Thunderbolt flaw allows a hacker to obtain access to a PC's data within minutes
#1
Information 
Quote:Last month, we saw a team of researchers uncover a security flaw baked into Microsoft Teams that used GIFs to gain access to a user's data. Now, a security researcher, Björn Ruytenberg, has uncovered a vulnerability dubbed 'Thunderspy' in the ubiquitous Intel Thunderbolt port. It allows a hacker with brief physical access to the device the ability to access the target's data.

Although Thunderspy requires physical access to the device itself, it is possible even if the device is locked, encrypted, or set to sleep. Here's a video of Ruytenberg demonstrating the entire procedure in five minutes.
 
Intel has responded to the report by stating that operating systems in 2019, including Windows 10 1803 RS4 and later, Linux kernel 5.x and later, and MacOS 10.12.4 and later, have implemented Kernel Direct Memory Access (DMA) protection to mitigate and prevent these attacks.
Quote:The researchers did not demonstrate successful DMA attacks against systems with these mitigations enabled.
But according to Wired, Kernal DMA has not been universally implemented and is in fact, incompatible with Thunderbolt peripherals made before 2019.
Quote:In their testing, the Eindhoven researchers could find no Dell machines that have the Kernel DMA Protection, including those from 2019 or later, and they were only able to verify that a few HP and Lenovo models from 2019 or later use it.

Read more: https://www.neowin.net/news/thunderbolt-...in-minutes
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply
#2
Additional Info: https://www.ghacks.net/2020/05/11/thunde...ty-issues/
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Privazer 4.0.120.2
Privazer 4.0.120.2...harlan4096 — 07:30
Brave 1.88.138 (Chromium 146.0.7680.178)
Release v1.88.138 ...harlan4096 — 07:28
Opera 129.0.5823.44
Hello! New Oper...harlan4096 — 07:27
Microsoft Edge 146.0.3856.97
Version 146.0.3856...harlan4096 — 07:26
AnyDesk 8.0.2 for Linux
Version 8.0.2 for ...harlan4096 — 07:25

[-]
Birthdays
Today's Birthdays
avatar (48)cticigges
avatar (50)ecoFit
avatar (44)soccejeS
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (46)JamesZic
avatar (43)Sanfordbup
avatar (38)Der.Reisende
avatar (36)Kiran78

[-]
Online Staff
harlan4096's profile harlan4096
Administrator

>