Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 16 submissions in the queue.

Submission Preview

Link to Story

Proof of Concept - Compromise Mac Firmware via Thunderbolt

Accepted submission by Leebert at 2015-01-07 22:14:15
Security
ArsTechnica, among others, is reporting [arstechnica.com] about a proof-of-concept exploit that can compromise the firmware of a Mac with only brief physical access. The exploit, dubbed "Thunderstrike [trmm.net]", works by connecting a malicious Thunderbolt device to the Mac.

Because the exploit can change the RSA public keys in the boot ROM, it can deliver firmware that is all but impossible to replace.

It opens up all sorts of interesting attacks, including snarfing passwords for encrypted hard disks. I'm personally tempted to hang around Starbucks for a while and wait for an aspiring novelist to go to the bathroom or get a drink refill...

Original Submission