Live data from Hacker News

When Lightning Strikes Thrice: Breaking Thunderbolt 3 Security

thunderspy.io

1–10 of 109 posts

Re: When Lightning Strikes Thrice: Breaking Thunderbolt 3 Security

#3
> there is no malicious piece of hardware that the attacker tricks you into using

> All the attacker needs is 5 minutes alone with the computer, a screwdriver, and some easily portable hardware.

Just started reading, but the comparison is already a little bizarre. It almost seems like the digital version of "This murderer is on the loose and you're in danger! He doesn't need to inject poison into your food. All he needs is just 5 minutes in front of you with a knife!"

Re: When Lightning Strikes Thrice: Breaking Thunderbolt 3 Security

#4
post #3

> there is no malicious piece of hardware that the attacker tricks you into using > All the attacker needs is 5 minutes alone with the computer, a screwdriver, and some easily portable hardware. Just started reading, but the comparison is already a little bizarre. It almost seems like the digital version of "This murderer is on the loose and you're in danger! He doesn't need to inject poison into your food. All he ne…

I think that was the point.

Re: When Lightning Strikes Thrice: Breaking Thunderbolt 3 Security

#5
What would it take to have a Thunderbolt/USB C condom? You know, like those standard USB adapter that just drops the data leads on a usb charger to make attacks like this impossible. Maybe we would have to implement a hardware switch on the device itself?

I'm not going to feel safe charging with a public use charger until I find some way to insure only power and not data is making it to my device. Even POE feels like it's safer than modern peripheral standards right now.

(I admit this might not be perfectly linked to the article, it's just a need I've felt for a while but I can't seem to buy a solution for.)

Re: When Lightning Strikes Thrice: Breaking Thunderbolt 3 Security

#7
post #4
post #3

> there is no malicious piece of hardware that the attacker tricks you into using > All the attacker needs is 5 minutes alone with the computer, a screwdriver, and some easily portable hardware. Just started reading, but the comparison is already a little bizarre. It almost seems like the digital version of "This murderer is on the loose and you're in danger! He doesn't need to inject poison into your food. All he ne…

I think that was the point.

Then I guess the comparison didn't help, but what I'm trying to say is, hidden threats are harder to protect against, not easier. Telling me I need to watch out for a threat because it's visible doesn't make any sense. You tell people to be more on alert for hidden threats, not for obvious ones.

Re: When Lightning Strikes Thrice: Breaking Thunderbolt 3 Security

#9

Really though, if an attacker has unencumbered access to one’s device, all security goes flying out the window. The website is highly self-promoting.

As another commenter pointed out, public charging or borrowed chargers are an issue. Think airport charging kiosks/counters. Maybe power over data connectors isn’t the best idea (I enjoy single cable docking, but an extra, magnetic power cable wasn’t that much more work).

Re: When Lightning Strikes Thrice: Breaking Thunderbolt 3 Security

#10
I skimmed the paper and while the research looks solid, just in terms of the digging they did and the documentation they're providing, this website really buries its lede: if you've got a Macbook running macOS, the Macbook IOMMU breaks the DMA attack, which is the thing you're actually worried about here.

Additionally, regardless of the OS you run, Macbooks aren't affected by the Security Level/SPI flash hacks they came up with to disable Thunderbolt security.

Post reply on HN