Thunderbolt-DMA-land: Hacking Macs through the Thunderbolt interface
1–10 of 25 posts
Re: Thunderbolt-DMA-land: Hacking Macs through the Thunderbolt interface
#2I am shocked, shocked, good sir!
Re: Thunderbolt-DMA-land: Hacking Macs through the Thunderbolt interface
#3You mean with someone with physical access to my machine can trivially bypass software security measures? I am shocked, shocked , good sir!
Physical access is relative. 'Remote' vulns are still exploited with some level of physical access: i.e. via a network that lets you touch bits on the other side of the machine's ethernet jack / wireless card.
The other extreme is standing over the ripped carcass of the machine case, triumphantly raising an unencrypted hard disk over your head, and blowing a kiss to the receptionist on your way out through the main lobby.
The OP's attack can be staged multiple hops away, through a physical network of peripheral devices. In a heavy SAN or PPPoFW environment, where FW cables are regularly disappearing under desks, a somewhat-insider could dump a lot of RAM.
RAM which, for some goddamned reason on OS X, apparently contains an unencrypted copy of my login password?! Ouch.
Re: Thunderbolt-DMA-land: Hacking Macs through the Thunderbolt interface
#4You mean with someone with physical access to my machine can trivially bypass software security measures? I am shocked, shocked , good sir!
This attack is hot precisely bc it blurs the local/remote line. Physical access is relative. 'Remote' vulns are still exploited with some level of physical access: i.e. via a network that lets you touch bits on the other side of the machine's ethernet jack / wireless card. The other extreme is standing over the ripped carcass of the machine case, triumphantly raising an unencrypted hard disk over your head, and blowi…
Really? Most software does that, most crypto software and encryption algorithms are vulnerable to RAM attacks. It's not as easy to protect against that as you think it is.
Re: Thunderbolt-DMA-land: Hacking Macs through the Thunderbolt interface
#5Re: Thunderbolt-DMA-land: Hacking Macs through the Thunderbolt interface
#6Feel free to remove the FW driver from the OS.
Re: Thunderbolt-DMA-land: Hacking Macs through the Thunderbolt interface
#7You mean with someone with physical access to my machine can trivially bypass software security measures? I am shocked, shocked , good sir!
If this was VGA or DVI, you have no reason to be suspicious. But with Thunderbolt, you can never be sure anymore.
Re: Thunderbolt-DMA-land: Hacking Macs through the Thunderbolt interface
#8Re: Thunderbolt-DMA-land: Hacking Macs through the Thunderbolt interface
#9You mean with someone with physical access to my machine can trivially bypass software security measures? I am shocked, shocked , good sir!
This attack is hot precisely bc it blurs the local/remote line. Physical access is relative. 'Remote' vulns are still exploited with some level of physical access: i.e. via a network that lets you touch bits on the other side of the machine's ethernet jack / wireless card. The other extreme is standing over the ripped carcass of the machine case, triumphantly raising an unencrypted hard disk over your head, and blowi…
Did I mention that Thunderbolt daisychains, so compromising a Thunderbolt monitor (or better still, projector) is a simple matter of plugging an attack machine into the Daisy-chain out port.
Who really worries about plugging their laptop into a projector?