3 ms·
I often come to the comment section looking for a summary of a dense article like this. Didn't find it, so here is my best shot at one: Through the thunderbolt
by goo 12y ago
I often come to the comment section looking for a summary of a dense article like this. Didn't find it, so here is my best shot at one:
Through the thunderbolt port, an attacker can put code that controls the firmware updates onto a mac. This cannot be removed by software, and could do all sorts of nasty stuff.
Anyone with physical access to the computer and a weaponized version of this exploit could do this. This includes intercepting hardware en-route to its recipients, spending a few minutes with a laptop while its owners are away, or while crossing international borders.
According to the author, this exploit works with every Mac with a thunderbolt port that they tested. Apple has a partial fix coming as a firmware update soon, but the author expresses concern that the proposed fix could still be bypassed.
- spacefight 12y ago+1 for using the term "weaponize".
- lloeki 12y agoI seem to recall that FireWire ports were disabled in some way when the system was locked (tip: show Keychain Access icon in menubar to have a manual lock at a click's distance) and that such attacks therefore required the computer to be unlocked. Did I dream about that feature, and is that applicable to Thunderbolt?
- danesparza 12y agoIn-lining this exploit in a bit of cable would be fairly trivial. This is a nasty one.
- errata 12y agoJust note that the 2014 iMac Retina and Mac mini are (at least paritally) not longer vulnerable to this.