Thunderbolt flaw allows a hacker to obtain access to a PC's data within minutes
#1
Information 
Quote:Last month, we saw a team of researchers uncover a security flaw baked into Microsoft Teams that used GIFs to gain access to a user's data. Now, a security researcher, Björn Ruytenberg, has uncovered a vulnerability dubbed 'Thunderspy' in the ubiquitous Intel Thunderbolt port. It allows a hacker with brief physical access to the device the ability to access the target's data.

Although Thunderspy requires physical access to the device itself, it is possible even if the device is locked, encrypted, or set to sleep. Here's a video of Ruytenberg demonstrating the entire procedure in five minutes.
 
Intel has responded to the report by stating that operating systems in 2019, including Windows 10 1803 RS4 and later, Linux kernel 5.x and later, and MacOS 10.12.4 and later, have implemented Kernel Direct Memory Access (DMA) protection to mitigate and prevent these attacks.
Quote:The researchers did not demonstrate successful DMA attacks against systems with these mitigations enabled.
But according to Wired, Kernal DMA has not been universally implemented and is in fact, incompatible with Thunderbolt peripherals made before 2019.
Quote:In their testing, the Eindhoven researchers could find no Dell machines that have the Kernel DMA Protection, including those from 2019 or later, and they were only able to verify that a few HP and Lenovo models from 2019 or later use it.

Read more: https://www.neowin.net/news/thunderbolt-...in-minutes
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply
#2
Additional Info: https://www.ghacks.net/2020/05/11/thunde...ty-issues/
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.8.0 / 19.8.0 Update
Changes in 19.8.0: ...harlan4096 — 09:32
Mozilla Firefox Browser 152.0
Mozilla Firefox Br...harlan4096 — 08:00
qBittorrent 5.2.2
qBittorrent 5.2.2:...harlan4096 — 07:37
Opera 132.0.5905.73
Hello! We’ve ro...harlan4096 — 07:36
VirtualBox 7.2.10
VirtualBox 7.2.10 ...harlan4096 — 07:35

[-]
Birthdays
Today's Birthdays
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (39)biobdam
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>