Macs with ransomware similar to that which has plagued Windows PCs, have yielded foresight in Apple engineers, to fit the new iMac Pro with what Apple calls “root of trust”. When the iMac starts up, the T2 performs a full range of security checks, to verify the bootloader’s signature, as it moves on with the next stages of the booting process.
Different levels of security can be defined in the Startup Security app, available in recovery mode, which puts the T2 in charge of handling different security settings when using the iMac Pro.
The default setting is set to Full, which allows to run only the current version of Mac OS. Those who want to install older versions of Mac OS, or even Windows 10, can do so by lowering the security settings, in a similar way as they would through the BIOS application of a Windows PC.”
A detail look at T2 and what the future may hold:
https://derflounder.wordpress.com/2...dware-encryption-and-the-future-of-filevault/
Overall picture of where Apple is heading and why it is doing co-processors in their Macs:
https://mashable.com/2018/01/29/apple-3-new-macs-co-processor-launching-2018/#HRUD86S5NkqR