Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Because the computer is locked?


There have been successful attacks on locked macs via the thunderbolt port.

I'm thinking of one in particular which I can't find at the moment, but I remember seeing a really fantastic video where one guy described in detail how he reverse engineered the mac thunderbolt interface and was able to flash malware bootcode on to it even when locked. Once that malware was installed, it could do pretty much anything, including get encryption keys to your hard drive, intercept all keystrokes, etc.

If anyone has a link to that, please post it here.

Also, there this:

https://news.ycombinator.com/item?id=7123121


If they don't have full disk encryption, booting a mac holding command and R will get you into recovery mode where you can change the root password, or change the boot device to something that simply doesn't care about the login permisions. Pretty much any machine without full disk encryption at rest is vulnerable when you have physical access. And if they do, you can still probably do a lot of damage, without Bumping into someone at lunch with their laptop.

Not saying it's not a real vector, but it's hardly one that would keep me up at night.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: