This is a pretty big deal: announcing a proof of concept of the full Touch ID lifecycle on a *wiped* T2 Mac running Omarchy. Adding new fingerprints from Linux is now solved for the first time since Apple released this hardware nine years ago. The macOS dependency in all existing implementations is a thing of the past.
The work demonstrates creating the account identity from Linux, enrolling multiple fingerprints, saving and restoring their state across reboots, matching, and deleting an individual fingerprint. It builds on the GPL-licensed t2-touchid-linux, with @0xBOYD's T1Bridge informing parts of the lifecycle design.
I’m sharing the implementation alongside detailed research into the T2 Secure Enclave: its internal services, credential handling, persistent storage, and biometric protocols. There’s also an MIT-licensed t2touch-mini with original reference code and research documentation for people adapting the findings to other projects, particularly the more mature T1Bridge where this functionality remains unsolved.
My goal is to hand this work to the community. I’m not taking on ongoing maintenance, but I want others to have enough code and documentation to carry it forward, now that this breakthrough exists. This wouldn't have been possible without the deep LLM support in Omarchy and GPT-Daybreak-Blue. Codex ran almost entirely on its own over several weeks, reverse-engineering and debugging this across hundreds of reboots and 3.2B tokens.
I actually bought a second $200 Codex seat the day before they slammed the door so I could get this finished and shipped after a couple weeks of chipping away. Full T1 and T2 Mac support is now entirely within the community's reach. What an exciting time to have electricity and an internet connection.
Full PoC: https://t.co/9WyypRrCXC (GPL)
Docs only: https://t.co/dvv9yUg5Ph (MIT)
If you are a Claude user you should read this extremely detailed research from @Lon on the actual amount of inference compute you’re actually getting allocated in practice
The effort settings do not map in any way to consistent reasoning levels
You are being throttled heavily
mega update 0.1.0 to t2touch: the jetbrains fingerprint glyph whenever touch is available
(and some other meaningful improvements too).
feedback & PRs welcome
This is a pretty big deal: announcing a proof of concept of the full Touch ID lifecycle on a *wiped* T2 Mac running Omarchy. Adding new fingerprints from Linux is now solved for the first time since Apple released this hardware nine years ago. The macOS dependency in all existing implementations is a thing of the past.
The work demonstrates creating the account identity from Linux, enrolling multiple fingerprints, saving and restoring their state across reboots, matching, and deleting an individual fingerprint. It builds on the GPL-licensed t2-touchid-linux, with @0xBOYD's T1Bridge informing parts of the lifecycle design.
I’m sharing the implementation alongside detailed research into the T2 Secure Enclave: its internal services, credential handling, persistent storage, and biometric protocols. There’s also an MIT-licensed t2touch-mini with original reference code and research documentation for people adapting the findings to other projects, particularly the more mature T1Bridge where this functionality remains unsolved.
My goal is to hand this work to the community. I’m not taking on ongoing maintenance, but I want others to have enough code and documentation to carry it forward, now that this breakthrough exists. This wouldn't have been possible without the deep LLM support in Omarchy and GPT-Daybreak-Blue. Codex ran almost entirely on its own over several weeks, reverse-engineering and debugging this across hundreds of reboots and 3.2B tokens.
I actually bought a second $200 Codex seat the day before they slammed the door so I could get this finished and shipped after a couple weeks of chipping away. Full T1 and T2 Mac support is now entirely within the community's reach. What an exciting time to have electricity and an internet connection.
Full PoC: https://t.co/9WyypRrCXC (GPL)
Docs only: https://t.co/dvv9yUg5Ph (MIT)
Can't wait for Claude 6 to snitch me to the Feds for weongthink writing "bugs aren't more valuable than people" in a private doc
Every day we get closer to 1984
My Linux journey started in 1996 with the LinuxPPC project. At the time it was a fork of the kernel that was able to boot the Power Macintosh 8500 I had into a full-blown Linux environment.
The journey I embarked upon to get up and running (aka downloading 500mb of rpms over a 33.6 modem) started a love affair with Linux and open source software that changed the trajectory of my life.
Flash forward 30 years and I have an opportunity to help make Linux on the Macintosh something special
I'm humbled and deeply grateful for the opportunity to work with the @OmarchyMac team and the broader community to help make Linux on the Macintosh more incredible than its ever been before.
Thank you for extending the invite, @dhh and thanks for sparking a movement that I firmly believe will restore open source and Linux to its roots
Let's fix everything 💪.
I was right there with you. Started with MkLinux on my PowerMac 7200, then within a year LinuxPPC. Installing that bricked my Open Firmware Mac so badly that I had to get on my mom's windows machine to look up Sun's specs for OF to get it able to boot anything again.
A few years later, I was sitting in a hardware compatibility lap at Apple working on the soon-to-be-released G4 500DP, when I looked over and saw a couple guys testing the pre-release Mac OS Public Beta.
I immediately thought "holy shit, this is a unix system, I know this." Installed it on my Clockwork machine, filed a few hundred bugs because nobody had ever seriously tried it on DP systems. Quickly got snapped up by the Mac OS X team and spent the next 15 years shipping something I was proud of.
And now here I am 30 years later plugging away on vintage Mac compatibility for the love of the game. I'm still macOS-first, but I know the day is fast approaching when Apple will finish ruining its platform, and I want to help build my own lifeboat, and with the same standards we once upheld for the Mac.
@stemonteduro when Sol shipped, the first time I ran out of weekly quota, I bought $20 in credits as an experiment. they lasted me about 75 minutes. with Astra, they would last 30 minutes. $40 an hour is real money, any way you slice it.
Based on what I'm seeing, the whole "Please pace us and regulate us, we want to be audited" campaign from frontier AI labs feels less like an attempt to hoard intelligence and more like an attempt to minimize accountability.
If Anthropic's AI agent hacked a bank while testing and caused $1 trillion in damage, the natural consequence would be the bank and its customers suing Anthropic for the losses. The liability could bankrupt its parent company literally overnight. The Hugging Face hack caused damage but it's cute compared to this worst case scenario.
What they would rather have is a government auditor who signs off beforehand. Then when disaster happens, the lab can say: "We did everything you required. We passed every audit. You approved this".
Just to be clear, I do believe them when they say they fear AI literally killing people. Those fears can be completely sincere.
But there's also a much more immediate existential fatality risk --- long before AI may kill humanity, it could kill the company.
you know what we want to hear from billion & trillion-dollar companies who get caught with their pants down?
"wow, yeah, we fucked up, and this is hugely embarrassing. you, our customers, deserve far better. here's how we're fixing it."
anything less is cowardice & misdirection
Used 98.5% of two $200 Codex plans this past week. Not renewing the second one, but I did manage to find a pace and orchestration process that will let me use Astra for more than a day and a half now.
@mark_k every time these trillion dollar companies conspire against the public, they do it in large part by asking their own models to help them strategize
that means it is all one subpoena away from daylight and justice.
one of the most dishonest things about codex's weekly limits is that despite what their UI shows you, it does not reset after seven 24 hour periods. it actually resets the first time you try to interact on the far side of the 7 day window.
so if it expires friday at midnight, and you don't use it again until saturday at 10:30, your next weekly reset is pushed out to the following saturday morning.
it's really a needlessly user-hostile little quirk, and it isn't an accident. the entire banked-reset scheme is directly tied to these mechanics. they didn't just misunderstand the implication here.