Thunderbolt ports may put your PC in jeopardy, but only if you leave it alone with a capable and well-prepared hacker.
That's according to security researcher Björn Ruytenberg from the Eindhoven University of Technology, who outlined seven vulnerabilities in Thunderbolt, collectively called Thunderspy, in a recent paper (via Wired). The vulnerabilities are serious — a hacker who knows what they are doing could gain full access to data on a laptop that's locked and encrypted.
Laptops made before 2019 with Thunderbolt ports running Windows and Linux are vulnerable. Macs built before 2019 are a little safer, as an attacker would have to use another attack in conjunction with Thunderspy to gain access. The researcher claims the bugs cannot be fixed via a software update.
Pulling off the attack isn't easy, though. The hacker needs physical access to the machine, so they can unscrew it and attach a device to it (see Ruytenberg's video below).
Thunderbolt is a practical hardware interface as it allows for high-speed data transfer as well as charging, and it's compatible with USB-C. It was first introduced on Apple's MacBook Pro in 2011.
Thunderbolt is Intel's standard, and the company issued a response Sunday, claiming that a new security scheme called Kernel Direct Memory Access (DMA) has been implemented since 2019, protecting from these types of attacks. In his paper, Ruytenberg says that "systems supporting Kernel DMA Protection in place of Security Levels, released from 2019 onward, are currently subject to further investigation."
SEE ALSO: Apple launches 13-inch MacBook Pro with Magic Keyboard, new processorThunderbolt came under scrutiny in 2019, when security experts outlined a number of security vulnerabilities under the collective name Thunderclap, which also allow attackers with physical access to a PC to compromise its security. It's worth noting that Microsoft's recently launched Surface devices do not support Thunderbolt, allegedly due to security concerns.
Copyright © 2023 Powered by
Thunderbolt bugs can expose a PC if you leave it alone with a hacker-坐而论道网
sitemap
文章
6
浏览
68661
获赞
64
5 things I noticed during my 24 hours with the Apple Watch Series 6
Given my very brief time with the Apple Watch Series 6, I’m a little hesitant to fully deliverIranian spies allegedly used Facebook to target U.S. intelligence agents
It was just a simple friend request. However, nothing is ever simple when the U.S. intelligence commAn underage woman paid by R. Kelly to remain silent about sexual relationship speaks out
A report from BuzzFeedfinds R. Kelly paid off an underage woman in exchange for silence about theirQualcomm is building 5G into chipsets and PCs
BARCELONA—Qualcomm is taking the next step into 5G, promising 5G-enabled Windows laptops and tUse the new 'Close Friends' sticker for Instagram stories to prank followers
Now you can convince anyone they're on your Close Friends list. When Instagram released its Close FrJoanna Newsom and Andy Samberg welcome their first child
New to the parenthood scene: Harpist Joanna Newsom and her husband Andy Samberg recently welcomed thSonic the Hedgehog is now a symbol of the anti
Sonic, SEGA's iconic and adorable racing videogame hedgehog -- who even has a protein named after hiApple updates 21.5 and 27
New iMacs are finally here.Nearly two years since their last update, Apple's finally beefing up itsThe Vatican was reportedly hacked by China
Sounds kind of like the plot of Mission Impossible IIIor a Dan Brown book.Hackers with links to theFake news sites are simply changing their domain name to get around Facebook fact
Facebook has been cracking down on the fake news that gets shared on its platform. One problem: oneXbox One consoles are down (Update: they're back)
UPDATE: Jan. 30, 2019, 3:25 p.m. EST The official Xbox Support Twitter account announced that the prPoor pup, like all of us, is terrified of a giant spider
Once a spider has entered your home, there's no sleeping until it's gone. Even if it takes days to gApple's next iPad Pro to have mini
We've been hearing about Apple implementing a mini-LED display into its products for years now, butGeneral Kelly's face had its own press conference yesterday
General John Kelly, a man whose own face appears to have been chiseled out of bedrock, isn't exactlySamsung to build two more foldable phones, report says
Samsung Galaxy Fold is not the only foldable phone coming from the Korean giant's workshop. Accordin