4 ms·
If an attacker has physical access long enough to connect a MITM on your fingerprint reader, it's not your laptop anymore.
by arjvik 3y ago
If an attacker has physical access long enough to connect a MITM on your fingerprint reader, it's not your laptop anymore.
- blowski 3y agoThis line of thinking can and is used as an excuse for all sorts of security shortcomings. Yes, in threat modelling, this would be give fairly limited opportunity as an attack vector, but any successful attack could have a massive impact. It makes sense for device owners to consider this possibility in how they protect their machines, and for device manufacturers to attempt to mitigate it.
- offices 3y agoNo, this line of thinking is basic threat modelling and stops us wasting time and effort on navel gazing when it would be better spent on things we can control. An invasive, non-destructive physical attacker also has access to (likely unencrypted) drives, memory buses, HIDs, audiovisual inputs... 'Fixing' this doesn't make your machine any less pwned if you let them touch it.
- blowski 3y agoThe linked article says it's not a problem with all implementations. This would suggest device manufacturers can defend against it, but some have chosen not to. Given the choice of a laptop where this risk is mitigated and one where it isn't, all other things being equal, I'd choose the one with protections in place.
- NoLsAfterMid 3y agoOk, but none of modern computing was designed around this mentality. Virtually all computers are trivially compromisable if you have physical access to the machine.
- quenix 3y agoThis doesn't appear as true for the latest Apple Silicon macs. They are quite locked down by default
- NoLsAfterMid 3y ago[dead]
- tinus_hn 3y agoThat is not what this attack does. You steal the laptop and then do a trick to unlock the secrets without giving back the laptop. Your MITM is fooling the fingerprint reader and the OS, not the user. The point of the system is to protect against an attacker who steals the laptop so it is a complete failure.